August 2026 Cybersecurity Roundup

This August 2026 Cybersecurity Roundup lands in a month when several of the biggest breaches traced back to familiar weaknesses: a compromised employee credential, an overlooked customer-facing plugin, and infrastructure monitoring that watched the wrong signals. Here’s a look at the month’s key cyberattacks and CVEs, along with our take on what they mean for businesses of every size.

SafePal disclosed a breach affecting almost 40,000 crypto-wallet customers. A cyberattack on logistics giant CEVA rippled outward to household names including Ajax and Valve’s Steam hardware business. France’s tax authority confirmed that stolen VPN credentials led to the theft of nearly 700,000 taxpayer records. Latvia’s vehicle registration agency lost data on 1.2 million people despite a round-the-clock monitoring contract, triggering a full board resignation. And Manchester Airports Group had customer data published on the open web after attackers found admin keys sitting in plain sight on public websites. August also brought five CVEs worth patching immediately, spanning Windows, Adobe Commerce, Zimbra, MLflow, and Citrix NetScaler.

Cyberattacks in the August 2026 Cybersecurity Roundup

Five major August 2026 data breaches spanning crypto, logistics, government, and travel

Five separate incidents this month, one recurring pattern: identity, third-party, and application risk.

SafePal Data Breach

SafePal, a provider of cryptocurrency hardware and software wallets, disclosed on August 16 that an authorization flaw in the order-tracking function of a customer-facing plugin exposed information belonging to approximately 39,798 customers. The affected records covered orders placed between March 2, 2025, and April 11, 2026, and included names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal said the incident did not expose wallet seed phrases, private keys, wallet passwords, bank details, payment-card information, or government-issued IDs.

The exposure window was widened by a separate internal issue: order data had been retained for longer than intended, increasing the number of records ultimately affected. SafePal has since reduced its data-retention period to 90 days, engaged a third-party security firm to audit the fix, and taken down more than 30 phishing websites built using the exposed data — a clear sign of the increased phishing and social-engineering risk facing the affected customers.

Every internet-facing application forms part of the attack surface, regardless of whether it processes payments, stores intellectual property, or simply helps customers track an order. The SafePal breach is a reminder that vulnerability management can’t rely solely on patching known flaws. Regular penetration testing remains essential for identifying broken authorization controls and insecure business logic that automated vulnerability scanners frequently miss.

CEVA Logistics Cyberattack

CEVA Logistics, one of the world’s largest third-party logistics providers and headquartered in France, suffered a cyberattack — reportedly occurring between July 29 and August 1 — that disrupted operations at eight European warehouses and exposed customer-related data CEVA held on behalf of several downstream clients, including Dutch e-commerce group Bol, department store De Bijenkorf, eyewear retailer Ace & Tate, football club Ajax, and Valve’s Steam hardware business in Europe.

The fallout continued to widen after the initial disclosure. A former CEVA employee subsequently filed a proposed class-action lawsuit alleging the company failed to adequately safeguard employee data stolen in the breach, seeking at least $5 million in damages on claims including negligence and breach of implied contract. Those allegations have not been tested in court.

Think hard about your third-party cyber risks. A logistics provider, payroll processor, marketing platform, or managed service provider can become an extension of your attack surface overnight. Understanding which third parties process your customer data, where operational dependencies exist, and how your incident response plan accounts for disruptions originating outside your own network is no longer optional.

French Tax Authority Data Breach

France’s tax authority, the Direction Générale des Finances Publiques (DGFiP), confirmed that an attacker using the handle ZeroBytes accessed internal systems using the stolen VPN credentials of a legitimate employee, stealing data belonging to approximately 678,000 individuals. The stolen records included reference income figures, family quotients, and withholding tax rates for individuals, plus company names and SIREN numbers for affected businesses. ZeroBytes, a financially motivated actor previously linked to breaches at Intermarché Drive and gaming platform EVA GG, listed the database for sale on the PwnForums hacking forum on August 12.

The breach is notable because it hit one of the French government’s most sensitive departments, using nothing more advanced than a compromised legitimate identity. Tax authorities are attractive targets for financially motivated criminals and other threat actors because they hold extensive personal and financial information.

Businesses sometimes assume that deploying VPNs, identity platforms, or other perimeter controls is sufficient to secure sensitive systems. In reality, those controls are only as strong as the identities permitted to use them — and as the monitoring in place to notice when one behaves unusually.

Latvian CSDD Data Breach

Latvia’s Road Traffic Safety Directorate (CSDD) confirmed that attackers exploited a previously unpatched, undetected vulnerability in an internet-facing application — used by doctors to upload medical certificates for drivers — over the weekend of August 8–9, resulting in the theft of personal data on approximately 1.2 million individuals and 200,000 legal entities — including names, personal identification numbers, addresses, vehicle registration details, and historical payment records.

CSDD’s own specialists ultimately detected and cut off the intrusion, but not before missing Latvia’s legally required 72-hour reporting window. The delay, and the scale of the breach, led to the resignation of both CSDD’s management board and its supervisory council.

What makes the incident particularly instructive is that CSDD wasn’t short on paper protections. A five-year, roughly €9 million contract with telecoms provider Tet explicitly covered round-the-clock infrastructure monitoring, including firewall protection and incident detection. Tet has said its monitoring of data traffic ran continuously throughout, but that unusual traffic volume alone wasn’t a signal that indicated a cyber incident was underway — and CSDD’s own team, not Tet’s monitoring, is what ultimately caught and stopped the attack. A monitoring contract is only as good as the specific signals it’s actually built to detect; security leaders should treat “we have 24/7 monitoring” as a starting question, not a finished answer, and get explicit about which conditions trigger an alert and which don’t.

