Daylila

Cybersecurity · Tuesday, 18 August 2026

01 · Briefing · what happened

AI is finding flaws faster than ever. Devices past their support date get none of the fixes.

Cybersecurity 7 min 29 sources

A record year for discovered flaws collided this week with a botnet built from bugs as old as 2007. The gap between what gets found and what gets fixed is now the story.

398

flaws Microsoft fixed in one day

42 critical, one known to be under attack

50,340

flaws recorded in 2026 so far

up more than 72% on all of last year

2007

age of a flaw still being used

one of several the new botnet exploits

1.7bn

passwords stolen in six months

from 7.4 million infected devices

At a glance

  • Microsoft fixed 398 security holes in one Tuesday, 42 of them critical, but only one is known to be under attack.
  • 50,340 software flaws have been publicly recorded in eight months of 2026, more than 72% above all of 2025.
  • Cisco's chief executive says AI bug-finding is pushing customers to rip out unsupported network kit fast.
  • A new botnet, Evooo1Bot, is taking over routers and cameras using flaws first published as far back as 2007.
  • It turns each device into a relay that hides the attacker's traffic or opens a path into the network behind it.
  • SonicWall broke its own rule and patched two critical flaws in a product it had already discontinued.
  • A VMware flaw disclosed 29 July was being attacked by 5 August, reaching 361 victims in 47 countries by 7 August.
  • Breaches this week hit 1.6 million RingCentral accounts, 678,000 French taxpayers and possibly 19 million Poles.

Forces in play

Flaw discovery High

AI bug-hunting pushed recorded flaws to 50,340 in eight months, up 72% on all of 2025, and Microsoft now ships hundreds of fixes a month.

Ageing devices exposed High

The Evooo1Bot botnet is taking over routers and cameras from Alcatel, NETGEAR and D-Link using flaws published as long ago as 2007.

Speed of attack Building

A VMware flaw went from public disclosure on 29 July to 361 victims in 47 countries by 7 August; a GeoServer flaw drew attacks within hours.

Stolen passwords High

Flashpoint counted 1.7 billion passwords harvested from 7.4 million infected devices in six months, and ransomware victims up 45%.

Fixes for old devices Easing

SonicWall patched two critical flaws in its discontinued GMS platform, showing a support cut-off is a company policy and not a law.

Actually exploited Easing

Fewer than 1% of reported flaws show signs of being usable, and just one of Microsoft's 398 is known to be under attack.

In play Microsoft — shipped 398 fixes in one day, including one flaw already under attack Fortinet researchers — found the botnet exploiting flaws as old as 2007 NIST — asking whether AI should help run the US flaw database SonicWall — patched a product it had already discontinued CISA — added three actively exploited flaws to its catalogue on 11 August

How it unfolded

  1. 29 Jul Broadcom discloses the critical VMware vCenter flaw
  2. 5 Aug attacks on it begin; 361 victims in 47 countries by 7 August
  3. 11 Aug Microsoft fixes 398 flaws; CISA adds three exploited bugs
  4. 12 Aug GeoServer flaw posted publicly; attacks start within hours
  5. 17 Aug researchers detail the botnet built on 2007-era flaws

Where this points

Watch whether vendors start extending support on widely deployed kit rather than only shortening it, and whether the flood of machine-found flaws produces more fixes or just a longer queue.

Full briefing

Two numbers tell this week’s story, and they point in opposite directions.

The first is 398. That is how many security holes Microsoft closed in a single Tuesday’s update, 42 of them rated critical [3][4]. The second is 2007. That is the year of one of the flaws a newly discovered botnet is still using, right now, to break into home and office routers [5].

Both numbers are the same fact seen from different ends. Software makers are finding and fixing flaws faster than at any point in the industry’s history. Anything that has stopped receiving fixes is being left behind at exactly the same speed.

