~/greenteam/nerd

Monday, August 24, 2026

Daily digest

A critical Keycloak IAM vulnerability and a CISA emergency directive on Zimbra dominate today — both demand immediate patching attention in government-adjacent environments.

cybersec The Hacker News

Critical Keycloak Flaw Allows Unauthenticated Account Takeover via Password Reset

Red Hat and the Keycloak project patched CVE-2026-18963, a critical flaw (CVSS 9.1) in the open-source identity and access management server. The bug allows an unauthenticated remote attacker to force a password reset and take over any user account.

Why it matters: If Keycloak underpins any identity federation or SSO in your environment, this is a full account-takeover bug requiring immediate patching — treat it with the same urgency as an AD FS or Entra ID vulnerability.

cybersec BleepingComputer

CISA Orders 3-Day Emergency Patch for Actively Exploited Zimbra Flaw

CISA issued an emergency directive requiring U.S. federal agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The flaw is being actively used in the wild against unpatched instances.

Why it matters: Even if Zimbra isn't in your stack, this signals the kind of exploited-vulnerability response timeline CISA now expects — a useful benchmark for your own vulnerability management SLAs under NIST 800-171/CMMC L2.

cybersec The Register

$1T Investment Firm Apollo Breached via Social Engineering

Apollo Global Management was breached after attackers used social engineering to gain access to the firm's cloud platforms, remaining inside for four days before detection. Details on the scope of data accessed have not yet been disclosed.

Why it matters: A multi-day cloud-platform dwell time via social engineering is a direct reminder to review helpdesk/identity-reset procedures and conditional access policies protecting your AWS GovCloud and M365 GCC High tenants.

cybersec The Hacker News

UAT-10147 Uses AI to Scale Attacks, Deploys SPECTRE Malware with EDR Bypass and Linux Rootkit

A Chinese-speaking cybercrime group tracked as UAT-10147 is targeting Windows and Linux web servers globally in education, media, tech, and gaming sectors, with heaviest activity in Brazil, Bolivia, China, Canada, and Vietnam. The group deploys SPECTRE malware featuring EDR bypass techniques and a Linux rootkit, reportedly using AI to scale operations.

Why it matters: The Linux rootkit and EDR-evasion techniques are relevant to any Nutanix AHV hosts or Linux VMs — verify kernel integrity monitoring and EDR coverage extends fully to your virtualization layer, not just Windows endpoints.

cybersec BleepingComputer

ToxicPanda Android Banking Malware Expands to 349 Apps, Blocks Google Play via VPN Permissions

The ToxicPanda Android malware has been updated to target 349 applications and support 167 remote commands, up from earlier versions. It now abuses VPN permissions to block access to the Google Play Store on infected devices.

Why it matters: If Android devices are enrolled in Intune for BYOD or field use, confirm app protection policies and Play Protect enforcement can't be bypassed by malicious VPN profile abuse like this.

cybersec The Hacker News

Operation QUICSILVER Targets Myanmar Government with QUICAgent Backdoor

A cyber espionage campaign dubbed Operation QUICSILVER uses graduation ceremony invitation lures to deliver a Go-based backdoor called QUICAgent. Seqrite Labs attributes the campaign, targeting Myanmar government and IT sectors, to a China-nexus threat actor with moderate confidence.

cybersec Risky Business News

Threat Roundup: Iranian Hackers Hit UK Power Plant, Lazarus Breaches South Korean Presidential Office

Iranian state-linked hackers reportedly shut down a UK power plant, while North Korea's Lazarus Group breached South Korea's Presidential Office. Separately, new Android malware is infecting in-car systems to build a proxy botnet.

cmmc FedScoop

Federal Government Should Prioritize AI Speed Over Model Perfection

A FedScoop opinion piece argues federal agencies should focus on faster AI adoption rather than waiting to select the optimal model. The piece frames deployment speed as more valuable to mission outcomes than model selection precision.

infrastructure The Register

Canonical Funds Research to Translate Legacy C Code to Rust Using AI

Canonical is funding a research effort with Bristol researchers to test whether AI tools can reliably translate large volumes of existing C code into memory-safe Rust while preserving functionality. The project aims to evaluate whether mature codebases survive automated translation intact.

infrastructure BleepingComputer

Microsoft Issues Temporary Fix for Windows 11 Gaming Issues from August Patch Tuesday

Microsoft released a temporary workaround for gaming performance and stability issues caused by Windows 11 updates shipped in the August 2026 Patch Tuesday cycle. A permanent fix has not yet been issued.

Why it matters: Even if gaming isn't a concern, this points to broader instability in the August cumulative update — worth confirming your Intune update rings haven't surfaced related regressions before wider deployment.

cybersec The Hacker News

AI-Generated Code Is Outpacing Security Teams' Ability to Vet Dependencies

Increased use of AI coding assistants is accelerating introduction of open-source dependencies faster than security teams can review them, creating growing remediation backlogs. The piece outlines approaches for controlling this 'remediation debt' as AI-assisted development scales.

Why it matters: If your self-hosted AI stack or internal tooling relies on AI-assisted code generation, this is a direct prompt to audit dependency provenance and remediation SLAs before backlog becomes an 800-171 vulnerability management finding.

cybersec The Hacker News

Akamai: Top 5% of Enterprise AI Power Users Pose Outsized Security Risk

New Akamai research finds that a small subset of enterprise AI 'super-adopters' — roughly 5% of users — are embedding unvetted AI tools directly into critical business workflows, creating concentrated risk exposure beyond typical shadow-IT concerns.