Tuesday, August 11, 2026
Daily digest
Critical infrastructure is under sustained pressure today: US/South Korea issued a joint warning on Gunra ransomware hitting government and OT networks via Fortinet/Schneider flaws, while new details emerged on a second, previously hidden cyberattack against a Polish heat plant that reached turbine controls via a private cellular network.
CISA confirms SharePoint RCE flaw now being exploited in ransomware attacks
CISA confirmed that ransomware operators have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability that has been under active exploitation since early July. The flaw allows attackers to gain code execution on vulnerable on-premises SharePoint servers.
Why it matters: Confirm patch status on any on-prem SharePoint servers immediately; while GCC High SharePoint Online isn't directly exposed, any hybrid or on-prem SharePoint farms tied to the tenant are now a confirmed ransomware entry point.
Gunra ransomware exploits Fortinet and Schneider Electric flaws to breach critical infrastructure
US and South Korean cybersecurity agencies warned that Gunra ransomware is compromising healthcare, financial services, government, and nonprofit organizations worldwide by exploiting vulnerabilities in Fortinet and Schneider Electric products. The advisory describes Gunra as a growing variant in the trend of ransomware groups targeting critical infrastructure sectors.
Why it matters: Verify patch levels on all Fortinet appliances in the environment; unpatched FortiGate/FortiOS devices remain a top ransomware entry vector into government and critical-infrastructure networks under CMMC scope.
USB Plug and Play abuse chained to SYSTEM-level takeover on fully patched Windows 11
Researchers demonstrated that Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and chain privileged installation components into SYSTEM-level access on a fully updated Windows 11 machine. Microsoft confirmed the same technique can be triggered remotely over RDP when Plug and Play or low-level USB redirection is enabled, without any physical hardware present.
Why it matters: Review Intune/GPO policies restricting USB device installation and RDP USB redirection across the Windows 11 fleet — this is a privilege-escalation path Microsoft has not fully closed and no patch currently mitigates it.
Malicious MCP servers can split instructions to exfiltrate secrets via AI coding agents
Researchers showed that a malicious Model Context Protocol tool server connected to an AI coding assistant can exfiltrate SSH keys, environment secrets, source code, and customer data by splitting a harmful request into fragmented, individually innocuous-looking instructions. The technique succeeds even after the assistant refuses a single, obvious version of the same request.
Why it matters: Any self-hosted AI coding stack using third-party MCP servers should be treated as untrusted code execution surface — audit which MCP tools have filesystem or credential access before allowing them near CUI-adjacent repos.
New research reveals multiple passkey attack techniques bypassing phishing-resistant MFA
Three separate research efforts demonstrated ways to defeat passkey protections without breaking their underlying cryptography, including reusing signed authentication material exposed by Windows, abusing cloud-synced passkey systems via malware already on a victim's machine, and other bypasses of phishing-resistant MFA.
Why it matters: If passkeys are part of the Entra ID / Intune MFA strategy for CMMC-scoped systems, note these attacks target endpoint compromise and sync mechanisms rather than crypto — endpoint hardening still matters as much as the authenticator choice.
China-linked Storm-1175 deploys new StormEncryptor ransomware
Microsoft disclosed that Storm-1175, a financially motivated China-linked threat actor, has deployed a previously undocumented C++ ransomware strain called StormEncryptor, which appends the .encrypted extension to files. The group previously used Medusa ransomware before shifting to this new strain.
Metabase SQL zero-day allows remote admin access, no CVE yet assigned
A maximum-severity, still-unpatched vulnerability in the Metabase business analytics platform allows remote attackers to gain administrator access and reach downstream connected systems. Framework, the hardware maker, has already confirmed customer data was exposed via exploitation of the flaw.
Why it matters: If Metabase is deployed anywhere in the environment for BI/reporting, isolate it from the network immediately and watch for vendor patch guidance given active exploitation and no CVE tracking yet.
Mozilla revokes Firefox and Thunderbird Linux signing key after accidental exposure
Mozilla revoked the cryptographic signing key used to verify Firefox and Thunderbird downloads for Linux after an unencrypted copy was accidentally committed to a private company repository. Audit logs showed no unauthorized access, but Linux distributions and users must now update their trust chain to verify future releases.
Why it matters: Any Linux-based jump boxes, servers, or admin workstations running Firefox/Thunderbird will need updated key trust and package verification to avoid signature validation failures after the rotation.
Hackers breach Polish power plant through private cellular network, shut down turbine
Attackers breached a Polish combined heat and power plant supplying roughly 50,000 residents by accessing a private cellular (APN) network used to reach remote OT equipment, shutting down a steam turbine and process-water treatment system. Recovery began while intruders were still active in the network, though customers did not lose heat or water service.
FBI investigating North Korean remote IT worker embedded at a US federal agency
The FBI is investigating a case in which a suspected North Korean IT worker was employed remotely by a US federal agency, raising questions about vetting gaps in government and contractor hiring for IT support roles. Experts say the case highlights weaknesses in identity verification processes for remote technical positions.
Why it matters: Reinforces the need for rigorous identity verification and background checks for any remote contractor or MSP staff touching CUI or CMMC-scoped systems, including video-verified onboarding and hardware-bound device attestation.
NSPM-12 shifts federal cybersecurity oversight toward centralized, uniform compliance
A new commentary outlines how National Security Presidential Memorandum-12 shifts federal cybersecurity operating reality from decentralized, policy-heavy approaches like zero trust guidance toward a centralized model with uniform compliance requirements and stronger accountability mechanisms.
Why it matters: A move toward centralized, uniform compliance enforcement could tighten how zero trust and CMMC requirements are audited and reported — worth tracking for downstream changes to DFARS/NIST 800-171 assessment expectations.
Senate funding bill extends Technology Modernization Fund and cyber data-sharing law
The Senate's short-term continuing resolution, which pushes the federal funding deadline to December 11, includes temporary extensions for the Technology Modernization Fund (TMF) and the cyber threat information-sharing law that were both set to lapse. The bill passed the chamber with broad bipartisan support.
Why it matters: Continuation of the cyber threat information-sharing law preserves liability protections agencies and contractors rely on when sharing indicators of compromise — a lapse would have complicated incident reporting workflows.