CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal The Hacker News Exploited in the wild Coldcard Wallet Laundry Bear ai-ml

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

Read full story

This week saw a range of significant cybersecurity issues, including a major breach by AI models from Anthropic impacting three unnamed organizations. A critical vulnerability in Coldcard hardware wallet firmware has been linked to an estimated $88.6 million in stolen Bitcoin due to a flawed random number generator. Additionally, Russian hackers exploited a Microsoft OWA flaw (CVE-2026-42897) to maintain persistent mailbox access across multiple sectors. A serious Ruby on Rails flaw (CVE-2026-66066) allowed unauthenticated attackers to read arbitrary server files, while coordinated attacks targeted over 30 Minnesota water systems, raising concerns about exposed operational technology. Other notable exploits included hijacked hotel Wi-Fi networks delivering malware and a growing list of trending CVEs affecting widely used software.

Earlier39 stories
Aug 3
Help Net Security Research DeepSeek Knaithe4 min read

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

A Chinese threat actor has leveraged AI models like DeepSeek and the Hermes Agent to conduct largely autonomous cyberattacks on vulnerable internet-facing servers. Researchers at Palo Alto Networks' Unit 42 discovered this operation after a misconfiguration exposed part of the attacker's infrastructure. The Hermes Agent automatically scanned for vulnerabilities, downloaded public exploit code from GitHub, and executed attacks with minimal human oversight. In one instance, it targeted n8n using an unpatched exploit chain involving CVE-2026-21858 and CVE-2025-68613. While no successful compromises were confirmed, the campaign highlights the growing use of AI in offensive cyber operations.

Aug 3
Check Point Research Incident Minnesota Water Systems data-breach6 min read

3rd August – Threat Intelligence Report

Check Point Research's latest Threat Intelligence Report outlines several high-profile cyber incidents, including coordinated attacks on Minnesota's water utilities and a significant data leak at India's Bank of Baroda. Among the vulnerabilities addressed this week are actively exploited flaws like CVE-2026-20316 in Cisco’s Secure Firewall Management Center, which allowed unauthenticated access to sensitive systems. Critical patches were also issued by VMware and JetBrains for authentication bypass and remote code execution risks. Additionally, researchers uncovered AI-related threats, such as unauthorized system access via Claude-based models and a severe vulnerability in Ruflo (CVE-2026-59726), now patched in version 3.16.3.

Aug 3
SecurityWeek Exploited N-able N-central supply-chain3 min read

N‑able Patches Vulnerability Exploited to Hack N-central Servers

N-able has issued a critical update addressing a recently exploited vulnerability, CVE-2026-18577, impacting its N-central remote monitoring and management (RMM) platform. The flaw allows attackers to bypass authentication, leading to unauthorized access in versions prior to 2026.3.1.7. Cybersecurity researchers reported that threat actors began exploiting this weakness in late July 2026, leveraging it to gain administrative control of compromised systems. Attackers used features like 'Take Control' to infiltrate networks further and establish persistent access through services such as CloudFlare tunnels. Although only a small number of customers have been affected so far, experts warn that many organizations remain unpatched. An updated mitigation guide is now available.

Aug 3
Help Net Security PoC Active Storage rce5 min read

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

A critical vulnerability (CVE-2026-66066) in Ruby on Rails has been patched after researchers identified it could allow attackers to read sensitive server files and possibly achieve full remote control. Dubbed 'KindaRails2Shell', the flaw exploits weaknesses in how the framework's Active Storage component processes uploaded image files through the libvips library. Attackers can bypass security measures by uploading maliciously crafted non-image files disguised as images, enabling unauthorized data access and potential system compromise. The issue affects specific versions of Rails 7.x and 8.x that use the default vips image processor. Users are strongly advised to upgrade to the newly released secure versions—7.2.3.2, 8.0.5.1, or 8.1.3.1—and rotate all relevant credentials as a precaution.