The bug-finding machine changed gear

Eight months into 2026, 50,340 software flaws have been publicly recorded. That is more than 72% up on the whole of 2025, per an analysis by Cisco engineer Jerry Gamblin cited by Dark Reading [2]. The cause is not that software suddenly got worse. It is that machines got better at reading it.

Cisco chief executive Chuck Robbins has a name for the effect. He calls it “The Mythos Effect”, after Anthropic’s bug-finding model, and told investors it will push customers to scour their networks for unsupported devices and replace them fast [1]. Adobe now ships security bulletins twice a month rather than once. Cisco, Google, Mozilla and Oracle are all patching more often and in larger batches [3].

The keeper of the official US flaw database is struggling to keep pace. On 12 August the National Institute of Standards and Technology asked the public whether artificial intelligence should help run the National Vulnerability Database, with comments open until 13 October [2]. Its own request said the traditional approach, built on periodic scanning and manual fixing, is “increasingly apparent” in its inadequacy [2].

A word on the counting. Different trackers count different things, and their totals diverge sharply. CVE.ICU counts formal CVE records and reports the 72% surge above [2]. The threat-intelligence firm Flashpoint counts what it calls vulnerability disclosures, logged 21,667 in the first half of 2026, and puts the rise at 8% [9]. Both are real measurements of different objects. Neither is the number of flaws anyone is actually being attacked with.

That last point matters. Fewer than 1% of reported flaws show signs of being exploitable, on Gamblin’s reading of GitHub and VulnCheck data [2]. Of Microsoft’s 398, exactly one is known to be under active attack [3]. It is CVE-2026-68820, a flaw in afd.sys, the driver behind Windows network connections on effectively every machine [3]. Check Point Research says the North Korea-linked Lazarus group used it in a campaign aimed at defence firms [4].

What the other side of the line looks like

While supported products get more fixes, unsupported ones get an audience.

Fortinet researchers this week detailed Evooo1Bot, a Linux botnet built on the leaked Mirai code that has been quietly taking over edge devices since at least July [6][7]. It targets kit from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link [6]. The list of flaws it exploits includes CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931 and CVE-2020-10987 [5].

None of those is new. Some are nearly two decades old. As one researcher quoted by Dark Reading put it, attackers do not need cutting-edge tools when forgotten devices carry old flaws [5].

What the botnet does with them has changed, though. Beyond the usual flooding attacks, Evooo1Bot turns each infected router, firewall or camera into a relay for someone else’s traffic [7]. Fortinet says the victim’s own internet address then disguises the attacker’s activity, or opens a path into the network behind the device [7]. Newer builds also probe Hikvision cameras, Zyxel firewalls, TP-Link routers and Kubernetes ingress software [6]. Some of those exploits are badly written and simply fail [6].

The defenders’ advice is plain, and unusual for naming the hardest step. Update firmware, change default passwords, switch off remote access panels, and replace devices once the maker stops supporting them [6].

The honest counter-example

Support endings are a policy, not a law of physics, and a vendor can choose otherwise. SonicWall this week patched two critical flaws in its GMS management platform, a product it has discontinued [8]. CVE-2026-66147 scores 9.4 and CVE-2026-66145 scores 9.1; both let a remote attacker with no account run code on the server [8]. Fixes landed in version 9.5.2 [8].

That is a vendor coming back for a product it had already put down. It happens. It is not something a buyer can count on.

The clock on everything else

For supported software, the gap between disclosure and attack keeps shrinking.

Broadcom disclosed a critical VMware vCenter flaw, CVE-2026-59310, on 29 July [10]. Attacks began by 5 August [10]. By 7 August, 361 victim internet addresses across 47 countries had been identified, more than half in Germany, the United States, Turkey, Iran and France [11]. The attackers installed an open-source reverse-SSH tool to keep a way back in [11]. Dark Reading notes that applying the patch may not be enough on its own, because that foothold survives it [12].

