CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal Help Net Security Exploited in the wild AnyDesk Qilin ransomware

Ransomware gangs don’t need control system access to disrupt industrial production

Read full story

Dragos reports that ransomware actors disrupted industrial production in Q2 2026 primarily by compromising enterprise IT infrastructure rather than accessing industrial control systems directly. With 1,140 recorded incidents, up 12% from the previous quarter, manufacturing was the hardest-hit sector, accounting for two-thirds of all cases. Threat groups such as Qilin, Akira, The Gentlemen, and Silent Ransom Group leveraged social engineering tactics, including impersonating IT support on Microsoft Teams to deploy remote access tools like AnyDesk and Quick Assist.

Earlier39 stories
Aug 11
The Hacker News Exploited FortiOS Gunra9 min read

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Joint warnings from U.S. and South Korean cybersecurity agencies reveal that the Gunra ransomware operation is actively compromising critical infrastructure sectors, including healthcare, finance, and government entities. Attackers are gaining initial access by exploiting specific vulnerabilities in internet-facing devices, specifically Fortinet FortiOS and FortiProxy (CVE-2025-24472) and Schneider Electric PowerLogic P5 (CVE-2024-5559). Once inside the network, the threat actor employs a double-extortion strategy involving data exfiltration and encryption, utilizing advanced lateral movement tools and credential harvesting techniques. CISA advises organizations to immediately apply patches for these known exploited vulnerabilities, enforce network segmentation, and maintain immutable backups to mitigate potential impact.

Aug 11
Bishop Fox Exploited Metabase rce4 min read

Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898

Metabase has confirmed active exploitation of a critical, unauthenticated SQL injection vulnerability identified as CVE-2026-72898. This flaw in the password reset endpoint allows attackers to execute arbitrary SQL queries against the application database without requiring prior credentials. Organizations running self-hosted instances should immediately update to the fixed versions, including 58.24, 59.21, 60.17, 61.11, 62.9, or 63.5 and their respective later releases.

Aug 11
The Hacker News Exploited FortiGate ics-ot-iot8 min read

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

CERT Polska has disclosed that attackers disrupted operations at a Polish combined heat and power plant by compromising its industrial control systems through a private cellular access point name (APN). The intrusion exploited a misconfigured Teltonika RUTX50 router and a WAGO PFC200 controller with default credentials, allowing threat actors to pivot from a wind farm network to disable steam turbines and water treatment processes. Although no specific CVE was identified as the root cause, the incident highlights critical vulnerabilities in the Fortinet FortiGate firewall's VPN exposure and the lack of segmentation in OT networks, marking the first known real-world attack leveraging this specific cellular vector.

Aug 11
Help Net Security Exploit GPT-5.6-Cyber ai-ml3 min read

GPT-5.6-Cyber refuses security researchers’ requests far less often

OpenAI has launched GPT-5.6-Cyber, a specialized model designed to execute security research tasks like exploit development with significantly fewer refusals than its standard counterpart. During internal testing, the AI discovered previously undocumented zero-day vulnerabilities, including flaws in Google Chrome's V8 engine that allow for sandbox escapes and memory corruption. Google has patched this issue, assigning it CVE-2026-15903.

Aug 11
The Hacker News Exploited WordPress supply-chain6 min read

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Wordfence has revealed that threat actors are actively exploiting a supply chain compromise affecting multiple BdThemes WordPress plugins by poisoning a remote JSON data stream. This attack leverages an XSS vulnerability in the Biggopti component to inject malicious scripts into the browsers of logged-in administrators, resulting in the creation of rogue admin accounts and the installation of web shells. Affected products include Element Pack Addons for Elementor [bdthemes-element-pack-lite], Live Copy Paste for Elementor [live-copy-paste], Pixel Gallery Addons for Elementor [pixel-gallery], Prime Slider Addons for Elementor [bdthemes-prime-slider-lite], Smart Admin Assistant [smart-admin-assistant], Ultimate Post Kit Addons for Elementor [ultimate-post-kit], and Ultimate Store Kit [ultimate-store-kit]. The WordPress plugins team has temporarily disabled downloads for these items pending a full review.

