
Enterprise cloud architects, SaaS security engineers, and Identity and Access Management (IAM) professionals are facing urgent configuration auditing mandates following the public disclosure of a sophisticated, long-running data harvesting operation. Disclosed on August 18–19, 2026, by SaaS security platform Reco, threat researchers have detailed the ‘City Forum’ campaign—a sustained reconnaissance and data-exfiltration operation that has…

Enterprise artificial intelligence infrastructure, MLOps engineering environments, and cloud computing clusters are facing urgent security remediation requirements following an emergency directive from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Disclosed on August 18, 2026, CISA officially added a critical remote code execution vulnerability impacting the Ray AI distributed computing framework to its Known Exploited…

WordPress administrators, enterprise web hosting providers, and cybersecurity engineering teams are urged to immediately inspect their content management systems following critical security advisories published by WordPress security firm Wordfence. Disclosed on August 17–18, 2026, researchers have detailed a maximum-severity flaw in Forminator Forms—a popular custom form, survey, and payment builder plugin with more than 600,000…

Mobile security researchers and enterprise device administrators are raising alarms following forensic disclosures from vulnerability research firm SSD Secure Disclosure. Published in mid-August 2026, researchers have detailed a devastating two-stage exploit chain that allows remote attackers to compromise cellular baseband processors and achieve full Android Linux kernel execution simply by placing a Voice over LTE…

Cloud infrastructure engineers, DevSecOps teams, and software supply chain security specialists are reviewing CI/CD automation practices following disclosures from cloud security firm Wiz. Disclosed on August 17–18, 2026, researchers revealed how an unvetted script-injection vulnerability in Snowflake’s public GitHub Actions workflow allowed attackers to execute arbitrary shell commands and harvest internal enterprise Jira API credentials.…

Enterprise cybersecurity teams and identity protection administrators are raising alerts following disclosures from threat intelligence firm CTM360 regarding RecruitTrap, a sophisticated global cyber espionage and credential-theft campaign. Disclosed on August 14–15, 2026, the operation utilizes more than 3,000 active phishing URLs employing Browser-in-the-Browser (BitB) techniques to hijack enterprise accounts and relay Multi-Factor Authentication (MFA) challenges…

DevOps engineers, software supply chain security teams, and GitLab administrators are facing urgent upgrade advisories following GitLab’s emergency security release on August 17–18, 2026. The security update addresses a critical flaw in GitLab’s GraphQL API directive engine that allows unauthenticated remote attackers to modify or delete repository data without valid user credentials. Deconstructing the GraphQL…

Enterprise infrastructure administrators, GIS mapping specialists, and security operations teams are urged to implement immediate defensive mitigations following disclosures of an unpatched zero-day vulnerability in GeoServer. Disclosed across threat intelligence feeds on August 14–15, 2026, the flaw is currently facing active in-the-wild scanning and exploitation attempts that can lead to full Remote Code Execution (RCE).…

Enterprise datacenter administrators and virtualization platform engineers are facing urgent security alerts following active, in-the-wild exploitation of a maximum-severity vulnerability in Broadcom VMware vCenter Server. Disclosed by incident response firm QUIRSO and cybersecurity researchers in mid-August 2026, threat actors are leveraging the flaw to establish persistent reverse SSH backdoors across compromised enterprise virtualization clusters. Deconstructing…

Enterprise security operations centers and cloud engineering teams are initiating emergency credential rotation protocols following new forensic disclosures surrounding the LiteLLM software supply chain compromise. Disclosed on August 13, 2026, by threat intelligence firms Hudson Rock and CloudSEK, a massive 153GB archive containing stolen CI/CD secrets and cloud access tokens has surfaced, exposing data from…