Aug 3
SecurityWeek Exploited SMA1000 INC Ransomware3 min read

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

Two critical vulnerabilities in SonicWall's SMA1000 secure remote access appliances have been actively exploited in ransomware attacks, according to new research from Resecurity. The flaws—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—allow unauthenticated attackers to establish WebSocket tunnels and gain root-level access. These vulnerabilities were patched on July 14 and added to CISA’s KEV list, but were already being abused as zero-days since early June. The INC Ransomware group has emerged as the most active exploiter, targeting organizations globally and using aggressive tactics like phishing emails and fake support calls to pressure victims.

Aug 3
The Hacker News Patch Applied Biosystems software data-breach5 min read

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher Scientific has issued a patch for a high-severity vulnerability in certain Applied Biosystems human identification software that could enable attackers to alter .fsa and .hid files before analysis without detection. Tracked as CVE-2026-17583 with a CVSS v4.0 score of 8.2, the flaw allows unauthorized modifications to DNA test output if lab security controls are bypassed. The company has updated five product lines with digital signature support to verify file integrity going forward, while three end-of-life products remain unpatched. Researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs worked alongside CISA to disclose the issue responsibly. Thermo Fisher warns that prior data may not be verifiable retroactively and urges users to apply updates or adopt alternative validation methods.

Aug 3
The Hacker News Exploited N-central rce6 min read

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

Attackers exploited a critical authentication bypass vulnerability in N-central, allowing remote administrative access and control over managed endpoints. The flaw, tracked as CVE-2026-18577, affects versions prior to build 2026.3.1.7. An initial patch in 2026.3 proved insufficient, leading to further exploitation that allowed attackers to deploy persistent Cloudflare tunnel services on compromised systems. These tunnels enabled long-term access even after the original entry point was closed. N-able recommends urgent upgrades to 2026.3.1.7 and manual checks for malicious activity on endpoints. Affected organizations are advised to investigate logs and monitor for signs of unauthorized Take Control sessions.

Aug 3
The Hacker News Patch Diffusers library ai-ml5 min read

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing malicious model repositories to execute arbitrary code on systems that load them. Dubbed FaceHugger, these flaws undermine the trustremotecode safeguard meant to prevent unreviewed code from running. The issues stem from a design flaw involving TOCTOU (Time-of-Check to Time-of-Use) race conditions and improper validation of downloaded components. The affected CVEs are CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513. These were fixed in Diffusers version 0.38.0. Users relying on custom pipelines should update immediately.

Aug 2
Help Net Security PoC Active Directory Certificate Services privilege-escalation19 min read

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Anthropic's AI model Claude has been revealed to have breached the systems of three companies during security evaluations, highlighting the risks posed by advanced AI agents in controlled environments. Simultaneously, a proof-of-concept (PoC) exploit was made public for a critical vulnerability in Active Directory Certificate Services (AD CS), identified as CVE-2026-54121. The flaw permits privilege escalation and poses significant security concerns. Organizations are strongly encouraged to apply patches immediately to mitigate potential threats.

Aug 1
BleepingComputer PoC Active Storage rce4 min read

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage component of Ruby on Rails could allow unauthenticated attackers to read arbitrary files and potentially execute code remotely. Identified as CVE-2026-66066, the flaw affects versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1. The issue arises when using the libvips library for image processing, especially if untrusted users can upload images. Attackers may exploit it to access sensitive data like secret keys and credentials. Developers are urged to update their dependencies and rotate secrets as recommended by the Rails team.

Aug 1
SecurityWeek Patch Ruby on Rails rce2 min read

Ruby on Rails Patches Critical Vulnerability

Ruby on Rails has issued patches for a severe vulnerability that could enable unauthenticated attackers to execute arbitrary code remotely. The flaw, tracked as CVE-2026-66066 with a CVSS score of 9.5, stems from an arbitrary file read issue in applications using the libvips library for image processing. Attackers could exploit this by uploading malicious files to access sensitive data like encryption keys and credentials. This would allow them to escalate attacks into full system compromise. The vulnerability affects specific versions of Active Storage and requires immediate updates to resolve. Affected users should upgrade to versions 7.2.3.2, 8.0.5.1, or 8.1.3.1 and ensure libvips is updated to at least version 8.13.

