CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal The Hacker News Exploited in the wild Windows Lazarus Group nation-state

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Read full story

Check Point Research has attributed the exploitation of CVE-2026-68820 to the Lazarus Group, a North Korean state-sponsored threat actor targeting defense and aerospace firms in France, Germany, Brazil, and India. This privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) allows attackers to gain SYSTEM-level control, enabling them to deploy the ForestTiger backdoor and evade detection via Smart App Control manipulation. The campaign, part of the ongoing 'Dream Job' operation, lures victims with fraudulent job offers to install trojanized PDF viewers or malicious DLLs. These payloads execute MISTPEN modules to harvest system information and trigger the AFD.sys exploit. Organizations should immediately apply the fixes released in Microsoft's August 2026 Patch Tuesday updates and monitor for suspicious activity associated with compromised web infrastructure.

Earlier39 stories
Aug 12
BleepingComputer PoC Windows privilege-escalation8 min read

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have presented "Plug and Pwn" techniques at DEF CON 34 that exploit the Windows Plug and Play mechanism to achieve full SYSTEM privilege escalation. By emulating specific USB devices using hardware like FaceDancer, attackers can trick Windows into automatically installing signed vendor packages that contain exploitable weaknesses, bypassing User Account Control. The demonstrations include both physical zero-click scenarios involving Sierra Wireless and Sony FeliCa drivers, as well as a remote variant, termed "NoPlug & Pwn," that leverages RDP USB redirection to target virtual desktop environments. While mitigations such as disabling co-installers reduce risk, the underlying attack surface persists, highlighting the need for stricter device installation policies on sensitive Windows systems.

Aug 12
BleepingComputer Exploited Windows Lazarus Group4 min read

Lazarus hackers exploited Windows zero-day to target defense firms

Microsoft disclosed that North Korea's Lazarus Group is actively exploiting a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, identified as CVE-2026-68820. This zero-day flaw allows attackers to escalate local privileges to SYSTEM level on Windows 11 systems, specifically builds 26100 and 26200, through a race condition triggered by a crafted application. The exploitation is part of the "Operation Dream Job" campaign, which targets defense, aerospace, and aviation organizations in Europe and India via deceptive job offers. To maintain access, Lazarus updated its FudModule rootkit to leverage this privilege escalation and deployed a new PHP web shell named RelayShell on compromised Roundcube instances.

Aug 12
SecurityWeek Exploited SharePoint auth-bypass3 min read

SharePoint Vulnerability Exploited Shortly After PoC Release

Active exploitation has been observed for CVE-2026-55040, a weak authentication vulnerability in Microsoft SharePoint that was patched during July Patch Tuesday. The attacks began immediately following the publication of a proof-of-concept exploit by Rapid7, allowing unauthenticated remote attackers to bypass security controls and access sensitive data. This incident marks the fifth SharePoint flaw targeted this summer, prompting urgent patching recommendations from CISA.

Aug 12
BleepingComputer Exploited Microsoft web-app4 min read

Hackers leverage new Microsoft SharePoint exploit in attacks

Cybercriminals have begun deploying a proof-of-concept exploit for the critical authentication bypass flaw tracked as CVE-2026-55040, which affects Microsoft SharePoint Server. Published by Rapid7, the code allows unauthorized users to impersonate valid identities within SharePoint environments by exploiting weaknesses in the JWT token validation process. Although Microsoft patched this vulnerability during the July 2026 Patch Tuesday cycle for SharePoint Enterprise Server 2016 and SharePoint Server 2019, threat intelligence firm Defused confirmed that attackers are actively using the tool against exposed systems.

