Featured image of post Cybersecurity Week in Review: August 18–24, 2026

Cybersecurity Week in Review: August 18–24, 2026

Cyberattacks, data breaches, zero-days, and global responses—discover the biggest cybersecurity headlines of this week.


Major Data Breaches

CareCloud Healthcare Data Breach

Healthcare technology giant CareCloud confirmed a data breach impacting over 3.75 million patients. The breach exposed sensitive medical records, Social Security numbers, and bank details. The incident, first flagged in March, was officially disclosed this week, marking one of the largest healthcare data incidents of the year. The breach originated from unauthorized access to CareCloud’s cloud systems, and the company has since notified federal regulators and affected individuals. The scale and sensitivity of the exposed data highlight ongoing risks in healthcare IT and the critical need for robust cloud security controls1.

Apollo Global Management Breach

Private equity giant Apollo Global Management confirmed a breach in which hackers accessed personal information from its cloud systems. Names, dates of birth, contact information, home addresses, and Social Security numbers were among the data stolen. The breach is part of a broader wave targeting financial and private equity giants, raising concerns about the security of cloud-based financial data1.

French Tax Authority Data Breach

Hackers compromised credentials to access enterprise and personal tax-related data from the French tax authority, impacting 680,000 individuals. The breach underscores the persistent risk to critical government services and the importance of strong multi-factor authentication and credential hygiene. The incident has prompted calls for enhanced monitoring and proactive credential protections2.


Significant Cyberattacks

ReliaQuest and ShinyHunters

The ShinyHunters group claimed a breach of US-based cybersecurity firm ReliaQuest, listing the company as a victim on its leak site. ReliaQuest responded that only one employee identity was compromised before defenses stopped the attack. This incident highlights the ongoing threat posed by social engineering and the importance of rapid detection and response1.

AI-Powered Attacks on Siemens PLCs

US government agencies warned of active, AI-powered attacks targeting Siemens S7 Series programmable logic controllers (PLCs) used in critical infrastructure sectors. Threat actors are leveraging AI-generated scripts to exploit internet-exposed PLCs, potentially causing disruption of industrial processes, safety incidents, and equipment damage. The attackers use legitimate scanning services to identify vulnerable systems and deploy scripts masquerading as monitoring tools. The agencies emphasized the need for improved segmentation and monitoring of industrial control systems3.

WordPress Crime Ring

Check Point Research uncovered a global cybercrime ring operating through a network of 2,000 compromised WordPress sites. The operation, dubbed “StopAndProtect,” involved 5,000 infected computers and exploited vulnerabilities in WordPress plugins to run malicious campaigns. This highlights the widespread risk posed by vulnerable CMS platforms and the need for continuous patching and monitoring1.


Critical Vulnerabilities

GitLab CE/EE Remote Project Deletion (CVE-2026-19478)

A critical vulnerability in GitLab CE/EE (CVE-2026-19478, CVSS 9.4) allows unauthenticated attackers to delete public projects and modify data. The flaw was actively exploited within days of disclosure, prompting urgent patching of all internet-exposed GitLab instances. The vulnerability underscores the importance of rapid response to newly disclosed flaws in widely used development platforms23.

WordPress Forminator Forms RCE (CVE-2026-15748)

A remote code execution vulnerability in WordPress Forminator Forms (CVE-2026-15748) enables unauthenticated attackers to upload malicious PHP scripts. All WordPress sites running Forminator Forms are advised to patch immediately and audit for signs of compromise23.

VMware vCenter Directory Traversal (CVE-2026-59310)

A severe directory traversal vulnerability in VMware vCenter (CVE-2026-59310, CVSS 9.8) was exploited by a suspected China-nexus APT group, deploying Babuk-derived ransomware. The rapid exploitation following patch disclosure demonstrates the critical need for timely updates in virtualized infrastructure2.

Microsoft Copilot Personal (CVE-2026-24301)

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch. The most severe, CVE-2026-24301, allows a single click on a crafted link to silently exfiltrate data from connected apps. Microsoft released patches on August 18, 2026. The vulnerabilities highlight risks in AI-powered assistants and the importance of reviewing connected app permissions4.

Unisoc VoLTE Video Call Exploit Chain

Security researchers published a two-stage exploit chain affecting Android devices running Unisoc modem firmware. The chain enables full kernel access via a crafted VoLTE video call, with no patch available from the vendor. Organizations with Unisoc-powered devices are advised to restrict VoLTE calls and monitor for anomalous activity23.


Government Responses

CISA Ray RCE Advisory (CVE-2025-62593)

CISA issued an urgent advisory for federal agencies to patch a critical remote code execution vulnerability in Ray, an open-source framework for scaling Python and machine-learning workloads. The bug, tracked as CVE-2025-62593 (CVSS 9.4), is actively exploited and allows attackers to achieve RCE via Firefox or Safari. Agencies were given three days to remediate1.

FBI Warning: Gunra Ransomware Exploiting Fortinet Flaws

The FBI warned that Gunra ransomware operators are actively exploiting vulnerabilities in Fortinet products. Organizations using Fortinet are urged to patch immediately and review their security posture5.


Miscellaneous

Zombie Card Attack on Expired Visa Cards

Academic researchers demonstrated a “Zombie Card” attack that bypasses cryptographic checks to complete contactless payments using expired Visa credit cards. The attack leverages a smartphone relay setup to alter the expiration date fed to the point-of-sale terminal. While there is no evidence of exploitation in the wild, the findings highlight weaknesses in payment terminal security3.

Cloudflare Workers Spectre Attack

A remote Spectre attack against Cloudflare Workers was found to leak JSON Web Tokens (JWTs) from co-located Workers in production environments. The attack achieves a leak rate of up to 12 bits per second, significantly faster than previous demonstrations. Cloudflare is reviewing mitigations3.


Conclusion

This week’s cybersecurity landscape was marked by large-scale data breaches in healthcare and finance, rapid exploitation of critical vulnerabilities, and new attack methodologies leveraging AI and supply chain weaknesses. Government agencies responded with urgent advisories, and researchers highlighted emerging risks in payment systems and cloud infrastructure. The speed and sophistication of attacks underscore the need for continuous vigilance, rapid patching, and robust security controls across all sectors.


Sources: