HomeWeekly DigestsThis Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Aug 10 to Aug 17, 2026

Weekly threat intelligence digest from 398 items (49 critical, 281 high).

August 17, 2026 398 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST August 10 – August 17, 2026 This week the data reinforced a clear shift: attackers are no longer hunting for a single vulnerable server, they are hijacking trusted, privileged pathways. From ransomware groups weaponising an N‑able RMM flaw to AI‑driven zero‑day exploits that bypass authentication in seconds, the dominant vector is privileged access—whether through MSP platforms, SaaS admin consoles, or supply‑chain components. The result is rapid, enterprise‑wide impact that spans data loss, service outage, and downstream vendor exposure. 👉 Access, not just vulnerability, is the primary risk driver. 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain is the entry point → MSPs, CI/CD pipelines, SaaS API consoles, and plugin ecosystems were repeatedly leveraged to breach downstream customers. * Privilege determines impact → A single compromised admin credential or signing key enabled ransomware on thousands of devices and the exfiltration of tens of terabytes of data. * Blind spots remain → OT networks accessed via private APNs and legacy data stores (e.g., 20‑year‑old population registries) sit outside most control inventories and audit scopes. 🔍 WHAT CHANGED THIS WEEK * AI accelerates exploit timelines – AI‑generated exploit chains for SharePoint and zero‑day RCEs were weaponised within minutes of disclosure. * Ransomware groups target privileged management layers – N‑able RMM, Fortinet firewalls, and Schneider Electric platforms are now primary infection vectors. * Misconfiguration attacks move into OT – Private cellular routers and APNs were used to shut down a Polish CHP plant, showing that network‑layer errors can cripple critical infrastructure. * Supply‑chain compromises embed malicious code in widely‑used plugins and CI/CD dependencies (BdThemes, LiteLLM, PraisonAI), expanding the attack surface beyond the original vendor. 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * Managed Service Provider platforms – N‑able N‑central and similar RMM tools. * Cloud admin consoles and SaaS APIs – Microsoft SharePoint, SAP Commerce Cloud, Salesforce/ServiceNow portals. * CI/CD and open‑source package ecosystems – LiteLLM, BdThemes plugins, PraisonAI agents, GitHub Actions. * OT connectivity via private APNs and cellular routers – Fortinet VPNs, Teltonika routers used in energy utilities. * Legacy data stores and unarchived personal data – old government registries, undocumented backups, and long‑term archives. ⚡ WHAT COMPLIANCE & SECURITY LEADERS SHOULD DO THIS WEEK 1. Refresh Vendor‑Risk Management Controls – Map every MSP and SaaS provider to SOC 2 CC1.1 (Vendor Management). – Collect current SOC 2 reports or equivalent attestations and verify patch‑management cadence. 2. Harden Privileged Access Monitoring #Compliance #SOC2 #AuditReadiness #Cybersecurity #ThreatIntel #ContinuousCompliance #LiveThreat #VerisqAI

Articles Referenced in This Digest 398 items

Advisory (43)

