Today’s digest is a reminder that “patch it” and “notify the people affected” run on very different clocks: CISA’s latest Known Exploited Vulnerabilities update covers flaws attackers are already using right now, while two breach disclosures show incidents from months ago still growing as investigations wrap up. Here’s what’s new since yesterday’s digest.
Actively exploited watch: CISA adds four actively exploited flaws in Apple macOS, SharePoint, VMware vCenter, and Windows IKE to its KEV catalog
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18 based on confirmed evidence of active exploitation, giving federal agencies until August 21 to patch. CVE-2026-65400 (CVSS 9.8) is an improper-authentication bug in Apple macOS that lets an attacker on the network authenticate to Screen Sharing without valid credentials. CVE-2026-55040 (CVSS 9.1) is a weak-authentication flaw in Microsoft SharePoint that lets an unauthorized attacker bypass a security feature over the network. CVE-2026-59310 (CVSS 9.8) is a path-traversal vulnerability in Broadcom VMware vCenter that lets a threat actor with network access to vCenter execute arbitrary code — researchers have tied exploitation to a suspected China-nexus APT. CVE-2026-33824 abuses a double-free in the Windows IKE service to achieve remote code execution over the network. CISA · The Hacker News
Four unrelated products landing in the same KEV batch is a good forcing function to check all four at once rather than triaging one and forgetting the rest. If you run vCenter, SharePoint, or manage macOS or Windows fleets, confirm patch status today — the vCenter path-traversal bug in particular carries the kind of unauthenticated, network-reachable code-execution profile that state-aligned actors move on fast.
Breach watch: A third-party cloud platform breach at Heights Finance exposes Social Security numbers for 1.2 million loan customers
Consumer lender Heights Finance is notifying more than 1.2 million people that hackers accessed a third-party cloud platform used to store customer data, after discovering the intrusion on May 7 and completing its investigation ahead of notifications that began August 11. The exposed data includes names, addresses, phone numbers, Social Security numbers, government ID and driver’s license numbers, dates of birth, and bank account details. Heights says the platform has since been secured, its own loan-management systems and networks were not affected, and the incident was reported to federal law enforcement. Notices filed with state attorneys general put the bulk of those affected in Texas (734,828) and South Carolina (486,463). Heights is offering 24 months of free credit monitoring and identity-protection services. SecurityWeek · Security Affairs
A three-month gap between discovery and public notification is fairly typical for an incident this size, but it’s a reminder that “breach discovered” and “breach disclosed” are different dates worth tracking separately in your own incident response planning. If your organization stores SSNs or financial account data with a third-party cloud vendor, this is a fair prompt to confirm what monitoring and access logging you actually get visibility into on their side, not just your own.
Breach watch: A healthcare data breach at EHR provider CareCloud grows to 3.7 million patient records
CareCloud, an electronic health record and healthtech vendor, confirmed in an August 18 filing with the Department of Health and Human Services that a breach first disclosed in July now affects more than 3.7 million individuals — up from the roughly 350,000 CareCloud reported when it began notifications on July 25. The investigation found attackers had access to one of CareCloud’s AWS environments between March 10 and March 16, 2026, taking names, addresses, Social Security numbers, driver’s license numbers, dates of birth, health insurance details, and medical and healthcare information. No cybercrime group has publicly claimed responsibility, and CareCloud has not attributed the intrusion. It now ranks as one of the largest healthcare data thefts disclosed so far this year. TechCrunch · BleepingComputer
A tenfold jump in the confirmed victim count between the initial notification and the final HHS filing is the pattern to expect from any breach investigation that starts with log analysis in a cloud environment — early counts are frequently a floor, not a ceiling. If you handle protected health information in AWS or another cloud environment, this is a good case for reviewing how far back your access and data-egress logs actually retain, since a five-month-old intrusion window is exactly what investigators need to reconstruct after the fact.
Final thought
Today’s stories split cleanly into two clocks: CISA’s KEV additions are an act-now list, four unrelated products attackers are exploiting today. The Heights Finance and CareCloud disclosures are the opposite — both traced back to intrusions from months earlier, with victim counts and scope still settling as investigations closed out. Keeping both timelines in view is the job: patch what’s being exploited right now, and make sure your logging depth can still answer “how far back does this go” months after the fact. If you want help sizing up your log retention against that kind of after-the-fact investigation, see our how-to guides or book a discovery call.