By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Top 10 Cybersecurity News (August 17, 2026): Jewelbug APT Runs Espionage and Crypto Fraud in Parallel, Iran-Linked Hackers Hit New Jersey, Alabama Water Utilities, and More

WEEKLY TOP TEN: August 17, 2026, 16:00 GMT

  1. Iran-Linked Hackers Hit New Jersey, Alabama Water Utilities

    Iran-linked hackers expanded their targeting of US water infrastructure to New Jersey and Alabama, bringing the confirmed count of affected states to at least 12 since late July. The City of Cape May Sewer Department and the Borough of Woodbine Water Department in New Jersey both reported near-simultaneous attacks on July 27 that disrupted operations for roughly 12 hours, though water quality was not affected. In Alabama, the Childersburg Water, Sewer and Gas Board confirmed its industrial control network was targeted the same day, prompting officials to temporarily disconnect systems. Neither state reported compromised customer data. The attacks are linked to Iranian threat actors targeting programmable logic controllers made by Rockwell Automation and other major vendors.
  2. Global Campaign Hits Critical VMware vCenter Flaw

    A single threat actor launched a global exploitation campaign against a critical VMware vCenter directory traversal vulnerability, CVE-2026-59310, just days after the flaw’s public disclosure on July 29. Researchers traced attack activity to 361 unique IP addresses across 47 countries, with the US, France, Iran, and Turkey among the most heavily targeted. The attacker is establishing persistence using reverse_ssh, an open-source penetration testing tool that creates outbound control channels from compromised systems, meaning that patching the underlying flaw alone may not fully remove attacker access. Security researchers urged organizations to treat vCenter and similar control planes as untrusted zones, isolating management interfaces and restricting outbound connectivity to prevent reverse-shell persistence.
  3. Belgium’s eID System Exposed Citizens to Remote Code Execution

    Researcher James Arnott disclosed critical vulnerabilities in Connective, the signing system underlying Belgium’s national eID authentication framework, that could have let attackers steal citizens’ identities, hijack payment cards, and achieve remote code execution on victims’ computers. The flaws stemmed from a browser extension that failed to properly validate messages, allowing malicious websites to command the extension to perform actions on a victim’s behalf across authenticated sessions. The vulnerabilities were fixed on July 22, before the DEF CON 34 disclosure, but the case highlights broader risks in browser-extension-based authentication used across government and banking portals. Security researchers said the flaw class is increasingly common and, in some cases, more severe than typical remote code execution because it can compromise every authenticated session in a victim’s browser at once.
  4. Microsoft Patches 421 Flaws, One Exploited Zero-Day

    Microsoft’s August 2026 Patch Tuesday addressed 421 CVEs, including an actively exploited elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), tracked as CVE-2026-68820. The update also fixed two publicly disclosed zero-days affecting the User Profile Service and the Container Isolation FS Filter Driver. Of the total, 42 flaws were rated Critical, with the bulk of fixes touching Windows, Office, and SharePoint Server. Microsoft said threat actors have been exploiting the AFD.sys bug to gain SYSTEM-level privileges, prompting urgent prioritization across enterprise fleets. Security teams were advised to patch the exploited driver first, then move to internet-facing remote code execution flaws in DNS Server, RRAS, and Deployment Services before addressing the remaining Important-rated bugs.
  5. Researcher Releases Microsoft Defender Zero-Day Exploit

    ecurity researcher Nightmare Eclipse released a new Microsoft Defender zero-day exploit, dubbed “ShieldBreak,” that grants SYSTEM-level privileges shortly after Microsoft shipped its August 2026 Patch Tuesday updates. The disclosure follows a pattern from the same researcher, who previously released the RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma Defender flaws in prior months. Microsoft confirmed it is investigating the claims and reiterated its support for coordinated vulnerability disclosure, but as of publication no official patch for ShieldBreak had been issued. Organizations running Microsoft Defender should monitor vendor guidance closely and consider compensating controls until a fix becomes available, given the researcher’s track record of disclosing exploitable Defender flaws immediately after Patch Tuesday.
  6. CISA Adds Cisco, Microsoft, Metabase Bugs to KEV List

    CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: a heap-inspection flaw in Cisco Secure Firewall ASA and Firewall Threat Defense (CVE-2026-20349), the Windows AFD.sys privilege-escalation bug (CVE-2026-68820), and a SQL injection vulnerability in the Metabase business intelligence platform (CVE-2026-72898). The three span distinct risk categories: an edge-device compromise path, a post-exploitation Windows privilege-escalation bug, and an application-and-data-access issue in Metabase that could expose connected databases and credentials. Federal civilian agencies must remediate under Binding Operational Directive 26-04, and CISA is urging all organizations to treat the additions as high-priority patching targets given their frequent use as initial-access and escalation vectors.
  7. Metabase SQL Zero-Day Could Have Wide Blast Radius

    A SQL injection zero-day in the open-source Metabase business intelligence platform is drawing scrutiny for its potential to expose sensitive backend databases across a large number of organizations. Metabase is widely deployed for internal analytics and dashboards, often with direct connections to production databases containing customer and financial data, making successful exploitation especially damaging. CISA has since confirmed active exploitation and added the flaw to its Known Exploited Vulnerabilities catalog. Security researchers noted that the blast radius extends beyond Metabase itself to any database the platform is configured to query, meaning a single compromised instance can expose far more than analytics data. Organizations running Metabase should isolate instances from sensitive production data stores and apply vendor patches immediately.
  8. Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

    A joint law enforcement advisory warned that the Gunra ransomware gang is exploiting known Fortinet vulnerabilities for initial access, circumventing multifactor authentication protections that organizations rely on to stop ransomware intrusions. The FBI observed Gunra actors using CVE-2024-55591, a critical FortiOS and FortiProxy authentication bypass flaw that grants “super admin” privileges on Fortinet appliances. Gunra, which began by targeting Windows environments before developing a Linux variant, has expanded into a structured ransomware-as-a-service affiliate program advertised on dark web forums since early 2026. The group’s reliance on N-day vulnerabilities in firewall and VPN appliances highlights the ongoing risk unpatched edge devices pose to organizations of every size.
  9. Jewelbug APT Runs Espionage and Crypto Fraud in Parallel

    Symantec researchers exposed Jewelbug, a China-based hackers-for-hire group that runs government espionage campaigns and a for-profit cryptocurrency fraud business from the same command-and-control infrastructure. The group, also tracked as Earth Alux, REF7707, and CL-STA-0049, compromised government, military, and telecommunications targets across the Middle East, Southeast Asia, and South Asia while simultaneously operating hundreds of fake cryptocurrency exchange sites aimed at Chinese-speaking victims. Investigators found more than one million implant check-ins, 580,000 stolen browser cookies, and thousands of harvested credentials tied to the group’s central “XG-Web” control panel. Jewelbug’s commercial arm is linked to a registered company in China’s Hunan Province, illustrating the blurred line between state-directed and financially motivated cyber operations.
  10. Storm-1175 Swaps Medusa for New StormEncryptor Ransomware

    Microsoft warned that Storm-1175, a China-linked, financially motivated threat group previously associated with Medusa ransomware, has begun deploying a new strain called StormEncryptor. Written in C++, the new ransomware encrypts files with a “.encrypted” extension and drops a ransom note in every scanned directory. Microsoft said the group is likely exploiting the N-able N-central authentication bypass vulnerability, CVE-2026-18577, which was disclosed August 2 and added to CISA’s Known Exploited Vulnerabilities catalog the following day. The shift to a new, purpose-built encryptor suggests Storm-1175 is investing in its own tooling rather than relying solely on affiliate ransomware programs, a trend that could make attribution and decryption support more difficult for defenders going forward.

Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.

Previous Post

Women Technology Leaders Are Already Flying. The Enterprise Is Still Building the Runway.

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.