██████╗██╗   ██╗██████╗ ██████╗     ██████╗██╗  ██╗
 ██╔════╝╚██╗ ██╔╝██╔══██╗██╔══██╗   ██╔════╝╚██╗██╔╝
 ██║      ╚████╔╝ ██████╔╝██████╔╝ ● ██║      ╚███╔╝ 
 ██║       ╚██╔╝  ██╔══██╗██╔══██╗   ██║      ██╔██╗ 
 ╚██████╗   ██║   ██████╔╝██║  ██║   ╚██████╗██╔╝ ██╗
  ╚═════╝   ╚═╝   ╚═════╝ ╚═╝  ╚═╝    ╚═════╝╚═╝  ╚═╝
────────────────────────────────── STAY SHARP ───

Hackers Actively Exploit AI Framework Ray's Critical Code Flaw

Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 18, 2026

Share

cybr.cx Daily Digest — August 18, 2026


Critical Vulnerabilities

⚠️ Actively exploited — CVE-2025-62593 | Anyscale Ray | No CVSS listed
Ray, the popular distributed ML compute framework, has a code injection vulnerability enabling remote code execution — and it's being actively weaponised right now. CISA added it to the KEV catalogue yesterday with a remediation deadline of August 20, meaning federal agencies have two days. Notably, exploitation is possible via Firefox and Safari, suggesting browser-based attack surfaces in Ray's dashboard or job submission interfaces. If you're running Ray clusters — especially internet-exposed development environments — isolate or patch immediately.

⚠️ Actively exploited — CVE-2026-20349 | Cisco ASA & FTD | No CVSS listed
Unauthenticated remote attackers are triggering unexpected device reloads against Cisco's Secure Firewall ASA and FTD products via a heap inspection vulnerability. The CISA KEV due date has already passed (August 14), meaning any unpatched device at this point represents an overdue risk. Perimeter firewall DoS in active exploitation is a serious operational concern — a rebooting ASA during an incident is an attacker's best friend.

⚠️ Actively exploited — CVE-2026-72898 | Metabase | No CVSS listed
Unauthenticated SQL injection in Metabase allows attackers to inject arbitrary SQL directly into the application database, yielding administrator access without any credentials. From that foothold, configuration changes, credential theft, and lateral movement are all on the table. Metabase instances are frequently exposed to internal networks with broad database connectivity, making the blast radius significant. Patch or take offline — CISA's remediation deadline has passed.

⚠️ Actively exploited — CVE-2026-68820 | Microsoft Windows WinSock AFD Driver | No CVSS listed
A use-after-free in the Windows Ancillary Function Driver for WinSock is being exploited to elevate privileges locally. This is a classic post-exploitation stepping stone: pair it with any initial access vector and you have SYSTEM. Remediation deadline is August 25 — apply August Patch Tuesday updates now if you haven't.

CVE-2026-74877 | openssl_encrypt < 1.4.0 | CVSS 8.8
An ownership verification flaw in revoke_key lets any authenticated client revoke any other client's key, as long as they can produce a valid ML-DSA signature. The practical impact is key revocation chaos — targeted disruption of cryptographic authentication for legitimate users. Update to 1.4.0.

CVE-2026-70495 | search-v2-operator (OpenShift/Kubernetes) | CVSS 8.8
The search-serviceaccount carries wildcard impersonation permissions across the entire cluster. Any attacker who compromises a pod running under this service account inherits system:masters — full cluster control. Kubernetes RBAC misconfigurations that grant impersonate at cluster scope are notoriously hard to detect after the fact. Audit service account permissions now.

CVE-2026-74798 | SiYuan < v3.7.4 | CVSS 8.7
A path traversal in the database_clean MCP tool passes a user-controlled id parameter to filepath.Join without format validation, allowing authenticated MCP clients to traverse the filesystem. The fix is in v3.7.4 — if you're running SiYuan as a personal knowledge base with MCP enabled, update immediately.

CVE-2026-19979 | GL.iNet Routers (multiple models, up to 4.8.x) | CVSS 8.3
An authorisation bypass in the WebDAV COPY/MOVE handler affects a broad range of GL.iNet consumer and prosumer routers. Remotely exploitable without authentication bypass elsewhere in the chain. GL.iNet hardware is common in travel and home lab setups — a compromised router means compromised network visibility. Check for firmware updates.