Aug 12
Help Net Security Exploited Windows AFD.sys Lazarus Group5 min read

Lazarus hackers pair fake job offers with Windows zero-day exploit

Check Point researchers have revealed that the North Korea-linked Lazarus Group is actively exploiting a previously unknown Windows vulnerability, designated as CVE-2026-68820, within its ongoing 'Operation Dream Job' campaign. The attack vector involves luring targets, primarily from the defense industry, with fraudulent recruitment offers for companies like Lockheed Martin. Upon downloading trojanized PDF files, victims are subjected to an infection chain that leverages the AFD.sys driver flaw to escalate privileges and deploy the FudModule rootkit. Microsoft addressed the critical local privilege escalation issue during its August 11 Patch Tuesday update. In addition to the zero-day, the campaign utilizes modified versions of SecurityPDF and Roundcube webmail servers to establish persistent command-and-control infrastructure.

Aug 12
The Hacker News Patch ColdFusion web-app3 min read

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has distributed security updates for its ColdFusion, Commerce, and Campaign Classic platforms to resolve multiple high-severity vulnerabilities that could enable remote code execution and privilege escalation. Among the patched issues are three defects with a maximum CVSS score of 10.0: two incorrect authorization flaws in Campaign Classic (CVE-2026-71398 and CVE-2026-27302) and one operating system command injection vulnerability in ColdFusion (CVE-2026-48362). Additionally, an eval injection flaw in ColdFusion (CVE-2026-48273) and incorrect authorization weaknesses in both ColdFusion and Commerce are addressed. No active exploitation of these specific bugs has been observed, but Adobe rates the updates as Priority 1 due to the significant risk they pose. Administrators should apply the fixes immediately, ideally within 72 hours. For ColdFusion, users must upgrade to versions 2025.0.12 or 2023.0.23, while Campaign Classic on-premise and hybrid deployments need to be updated to ACC v7 7.4.4 build 9400; note that Adobe-hosted instances do not require manual intervention.

Aug 12
BleepingComputer PoC Microsoft Defender zero-day4 min read

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

Researcher Nightmare Eclipse has published a proof-of-concept for "ShieldBreak," a Microsoft Defender vulnerability that allows privilege escalation to SYSTEM on fully patched Windows systems. This exploit functions as a bypass for the previously patched RoguePlanet flaw (CVE-2026-50656), effectively rendering the July security fix ineffective. The PoC has been verified to work with a high success rate on Windows 11 25H2, Windows 10, and Windows Server editions where Microsoft Defender is active.

Aug 12
Help Net Security Exploited Windows Lazarus Group6 min read

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft released over 400 security fixes in its August 2026 update cycle, addressing active attacks on Windows via a use-after-free flaw identified as CVE-2026-68820. Check Point researchers confirmed that Lazarus Group actors are leveraging this bug to install kernel-mode rootkits as part of their 'Operation Dream Job' intrusion campaign. The release also resolved several previously disclosed issues, including a User Profile Service privilege escalation (CVE-2026-62832) and two other flaws with public proof-of-concept exploits. Notably, researcher "Nightmare Eclipse" has published a "ShieldBreak" tool that reportedly circumvents recent protections for the Microsoft Defender vulnerability CVE-2026-50656.

Aug 12
The Hacker News Exploited VMware vCenter cloud4 min read

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom’s VMware vCenter, to gain remote code execution capabilities. German security firm QUIRSO confirmed active attacks affecting at least 361 victim IPs across 47 countries, beginning five days after the official disclosure. Attackers established persistence by deploying malicious cron jobs using reversessh to connect back to their infrastructure, likely driven by an advanced persistent threat group.

Aug 12
SecurityWeek Exploited Windows AFD.sys Lazarus Group4 min read

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

Check Point has reported that North Korea's Lazarus Group is actively exploiting a newly patched Windows zero-day vulnerability to compromise systems within the global defense sector. The attacks leverage a use-after-free flaw in the Ancillary Function Driver for WinSock (afd.sys), identified as CVE-2026-68820, to achieve System-level privileges. Microsoft addressed this critical race condition during its August 2026 Patch Tuesday cycle, and CISA has since added the identifier to its Known Exploited Vulnerabilities catalog. The campaign, dubbed Operation Dream Job, utilizes social engineering tactics involving fake recruitment offers to deliver malware such as Mistpen and ForestTiger.

Aug 12
SecurityWeek Patch Endpoint Manager2 min read

Ivanti EPM Update Patches Remotely Exploitable Flaws

Ivanti has released security updates addressing four vulnerabilities affecting its Endpoint Manager and Neurons for MDM products. The Endpoint Manager update resolves three high-severity issues, including CVE-2026-18129 and CVE-2026-18125, which allow remote unauthenticated attackers to perform man-in-the-middle credential theft or crash agent services via out-of-bounds reads. Additionally, the patch corrects CVE-2026-18127, an input validation flaw that could permit unauthorized file control in S3 buckets used for session recordings. These fixes are available in Endpoint Manager version 2024 SU7, while the medium-severity command injection bug in Neurons for MDM was already addressed in version R124 without requiring customer action. Ivanti stated it is currently unaware of any active exploitation of these specific vulnerabilities.

Aug 12
The Hacker News Exploited LiteLLM TeamPCP8 min read

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Threat intelligence firm CloudSEK has released a public dataset indicating that the recent TeamPCP (UNC6780) supply-chain campaign may have affected over 2,500 organizations via compromised releases of the LiteLLM AI gateway and Aqua Security's Trivy scanner. The incident, tracked as CVE-2026-33634, involved malicious versions 1.82.7 and 1.82.8 of LiteLLM hosted on PyPI from March 24 until quarantine, containing code that harvested cloud keys, SSH credentials, and Kubernetes tokens. The FBI has warned that stolen long-lived secrets remain a persistent risk, urging organizations to audit their environments for these specific package versions installed between 10:39 and 16:00 UTC on March 24. Affected entities should rotate all associated credentials and scan GitHub repositories for suspicious artifacts named tpcp-docs or docs-tpcp.

Aug 12
The Hacker News Patch SAP Commerce Cloud rce3 min read

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has distributed a patch for a critical vulnerability in its Commerce Cloud (Data Hub Adapter) that permits unauthenticated attackers to execute arbitrary code. Identified as CVE-2026-58231, the flaw carries a perfect CVSS score of 10.0 due to insufficient authorization checks and input validation, which can lead to full compromise of application confidentiality, integrity, and availability. The update also resolves three other severe issues, including CVE-2026-44772 and CVE-2026-44758 in Manufacturing Integration and Intelligence, and CVE-2026-34265 in Application Server ABAP for SAP NetWeaver. Security firm Onapsis advises organizations to apply the latest release immediately or configure IP Filter Sets to restrict access to vulnerable endpoints until updates are deployed.

Aug 12
SecurityWeek Patch Global Management System rce2 min read

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

SonicWall has released patches for eight vulnerabilities affecting its Global Management System (GMS) and Email Security platforms, addressing critical remote code execution risks. Notably, CVE-2026-66147 (CVSS 9.4) and CVE-2026-66145 (CVSS 9.1) in GMS allow unauthenticated attackers to execute arbitrary code via command injection and zipslip vulnerabilities, respectively. While GMS was discontinued in October 2025, updates for versions 9.5.1 and earlier are available in release 9.5.2. Additionally, two high-severity code injection flaws in Email Security appliances were resolved in version 10.0.36.

Aug 12
The Hacker News PoC Microsoft Defender privilege-escalation4 min read

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

Security researcher Chaotic Eclipse has published a proof-of-concept exploit named ShieldBreak that serves as a complete patch bypass for the previously addressed Microsoft Defender vulnerability CVE-2026-50656. The flaw allows attackers to achieve privilege escalation to SYSTEM level on Windows 11 25H2 and Windows Server 2025, rendering recent security updates ineffective. While CISA is simultaneously adding the actively exploited WinSock zero-day CVE-2026-68820 to its Known Exploited Vulnerabilities catalog, this new disclosure highlights lingering issues in the Defender malware protection engine.

