██████╗██╗   ██╗██████╗ ██████╗     ██████╗██╗  ██╗
 ██╔════╝╚██╗ ██╔╝██╔══██╗██╔══██╗   ██╔════╝╚██╗██╔╝
 ██║      ╚████╔╝ ██████╔╝██████╔╝ ● ██║      ╚███╔╝ 
 ██║       ╚██╔╝  ██╔══██╗██╔══██╗   ██║      ██╔██╗ 
 ╚██████╗   ██║   ██████╔╝██║  ██║   ╚██████╗██╔╝ ██╗
  ╚═════╝   ╚═╝   ╚═════╝ ╚═╝  ╚═╝    ╚═════╝╚═╝  ╚═╝
────────────────────────────────── STAY SHARP ───

Cisco Firewall Zero-Day Under Active Attack, Patch Now

Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 14, 2026

Share

cybr.cx — Daily Digest | August 14, 2026


Critical Vulnerabilities

⚠️ Actively exploited — CVE-2026-20349 | Cisco ASA & FTD | No CVSS in NVD (KEV-listed)
Cisco's Secure Firewall ASA and Secure Firewall Threat Defense platforms are being actively targeted right now. An unauthenticated remote attacker can trigger a heap inspection vulnerability that forces the device to reload, causing a denial-of-service condition. CISA's remediation deadline was today — if you haven't patched, you're already late. Perimeter firewall availability is not optional.

⚠️ Actively exploited — CVE-2026-72898 | Metabase | No CVSS in NVD (KEV-listed)
An unauthenticated SQL injection in Metabase allows remote attackers to inject arbitrary SQL into the application database and escalate to administrator access from there. With admin access, attackers can pivot to stored credentials, API keys, and platform configuration. CISA's remediation deadline was also today. Metabase instances exposed to the internet should be treated as compromised until patched and audited.

⚠️ Actively exploited — CVE-2026-8037 | Progress LoadMaster | No CVSS in NVD (KEV-listed)
Unsanitized input across multiple command endpoints in Progress LoadMaster enables pre-authentication command injection — attackers can run arbitrary OS commands on the appliance. CISA's due date passed August 10, meaning any unpatched instance has been exposed for days. LoadMaster sits at the network edge; treat this as critical regardless of internal exposure.

⚠️ Actively exploited — CVE-2026-68820 | Microsoft Windows (WinSock AFD) | No CVSS in NVD (KEV-listed)
A use-after-free in the Windows Ancillary Function Driver for WinSock is being weaponised for local privilege escalation by authorised-but-low-privileged attackers. This class of vulnerability is a staple of post-exploitation toolkits — once an adversary has a foothold, this is the kind of bug that gets them to SYSTEM. Remediation deadline is August 25, but don't wait.

CVE-2026-73625 | GitPython < 3.1.54 | CVSS 8.8
GitPython's check_unsafe_options guard can be bypassed by smuggling malicious git options inside single-character kwarg values. Affected methods include clone_from, fetch, pull, push, ls_remote, iter_commits, blame, and archive — essentially the entire surface of common git operations. Exploitation leads to arbitrary OS command execution via --upload-pack. Any application using GitPython to process user-influenced repository inputs should patch to 3.1.54 immediately.

CVE-2026-73615 | Network-AI < 5.15.1 | CVSS 8.8
A quote-handling mismatch between Network-AI's security policy matcher and its command executor creates a sandbox bypass. The policy evaluator inspects raw quoted command strings, while the executor strips quotes before running — so an attacker can craft a quoted command that passes blocklist and approval checks but executes the dangerous unquoted form. This is a logic flaw masquerading as a parsing edge case, and it completely undermines the trust model of the sandbox.

CVE-2026-16674 / 16722 / 16975 / 16987 / 17029 / 17223 | IBM i 7.3–7.6 | CVSS 8.8 (all)
IBM i has received a cluster of six high-severity CVEs covering: remote code execution via untrusted search path (16674), improper privilege management (16722), heap-based buffer overflow RCE (16975), local privilege escalation via LANG environment variable manipulation (16987), local arbitrary code execution via out-of-bounds write (17029), and remote RCE via buffer overflow (17223). IBM i powers a significant slice of enterprise financial and manufacturing infrastructure — the combination of remote and local vectors across four supported versions makes this patch cycle mandatory.


