8news

Tech • AI • Robotics

VIDEO
ENFR
TodayShortsTop StoriesYour topicFor youTopicsAll videosYT channelsArchivesSearchFavorites

Cybersecurity Highlights August 18, 2026: Major French Treasury Breach and Microsoft Copilot Vulnerabilities

CybersecTuesday, August 18, 2026

50 articles analyzed by AI / 251 total

Key points

Audio player
0:00 / 0:00
  • The French Treasury suffered a major cyberattack in 2026 compromising the personal data of approximately 678,000 taxpayers. This breach highlights significant vulnerabilities in government financial systems and has initiated investigations into data security measures and response protocols.[Escudo Digital]
  • The US Department of Justice charged 17 individuals connected to an Iran-backed hacking campaign targeting various US organizations in 2026, showcasing persistent nation-state cyber espionage activities. This large-scale operation underlines ongoing geostrategic cyber conflicts affecting national security.[Cybersecurity Dive]
  • Over 14,000 Dahua cameras across Ukraine and Russia were compromised in Operation CameraSwarm using advanced techniques such as credential brute force and authentication bypass. The attack exposed sensitive operator directories on open servers, demonstrating escalating IoT security challenges in 2026.[Reddit /r/netsec]
  • Healthcare cybersecurity faced setbacks with Baylor Genetics disclosing a breach that exposed sensitive personal and medical data of patients. This 2026 incident underscores the critical need for stronger data protection in health technology environments.[MedTech Dive]
  • Regulatory enforcement in cybersecurity intensified as the New York Department of Financial Services imposed a $250,000 fine on a financial licensee for insufficient cyber risk assessments. This action within 2026 sends a strong message on compliance expectations for financial institutions.[Data Protection Report]
  • Security researchers revealed dangerous vulnerabilities in Microsoft Copilot Personal, including three flaws that allow silent data exfiltration via a single click, raising cloud application security concerns. This discovery in 2026 may prompt urgent mitigation to protect user data in AI-powered environments.[The Hacker News RSS]
  • A critical server-side request forgery vulnerability in the MLflow machine learning platform was exploited to steal cloud credentials and secrets in 2026, highlighting emerging risks in AI/ML cloud infrastructure security. The incident reveals attack vectors targeting model management services.[The Hacker News]
  • GitLab issued an emergency patch in 2026 for a critical code injection vulnerability that threatened arbitrary code execution and compromised DevOps pipelines. This rapid response underscores the importance of timely vulnerability management in software development tools.[Cybersecurity Dive]
  • The Python implant framework TWINLOOT was discovered abusing Microsoft SharePoint and Teams platforms to steal credentials and maintain command-and-control servers. This 2026 finding illustrates sophisticated cyberattack methods using popular collaboration tools for stealthy network infiltration.[The Hacker News RSS]
  • Security analysts identified a typosquatting campaign targeting 16 RubyGems packages designed to steal browser credentials and cryptocurrency wallets. Named StubMaker and identified on August 15, 2026, the campaign reflects ongoing threats in software supply chain security affecting developers and users.[The Hacker News RSS]
Explain this

Relevant articles

Go deeper

This day's Daily Podcast — Top 24h, all topics