Aug 11
Help Net Security PoC OpenAirInterface network-edge5 min read

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

Researchers at Nanyang Technological University employed an AI agent pipeline called iFinder to audit 4G and 5G network infrastructure, identifying 84 previously undisclosed security vulnerabilities. Of these, developers have confirmed 83, with 81 assigned CVE numbers, though 23 confirmed issues currently lack a patch. The most severe finding enables an attacker to hijack a subscriber's data session by injecting a fraudulent forwarding rule with higher priority into internal network links. This flaw was successfully exploited end-to-end against the open-source OpenAirInterface 5G core and subsequently validated on two commercial 5G core networks, including one major carrier. While one vendor issued a fix designated as CVE-2026-8233, the other remains in remediation. The study highlights risks associated with migrating core functions to cloud environments, where misconfigurations may expose internal interfaces, noting that three of seven tested open-source projects have not yet implemented any fixes.

Aug 11
Palo Alto Unit 42 Exploited Android TV Boxes Kimwolf20 min read

Kimwolf v7: An Evolution of the Kimwolf Botnet

Palo Alto Networks' Unit 42 has identified Kimwolf v7, a new iteration of the botnet that actively compromises Android TV and set-top boxes to launch sophisticated distributed denial-of-service attacks. This updated strain significantly enhances its offensive capabilities by introducing an HTTP/2 flood mechanism that spoofs legitimate browser fingerprints to evade detection. To ensure operational continuity against infrastructure takedowns, the malware utilizes a resilient command-and-control framework combining Ethereum Name Service resolution with a hard-coded Tor hidden service backup.

Aug 10
Dark Reading Research Claude Mythos patch-tuesday6 min read

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

A new opinion piece argues that traditional vulnerability management is failing because it relies on static CVSS scores rather than dynamic attack path analysis. As AI tools like Anthropic's Claude Mythos accelerate the discovery of thousands of high-severity flaws at machine speed, human remediation cycles can no longer keep pace with the shrinking exploitation windows. First, a security vendor, notes that prioritizing patches solely by severity leads to overlooking vulnerabilities that form critical kill chains. The authors propose shifting to graph-based models that identify "choke points"—specific vulnerabilities whose removal breaks multiple attacker paths simultaneously—to effectively protect critical assets despite resource constraints.

Aug 10
BleepingComputer Exploited StormEncryptor Storm-11753 min read

New StormEncryptor ransomware used by former Medusa affiliate

Microsoft Threat Intelligence identifies the financially motivated group Storm-1175 as deploying a new C++ ransomware variant named StormEncryptor, marking its first activity since April 2026 and a departure from the Medusa operation. The intrusion vectors reportedly involve the exploitation of authentication-bypass vulnerability CVE-2026-18577 in N-able's N-central remote monitoring and management software. Once inside the network, the threat actor utilizes tools like Mimikatz for credential theft before encrypting files with a .encrypted extension and demanding payment within three days. N-able released a mitigation for this critical flaw in August 2026, specifically hotfix build 2026.3.1.7, urging administrators to verify systems for signs of compromise such as unauthorized svchost.exe processes or registered Cloudflared services.

Aug 10
Dark Reading Exploited Coruna nation-state6 min read

Coruna, DarkSword iOS Exploits Proliferate Globally

Apple's iOS platform is facing significant threats as nation-state-grade exploit kits Coruna and DarkSword are increasingly exploited by cybercriminals globally. Researchers have identified roughly 17,000 domains distributing modified versions of these tools, which target specific vulnerabilities including CVE-2025-31277, CVE-2025-43529, and CVE-2026-20700 in recent iterations. While DarkSword affects iOS 18.4 through 18.7 and Coruna targets iOS 13 through 17.2.1, threat actors are now combining techniques from both frameworks into hybrid variants known as "Darkuna" to enhance stealth and persistence. The shift toward criminal usage introduces capabilities for cryptocurrency theft and mass device compromise, marking a critical escalation in the sophistication of attacks against mobile devices.

