Cybersecurity Headlines — August 18, 2026
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware — Internet
- Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI — Theregister.com
- Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI — Theregister.com
- Stopping a cyberattack while walking your dog - defensive AI security CEO says it’s not ruff to do — Theregister.com
- Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day — Help Net Security
- A phone company just lost 1.6 million records to a phone call — The Next Web
- Dark Web Intelligence Claims US Fitness Data Exposure Involving Body20 — Undercodenews.com
- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure — Tenable.com
- Frontier AI Threats Drive Companies to Boost Security Budgets — pymnts.com
- Max severity SAP Commerce Cloud flaw now targeted in attacks — BleepingComputer
From the Trenches
As a cybersecurity practitioner, I’m seeing a disturbing trend of Chinese companies making headlines for all the wrong reasons. The latest exploit to grab my attention is the suspected China-Nexus Actor’s use of a VMware vCenter flaw to deploy Babuk-Derived Ransomware. This is a clear example of nation-state sponsored attacks, and it highlights the need for organizations to prioritize patching their VMware infrastructure.
The fact that this attack leveraged a known vulnerability in VMware vCenter makes it all too easy for attackers to gain access to an organization’s network. As a practitioner, I’ve seen firsthand how quickly these types of attacks can spread once they gain foothold. The Babuk-Derived Ransomware adds another layer of complexity to the threat landscape, making it essential for organizations to have robust incident response plans in place.
Another story that caught my attention is Zhipu’s claim that its new AI model is a better bug-finder than Anthropic and OpenAI. While I’m excited about the potential advancements in AI-powered security tools, I need to see concrete evidence of their effectiveness before I start recommending them to clients. The reality is, no amount of AI can replace good old-fashioned human expertise and vigilance when it comes to cybersecurity.
🔧 Patch Priority: Max severity SAP Commerce Cloud flaw now targeted in attacks.
Compiled daily. Stay patched, stay vigilant.