2026-08-16
Review the tracked stories and available summary evidence for the archived period shown.
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- vulnerabilities
Wireshark 4.6.8 Released
Wireshark released version 4.6.8, which addresses 28 vulnerabilities and resolves 25 bugs. The update is available and documented through the SANS Internet Storm Center.
Why it matters: Network analysts and security teams using Wireshark should update to 4.6.8 to patch vulnerabilities that could be exploited through malformed packet captures or live traffic analysis.
- breaches incidents
Large-scale DDoS attacks disrupted Threema secure messaging service
Distributed denial of service (DDoS) attacks disrupted Threema, a secure messaging service, earlier in the week of August 16, 2026. The attacks caused significant service interruptions for users.
Why it matters: Threema users relying on the service for private communications experienced downtime; practitioners should assess whether their organization depends on Threema and consider redundancy or failover options for critical messaging needs.
- threat intel
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
AmnesiaStealer is a newly discovered information-stealing malware targeting macOS users through ClickFix attacks. The malware includes a streaming module that enables attackers to interactively control the victim's web browser, expanding its capability beyond passive data theft.
Why it matters: macOS users are at risk of credential theft and session hijacking through deceptive ClickFix attacks; defenders should monitor for suspicious browser behavior and educate users about fake support prompts.
- breaches incidents
New Jersey Federal Judge Dismisses Data Breach Class Action Against Background Check Company
A federal judge dismissed a class action lawsuit against TABB Inc., a New Jersey background check company, because the plaintiff could not demonstrate concrete injury required for federal court standing. The dismissal centers on whether individuals whose data was exposed in a 2024 breach have legal grounds to sue.
Why it matters: Data breach plaintiffs and their counsel should track this ruling, as it raises the bar for establishing standing in breach-related federal litigation and may affect similar cases pending against background check firms and other data handlers.
- breaches incidents
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack
Anubis ransomware group claims responsibility for attacking Fairlife, a Coca-Cola subsidiary, exfiltrating data from approximately 500 hosts totaling 1 TB. The group provided exclusive details to a researcher outlining its methods and stated it would not negotiate, while Coca-Cola's public statements differ from the attacker's account of the incident.
Why it matters: Beverage and food supply chain organizations need to assess their exposure to ransomware groups targeting large corporations; the public disagreement between victim and attacker narratives makes it difficult to assess actual data exposure and the credibility of threat claims.
- breaches incidents
Rep. Thompson brings bipartisan rural hospital cybersecurity act to House
A bipartisan group of six House representatives introduced the Rural Hospital Cybersecurity Enhancement Act, aimed at strengthening cyber defenses for rural hospitals. The bill targets a sector facing acute resource constraints and exposure to cyber threats.
Why it matters: Rural hospital administrators and healthcare IT leaders need to monitor this legislation as it may establish new federal cybersecurity requirements, funding mechanisms, or compliance timelines affecting their operations.
- vulnerabilities
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
GitHub extended Dependabot malware alerts to cover eight package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, after previously monitoring only npm. The expansion provides developers with warnings across a broader range of dependency sources.
Why it matters: Developers relying on non-npm packages now gain malware detection visibility in their supply chain; practitioners should update their dependency scanning processes to leverage the newly covered ecosystems.
- breaches incidents
NC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposed
Wake County Board of Elections suspended use of a software vendor after the vendor reported a possible cyberattack. County officials stated that voting machines, ballots, voter registration records, and vote-counting systems were not affected, though poll workers' data may have been exposed.
Why it matters: Election administrators and poll workers in Wake County and similar jurisdictions should verify whether their personal information was compromised and monitor their accounts for fraud. Practitioners should assess whether their election software vendors have adequate security controls and incident response plans.