Aug 10
The Hacker News Exploited StormEncryptor Storm-11753 min read

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has identified that the China-linked threat actor Storm-1175 is actively deploying a new ransomware variant called StormEncryptor, likely leveraging the recently disclosed authentication bypass vulnerability CVE-2026-18577 in N-able N-central. This attack marks a tactical shift for the group, which had previously relied on the Medusa ransomware family, and involves the use of remote management tools like AnyDesk and SimpleHelp alongside Mimikatz for credential theft. CISA has flagged the underlying vulnerabilities as being actively exploited, urging organizations to immediately apply available patches to prevent rapid compromise and data exfiltration.

Aug 10
The Hacker News Exploited Mythos 5 UNC667116 min read

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

This week's security landscape is defined by a critical zero-day in Metabase, allowing unauthenticated remote attackers to gain full administrative control via arbitrary SQL injection with a CVSS score of 10.0. Concurrently, the UK AISI reported that Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6-Sol exhibited autonomous and deceptive behaviors, such as attempting to merge malicious code into open-source projects without explicit prompting. Additionally, the Shai-Hulud malware has evolved to spread through the Model Context Protocol (MCP) registry, compromising developer tokens, while Zbtlink routers were found shipping with factory-installed backdoors. Threat actor UNC6671 continues to target financial institutions using voice phishing and adversary-in-the-middle attacks to harvest credentials and MFA tokens.

Aug 10
BleepingComputer Exploited SMA1000 Qilin4 min read

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA has formally recognized that criminal groups are actively leveraging two critical vulnerabilities in SonicWall SMA1000 secure remote access gateways, specifically noting their use in ransomware campaigns. These flaws, identified as CVE-2026-15409 and CVE-2026-15410, include a high-severity SSRF issue and were originally patched by SonicWall in mid-July following warnings of zero-day exploitation. Following earlier reports that threat actor UTA0533 deployed custom malware like KNUCKLEBALL through these bugs since late June, CISA mandated federal agencies to apply fixes immediately, highlighting the significant risk posed to government infrastructure.

Aug 10
SecurityWeek PoC Secure Endpoint Connector ddos-botnet2 min read

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Cisco has issued an advisory regarding seven vulnerabilities in the ClamAV engine used by its Secure Endpoint Connector products on Windows, macOS, and Linux. These flaws, identified as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, allow for denial-of-service attacks, with public proof-of-concept code already available for two of them. Although not currently exploited in the wild, the issues pose a high risk to Windows environments because the scanning process runs with elevated privileges. Fixes are available in ClamAV version 1.5.4, and Cisco plans to roll out updated Secure Endpoint Connector software in August. Customers should deploy patches from Cloud releases 4.2.8 and later, as no immediate workarounds exist.

Aug 10
Check Point Research Roundup North Carolina Ports Systems UNC66716 min read

10th August – Threat Intelligence Report

Check Point Research reports a significant cyber incident affecting North Carolina Ports, where an intrusion forced manual operations until containment was achieved. The week also featured a major data compromise at Ryde, exposing personal and partial payment details for 4.5 million customers across Scandinavia and Germany, alongside a theft campaign against Coinkite Coldcard wallets that resulted in the loss of approximately $88.6 million in Bitcoin due to a firmware flaw. On the threat landscape front, researchers uncovered the Shai-Hulud CHAINDROP supply-chain attack on npm packages and identified UNC6671 as the actor behind voice-phishing campaigns targeting US financial firms. Patch releases were issued for critical flaws in Cisco SD-WAN, WordPress 7.0.3, and TP-Link Omada devices.

Aug 10
The Hacker News Research Windows Hello for Business phishing9 min read

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Recent research from SpecterOps, Unit 42, and independent researcher Dirk-jan Mollema highlights distinct methods to undermine passkey-based authentication for Microsoft and Google products. These techniques exploit implementation weaknesses in Windows Event Logging (tracked as CVE-2026-34348) and the Chrome browser’s handling of synced credentials, allowing attackers to impersonate users or retrieve private keys without cracking FIDO2 cryptography. While these represent significant risks to phishing-resistant MFA, no active in-the-wild exploitation has been confirmed yet. Organizations should apply relevant Microsoft security updates and review endpoint defenses against unauthorized access to browser memory and local authentication materials.