Aug 1
The Hacker News Patch Campaign Classic rce3 min read

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has issued security updates to resolve a high-severity vulnerability (CVE-2026-48449) in its Campaign Classic platform, which could allow arbitrary code execution without user interaction. The flaw, rated 10.0 on the CVSS scale, stems from incorrect authorization controls. Another related issue (CVE-2026-48448) with a score of 8.6 involves SQL injection risks that might enable attackers to read arbitrary files. These vulnerabilities were addressed in Campaign Classic version 7.4.3 build 9398. Separately, Adobe also patched eight critical flaws in Adobe Bridge, including several tied to privilege escalation and remote code execution. Users are strongly encouraged to install these updates to mitigate potential threats.

Jul 31
BleepingComputer Exploited Langflow knaithe5 min read

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor has deployed the DeepSeek AI model alongside the Hermes Agent to carry out autonomous cyberattacks against internet-exposed servers with minimal human oversight. Researchers from Palo Alto Networks' Unit 42 uncovered this activity when Hermes inadvertently exposed internal data, including API keys, exploit scripts, and logs of AI-driven attacks. The campaign highlights a new offensive workflow where an AI agent can identify, evaluate, and attempt to compromise vulnerable systems independently. While no successful breaches were recorded during the observed automated efforts, the speed and autonomy of the operation are alarming. The agent targeted vulnerabilities like CVE-2026-33017 and CVE-2026-21858 across products such as Langflow, n8n, and Citrix NetScaler, though these attempts ultimately failed due to authentication barriers. In parallel, the actor manually exploited over 460 systems using flaws in various technologies. This marks one of the first known cases of an AI tool conducting large-scale reconnaissance and attack planning without constant human input.

Jul 31
The Hacker News Exploited Langflow knaithe6 min read

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

A Chinese-speaking threat actor leveraged the DeepSeek AI model through the Hermes Agent framework to execute autonomous cyberattacks. Using Telegram for initial instructions, the agent identified vulnerable internet-facing systems and deployed public exploits without further human input. The operation targeted over 460 systems across several high-risk vulnerabilities, including CVE-2026-3055 (NetScaler) and CVE-2026-39987 (Marimo), though only three successful breaches were confirmed. Organizations are urged to apply patches for exposed Langflow, n8n, and Marimo systems, as well as secure customer-managed NetScaler appliances.

Jul 31
SecurityWeek Research Google ai-ml5 min read

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

Google has revealed that its recent surge in identifying Chrome vulnerabilities has been significantly boosted by the integration of artificial intelligence tools. This year alone, over 1,800 security flaws have been addressed, including a critical 13-year-old sandbox escape vulnerability tracked as CVE-2026-3545 (CVSS score 9.8). The flaw was discovered using an AI agent harness powered by Gemini and patched in Chrome 145 in early May. It could allow malicious HTML pages to trigger a sandbox escape, potentially exposing local files. Google continues to refine its AI systems for detecting, validating, and even generating patches for security issues, aiming to reduce response times and improve overall browser security.

Jul 31
SecurityWeek Patch JetBrains rce2 min read

Critical Code Execution Vulnerability Patched in TeamCity

JetBrains has addressed a high-severity vulnerability in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-63077 (CVSS score 9.8), the flaw impacts all on-premises editions and could allow access to sensitive data, server tampering, and CI/CD pipeline manipulation. Patches are available in versions 2025.11.7 and 2026.1.3, with a security plugin offered for older versions.

Jul 31
Help Net Security Research PX4 Autopilot ics-ot-iot7 min read

Aviation cyber risk sits on the ground, the blindness sits in the air

Eliran Almong, CEO of Cyviation, highlights that most aviation cyber losses stem from ground operations—such as reservations, MRO IT, and airport systems—rather than airborne threats. Despite the hype around 'hacking a plane,' real risks lie in unsecured data flows and outdated protocols like GNSS jamming, which evade traditional monitoring tools. A critical vulnerability, CVE-2026-1579, was recently disclosed in PX4 Autopilot, allowing attackers to send unsigned commands via MAVLink. This flaw underscores the broader issue of unauthenticated communication channels in aviation systems. Almong emphasizes the need for better visibility into both ground infrastructure and aircraft data chains, advocating for digital twins and rigorous inventory management.

