Article Read Time

Top 5 Cyber Security News Stories
1. Six Agencies Issue Joint Advisory on Gunra Ransomware, and Hand Linux Victims a Free Way Out
The FBI, CISA, DC3, NSA, U.S. Secret Service, and the Republic of Korea’s National Police Agency published a joint #StopRansomware advisory on Gunra, a Conti-derived double-extortion operation active against government, healthcare, and critical infrastructure across five continents. Gunra actors have gained initial access primarily by exploiting Fortinet FortiOS and FortiProxy authentication-bypass flaws (CVE-2024-55591 and CVE-2025-24472), and have defeated enterprise multi-factor authentication by modifying authentication servers so an attacker-chosen code always validates. The advisory also disclosed a flaw in the Gunra Linux variant’s key generation: victims who preserved their encrypted files may be able to reconstruct decryption keys from timestamps alone, without paying.
Source: CISA URL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
2. Cisco Confirms Active Exploitation of ASA and FTD VPN Flaw That Crashes Firewalls
Cisco warned that CVE-2026-20349, an 8.6-severity flaw in Secure Firewall ASA and FTD software, is being exploited in the wild to knock devices offline. Insufficient error checking in HTTP request processing lets an unauthenticated attacker send a crafted request to the Remote Access SSL VPN service and force a device reload, producing a denial-of-service condition on the exact appliance many organizations rely on for remote access. No workarounds exist, and CISA added the flaw to its Known Exploited Vulnerabilities catalog with an August 14 federal remediation deadline.
Source: BleepingComputer URL: https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
3. Google Exposes UNC6671, the Vishing Crew Running Four Extortion Brands at Once
Google Threat Intelligence Group detailed UNC6671, a voice-phishing extortion group that emerged in early 2026 as “BlackFile” and now operates under at least four public brands: Redact, Pink, Helix, and Falcon. Operators pose as IT helpdesk staff running urgent security migrations, frequently calling employees on personal mobile devices, then steer victims to spoofed portals where adversary-in-the-middle infrastructure captures credentials and MFA tokens. Targeting has climbed the value chain through 2026, moving from manufacturing and healthcare to technology and hospitality, and most recently to financial and legal firms, with ransom demands reported between $750,000 and $3 million.
Source: Google Cloud Threat Intelligence URL: https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments
4. Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Researchers documented an ongoing npm supply chain campaign seeding close to 800 malicious packages (with over 1,000 confirmed in total) carrying a dropper tracked as WEL1DROPPER. The packages use machine-generated typosquat names and, unusually, ship README files that instruct developers to load them with require(), triggering execution. WEL1DROPPER fingerprints the host operating system and architecture, pulls a matching payload from Cloudflare Workers infrastructure, and falls back to DNS TXT records when HTTPS retrieval fails, delivering RAT and infostealer payloads to Windows, macOS, and Linux developers alike.
Source: The Hacker News URL: https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
5. Microsoft Patches 421 CVEs, Including a Zero-Day Tied to Lazarus
August Patch Tuesday landed with unusual weight: roughly 421 CVEs addressed, 42 of them critical, including 37 remote code execution issues. The headline item is CVE-2026-68820, an elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock that has reportedly been exploited by the North Korean Lazarus group to escalate to SYSTEM. Two additional flaws were publicly disclosed before patches shipped, giving opportunistic attackers a head start on organizations that defer their update cycles.
Source: SecurityWeek URL: https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