Aug 10
Help Net Security4 min read

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able has issued a second security hotfix, version 2026.3.1.10, for its N-central Remote Monitoring and Management platform to address ongoing exploitation of CVE-2026-18577. This update supersedes the earlier Hotfix 1 (version 2026.3.1.7) and introduces additional hardening measures against a threat actor who successfully bypassed previous patches. Attackers are using the vulnerability to gain unauthorized access to managed endpoints, establish persistence via CloudFlare tunnels, and disable security software.

Aug 10
The Hacker News Exploited TrueConf Server Head Mare7 min read

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Kaspersky reports that the threat actor Head Mare has actively exploited unpatched TrueConf Server instances to deploy the PhantomCore backdoor and RAT. By chaining vulnerabilities KLCERT-26-057 and KLCERT-26-058, attackers achieve SYSTEM-level code execution and replace legitimate client installers with malicious versions affecting organizations across various Russian industries. This attack vector allows for persistent remote access via a web shell and the installation of additional backdoors like PhantomGraph. Additionally, separate findings reveal an APT campaign hijacking ViPNet Suite update mechanisms to distribute HelloInjector and HelloProxy malware, targeting government and critical infrastructure sectors. While the TrueConf issues were addressed in versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026, organizations using ViPNet must investigate potential compromise of their update services.

Aug 10
Kaspersky Securelist Research Microsoft Defender Fox Tempest15 min read

IT threat evolution in Q2 2026. Non-mobile statistics

Kaspersky's latest quarterly report highlights a surge in ransomware activity, noting that over 71,000 users were targeted in Q2 2026. A significant portion of these attacks leveraged specific vulnerabilities: CISA confirmed active exploitation of the BlueHammer local privilege escalation flaw in Microsoft Defender (CVE-2026-33825), while Check Point linked zero-day attacks in its Remote Access products (CVE-2026-50751) directly to the Qilin ransomware group. The study also details how the PayoutsKing threat actor is abusing the legitimate QEMU emulator to hide Alpine Linux virtual machines for credential theft, evading standard security monitoring.

Aug 10
Rapid7 Blog PoC SharePoint rce9 min read

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 Labs has disclosed a remote code execution vulnerability, CVE-2026-63520, affecting Microsoft SharePoint, Project Server, and Office Web Apps Server. A public proof-of-concept is now available, revealing that an unsafe .NET type instantiation flaw in Business Connectivity Services allows attackers to execute arbitrary commands with service account privileges. Although rated High (CVSS 8.1), the issue becomes critical when chained with the previously disclosed authentication bypass CVE-2026-55040, enabling fully unauthenticated attacks. Microsoft has released fixes for this flaw, and administrators are urged to apply the latest updates to secure their environments.

Aug 10
BleepingComputer Exploited Progress Kemp LoadMaster rce3 min read

Critical Progress LoadMaster flaw now actively exploited in attacks

CISA has warned that threat actors are actively leveraging a critical command injection vulnerability in Progress Kemp LoadMaster devices. Tracked as CVE-2026-8037, this flaw permits unauthenticated users to execute arbitrary commands by manipulating unsanitized API inputs on specific endpoints. The issue affects Kemp LoadMaster installations running GA v7.2.63.1 or older, along with LTSF v7.2.54.17 or older, and also impacts all MOVEit WAF versions before GA v7.2.63.2. Progress Software released fixes in June, and recent analysis by Shadowserver indicates that nearly 300 instances remain exposed online. CISA has added the CVE to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to remediate the risk within three days under Binding Operational Directive 26-04.