An unpatched flaw in GeoServer, open-source mapping software, went public on X on 12 August at 10:46 UTC [14]. Attack attempts began within hours, and researchers at watchTowr have since recorded hundreds of them [13]. It still has no CVE number and no patch [14].

A Microsoft SharePoint flaw patched in July, CVE-2026-55040, started drawing attacks after Rapid7 published proof-of-concept code, with eight of twelve recorded attempts landing on 12 and 13 August [15]. A separate SharePoint flaw, CVE-2026-45659, was flagged by CISA on Tuesday as now being used by ransomware crews [16]. And a Cisco firewall flaw, CVE-2026-20349, is being exploited to knock devices offline through their remote-access VPN service [17]. CISA added three flaws to its catalogue of actively exploited bugs on 11 August, including the Cisco and Windows ones [18]. On 17 August it added one more, a code-injection flaw in the Ray machine-learning framework [19].

The week’s breaches

The extortion group ShinyHunters took personal data on 1.6 million RingCentral accounts after breaking in during July [20]. France’s tax authority confirmed an intruder viewed and extracted data on 678,000 people and businesses, entering in late June through a stolen or misused identity [21]. Poland is investigating a breach at MyDr, a healthcare software supplier, that may touch nearly 19 million people and more than 12,000 medical facilities [22].

Suisun City, a Bay Area town of 30,000, lost 911 call routing, police and fire dispatch to a cyberattack on a Friday [23]. It declared a state of emergency the next day [23]. It was one of several US local governments hit in a week [23].

A July attack on the freight company Ceva Logistics disrupted eight European warehouses [24]. The ripples reached retailers including Bol, De Bijenkorf and Ace & Tate, plus Steam’s hardware business [24]. Pokemon Center is now notifying UK and German customers that their order details were exposed [25].

Stolen passwords remain the cheapest way in. Flashpoint recorded 7.4 million devices infected with password-stealing malware in the first half of 2026, up 27%, harvesting 1.7 billion credentials [9]. It also counted 6,256 ransomware victims, up 45% on the previous six months [9].

The LiteLLM supply-chain compromise shows how those numbers get made. Terabytes of credentials, including cloud keys belonging to Microsoft, Amazon, Cisco, Samsung and Salesforce, were scraped during a 40-minute window in March [27]. CloudSEK’s dataset maps potential exposure to more than 2,500 organisations, having earlier said 2,100 [28]. The firm told The Hacker News that figure is not a victim count, but a map of what the attackers captured [28]. SecurityWeek reports that over 95% of affected companies were exposed through the earlier hack of the Trivy scanner, before the poisoned LiteLLM packages even shipped [26].

The long tail

One story this week is a preview of how slowly consequences arrive. Britain’s data regulator formally reprimanded the Criminal Records Office over a breach that ran from August 2022 to March 2023 [29]. An intruder reached its website and content system, exposing names, dates of birth, passport and bank details, and criminal-record information on 10,920 people [29]. Record-keeping was so poor that, three years on, nobody can say whether the data was actually taken [29].

The break-in was old. The reckoning is this week.

02 · Lesson · why it matters

The thing that got more dangerous without changing

Nothing about the router changed. The world around it did, and that was enough to make it unsafe.

How it works

  1. A product ships genuinely secure for its time
  2. The world keeps moving: new flaws found, new techniques become routine
  3. Fixes keep arriving, so the product keeps pace
  4. Support ends, and the fixes stop
  5. The finding does not stop, so the gap opens on its own
  6. The device is now less safe than the day it shipped, unchanged

The twist

Security is not something a product has. It is a relationship with a world that keeps moving, so a device nobody has touched in five years is less safe than it was.