Aug 12
The Hacker News Exploited Secure Firewall Adaptive Security Appliance ddos-botnet5 min read

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has disclosed that attackers are actively exploiting a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. Tracked as CVE-2026-20349, this flaw involves insufficient error handling during HTTP request processing, allowing unauthenticated remote attackers to force a device reload and cause a denial of service. The advisory notes that exploitation targets specific configurations such as IKEv2, SSL-VPN, or Zero Trust Network Access. Organizations using affected versions should immediately apply the relevant hotfixes or upgrade to fixed releases, as CISA has added the issue to its Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026.

Aug 12
SecurityWeek Exploited Secure Firewall Adaptive Security Appliance ddos-botnet2 min read

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco has released emergency patches for a zero-day denial-of-service vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). The flaw, identified as CVE-2026-20349, permits remote attackers without authentication to trigger an appliance reload by sending malformed HTTP requests to the Remote Access SSL VPN service. With CISA adding the issue to its Known Exploited Vulnerabilities catalog due to confirmed active attacks since August 2026, organizations are urged to install the available hotfixes immediately to prevent network disruptions.

Aug 11
Cisco Talos Exploited Windows patch-tuesday21 min read

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has issued its August 2026 security updates to address 421 vulnerabilities across Windows, SharePoint Server, Exchange Server, and Office, including 62 rated as critical. Notably, one flaw, CVE-2026-68820, a use-after-free error in the Windows Ancillary Function Driver for WinSock, is confirmed to be under active exploitation in the wild. The release also highlights high-severity remote code execution issues such as CVE-2026-62893 in Windows Deployment Services (CVSS 9.8) and CVE-2026-65665 in Microsoft SharePoint Server (CVSS 8.8). Cisco Talos has published updated Snort rules to detect exploitation attempts against several of these newly disclosed weaknesses.

Aug 11
Qualys Security Blog Exploited Windows patch-tuesday23 min read

Microsoft Patch Tuesday, August 2026 Security Update Review

Microsoft has released its August 2026 security updates, addressing a total of 421 vulnerabilities across Windows, Azure, and Exchange Server. Among these are three zero-day flaws, with one specifically identified as being actively exploited in the wild. Organizations should prioritize applying these patches immediately to mitigate risks, particularly regarding the active exploitation and several critical remote code execution issues.

Aug 11
Dark Reading Exploited Windows patch-tuesday6 min read

Microsoft's Patch Tuesday Deluge Continues With August Updates

Microsoft has released its August 2026 security updates, addressing a total of 421 unique vulnerabilities with particular emphasis on Windows, Office, and SharePoint Server. The update package includes the active exploitation of CVE-2026-68820, a zero-day elevation of privilege flaw in the WinSock driver that grants attackers full SYSTEM access without user interaction. Security researchers also flag CVE-2026-62832 as a high-risk candidate for imminent abuse when combined with the initial foothold provided by the zero-day. Additionally, the release contains several critical remote code execution issues, such as the wormable CVE-2026-62878 in Windows DNS Server and CVE-2026-62815 in the QUIC protocol, both rated CVSS 9.8. Organizations should prioritize applying these cumulative updates immediately to mitigate the risk of lateral movement and full system compromise.

Aug 11
Krebs on Security Exploited Windows patch-tuesday5 min read

Microsoft Plugs Nearly 400 Security Holes

Microsoft released its August security updates, addressing 398 vulnerabilities across Windows and other supported software, with one flaw under active exploitation and two previously publicly disclosed issues. The critical vulnerability CVE-2026-68820 allows privilege escalation through a race condition in the afd.sys driver, while CVE-2026-62832 targets the User Profile Service. Users should apply these patches promptly to secure their systems against ongoing threats.

Aug 11
Dark Reading Exploited FortiOS Gunra7 min read

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The FBI and South Korean authorities have issued a joint alert identifying Gunra as an active ransomware-as-a-service operation targeting critical infrastructure and government entities worldwide. The group is actively exploiting CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities in FortiOS and FortiProxy, to gain initial access to networks. In one observed attack vector, Gunra affiliates manipulated VDI portals to capture employee session data, allowing them to completely circumvent multi-factor authentication protections. Agencies advise immediate patching of affected appliances alongside the implementation of immutable offline backups and strict network segmentation.