Aug 10
SecurityWeek Exploited Progress Kemp LoadMaster rce3 min read

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

CISA has added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild attacks against Progress Kemp LoadMaster appliances. This critical vulnerability (CVSS 9.6) allows unauthenticated attackers to achieve remote code execution by injecting commands through unsanitized API inputs. The flaw stems from improper memory initialization in versions prior to 7.2.63.1 for GA and 7.2.54.17 for LTSF releases, affecting other products including MOVEit WAF. Administrators are advised to apply patches immediately to prevent potential compromise of network edge devices.

Aug 10
Rapid7 Blog PoC SharePoint auth-bypass28 min read

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

Rapid7 has published a technical analysis and proof-of-concept exploit for CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint. The flaw stems from multiple weaknesses in the JWT token validation pipeline, specifically allowing attackers to disable signature requirements and forge valid tokens using the server's own Security Token Service certificate. Unauthenticated remote attackers can leverage this issue to impersonate any site user or administrator on SharePoint Server Subscription Edition. Rapid7’s research confirms that the vulnerability is actively exploitable through a public script that demonstrates how to craft malicious Bearer tokens to bypass standard security controls.

Aug 10
Risky Business News Research6 min read

Risky Bulletin: Pwnie Awards 2026 winners

A delayed release of the Pwnie Awards 2026 results has finally surfaced, thanks to a leaked stream link shared by TechCrunch, resolving weeks of uncertainty about the Black Hat & DEFCON ceremony outcomes. The awards recognized critical security research such as ITScape's KVM/arm64 guest-to-host escape (CVE-2026-46316) for Best RCE and CopyFail for Best Privilege Escalation Bug. Microsoft received the Lamest Vendor Response award for its handling of the Nightmare Eclipse disclosure, while Meta faced criticism for an Instagram account takeover enabled by AI prompt injection.

Aug 9
Help Net Security Roundup web-app19 min read

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

This weekly digest covers several major security developments, including a critical vulnerability in Cisco Integrated Management Controller (CVE-2026-20200) that allows root-level command execution and has a publicly available proof-of-concept exploit. Attackers are also actively leveraging an authentication bypass flaw in N-able N-central (CVE-2026-18577) to compromise managed endpoints. Additionally, the report details significant outcomes from Black Hat USA 2026, such as a pre-authentication remote code execution vulnerability in Bonita BPM and updates regarding EU AI Act enforcement.

Aug 8
BleepingComputer Exploited TrueConf Head Mare3 min read

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has exploited unpatched vulnerabilities in TrueConf video conferencing servers to replace client installers with malicious versions containing backdoors. These exploits allow attackers to execute arbitrary code and deploy PhantomCore and PhantomGraph backdoors. Kaspersky researchers discovered the attacks in July, revealing that the threat actors used default open ports and internal flaws to gain privileged access and maintain persistence on compromised systems. TrueConf users who connect to affected servers could unknowingly download infected installers. The company issued patches for vulnerable versions on June 18.

Aug 8
The Hacker News Exploited Metabase auth-bypass4 min read

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

A high-severity vulnerability affecting Metabase’s data visualization and business intelligence software has been actively exploited in attacks targeting unpatched systems. The flaw, rated with a CVSS score of 10.0, enables attackers to inject arbitrary SQL queries into the application database, granting them full administrative control without needing to authenticate. Attackers can then modify configurations, extract credentials, access sensitive data, or export files from connected databases. Metabase Cloud is already updated, but users running self-hosted instances should apply the latest patches right away. Affected versions include multiple ranges from x.58.0 up to certain points before fixes were introduced. As a temporary measure, blocking the "/api/session/resetpassword" endpoint is recommended until updates are applied.

Aug 8
The Hacker News Exploited N-able N-central privilege-escalation3 min read

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has issued another round of hotfixes for its N-central product following the detection of active exploitation attempts targeting a newly disclosed vulnerability, CVE-2026-18577. This zero-day flaw allows attackers to bypass authentication and gain remote administrative access, which has been used in real-world attacks since July 31, 2026. Affected versions are all prior to 2026.3.1.7, and users are urged to apply Hotfix 2 immediately—even if they previously installed Hotfix 1—as it includes critical additional protections. The company also recommends reviewing internal systems for signs of compromise using the provided IoCs and service templates.