CVE-2026-74234 | Legora < 2026-08-14 | CVSS 7.7
A stored XSS in Legora exploits the interaction between gray-matter front-matter parsing and Mermaid diagram rendering: the front-matter parser calls eval() on attacker-controlled JavaScript before SVG sanitization runs. Anyone viewing a malicious diagram gets arbitrary JS executed in their browser session. Update to the August 14 build or later.


Headline News

iCloud Private Relay's Real-IP Leak via WebKit

Three WebKit features — likely related to media handling, WebRTC, or prefetch behaviours — can be abused to leak a Safari user's real IP address even when iCloud Private Relay is active. The issue matters because Private Relay is Apple's flagship privacy promise for iCloud+ subscribers: the entire value proposition is that websites cannot determine your origin IP. Practitioners running threat intelligence or fraud detection operations should be aware that relay attribution is less reliable than assumed, and conversely, users depending on Private Relay for anonymity cannot currently treat it as a guarantee. Apple has not yet confirmed a patch timeline. The WebKit attack surface for privacy leaks continues to prove more porous than the marketing implies.

SafePal Crypto Wallet Breach Exposes Nearly 40,000 Customers

Hardware and software crypto wallet provider SafePal has confirmed a breach affecting 39,798 customers, with the company now actively warning its user base about follow-on phishing campaigns targeting exposed data. Breaches at crypto wallet companies carry outsized risk relative to their customer count: exposed PII combined with known crypto holdings creates highly targeted spear-phishing and SIM-swapping opportunities. Practitioners should note the attacker playbook here — breach data from wallet providers gets operationalised quickly into social engineering chains designed to drain funds. If you or clients use SafePal, treat inbound communications as suspect and verify wallet addresses independently of any guidance arriving via email or SMS.

White House "Cyber Privateer" Strategy Sparks Offensive Security Debate

A White House memorandum floating a framework for state-sanctioned offensive cyber operations by private actors — so-called "cyber privateers" — has drawn sharp debate across the security community. Proponents argue it offers a scalable mechanism to impose costs on criminal infrastructure without direct government attribution risk; critics counter that licensing private offensive capability creates uncontrollable escalation risk and blurs the legal lines governing computer fraud statutes domestically and internationally. The practical concern for defenders is environmental: a legitimised privateer ecosystem likely expands the overall pool of offensive tooling and TTPs in circulation, some of which reliably bleeds into criminal hands. For red teams and incident responders, the policy direction is worth tracking closely — it signals a posture shift that will shape both the threat landscape and the legal guardrails around offensive engagements.


Schrödinger's Feed

QpiAI has inaugurated an 8-inch quantum chip foundry in Bengaluru, with an explicit target of fabricating processors scaling to 10,000 qubits using flip-chip superconducting architectures. That qubit count, if realised, starts entering territory where timelines for cryptographically relevant quantum computation become less theoretical. The manufacturing infrastructure angle is underappreciated: the bottleneck for large-scale QPUs has always been fabrication consistency at scale, not just qubit counts on paper. Security practitioners planning post-quantum migration roadmaps should watch hardware manufacturing milestones as a leading indicator — when foundry capacity scales, the timeline pressure on RSA and ECC deployments accelerates with it.


/dev/random

Wiz's red team discovered that GitHub Copilot's Autofix feature — designed to automatically suggest security fixes in pull requests — could itself be manipulated to introduce a malicious code change that compromised Snowflake's Jira instance via their CI/CD pipeline. The attack essentially weaponised the AI-generated fix suggestion as an injection vector: the red team influenced what Autofix proposed, the proposed change was trusted and merged, and the pipeline did the rest. It's a delightful and deeply uncomfortable irony — the security tool becoming the attack surface, with human reviewers presumably thinking "the AI caught a bug, great" and clicking approve. The lesson is not that Autofix is irredeemably broken, but that AI-generated code in security-sensitive pipelines deserves the same adversarial scrutiny as any third-party contribution.