Aug 11
The Hacker News Exploited Windows Lazarus Group5 min read

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft has released its August security update, addressing 398 vulnerabilities including CVE-2026-68820, a privilege escalation flaw in the Ancillary Function Driver for WinSock (afd.sys) that is under active exploitation by the Lazarus Group. This zero-day allows attackers with existing code execution to elevate privileges to SYSTEM and requires immediate patching. Additionally, the release fixes four critical remote code execution bugs (CVSS 9.8) that require no user interaction or authentication, affecting Windows DNS Server (CVE-2026-62878), Windows Deployment Services (CVE-2026-62893), Microsoft QUIC (CVE-2026-62815), and HPC Pack (CVE-2026-59124). Administrators should also apply the patch for CVE-2026-63520 to fully mitigate a SharePoint attack chain that combines this RCE with the previously fixed authentication bypass CVE-2026-55040.

Aug 11
BleepingComputer Exploited Cisco Secure Firewall ASA network-edge3 min read

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Cisco has released hot fixes for CVE-2026-20349, a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software that is currently being actively exploited to crash devices. The flaw, which stems from insufficient error handling of HTTP requests, allows attackers to remotely trigger a device reload without authentication or user interaction when specific remote access services like SSL VPN are enabled. Affected products include ASA versions 9.16 through 9.24 and FTD releases 7.0 through 10.0, though Secure Firewall Management Center remains unaffected. Since there are no workarounds, administrators should immediately upgrade their systems to the patched releases provided by Cisco.

Aug 11
The Hacker News PoC Zoom Workplace rce5 min read

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

A Security has disclosed a proof-of-concept for three vulnerabilities in the Zoom Workplace annotation feature, which could enable remote code execution without user interaction. The issues affect Zoom Workplace versions prior to 7.1.5 and 7.0.6, as well as specific VDI Client and Meeting SDK versions. Identified as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, these flaws stem from improper handling of structured data within the drawing tool.

Aug 11
SecurityWeek Exploited Windows Lazarus group3 min read

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft has released its August 2026 security updates to address 421 vulnerabilities, notably including a high-severity zero-day in Ancillary Function Driver for WinSock identified as CVE-2026-68820. This use-after-free defect allows local attackers to achieve SYSTEM-level privileges without user interaction and is currently being exploited in the wild. Analysts suggest potential involvement from nation-state actors, drawing parallels to previous incidents targeting the same component attributed to the Lazarus group. The update cycle also resolves significant risks in Windows DNS and Exchange Server, alongside broader fixes across Office and Azure products.

Aug 11
BleepingComputer Exploited Windows Lazarus group67 min read

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Microsoft has released its August 2026 security updates, addressing 400 vulnerabilities including three zero-days. One of these, CVE-2026-68820, is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that was actively exploited by the North Korean Lazarus group to deploy the FudModule rootkit. This vulnerability allows a local attacker to escalate privileges to SYSTEM level without user interaction. The patch also resolves two other publicly disclosed elevation-of-privilege issues within the Windows User Profile Service.

Aug 11
SANS Internet Storm Center Exploited Windows zero-day44 min read

Microsoft Patch Tuesday August 2026 - SANS ISC

Microsoft released patches for 418 vulnerabilities this month, addressing a mix of critical issues across its product ecosystem. The most pressing concern is CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock that is currently being actively exploited in the wild. Additionally, two zero-days were publicly disclosed before release: CVE-2026-62832, affecting the Windows User Profile Service, and CVE-2026-72971, which impacts container isolation via the unionfs.sys driver. Administrators should also prioritize fixing remote code execution vulnerabilities in Microsoft QUIC (CVE-2026-62815) and Windows DNS Server (CVE-2026-62878), both rated Critical with high CVSS scores.