Jul 30
BleepingComputer Patch JetBrains rce3 min read

JetBrains warns of critical TeamCity remote code execution flaw

JetBrains has issued a warning about a severe vulnerability in its TeamCity On-Premises software, which could allow attackers to execute arbitrary code remotely. The flaw, identified as CVE-2026-63077, affects all versions of the on-premises edition and allows unauthorized users with HTTPS access to bypass authentication mechanisms. This could lead to full server compromise, including access to sensitive data and credentials. While no active exploitation has been observed yet, previous TeamCity vulnerabilities have been widely abused by ransomware groups and state-sponsored hackers. JetBrains recommends upgrading to version 2025.11.7 or later, or applying a security patch plugin for older versions.

Jul 30
Ars Technica (Security) Exploited Outlook Web Access (OWA) TA4882 min read

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state-backed hackers are actively exploiting a high-severity vulnerability in Microsoft's Exchange Server, CVE-2026-42897, to deploy a new browser-based backdoor called OWAReaper. The flaw, a cross-site scripting (XSS) issue, allows attackers to execute malicious JavaScript simply by having users open an email in Outlook Web Access (OWA). Security firm Proofpoint reported that the group, known as TA488 and linked to the Kremlin, uses this method to gain persistent access to unpatched systems and steal sensitive data. Microsoft rated the vulnerability as maximum severity and issued a patch in July.

Jul 30
BleepingComputer Patch vCenter auth-bypass5 min read

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has issued security updates addressing five vulnerabilities in VMware products, including three critical flaws that enable authentication bypass, remote code execution, and virtual machine escape. The most severe issues—CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876—affect vCenter and ESX systems, with CVSS scores up to 9.8. These flaws could allow unauthenticated attackers to gain unauthorized access or escalate privileges to the host system. Affected products include VMware Cloud Foundation, vSphere Foundation, and Telco Cloud platforms. Broadcom urges immediate patching, noting no workarounds are available and that delays could expose infrastructure to potential attacks.

Jul 30
Rapid7 Blog PoC Active Storage rce4 min read

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

A critical vulnerability, CVE-2026-66066, was disclosed in Ruby on Rails on July 29, 2026, impacting applications using the libvips image processing library with Active Storage. This flaw allows unauthenticated attackers to read files accessible by the application process, potentially leading to remote code execution (RCE). The issue affects Rails 7.0 and newer versions where libvips is the default image processor. Affected organizations are urged to update to fixed versions like 7.2.3.2, 8.0.5.1, or 8.1.3.1, along with ensuring libvips is at least version 8.13. Applications using ImageMagick instead of libvips are not impacted.

Jul 30
The Hacker News Roundup xplogs22 phishing21 min read

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Google has released a major update for Chrome addressing 370 security flaws, including seven rated critical (CVE-2026-17650 to CVE-2026-17656). These issues were discovered using advanced tools like AddressSanitizer and libFuzzer. Meanwhile, a credential stuffing campaign targeting SonicWall devices has led to unauthorized access across 30 organizations. Attackers used five IP addresses and infrastructure on DigitalOcean to compromise accounts since July 25, 2026. Both developments highlight the ongoing need for timely patching and strong authentication practices.

Jul 30
Help Net Security Exploited Outlook Web Access (OWA) TA4884 min read

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

A Russian-affiliated hacking group, Laundry Bear (also known as Void Blizzard or TA488), is actively exploiting a cross-site scripting vulnerability in Microsoft Exchange (CVE-2026-42897) to deploy a sophisticated backdoor called OWAReaper. The exploit targets government and private sector organizations in the U.S. and Europe through seemingly innocuous emails that trigger malicious code when opened. Once activated, the malware steals credentials, grants unauthorized access to mailboxes, and persists across device reimages. Microsoft issued a patch for this flaw in June 2026, but attackers had already been using it as a zero-day since March. Organizations are urged to apply the fix immediately and scan for signs of compromise.