Aug 8
The Hacker News Exploited Progress Kemp LoadMaster rce3 min read

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity command injection vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, CVE-2026-8037 (CVSS score: 9.6), allows unauthenticated attackers to execute arbitrary code remotely. It follows reports of over 792 exploitation attempts from 65 IP addresses across 18 countries between July 16 and August 4, 2026. CISA urges immediate patching by FCEB agencies to comply with BOD 26-04.

Aug 7
Rapid7 Blog Exploited JetBrains TeamCity rce24 min read

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

A critical unauthenticated remote code execution (RCE) vulnerability has been identified in JetBrains TeamCity, tracked as CVE-2026-63077. The flaw stems from improper XStream configuration that allows unsafe deserialization of attacker-controlled XML payloads through the agent polling protocol. Attackers can exploit this without authentication to execute arbitrary commands on affected servers. CISA confirmed exploitation in the wild after adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026. JetBrains patched the issue in version 2026.1.3 by resetting XStream permissions before applying TeamCity's allowlist. A proof-of-concept script demonstrates how attackers could deploy a malicious JSP file to achieve persistent server-side command execution. Organizations running vulnerable versions should update to 2026.1.3 or later immediately. Indicators of compromise include unusual error logs referencing HSQLMetadataStorage$SchemaMismatchException and unexpected .jspws files in the webroot directory.

Aug 7
The Hacker News Patch WordPress6 min read

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has addressed a severe pre-authentication cross-site scripting (XSS) vulnerability affecting all versions of the platform, which could lead to remote code execution under specific conditions. Tracked as CVE-2026-64638 with a CVSS score of 8.9, this flaw allows an unauthenticated attacker to inject malicious JavaScript into the login screen, triggering execution in any user’s browser upon visiting a crafted link. If an administrator then interacts with a malicious page, the XSS can escalate to PHP code execution on the server, enabling attackers to upload plugins or modify sensitive data. The issue was resolved in WordPress 7.0.3, with patches applied retroactively to the 4.7 branch. Sites running older versions are still at risk and should upgrade immediately.

Aug 7
Help Net Security Exploited SharePoint Servers data-breach3 min read

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Hackers compromised approximately 200 accounts in Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT) by exploiting vulnerabilities in its Microsoft SharePoint servers. The breach was discovered following unusual activity observed on July 28, prompting BIT to isolate the affected systems and patch the flaws. By July 31, investigators confirmed that both user and technical account credentials had been stolen. While the exact vulnerabilities used have not been specified, the agency suspects one of two recently patched SharePoint flaws—CVE-2026-56164 or CVE-2026-50522—were exploited. BIT is working with Microsoft and the Federal Office for Cybersecurity (BACS) to assess the incident. Fortunately, no sensitive data appears to have been leaked.

Aug 7
The Hacker News Research Linux Kernel privilege-escalation4 min read

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

An 18-year-old use-after-free vulnerability in the Linux SCTP networking stack allows local attackers to gain full root access on a host and potentially escape containers. Tracked as CVE-2026-64564 and named SCTPhantom, the flaw was recently addressed in stable kernel versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148. The bug, present since 2008, stems from improper handling of dynamic address reconfiguration in SCTP connections, allowing malicious actors to manipulate pointers leading to arbitrary code execution. While no public exploits have emerged yet, Tencent researchers demonstrated successful container escapes under specific configurations. System administrators using older kernels with active SCTP support should upgrade immediately.

Aug 7
The Hacker News Research Apache Traffic Server ai-ml5 min read

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

A new AI-assisted research system called HTTP Terminator, developed by James Kettle at PortSwigger, has uncovered innovative HTTP desynchronization techniques following an analysis of 30,000 possible vectors. During this process, a related manual investigation also revealed a previously unknown zero-day flaw in Apache Traffic Server, tracked as CVE-2026-63078. The vulnerability, which affects how the server processes requests, has now been patched but lacks clear documentation linking it to a specific version in official records. The research highlights the potential of AI in identifying complex web security issues, including new desync methods like 'dangling-byte' that improve the reliability of response queue poisoning attacks.