Aug 11
Check Point Research Exploited Windows Lazarus group29 min read

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Check Point Research has identified a new wave of the Operation Dream Job campaign, attributed to the DPRK-linked Lazarus group, which targets organizations in the European and Indian defense sectors. The attackers employed a zero-day vulnerability, CVE-2026-68820, in the Microsoft AFD.sys driver to escalate privileges and deploy their FudModule rootkit, effectively blinding endpoint detection systems. Additionally, the threat actors compromised Roundcube webmail servers by exploiting CVE-2025-49113 to install RelayShell, a new PHP webshell used for command-and-control relaying. Microsoft addressed the kernel driver flaw during their August Patch Tuesday updates, so immediate remediation is recommended.

Aug 11
SecurityWeek Patch ColdFusion rce2 min read

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Adobe has released security updates addressing more than 50 vulnerabilities, with top-priority patches targeting Critical-severity defects in ColdFusion, Campaign Classic, and Commerce. The ColdFusion update resolves 15 issues, including CVE-2026-48362 (OS command injection) and CVE-2026-48273 (eval injection), which pose risks of arbitrary code execution and denial-of-service. Similarly, the Campaign Classic patch addresses three critical flaws, such as CVE-2026-71398 and CVE-2026-27302 (incorrect authorization) and CVE-2026-48381 (SQL injection), enabling potential remote code execution. While Adobe reports no known active exploitation, administrators are urged to apply these Priority 1 patches immediately due to the high likelihood of real-world targeting.

Aug 11
The Hacker News PoC SharePoint ai-ml5 min read

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Rapid7 has disclosed a public proof-of-concept exploit chain that allows unauthenticated remote attackers to achieve code execution on Microsoft SharePoint servers. The attack leverages CVE-2026-55040, a critical JWT authentication bypass, combined with CVE-2026-63520, an unsafe .NET type instantiation flaw in Business Connectivity Services. These vulnerabilities affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Notably, the discovery of this chain was facilitated by an AI agent during rapid research sprints. Organizations should apply the July updates, specifically KB5002882, KB5002883, and KB5002891, to mitigate this risk.

Aug 11
SecurityWeek PoC Zoom Workplace rce3 min read

Zoom Patches Zero-Click Code Execution Vulnerability

Zoom has deployed security updates addressing four vulnerabilities across its Workplace and Rooms products, most notably CVE-2026-53413. This critical memory corruption flaw in the annotator function enables zero-click remote code execution, allowing attackers to compromise participants' machines without any interaction. The advisory also covers a denial-of-service issue and a path traversal vulnerability that results in information disclosure. To mitigate these risks, users should upgrade to Zoom Workplace 7.1.5 or 7.0.6, Zoom Rooms 7.1.5, and the corresponding VDI client versions.

Aug 11
SecurityWeek Patch SAP Commerce Cloud rce3 min read

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SAP has issued its August 2026 security patch day updates, addressing four critical vulnerabilities including CVE-2026-58231, a CVSS 10/10 authentication bypass flaw in SAP Commerce Cloud that allows remote code execution. Additionally, two critical code injection vulnerabilities, CVE-2026-44772 and CVE-2026-44758, affect Manufacturing Integration and Intelligence, enabling attackers to execute arbitrary commands via vulnerable servlets. The final critical fix, CVE-2026-34265, addresses an unauthenticated memory corruption issue in Application Server ABAP for NetWeaver that can lead to system crashes or data disclosure. Administrators should apply the latest security notes to mitigate these risks, particularly given the high exploitability of the remote code execution vectors.

Aug 11
The Hacker News Advisory GPT-5.6-Cyber ai-ml7 min read

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI has introduced GPT-5.6-Cyber, a specialized model available through its Daybreak Red tier that operates with fewer safety constraints to support offensive security tasks. The system is designed to assist with vulnerability discovery, penetration testing, and exploit chain development, having recently identified CVE-2026-15903, a high-severity flaw in the V8 JavaScript engine. While the tool aims to help defenders close security gaps, it carries inherent risks associated with models trained to perform dual-use cyber activities with minimized refusals.