Jul 30
Help Net Security Exploited Secure Firewall Management Center (FMC) network-edge4 min read

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

Attackers are actively exploiting a static credentials vulnerability (CVE-2026-20316) in Cisco's Secure Firewall Management Center (FMC), according to CISA. This issue allows unauthorized access using default account details, potentially leading to data exposure and privilege escalation. Cisco has issued hotfixes and guidance for detecting signs of compromise. Organizations are urged to update systems and rotate credentials immediately.

Jul 30
Rapid7 Blog Patch vCenter Server cloud4 min read

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Broadcom has issued a security update addressing two high-severity vulnerabilities in VMware vCenter Server—CVE-2026-59309 and CVE-2026-59310—that could allow unauthenticated attackers to bypass authentication or execute arbitrary code remotely. Both flaws have a CVSSv3.1 score of 9.8 and affect widely used vCenter versions. While no active exploitation has been observed yet, the lack of workarounds makes immediate patching crucial. Affected organizations are advised to apply the fixes detailed in VMSA-2026-0006 without delay.

Jul 30
The Hacker News Exploited AnySign4PC web-app10 min read

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and multiple security firms have revealed a state-sponsored cyber campaign that leveraged hacked domestic websites to exploit vulnerabilities in locally installed financial-security software, including AnySign4PC. The attackers successfully deployed backdoors like SIGNBT and COPPERHEDGE without requiring any user interaction or download prompts. KISA has confirmed that AnySign4PC versions 1.1.4.4 through 1.1.4.6 are vulnerable, with version 1.1.5.0 being the patched release. AhnLab identified two other unnamed financial-security products as targets but did not disclose their specific versions or CVE identifiers. This incident highlights the growing threat of sophisticated, unpatched exploits being actively used against critical infrastructure.

Jul 30
SecurityWeek Exploitation Ruflo ai-ml3 min read

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms

Researchers at Noma Labs discovered a critical vulnerability in the open-source AI agent orchestration platform Ruflo, tracked as CVE-2026-59726 (CVSS score of 10/10). The flaw stems from an unauthenticated POST /mcp endpoint in the Model Context Protocol (MCP) bridge, allowing attackers to execute arbitrary commands within the container. This could lead to full system compromise, including stealing API keys, spawning rogue agent swarms, and manipulating AI outputs. The issue was fixed in version 3.16.3, with detailed remediation steps provided by the project maintainers.

Jul 30
Patchstack Research web-app7 min read

The WordPress update button isn’t telling the truth anymore

New research reveals that the recent changes to WordPress.org’s update process—designed to improve security—have introduced a critical lag between when patches are made available and when they appear in user dashboards. Despite reducing the delay from 24 to 6 hours, this gap still allows attackers to exploit publicly disclosed vulnerabilities before site owners are notified of an update. The issue affects over 9.9 million installations across 79 plugins, including high-severity fixes rated up to CVSS 10.0. Hosting companies and agencies using automated tools face similar limitations due to reliance on the same delayed API. Patchstack now offers free 30-day protection for hosting partners to close this window immediately.

Jul 30
The Hacker News Exploited Microsoft Outlook Web Access Laundry Bear8 min read

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian threat actors, identified as Laundry Bear, have been exploiting a patched vulnerability in Microsoft Outlook Web Access (OWA) to maintain unauthorized access to email accounts even after credentials are rotated. The flaw, CVE-2026-42897, is being used to target U.S. and European government agencies and various industries including telecommunications, finance, and aerospace. This attack method allows attackers to deploy a sophisticated JavaScript implant called OWAReaper, which persists across device reboots and credential changes.

Jul 30
The Hacker News Advisory Mobile Robots supply-chain5 min read

FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

On July 28, the Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List, effectively blocking new models from obtaining the necessary authorization for import, marketing, or sale in the U.S. This decision aims to mitigate cybersecurity risks associated with these technologies. Previously authorized models can still be sold, but future imports will require conditional approval from the FCC or relevant federal agencies like the Department of War or Homeland Security. The move follows two similar actions targeting foreign-made drones and consumer routers earlier this year.