HighWireshark 4.6.8 Released, (Sun, Aug 16th)
HighAnthropic confirms Claude is down in major outage affecting multiple services
HighUS Authorizes Private Cyber Firms to Hack Transnational Criminal Networks
HighHow BitLocker PINs help protect your data and devices
HighHackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare
HighMicrosoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
HighCISA Adds Three Known Exploited Vulnerabilities to Catalog
HighMultiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
HighCritical Patches Issued for Microsoft Products, August 11, 2026
HighMicrosoft's Patch Tuesday Deluge Continues With August Updates
HighWindows 11 KB5121003 & KB5120240 cumulative updates released
HighMicrosoft releases Windows 10 KB5120249 extended security update
HighPost-Quantum Deadlines Collide With OT Reality
HighCalifornia Puts AI Inside Its Critical Infrastructure Defenses
HighLocking your ssh-agent exposed local-only keys until OpenSSH 10.5
HighKids’ online safety bill faces dim prospects of passage this session despite progress
HighElevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
HighThe Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
High#StopRansomware: Gunra Ransomware
MediumMicrosoft Plans to End SMS and Voice Authentication for Entra ID
MediumMozilla updates GPG signing key for Firefox releases after exposure
MediumA Playbook for Securing Open-Weight and Open-Source AI Models
MediumYour security vendor gets the frontier cyber model, you get the findings
MediumEdge is dropping older extensions, affecting popular privacy tools
MediumAnthropic to put AI in charge of reviewing Claude Code actions by default
MediumMicrosoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
InformationalHow Anthropic plans to watermark Claude's AI-generated text
InformationalWhatsApp is testing a new warning for scam messages
InformationalAWS Certificate Manager sets 2027 end date for email-validated certificate renewals
Informational17 draft Cyber Resilience Act standards are open for comment
InformationalMicrosoft is merging Copilot and Copilot 365 into one unified app - and retiring 3 features
InformationalFour corporate investigation mistakes organizations make under pressure
InformationalWhatsApp rolls out new feature that flags potential scam messages
InformationalShaping the NVD for the Future: We Need Your Feedback on AI-Enabled Vulnerability Management
InformationalQualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation
InformationalDeloitte strengthens AI governance to support trusted enterprise adoption
LowSignal’s new security feature checks if your encrypted chats were tampered with
InformationalHelp shape the future of resilient private 5G
InformationalSignal adds new security feature to thwart man-in-the-middle attacks
InformationalCitrix expands Platform Flex with observability and secure developer services
InformationalElevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
InformationalWater sector example added to the NCSC’s Secure connectivity principles
InformationalCourt Sets Tight Security for Change Health's Stolen Data

Breach (46)

HighSafePal data breach impacts 39,798 customers, stolen info for sale
HighAPT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
HighSophisticated Cyberattack Exposes Data of 678,000 French Taxpayers
HighWeek in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
HighInvestigation of banking hack leads to arrests in Germany, Brazil
HighScottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
HighFrance investigates tax authority breach after hacker claims 600,000 victims
HighData analyst sent to prison for stealing data, extorting employer
HighRingCentral data breach exposed info of 1.6 million accounts
HighShell investigates 'potential incident' after Clop data theft claims
HighHackers arrested over €30M bank fraud exploiting service provider flaw
HighTrezor discloses data breach affecting nearly 14,000 customers
HighHackers breach govt webmail while running parallel crypto fraud
HighAkira hackers disable EDR with Safe Mode, steal data but fail to encrypt
HighExtortion Gang Leaks Novo Nordisk's 'AI and ML Ecosystem'
HighRingCentral - 1,596,490 breached accounts
HighDentaQuest Breach Affects 15 Million in Largest US Health Data Breach Reported in 2026
High153GB of stolen credentials surface after LiteLLM supply chain attack
HighChina-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
HighRansomware Hits Colombian Justice Ministry Days Before Presidential Transition
HighAndroid malware combo takes out loans and relays victims' credit cards
HighA stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
HighThree intrusions at UK criminal records office went undetected for two years
HighFBI: Hackers using social engineering to breach accounts and steal explicit content
HighValve warns Steam hardware buyers: Expect fake delivery scams
HighIran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
HighExfilSquad Targets New Victims, Shares Data via Torrents
HighMozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
HighWesco confirms security incident after ExfilSquad claims data theft
HighCyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
HighBdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
HighHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
HighCourt Sets Strict Security for Change Health's Stolen Data
HighPreviously unseen entry vector used to breach Polish energy plant
HighWho will be the Stanislav Petrov in your organization?
High9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old
HighHackers Cross From IT to OT Through a Private APN in Poland
HighGym Booking Task Turns Into Real-World AI Cyberattack
HighThe Hugging Face Hack Was Cheap Persistence at Work
HighBdThemes plugins supply-chain hack creates rogue WordPress admins
HighHackers breached a small Polish energy plant via private APN last year
High77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
HighKlaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers
HighCyberattack on Steam hardware shipper leaks names, addresses, and order data
HighValve notifies Steam hardware customers of a data breach
InformationalBreach Roundup: Def Con Dolt Suspected in Delta Wi-Fi Hack