Headline News

Lazarus Deploys Novel "Troy" Backdoor with Kernel Rootkit to Blind EDR

North Korea's Lazarus Group has been caught using a Windows zero-day — patched by Microsoft on August 12 — to deploy a previously undocumented backdoor named Troy alongside a kernel-level rootkit specifically engineered to undermine endpoint detection and response tooling. The campaign targeted defence and aerospace organisations, consistent with Lazarus's long-running interest in intellectual property from the defence industrial base. The rootkit's primary purpose appears to be EDR evasion: by operating at kernel level, it can manipulate the telemetry that security tools depend on, potentially rendering infections invisible to both real-time monitoring and retrospective log analysis. For practitioners, this underscores that EDR is a necessary but not sufficient control — kernel rootkit capability in a nation-state toolkit means defenders need kernel integrity monitoring and secure boot enforcement as baseline mitigations, not aspirational ones. Organisations in the defence and aerospace verticals should treat the August 12 patch as emergency-priority and audit for indicators of compromise retroactively.

Every Major AI Model's Hidden Reasoning Exposed via Global Key Failure

Researchers have disclosed a significant cryptographic design flaw in how major AI providers protect reasoning tokens — the internal "chain of thought" that frontier models generate before producing a final response. Every major provider examined was found to encrypt these reasoning blocks with a single global key, and by exploiting this, researchers were able to decode 315,320 hidden thinking blocks recovered from public logs. Among the recovered data were passwords and live API keys, meaning what was presented to users as opaque internal model reasoning was, in practice, a leaky channel carrying sensitive material. The architectural assumption — that encrypting intermediate outputs with one shared key is sufficient — reflects a broader tendency to treat AI pipeline internals as out-of-scope for traditional threat modelling. For security teams, this is a reminder that AI integrations are attack surface: any system where model reasoning touches sensitive context should be audited for what gets logged, where, and under what encryption assumptions.

White House Authorises Private Companies to Conduct Offensive Operations Against Foreign Cybercrime Groups

A new presidential directive has granted select private U.S. companies formal authorisation to conduct offensive cyber operations against transnational cybercrime organisations operating abroad. The policy represents a significant departure from a framework in which offensive cyber action was the exclusive domain of government agencies, effectively deputising private-sector threat intelligence and security firms under defined conditions. For practitioners, the immediate questions are operational: what authorisation thresholds apply, what liability protections exist, and how "transnational cybercrime group" gets defined in practice. The risk of misattribution — a persistent problem even for well-resourced government operators — becomes substantially higher when the actor pool expands to include commercial entities with varying intelligence capabilities. Expect this to reshape how threat intelligence firms structure their offensive research divisions, and watch for adversary retaliation framed around the legitimacy of private-sector "hack-back."


Schrödinger's Feed

BTQ Technologies has signed a memorandum of understanding positioning itself within the emerging "quantum trust infrastructure" space — the engineering layer that will need to exist before quantum networks can underpin real-world cryptographic operations. Quantum networks present a genuinely different security model: rather than encrypting data mathematically, quantum key distribution uses the physical properties of photons to make eavesdropping detectable in principle. The hard problem is making that work reliably at scale, across hardware that currently ranges from finicky to experimental. Practitioners building long-horizon cryptographic roadmaps should note that the race between quantum-safe classical algorithms (NIST PQC) and quantum networking infrastructure is now running on parallel tracks — and enterprise decisions made today about PKI and key management will need to account for both.


/dev/random

Someone decided the correct approach to running local AI models was to build a server from literal scavenged hardware — mismatched RAM, a GPU of uncertain provenance, and a case that appears to be making its structural integrity a matter of personal honour. The write-up documents, with commendable honesty, that the first boot produced smells, the second boot produced results, and the gap between those two events involved more thermal paste than any reasonable person would consider appropriate. The actual security angle is inadvertent: running inference locally on air-gapped junk hardware is, depending on your threat model, either completely unhinged or exactly correct. Jevons paradox may apply — the easier it gets to run AI on scrap, the more scrap people will run AI on.