Manchester Airports Group Data Breach

Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports, confirmed that attackers accessed the personal data of approximately 8.7 million customers and demanded a ransom, which MAG refused to pay. The extortion group FulcrumSec later claimed responsibility, saying it had obtained administrator API keys that had been left exposed in the public-facing JavaScript of each of the three airports’ websites, rather than through any more sophisticated intrusion.

Compromised information included names, email addresses, phone numbers, home towns, postcodes, and residential IP addresses tied to services such as car parking, lounges, Fast Track, and airport Wi-Fi sign-ups — though email addresses alone were exposed for the large majority of the 8.7 million customers affected. After MAG declined to pay, FulcrumSec published an initial batch of roughly 86 GB of compressed data and has since released approximately 550 GB of uncompressed data via the open web rather than a dark-web leak site, significantly increasing its accessibility.

The attack method here deserves as much attention as its scale: a hardcoded admin key sitting in public-facing website code is a basic, easily-avoidable exposure, not a sophisticated intrusion technique. Attackers are also increasingly willing to maximize disruption even when extortion fails — openly releasing millions of records rather than attempting to sell them privately increases the likelihood of downstream phishing and fraud while reinforcing the credibility of future ransom demands against other victims.

Critical CVEs in the August 2026 Cybersecurity Roundup

Five critical CVEs disclosed in August 2026, three already under active exploitation

Three of August’s five critical CVEs are already confirmed under active exploitation.

This August 2026 Cybersecurity Roundup also flagged five CVEs worth patching immediately — three of which are already confirmed under active exploitation and listed in CISA’s Known Exploited Vulnerabilities catalog.

  • Citrix NetScaler ADC & Gateway (CVE-2026-19490, CVSS 9.3): A critical authentication-bypass vulnerability affecting NetScaler ADC and Gateway appliances configured as gateways or AAA virtual servers, letting an unauthenticated remote attacker reach protected resources without valid credentials or user interaction. Fixed in versions 14.1-73.32 and 13.1-63.21 and later; exploitation attempts were already being observed in early September. NetScaler appliances commonly sit at the network edge protecting VPNs and remote access, making authentication-bypass flaws here particularly dangerous.
  • MLflow (CVE-2026-64849, CVSS 9.3): A critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow’s webhook-testing functionality, affecting versions before 3.15.0. Active exploitation began within hours of the CVE being assigned, letting attackers reach cloud metadata endpoints and steal live AWS, GCP, and Azure credentials; CISA added it to its Known Exploited Vulnerabilities catalog on August 19. As AI and machine-learning platforms become common in enterprise environments, they’re also becoming part of the attack surface.
  • Zimbra Collaboration Suite (CVE-2026-73570, CVSS 8.9): An unauthenticated remote code execution vulnerability triggered through Zimbra’s optional SNMP notification handling, letting attackers inject and run arbitrary commands with Zimbra user privileges. Fixed in Zimbra Collaboration 10.1.20; the flaw was added to CISA’s KEV catalog on August 21, and at least 267 Zimbra instances were confirmed compromised within days. Email servers remain high-value targets because they provide access to communications, credentials, and sensitive business information.
  • Adobe Commerce (CVE-2026-71362, CVSS 9.1): A critical incorrect-authorization vulnerability in Adobe Commerce, Commerce B2B, and Magento Open Source, caused by the platform failing to properly bind a customer’s identity to their session — letting an unauthenticated attacker hijack another shopper’s active account session with no credentials or user interaction required. Patched in Adobe’s August 2026 update; exploitation attempts began shortly after disclosure. Adobe Commerce powers thousands of e-commerce storefronts, making timely patching especially important for online retailers.
  • Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS 7.0): A local privilege-escalation vulnerability caused by a use-after-free flaw in the Windows kernel driver that services network socket requests, letting an attacker who already has a foothold on a device escalate to full SYSTEM privileges. Microsoft patched the flaw on August 11; it’s listed in CISA’s KEV catalog, and Check Point Research has tied observed exploitation to a new wave of the DPRK-linked “Operation Dream Job” campaign targeting defense, aerospace, and aviation organizations. Privilege-escalation flaws like this remain a common second stage of ransomware and post-exploitation attacks.

Getting the Fundamentals Right

A security team reviewing findings from a penetration test and monitoring dashboard together

Regular testing and monitoring turn “we have security” into a measurable, verifiable claim.

This August 2026 Cybersecurity Roundup reinforces a straightforward lesson: a compromised identity, an overlooked customer-facing application, or a monitoring contract that isn’t watching for the right signals can do as much damage as any zero-day. Regular penetration testing can uncover vulnerabilities in internet-facing applications before attackers do, phishing simulations help employees recognize social-engineering attempts built around stolen credentials, and managed detection and response (MDR) helps ensure that “we have monitoring” actually translates into an alert when it matters. Just as importantly, organizations should get explicit — in writing — about what any security provider’s monitoring is actually built to catch.

DIESEC helps organizations strengthen these foundations through Penetration Testing that covers internet-facing infrastructure and third-party integrations, SOC-as-a-Service for continuous monitoring built around measurable detection outcomes, and tailored Phishing Simulations that test teams against current attack patterns.

Contact us today to learn how we can help improve your cybersecurity posture.