~/greenteam/nerd

Wednesday, August 19, 2026

Daily digest

CISA added four critical, actively-exploited flaws to its KEV catalog today (macOS, SharePoint, vCenter, Windows IKE), plus a 3-day emergency patch deadline for a Ray RCE bug โ€” a heavier-than-usual vulnerability day demanding prioritized patch triage.

cybersec The Hacker News

CISA Adds Four Actively Exploited Critical Flaws to KEV Catalog

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation: an improper authentication flaw in Apple macOS (CVE-2026-65400, CVSS 9.8), plus critical bugs affecting SharePoint, VMware vCenter, and the Microsoft Windows IKE Extension. All four are confirmed under active attack in the wild.

Why it matters: Federal agencies and CMMC-scoped contractors are required to remediate KEV entries on CISA's mandated timeline; SharePoint and Windows components are directly in scope for GCC High and Intune-managed fleets.

cybersec BleepingComputer

CISA: Medusa Ransomware Has Hit Over 500 Critical Infrastructure Organizations

The FBI and CISA updated a joint advisory stating the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the U.S. since June 2021, up from a previously reported 300 victims. Many targets are in sectors overlapping with government and defense supply chains.

cybersec The Hacker News

Clop-Linked Web Shell Targets PTC Windchill for Credential Theft and Data Mapping

ReliaQuest researchers found a JSP web shell, deployed after exploitation of a critical PTC Windchill/FlexPLM flaw, purpose-built to decrypt stored credentials and map sensitive engineering vault data. The tool is described as a full extortion platform tied to Clop-linked activity.

cybersec The Hacker News

Microsoft Copilot Personal Flaws Allow One-Click Data Exfiltration

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could let a single click on a crafted link silently exfiltrate data from connected apps and other information available in a victim's Copilot session. The flaws stem from an undocumented URL parameter the assistant itself surfaces.

Why it matters: Any Copilot integrations tied to M365 GCC High tenants should be reviewed for exposure and link-click training reinforced, since this attack requires no user credentials โ€” just a click.

cybersec The Register

CISA Gives Federal Agencies 3 Days to Patch Actively Exploited Ray RCE Bug

CISA issued an emergency directive giving federal agencies three days to remediate an actively exploited remote code execution vulnerability in Ray, an open-source distributed computing framework widely used for AI/ML workloads. Attackers are reportedly using phishing and malvertising to target developers and gain access to corporate networks.

Why it matters: If Ray underpins any self-hosted AI/ML pipelines, this warrants immediate patch verification given the compressed federal remediation window and active exploitation.

cybersec Dark Reading

Critical GitLab Zero-Click Flaw Complicates Detection for Self-Managed Instances

A critical zero-click vulnerability, CVE-2026-19478, affects self-managed GitLab installations. Limited technical detail from GitLab makes it difficult for organizations to determine whether exploitation has already occurred.

Why it matters: If GitLab is part of the Ansible/automation toolchain, patch immediately and audit logs โ€” the lack of exploitation indicators means detection can't rely on public IOCs alone.

cmmc Federal News Network

White House Reviewing Governmentwide Cyber Supply Chain Security Data Standards

The federal CIO's office is reviewing governmentwide cyber supply chain security data call standards, aiming to better identify risks tied to foreign adversaries in the software and hardware supply chain.

Why it matters: Changes to supply chain data call requirements could add new reporting obligations for contractors already tracking CMMC L2 supply chain risk assessments.

cmmc Federal News Network

Funding and Cybersecurity Rules Reshaping the Defense Contracting Market

Industry analysts note that regulatory uncertainty around cybersecurity requirements and funding continuity is influencing defense market behavior as much as actual contract awards, with contractors facing a mix of unclear funding and unclear compliance rules.

Why it matters: Continued regulatory ambiguity around CMMC rollout timing directly affects budget and staffing decisions for defense-adjacent IT compliance programs.

infrastructure The Register

GitHub Blames 8-Hour Outage on Autoscaling Failure and VS Code Retry Storm

GitHub attributed an 8-hour service disruption to an autoscaling failure combined with a retry storm triggered by VS Code clients, after a monitoring blind spot allowed traffic to spiral out of control and overwhelm load balancers.

infrastructure AWS Security Blog

AWS Security Hub Extended Adds Supply Chain Security as Tenth Category

AWS added Supply Chain Security as a new category in Security Hub Extended, growing the program from 14 partners across 9 categories in February to 23 partners across 10 categories today, with several partners demoing integrations at Black Hat.

Why it matters: New supply chain security integrations in Security Hub could streamline NIST 800-171 supply chain risk monitoring for workloads running in AWS GovCloud.