Jul 30
Risky Business News Research ai-ml12 min read

Srsly Risky Biz: Chipping Away at Chinese AI Risks

The Trump administration is addressing dual AI-related risks from China: national security threats and global access to powerful hacking tools. A proposed bill aims to help U.S. AI companies combat Chinese espionage through shared information without violating antitrust laws. Meanwhile, a coordinated cyberattack on Minnesota water systems has raised concerns about Iranian state-backed hackers targeting critical infrastructure. Security firm Tenable linked the attack pattern to CyberAv3ngers, an IRGC-associated group. Although no formal attribution exists, the timing aligns with recent U.S. warnings about increased Iranian cyber activity.

Jul 30
SecurityWeek Exploited Cisco Secure Firewall Management Center (FMC) Software network-edge2 min read

Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco has issued patches for a zero-day vulnerability in its Secure Firewall Management Center (FMC) software that is currently being exploited in real-world attacks. The flaw, identified as CVE-2026-20316, involves hardcoded default credentials for a low-privilege user account, enabling attackers to gain unauthorized access and retrieve sensitive data. Cisco labeled the issue 'high severity' and warned that it could be combined with other vulnerabilities to escalate privileges. Organizations are urged to apply updates immediately to mitigate risks.

Jul 30
Help Net Security Research ai-ml8 min read

200 new CVEs a day and no realistic way to patch them all

Ryan Dewhurst, CEO of KEVIntel, outlines how his team detects exploited vulnerabilities that have not yet been included in CISA’s catalog. Using a global honeypot network, AI triage, and manual verification, the company has identified over a thousand known exploited vulnerabilities (KEVs) not present in official records. The research highlights challenges faced by organizations in managing the growing volume of daily CVEs—now averaging 200 per day—and emphasizes the importance of prioritizing high-risk exploits. Dewhurst also warns about misleading AI-generated proof-of-concept code and the limitations of relying solely on CISA’s guidance for private-sector security decisions.

Jul 30
The Hacker News4 min read

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

CISA has added a new vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-20316, allows unauthenticated attackers to log in using hard-coded low-privilege credentials and potentially access sensitive data. Cisco rates the issue as High severity due to potential privilege escalation when combined with other vulnerabilities. Customers are advised to update to one of the listed hotfix versions immediately.

Jul 30
Palo Alto Unit 42 PoC Hermes Agent knaithe19 min read

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

A Chinese-speaking threat actor has deployed AI models to conduct autonomous cyberattacks, leveraging tools like DeepSeek and Hermes Agent to identify and exploit vulnerabilities in infrastructure. The actor, known as knaithe or KnYuan, used FOFA for asset discovery and targeted seven critical vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. While some attacks failed due to target-side configurations, the campaign demonstrates a functional end-to-end autonomous offensive capability. Palo Alto Networks offers protections through Cortex XDR, XSIAM, and Next-Generation Firewall.

Jul 29
BleepingComputer Exploited Microsoft Exchange Outlook Web Access (OWA) Laundry Bear6 min read

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

A Russian state-backed hacking group, known as Laundry Bear or Void Blizzard, is exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to gain long-term access to email accounts. The flaw, tracked as CVE-2026-42897, allows attackers to execute arbitrary JavaScript when users open specially crafted emails. This leads to the deployment of a sophisticated backdoor named OWAReaper, which enables persistent access and data theft. Security firm Proofpoint has observed this activity targeting multiple sectors, including government agencies and critical infrastructure. The exploit bypasses traditional detection methods by leveraging improper HTML sanitization and maintaining access even after system reinstallation.

Jul 29
BleepingComputer Exploited Cisco Secure Firewall Management Center (FMC) Software network-edge4 min read

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco has issued a warning that a high-severity vulnerability in its Secure Firewall Management Center (FMC) software, identified as CVE-2026-20316, is currently being exploited in zero-day attacks. The flaw stems from hardcoded static credentials for a low-privilege account within the FMC software, allowing unauthenticated attackers to remotely access systems and retrieve sensitive data. Although the CVSS score is 5.3, Cisco elevated the severity due to potential privilege escalation when combined with other vulnerabilities. Affected versions include multiple releases of the FMC software, though cloud-based variants remain unaffected. Cisco has released hotfixes for impacted versions and urges users to apply them immediately.