Where you've seen this

Old medicine

a drug approved decades ago is not withdrawn when it stops being reviewed against newer evidence

Building codes

a house built to 1970s standards was legal then and is not rebuilt when the rules move

A written contract

clear terms in one era become ambiguous when the practices they assumed disappear

A qualification

training that matched the job in 1995 has not changed, but the job has

The catch

Running something past its end date is rarely carelessness. It is the machine that cannot be switched off, the supplier that no longer exists, or the safety certificate a replacement would void.

Full lesson

A flaw from 2007 is still the way in

Somewhere right now a router is being taken over using a flaw published in 2007. Not a clever new attack. A bug that was written up, given a number, and fixed by the maker while most of today’s phones did not exist.

The device running it has not changed either. Nobody misconfigured it. Nobody switched off a protection. It sits where it was installed, doing the job it was bought for, and it is now part of somebody else’s network of hijacked machines.

That is worth sitting with. A thing became dangerous without changing.

Security is not a property. It is a relationship.

We talk about security as if it lives inside the product, like weight or colour. A secure router. A secure operating system. As if you could measure it once and write the number down.

But security is a relationship between a thing and its surroundings, and only one half of that pair holds still. The other half moves constantly.

Three things move. People keep finding flaws in code that was already written, so a product’s flaw count only ever goes up. Techniques that were research papers become tools anyone can run. And the assumptions the design rested on quietly expire: this key length is plenty, nobody scans that port, no one bothers attacking hardware this small.

A product that keeps getting fixes gets pushed back up as the world pulls it down. That is what a patch is. Not an improvement, mostly. A correction against drift.

What the end of support ends

This is not the same as the gap between a flaw becoming known and a fix arriving. That gap is uncomfortable, but it closes. Someone ships the patch and the clock stops.

The end of support ends only the fixing. It does not end the finding. Researchers keep looking at that code, because the code is still running out there in the world. Attackers keep looking harder, because now nothing they find will ever be closed.

So the gap does not open and shut. It opens and stays open, and widens on its own, every month, with no further help from anyone.

The machine is unchanged. Its safety is not.

The date is a decision wearing the costume of a fact

An end-of-support date reads like a property of the product, the way a food expiry date reads like a property of the food. It is not. It is a number a company chose, weighing what it costs to keep maintaining old code against what it earns by selling the replacement.

You can watch the choice being made. This week a firewall maker released fixes for two serious flaws in a management product it had already discontinued. It could have said no. Nothing physical stopped it. It decided otherwise.

Which means the reverse is also true. When a maker stops, it is not because the thing has worn out. It is because supporting it stopped paying, and the risk moved from the company’s ledger to the owner’s.

Why the old machine is still switched on

The obvious response is that people should just replace things, and the obvious response is mostly wrong about why they don’t.

Some of it is money. Much of it is not. It is the production line that cannot be stopped without shutting a factory. It is the supplier that went under, leaving nobody to buy the new version from. It is the safety certificate that took two years and would have to be redone. It is the camera at the top of a mast in a field.

Old equipment is usually still running because of a real constraint. It is held by someone who knows perfectly well it is a risk and cannot get past it.

Who is inside this

You are, twice over.

Once directly: the router in the corner of your home, the phone in a drawer, the smart plug bought four years ago from a company that has since stopped answering. None of them will tell you the day the fixes stopped. There is no light that comes on.

And once through everyone else. A hijacked router becomes a relay, so someone else’s attack travels out under your address. A town’s ageing systems carry its 911 dispatch. A logistics company’s old server holds the address you gave a shop. The costs land far from the machine.

The uncomfortable part is that nobody has the full list. Not the company, not the regulator, not you. Every organisation that gets breached this way has an inventory it believed was complete. The gap between what we think we are running and what is actually plugged in is where most of this lives, and no single seat can see it.

03 · Lab · your turn

The Standstill

Rehearse the choice of what to replace and when, and feel how the cost of leaving a device past its support date compounds every year.

04 · Hope · carry this

The flaws are found faster now because people built machines to hunt them. For anything still being looked after, that same speed is exactly why it is safer this year than last.

Across the beats