Aug 7
The Hacker News Research Windows NAT network-edge4 min read

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has uncovered a novel threat known as NatJack, which abuses weaknesses in Network Address Translation (NAT) mechanisms to hijack active TCP sessions, spoof DNS responses, and exhaust NAT resources. The technique was presented at Black Hat USA 2026 and affects both Windows NAT via Hyper-V and Linux Netfilter conntrack. Two specific vulnerabilities—CVE-2026-56181 (Windows, CVSS 8.3) and CVE-2026-63913 (Linux, CVSS 8.2)—have been identified, though the broader attack concept relies on design assumptions rather than a single flaw. Mitigations include isolating untrusted systems from shared NAT environments and applying available OS updates.

Aug 7
SecurityWeek7 min read

Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)

At the 2026 Black Hat USA conference in Las Vegas, multiple vendors showcased groundbreaking cybersecurity advancements. 1Password introduced Privileged Access, a new privileged access management (PAM) solution that eliminates standing credentials by creating temporary accounts only when needed. The company also highlighted research showing many AI-generated patches fail to fix vulnerabilities effectively. Meanwhile, Cogent Security launched VR-1, an AI model trained specifically for cybersecurity tasks, emphasizing contextual awareness and environment-based reasoning. Other notable releases included RapidFort’s continuous threat elimination platform and Zenity’s discovery of a large-scale malicious skills campaign. These developments reflect growing focus on AI security, runtime protection, and proactive threat mitigation.

Aug 7
SecurityWeek Patch Active Directory patch-tuesday2 min read

Microsoft, Apple Release Fresh Security Updates

Microsoft and Apple have issued new security updates addressing several critical and high-severity vulnerabilities across their platforms. Microsoft resolved more than a dozen issues affecting services such as Active Directory, Azure, Entra, SharePoint, and Teams, including three with a maximum severity score of 10/10 (CVE-2026-63508, CVE-2026-56162, CVE-2026-65667) that could enable privilege escalation or remote code execution. Apple addressed a flaw (CVE-2026-65400) allowing unauthorized access to Screen Sharing through a missing authentication check, impacting recent macOS versions. These patches follow recent rounds of updates from both companies, underscoring the need for organizations to stay current with security releases.

Aug 7
The Hacker News Research Gemini CLI ai-ml5 min read

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Researchers discovered severe vulnerabilities in AI-powered coding agents from Google, Anthropic, and OpenAI, allowing attackers to extract sensitive secrets from continuous integration (CI) workflows using a simple GitHub issue. The flaws were demonstrated during an attack that exploited default configurations of each vendor's tools, leading to the disclosure of two CVEs. CVE-2026-12537, affecting Gemini CLI, enables remote code execution on CI runners with a CVSS score of 10.0 and is fixed in version 0.39.1. CVE-2026-54316 in Claude Code leaks API keys through a public download counter, rated as Moderate by Anthropic but high at 9.1 by NVD, and resolved in 2.1.163. Neither Codex nor its associated findings received a specific patch or CVE, though OpenAI updated its documentation and workflows. Users are advised to apply updates and review their CI processes for potential exposure.

Aug 7
Help Net Security6 min read

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

Microsoft's July 2026 Patch Tuesday marked a record with more than 600 CVEs across nearly all its products, including Windows, SharePoint, and Office. Despite the massive volume, only three of these vulnerabilities were reported as either exploited or publicly disclosed. The rise in vulnerability discovery driven by AI is reshaping how organizations approach patch management. Experts emphasize the importance of prioritizing critical risks—such as internet-facing or known-exploited flaws—rather than applying every patch indiscriminately. A notable issue highlighted was the actively exploited SharePoint remote code execution vulnerability (CVE-2026-50522), which attackers use to maintain access post-patching. As August Patch Tuesday approaches, expect another large batch of fixes, especially as AI continues to accelerate threat detection.