Daily cybersecurity intelligence digest from CyberNetSec.io - August 17, 2026
📊 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. SafePal Data Breach Exposes 40,000 Crypto Wallet Customers
Cryptocurrency hardware wallet provider SafePal has disclosed a data breach affecting 39,798 customers due to a vulnerability in a third-party e-commerce plugin. The incident, which occurred between March 2025 and April 2026, exposed customer names, email addresses, phone numbers, and shipping addresses. The stolen data is now reportedly for sale on a cybercrime forum. While the security of the hardware wallets and cryptographic keys was not compromised, the leaked personal information creates a significant risk of targeted phishing and social engineering attacks against the affected users. SafePal has patched the flaw, notified customers, and reduced its data retention policy to 90 days.
2. macOS Screen Sharing Flaw CVE-2026-65400 Exploited in the Wild
A critical authentication bypass vulnerability in Apple's macOS Screen Sharing feature, CVE-2026-65400 (CVSS 9.8), is being actively exploited to install Monero cryptomining malware. The flaw allows a remote attacker to gain root access to systems with an internet-exposed Screen Sharing service on port 5900. Apple released patches on August 6, 2026, for macOS Sequoia, Sonoma, and Tahoe. However, a public proof-of-concept exploit released shortly after has led to widespread attacks. The Dutch NCSC has confirmed active exploitation, and security experts warn that the root access could be used for more severe attacks like ransomware or data theft. Users are urged to apply updates immediately or disable the Screen Sharing feature.
3. Unpatched Unisoc Exploit Chain Gives Full Android Kernel Access
Security researchers have revealed an unpatched, two-stage exploit chain targeting Android devices with Unisoc modem firmware. The attack, which requires the victim to answer a malicious VoLTE video call from an attacker-controlled 4G network, can grant full Android kernel access. The vulnerability chain includes a remote code execution flaw in the modem firmware and a privilege escalation flaw (CWE-1189) that allows a pivot to the kernel. Affected chipsets like the T606, T612, and T7250 are used in phones from Motorola, Realme, and Xiaomi. The chipmaker has reportedly been unresponsive, leaving devices without a patch.
4. 'ShieldBreak' Zero-Day (CVE-2026-69414) Bypasses Defender Patch
A security researcher has publicly disclosed 'ShieldBreak' (CVE-2026-69414), a new zero-day privilege escalation vulnerability in Microsoft Defender. The exploit bypasses a patch for a previous flaw, 'RoguePlanet' (CVE-2026-50656), and allows a local attacker with low privileges to gain full NT AUTHORITY\SYSTEM access. The proof-of-concept exploit is reportedly 100% effective on fully updated Windows 10, Windows 11, and Windows Server systems where Defender is the active antivirus. Microsoft has confirmed it is investigating and developing a patch. The public, uncoordinated disclosure creates a significant risk for enterprises relying on Microsoft's native security tools.
5. Ransomware Attacks Surge 33% with AI-Powered Tooling
Ransomware attacks surged by 33% year-over-year in Q2 2026, with 2,139 victims posted on data leak sites, according to a new report from Check Point Research. The number of active ransomware groups grew from 71 to 93, indicating a more fragmented but active landscape. While Qilin remains a top player, the newcomer group 'The Gentlemen' rose rapidly, reportedly using AI coding assistants to develop its management panel in just three days. This confirms that AI is actively accelerating the development of malicious tools and shrinking the window between vulnerability disclosure and exploit weaponization, increasing pressure on defenders.
6. LiteLLM Supply Chain Attack Exposes 153GB of Credentials
The fallout from the March 2026 supply chain attack targeting the LiteLLM AI gateway has been revealed with the discovery of a 153 GB dataset of stolen credentials. The attack, by the group TeamPCP, involved compromising the CI/CD pipeline of the Trivy vulnerability scanner to steal PyPI credentials and publish trojanized versions of the LiteLLM package. The malware harvested API keys, passwords, and cloud configs from over 2,000 organizations that installed the malicious packages, including tech giants like Amazon, NVIDIA, and Samsung. The exposed data contains a vast array of secrets, posing a severe ongoing security risk.
7. SAP Commerce Cloud Flaw CVE-2026-58231 Exploited in Wild
A critical-rated vulnerability in SAP Commerce Cloud, CVE-2026-58231, is being actively exploited just three days after SAP released a patch on August 11, 2026. The flaw, which has a perfect CVSS score of 10.0, allows for unauthenticated remote code execution. Security firms reported detecting exploitation attempts on August 14, even before a proof-of-concept (PoC) exploit was made public on August 15. The rapid weaponization of this vulnerability highlights the extreme urgency for all SAP Commerce Cloud customers to apply the security update immediately. CISA has not yet added the flaw to its KEV catalog.
8. Liechtenstein Will Not Pay Ransom in Financial Registry Hack
The government of Liechtenstein has announced it will not pay a ransom following a major cyberattack that compromised the confidential registry of 31,000 financial entities. The breach, which occurred in late July 2026, exposed the names, birth dates, and nationalities of beneficial owners. Prime Minister Brigitte Haas confirmed the government's stance, stating that paying a ransom "wouldn't be an option." To date, the attackers have not been identified and have not made any demands. The breach is a significant blow to the privacy-focused financial center, which manages over 500 billion Swiss francs in assets.
9. Ransomware Attack Disrupts Colombia's Ministry of Justice
The Ministry of Justice in Colombia has been hit by a ransomware attack, causing service disruptions and the encryption of government files. The attack affected technological infrastructure, including systems related to legal processes and the monitoring of illicit drugs. While officials have confirmed the file encryption, they stated that an investigation has not yet detected any evidence of data theft. The identity of the threat actor and the full scope of the incident have not been disclosed. The attack is part of a wider trend of ransomware groups targeting government entities.
10. Major Data Breach at Polish Healthcare Platform MyDr
Poland's primary healthcare platform, MyDr, has reportedly suffered a massive data breach that could affect up to 19 million citizens. Unidentified attackers claim to have stolen 2.5 terabytes of highly sensitive data, including medical records, personal identification details, and prescription information. To prove their claim, the threat actors leaked the personal and prescription data of a senior Polish politician. The breach poses a severe privacy risk to a large portion of Poland's population, exposing them to potential fraud, blackmail, and identity theft. The attackers' identity and motives are currently unknown.
11. Qilin Ransomware Claims Attack on Canadian Chip Firm MOSAID
The prolific Qilin ransomware group has claimed responsibility for an attack on MOSAID Technologies, a Canadian semiconductor and intellectual property (IP) licensing firm. On August 17, 2026, MOSAID was listed as a victim on the group's data leak site. Qilin, one of the most active ransomware gangs in 2026, employs a double-extortion model, meaning they likely exfiltrated sensitive data before encrypting MOSAID's systems. The breach could expose valuable intellectual property and corporate data, although the full scope of the data theft is not yet known.
12. 'crpx0' Ransomware Gang Sells Data After Failed Extortion
The emerging ransomware group 'crpx0' has pivoted its strategy from simple extortion to selling stolen data on newly created leak sites. After 47 of its victims refused to pay ransom demands, the group has now listed their data for sale on both the clear and dark web. The crpx0 gang, first noted in July 2026, uses unusual social engineering lures, such as fake OnlyFans accounts, to distribute its malware. This tactical shift highlights the fluid monetization strategies of newer ransomware gangs when their initial extortion attempts fail.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)