Cybersecurity Headlines — August 18, 2026


From the Trenches

As a cybersecurity practitioner, I’m seeing a disturbing trend of Chinese companies making headlines for all the wrong reasons. The latest exploit to grab my attention is the suspected China-Nexus Actor’s use of a VMware vCenter flaw to deploy Babuk-Derived Ransomware. This is a clear example of nation-state sponsored attacks, and it highlights the need for organizations to prioritize patching their VMware infrastructure.

The fact that this attack leveraged a known vulnerability in VMware vCenter makes it all too easy for attackers to gain access to an organization’s network. As a practitioner, I’ve seen firsthand how quickly these types of attacks can spread once they gain foothold. The Babuk-Derived Ransomware adds another layer of complexity to the threat landscape, making it essential for organizations to have robust incident response plans in place.

Another story that caught my attention is Zhipu’s claim that its new AI model is a better bug-finder than Anthropic and OpenAI. While I’m excited about the potential advancements in AI-powered security tools, I need to see concrete evidence of their effectiveness before I start recommending them to clients. The reality is, no amount of AI can replace good old-fashioned human expertise and vigilance when it comes to cybersecurity.

🔧 Patch Priority: Max severity SAP Commerce Cloud flaw now targeted in attacks.


Compiled daily. Stay patched, stay vigilant.