Why Should I Care? โ 2026-08-18 | ๐ด 1 HIGH ยท ๐ก 0 MEDIUM ยท ๐ต 33 RADAR ยท โช 236 FILTERED
๐ Briefing โ 2026-08-18
34 vendor intel items scanned | ๐ด 1 HIGH | ๐ก 0 MEDIUM | ๐ต 33 RADAR | โช 236 FILTERED
๐ด Critical โ action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2025-62593) โ Yes, if you run Ray-Project Ray versions 1.12.0 - 1.14.3: code injection vulnerability, actively exploited in the wild.
Everything else can wait.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2025-62593
โ Why Should I Care?
Yes, if you run Ray-Project Ray versions 1.12.0 - 1.14.3: code injection vulnerability, actively exploited in the wild. Patch now.
๐ฏ Affected versions: Ray-Project Ray 1.12.0 - 1.14.3
Not affected: 1.15.0 and later
๐ญ In plain English:
An attacker can inject and execute arbitrary code in your Ray-Project Ray environment, taking full control of your system. For example, an attacker could remotely install malware, steal sensitive data, or disrupt your services without your knowledge.
๐ง Prerequisites:
- Running Ray-Project Ray versions 1.12.0 - 1.14.3
- Network access to the vulnerable service
โฑ Urgency: High urgency due to active exploitation in the wild.
๐ก Context: The vulnerability arises from insufficient input validation, allowing attackers to inject and execute arbitrary code.
โ Fixed in: 1.15.0, 1.15.1
Why Should I Care? ๐ก MEDIUM (0)
None.
Why Should I Care? ๐ต On the Radar (33)
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects (The Hacker News) โ A critical flaw in GitLab allows attackers to delete or modify public projects and user data without authentication. This affects self-managed installations of GitLab Community Edition (CE) and Enterprise Edition (EE).
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads (The Hacker News) โ A severe security flaw in the Forminator Forms WordPress plugin allows attackers to upload and execute malicious PHP files, leading to full site compromise. This affects over 600,000 installations.
- Hacker claims 3.6 million Azure account records stolen from major companies (BleepingComputer) โ A hacker claims to have stolen 3.6 million Azure account records from major companies, including McDonald's, Gap Inc., and Vodafone. The stolen data includes employee names, email addresses, job titles, and phone numbers. This highlights the risks of compromised credentials and the importance of robust security measures.
- Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access (The Hacker News) โ Security researchers have found a way to exploit Unisoc chipsets through VoLTE video calls, allowing attackers to gain full access to the Android kernel. This can affect devices from brands like Motorola, Realme, and Xiaomi.
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE (The Hacker News) โ A critical vulnerability in GeoServer allows attackers to inject SQL commands and potentially execute code remotely. This affects any organization using GeoServer for geospatial data management.
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner (The Hacker News) โ A critical flaw in macOS Screen Sharing allowed attackers to install Monero miners on exposed Macs. Apple has patched the issue, but it's important to ensure all systems are updated to prevent unauthorized access.
- SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch (The Hacker News) โ A critical vulnerability in SAP Commerce Cloud is being actively exploited. Unpatched systems can be compromised by attackers who can execute arbitrary code and gain unauthorized access.
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware (The Hacker News) โ A severe vulnerability in VMware vCenter (CVE-2026-59310) has been exploited by a suspected China-nexus APT group to deploy ransomware. This means that if your infrastructure uses VMware vCenter, you are at risk of unauthorized access and potential ransomware attacks.
- French tax authority data breach affects 678,000 individuals (BleepingComputer) โ A data breach at the French tax authority exposed sensitive data for 678,000 individuals. This could impact any organization with French operations or data, as it may lead to increased scrutiny and compliance requirements.
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection (The Hacker News) โ A security flaw in Snowflake's GitHub Actions workflow allowed attackers to inject commands through crafted GitHub issues, potentially exposing internal Jira credentials. This means that if you're using similar workflows, your internal credentials could be at risk.
- How MCP Servers Can Expose Enterprise Secrets (The Hacker News) โ MCP servers can expose sensitive enterprise data through insecure configurations and permissions, potentially allowing attackers to access critical systems and data. For example, if your MCP server stores API tokens in plaintext files, an attacker could easily access these files and use the tokens to perform unauthorized actions.
- Windows Server 2022 reaches end of mainstream support in 60 days (BleepingComputer) โ Windows Server 2022 is nearing the end of its mainstream support period, transitioning to extended support in October 2026. This means fewer updates and support options, so you should consider upgrading to Windows Server 2025 to stay within mainstream support.
- Certighost and the Privilege Hiding in Your Certificate Authority (BleepingComputer) โ A flaw (CVE-2026-54121) allows standard domain users to trick the Enterprise Certificate Authority into issuing a certificate that grants Domain Controller privileges, leading to full domain compromise. This means any standard user could potentially take control of your domain infrastructure.
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud (The Hacker News) โ A China-linked hacker group, Jewelbug, is using sophisticated tools to spy on governments and militaries, and commit cryptocurrency fraud. They use a browser-based tool called XG-Web to control victims' computers and steal information.
- CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps (The Hacker News) โ A phishing campaign is targeting marketing professionals with fake recruitment pages to steal Google and Facebook credentials, including MFA codes. This could lead to unauthorized access to business-critical services like advertising platforms and corporate social media.
โช 236 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 9 vendor feeds | CISA KEV