Security news, decoded.
What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)
SickKids data breach exposes employee and job applicant info
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
Hackers Target Zimbra Servers in Active Exploitation Campaign
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Citrix urges admins to patch new NetScaler flaws as soon as possible
MLflow Vulnerability Exploited for Cloud Credential Theft
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
CISA warns of hackers exploiting critical MLflow vulnerability
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Critical Zimbra RCE flaw now actively exploited in attacks
CERT Polska has confirmed that attackers are actively exploiting a critical remote code execution vulnerability identified as CVE-2026-73570 in the Zimbra Collaboration Suite. This flaw stems from insufficient input sanitization in the SNMP monitoring component, allowing unauthenticated users to execute arbitrary operating system commands when SNMP notifications are enabled. To remediate this issue, Zimbra released version 10.1.20 on July 20. Administrators should urgently apply this update and review system logs for signs of compromise, such as unexpected service restarts or unauthorized file creations within specific Jetty webapp directories.
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Citrix has released security updates for NetScaler ADC and NetScaler Gateway to remediate two distinct vulnerabilities, the most severe being an authentication bypass tracked as CVE-2026-19490 with a CVSS score of 9.3. This critical flaw allows remote, unauthenticated attackers to circumvent access controls on gateways configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA services without any user interaction. A second high-severity issue, CVE-2026-19489, involves a memory overflow in SIP ALG configurations that can result in denial-of-service conditions. Organizations should urgently apply the fixes available in NetScaler versions 14.1-73.32, 13.1-63.21, and other specified builds, as Rapid7 predicts imminent exploitation attempts given the widespread deployment of these appliances in enterprise perimeters.
Critical GitLab Flaw Exploited Shortly After Disclosure
WatchTowr has confirmed that threat actors began actively exploiting CVE-2026-19478, a critical code injection flaw in GitLab Community Edition (CE) and Enterprise Edition (EE), just two days after its public disclosure. The vulnerability allows unauthenticated attackers to remotely manipulate public projects, including deleting repositories and forging merge records, without requiring any prior credentials. Users are urged to update to fixed versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, or mitigate risk by restricting access to the /api/graphql endpoint.
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Researchers have identified a critical vulnerability in the Elementor Pro WordPress plugin that allows unauthenticated attackers to achieve remote code execution through file upload manipulation. Tracked as CVE-2026-32475 with a CVSS score of 9.0, the flaw exists in the Forms module's File Upload field, where discrepancies in extension checking and file handling permit the bypass of security restrictions. This issue affects all versions of Elementor Pro up to 4.2.1, but has been resolved in the recently released version 4.2.2.
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
Threat intelligence firm Hunt.io has identified a 35-day attack campaign dubbed CameraSwarm that compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia. The operation utilized a combination of brute-force attacks against TCP port 37777, exploitation of CVE-2021-33044 and CVE-2021-33045 to install persistent backdoors, and unauthorized cloud-relay access via serial numbers. Researchers recovered extensive operational data, including source code and credentials, from an unprotected server directory left open by the attackers. Administrators are advised to check devices for the malicious 'p2pwn' account, apply firmware updates per Dahua SA-2021-0130, and disable P2P services when not in use.
Critical Unauthenticated File Upload to RCE in Elementor Pro Plugin
A critical unauthenticated remote code execution vulnerability (CVE-2026-32475) affecting the Elementor Pro plugin for WordPress has been patched in version 4.2.2, following the release of a public proof-of-concept. The flaw resides in the Forms module's File Upload field, where a logic discrepancy between validation and processing loops allows attackers to bypass extension blocklists by submitting empty file entries alongside malicious PHP payloads. This issue enables unauthenticated visitors to place executable scripts in public directories if a form with an optional file upload is present, leading to full server compromise. Site administrators are urged to update immediately and review the wp-content/uploads/elementor/forms/ directory for any unexpected PHP files that may have been deployed prior to the patch.
Oracle Critical Patch Update, August 2026 Security Update Review
Oracle has distributed its August 2026 Critical Patch Update, resolving a total of 943 security vulnerabilities across its portfolio. The release places significant emphasis on Oracle Fusion Middleware and Oracle Hyperion, each receiving 262 individual patches, while Oracle Database components addressed 17 specific issues. Notable high-severity fixes include CVE-2026-60782 and CVE-2026-70926 in Oracle E-Business Suite, both rated with a CVSS base score of 9.8 and permitting remote code execution without authentication. Administrators should prioritize deploying these updates to mitigate exposure in network-accessible services such as Oracle Siebel CRM and Oracle Commerce.
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Researchers at Hunt.io identified a campaign dubbed Operation CameraSwarm that exploited over 14,500 Dahua devices between June and July 2026. The attackers utilized credential stuffing, the authentication bypass vulnerabilities CVE-2021-33044 and CVE-2021-33045, and peer-to-peer relay techniques to gain unauthorized access, with significant impacts reported in Ukraine and Russia. These flaws allow bypass of device identity checks and enable connections to devices behind NAT without initial authentication. Affected users are advised to apply firmware updates from Dahua’s official site, disable unnecessary P2P features, and audit credentials to mitigate these risks.
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware group has published the full names of over 40 organizations allegedly targeted through a campaign exploiting CVE-2026-12569, a critical vulnerability in PTC’s Windchill and FlexPLM product lifecycle management platforms. This improper input validation flaw allows unauthenticated remote attackers to execute arbitrary code, marking the first time a Windchill defect has been exploited in the wild. ReliaQuest noted that Cl0p deployed a custom implant to steal credentials and exfiltrate vast amounts of data, including engineering documents and databases, from victims such as Shell, Philips, and Fiserv.
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA has updated its Known Exploited Vulnerabilities catalog to include four high-severity flaws currently being targeted by threat actors. These vulnerabilities affect Apple macOS (CVE-2026-65400), Microsoft SharePoint (CVE-2026-55040), VMware vCenter (CVE-2026-59310), and Microsoft IKE (CVE-2026-33824). Active attacks range from cryptocurrency mining via the macOS flaw to ransomware deployment through the vCenter path traversal bug, with victims reported across 47 countries. Federal agencies are required to apply the vendor-provided patches by August 21, 2026, to mitigate these risks.