Aug 11
BleepingComputer Exploited SharePoint Server ransomware4 min read

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA has confirmed that ransomware campaigns are actively leveraging a high-severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-45659. This flaw, which stems from improper handling of untrusted data, enables low-privilege attackers to execute arbitrary code on SharePoint Server 2016, 2019, and Subscription Edition instances with minimal effort. Although the vulnerability was added to the Known Exploited Vulnerabilities catalog in early July, recent updates indicate its specific use in ransomware operations. Administrators are urged to verify that Microsoft’s latest security patches are installed and to monitor for signs of compromise using Microsoft Defender Antivirus detections.

Aug 11
Help Net Security PoC Android mobile5 min read

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

University of Birmingham researchers demonstrated that compromised SIM cards can leverage the Proactive SIM feature to execute arbitrary AT commands on compatible modems, potentially leading to code execution, data theft, or forced network downgrades. Testing revealed vulnerabilities in devices from Qualcomm, Quectel, OPPO, Autel, and ASUS, including a command injection flaw in an AUTEL EV charger using a Quectel module. The study also identified CVE-2025-48618, which allowed hostile SIMs to launch browser sessions on locked Android phones without user interaction; Google fixed this issue in Android 13 through 16. The team has published a toolkit called CATana and recommends retiring the RUN AT command entirely rather than just patching specific instances, as the underlying specification still permits significant risk.

Aug 11
The Hacker News PoC EV Chargers ics-ot-iot8 min read

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

Researchers from the University of Birmingham and Fuzzware have released a proof-of-concept demonstrating that malicious SIM cards can execute arbitrary code within cellular IoT devices, including electric vehicle chargers and industrial routers. By exploiting the standard RUN AT command feature on modems from vendors such as Qualcomm and Quectel, attackers can gain full control over the device's underlying operating system. The study identified the interface vulnerability as CVE-2026-57550 (tracked as CVD-2026-0122 by the GSMA) and confirmed impact across multiple products, including specific models from Autel, OPPO, and ASUS. While no active exploitation has been reported, vendors are advised to ensure the interface is disabled or patched to prevent potential compromise.

Aug 11
BleepingComputer PoC Secure Endpoint Connector ddos-botnet3 min read

Cisco warns of high-severity ClamAV flaws with public exploits

Cisco has issued an advisory for two high-severity denial-of-service vulnerabilities in the Secure Endpoint Connector, driven by flaws in the underlying ClamAV engine. The issues, tracked as CVE-2026-20337 and CVE-2026-20338, stem from improper boundary checks and memory handling in the ZIP archive parser, allowing unauthenticated remote attackers to crash the scanning process using crafted files. While proof-of-concept exploit code is already available, Cisco reports no evidence of active exploitation in the wild. The vulnerabilities affect ClamAV versions 1.5.0 through 1.5.3, primarily impacting Windows systems where the service runs with elevated privileges. Fixes are included in ClamAV version 1.5.4, and Cisco plans to distribute updated connector software for Windows, Linux, and macOS later this month.

Aug 11
BleepingComputer Exploited FortiOS ransomware3 min read

US and South Korea warn of Gunra ransomware targeting govt agencies

The U.S. Department of Homeland Security and South Korea’s National Policy Agency have issued a joint advisory warning that the Gunra ransomware group is actively targeting government agencies and critical infrastructure. The threat actor utilizes malware derived from the leaked Conti source code to compromise systems across various sectors, including healthcare and finance. Investigators report that Gunra specifically exploits authentication vulnerabilities CVE-2024-55591 and CVE-2025-24472 in Fortinet products, such as FortiOS and FortiProxy, alongside SSH misconfigurations to establish footholds. Defenders are urged to apply patches immediately, segment networks to limit lateral movement, and maintain offline backups to mitigate these expanding threats.