
Cybersecurity Updates: Solana API Targeted, AI Patch Failures, Gunra Ransomware, and Neo4j Flaw Highlighted in Stormcast Episode
The August 11, 2026, Stormcast episode from the Internet Storm Center covered several cybersecurity developments. Attackers targeted a Solana cryptocurrency development platform’s RPC API via a web honeypot, sending reconnaissance requests to check endpoint health, version, and Ethereum chain status—no active exploits were observed yet. A study by the Off-By-One Lab found that AI-generated patches for 6,000 vulnerabilities failed to address the underlying issues in half of cases, emphasizing the need for human oversight. A joint report by the FBI, U.S. cyber agencies, and South Korea’s National Police Agency detailed Gunra ransomware, which exploits vulnerable SEL VPNs, weak credentials, and protocols like SMB and RDP for lateral movement. Additionally, a critical flaw in Neo4j’s GraphQL implementation allowed attackers to bypass JWT signature validation, enabling unauthorized subscription to other users’ events and potential data leakage. Microsoft’s Patch Tuesday was noted for its high volume of AI-identified vulnerabilities, though AI’s role in patching remains unreliable. The episode concluded with a reminder to secure common ransomware attack vectors.