Ransomware (11)

CriticalChina-Linked Hackers Use N-able Flaw in Ransomware Attacks
HighStorm-1175 Replaces Medusa With New StormEncryptor Ransomware
HighRansomware Attack Disables Canadian Hospital's Doors, HVAC
HighRansomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
HighDeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
HighDeadLock ransomware uses blockchain to resist infrastructure takedown
HighRansomware gangs don’t need control system access to disrupt industrial production
HighLocal governments in four states dealing with cyberattacks that have shut down services
HighGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
HighNew StormEncryptor ransomware used by former Medusa affiliate
HighDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

ThreatIntel (156)

CriticalMax severity SAP Commerce Cloud flaw now targeted in attacks
CriticalHackers exploit macOS Screen Sharing flaw to deploy Monero miner
HighMeta’s Ray-Bans are being banned from pubs, restaurants, and theatres
HighCrooks Are Buying Your Expired Domains and Using Them to Deliver Malware
HighMustang Panda Upgrades CoolClient With a Kernel Rootkit
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110
HighDDoS Attacks Cause Major Threema Outages
HighNew AmnesiaStealer macOS malware hijacks browser sessions via remote control
HighLarge-scale DDoS attacks disrupted Threema secure messaging service
HighGoogle Says Chrome Cut 7 Billion Unwanted Android Notifications Per Day
HighCrooks Are Buying Your Expired Domains and Using Them to Deliver Malware
HighNew Evooo1Bot Linux botnet turns routers into traffic relay nodes
HighNew AI Playbooks Will Target Healthcare Cyber Risk
HighERP Security Struggles to Keep Pace With AI Agents
HighApple now uses iPhone alerts for targets of mercenary spyware
HighChess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping
HighAmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers
HighApple warned hundreds of users of mercenary spyware attacks
HighChatGPT's new Computer History tracks your Mac activity to create a timeline - but should you let it?
HighApple is warning users of new spyware attacks - what to do if you're a target
HighAPT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
HighUkrainian police raid 94 fraudulent call centers, seize $2 million
HighNew Android malware relays bank cards to fraudsters while victims still hold them
HighThe Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
HighWeak IAM affects up to 98% of cloud environments
HighApple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
HighMeta ordered to pay $942 million over harm to children
HighParents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
HighNew Android malware lets criminals use your bank card in real time
HighMalware Crypting Services and the Threat Actors Who Sell Them
HighThe Model Is the Malware | What Four Agentic Intrusions Tell Defenders
HighWhite House authorizes private US companies to hack foreign criminal networks
HighWhite House taps security firms for offensive hack-back operations
HighWho Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
HighAI 'watermark removers' flood the web. Almost none can prove they work.
HighUkraine shuts down 94 fraudulent call centers, seize millions in cash
HighWhy API Discovery Is Critical for Modern AppSec Programs
HighClaims Data Shows Where AI Risk Is Hitting Now
HighNew Mirai variant adds stealth capabilities to notorious botnet code
HighFlock tightens privacy controls amid scandals over officer abuse
HighJewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
HighJuly 2026 Cyber Attacks Statistics Infographic
HighSmashing Security podcast #480: This is the AI service you should never sign up to
High'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
HighArmored Likho expands its cyber-espionage toolkit
HighDDoS attacks hit record scale as 1 Tbps+ campaigns become more common
HighLong-running Data Theft Campaign Targeting Salesforce, ServiceNow
HighEnterprise Defenses Recovered at the Edge and Collapsed Inside
HighOpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
High737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
HighLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
HighPlug and Pwn attack uses fake USB devices for Windows SYSTEM access
HighHundreds of fake Chrome VPN extensions route traffic through a proxy
HighUS, South Korea Warn of Growing Gunra Ransomware Threat
HighCloudflare Report Shows Massive Spike in High-Volume DDoS Attacks: Here Is What the Data Shows
HighFBI, NCAA Warn Hackers Are Targeting College Athletes’ Private Photos
HighCrytica’s RDAi detects OT device tampering from within
HighLazarus hackers pair fake job offers with Windows zero-day exploit
HighFake CCleaner installs GhostDesk Chrome spyware 
HighKimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
HighAI Genie in the Wild
HighMalicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
HighGoogle says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
HighCalifornia Puts AI Inside Critical Infrastructure Defenses
HighAI deployments are stretching enterprise security to its limits
HighReady-made $500 kit puts a crypto scam within anyone’s reach
High338 million attack simulations reveal the state of enterprise defense
HighPost-quantum migration gets harder when every user holds a key
HighFake popular sites offer a free app, instead take over PCs
HighWatch out for fake TikTok Shops trying to steal your money
HighSexual predators targeting online accounts for intimate images, FBI warns
HighSocial media platforms crack down on drone factory recruiting game
HighGunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
HighMines, Minds, and Machines: The Journey of AI
HighKimwolf v7: An Evolution of the Kimwolf Botnet
HighResearchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
HighA Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
HighOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
HighSandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
HighKimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
HighDDoS attacks over 1 Tbps surged fivefold in the second quarter
HighVague Task, Total Access: When AI Delegation Becomes a Security Risk
HighDelta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
HighCisco warns of ASA and FTD VPN flaw exploited to crash devices
HighSandworm hackers target IT pros with trojanized WireGuard VPN client
HighProject CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
HighGPT-5.6-Cyber refuses security researchers’ requests far less often
HighBypassing Android Hardware Attestation from the Analyst's Chair
HighFrontier AI Just Made the Race to Patch Vulns That Much Harder
HighMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
HighUS and South Korea warn of Gunra ransomware targeting govt agencies
HighWhy recovery readiness has become the new standard for cyber resilience
HighA week in security (August 3 – August 9)
HighCoruna, DarkSword iOS Exploits Proliferate Globally
HighMultistate Water System Attacks Widen, Iran Suspected
High'GhostJacking' Exposes Identity Governance Gaps in AI Agents
HighThe Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
HighTrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
HighNew Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
HighKimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
HighChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
HighBritish ‘Com’ member who abused more than 100 girls worldwide jailed for two years
HighRussian military hackers pose as recruiters to target Ukrainian IT workers
HighSenate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity
HighPoland uncovers second heat plant cyberattack that went hidden for months
HighFBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
HighLexisNexis shuts down services after suspicious activity on servers
HighMember of The Com sent to prison for blackmail, sextortion
HighWhen Credentials Are No Longer Enough: Device Trust in the AI Era
HighCISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
HighAI Moves From Cheating in Theory to Hacking the Real World
HighFake The Odyssey Downloads Are Hiding Password-Stealing Malware
HighWhy managers are ransomware's top targets now - and 6 ways to stay safe
HighIT threat evolution in Q2 2026. Non-mobile statistics
HighGitHub Dependabot malware alerts now cover eight ecosystems
HighOpenAI locks down Astra over potential critical cyber capabilities
HighAudit Fix: Audit Readiness for the Post-Mythos Era
HighA GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark
HighOpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns
HighOpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
HighSolidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
MediumProduct showcase: ScamNet looks for warning signs in suspicious calls and shady links
MediumHazmat: Open-source containment for AI agents
MediumSingapore Is Literally Training People to Get Scammed
MediumISMG Editors: The Best of Black Hat 2026
MediumCyera's Oasis Security Buy Is All About AI Agent Control
MediumGemini voice calling on Android Auto keeps failing me - and Google has until September to fix it
MediumProduct showcase: Is this image real? Slop or Not investigates
MediumCisco Sees AI Fueling Network Upgrade Supercycle
MediumWeekly Update 516: Live From Vietnam
MediumChrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
MediumPrompt Injections for Defense
MediumPentestGPT: Open-source automated penetration testing agentic framework
MediumWhere an AI Watermark Can Hide in Plain Text
MediumMistral Expands Sovereign AI Push With European Compute
MediumHow to fake a data trail (and maybe lower prices) (Lock and Code S07E16)
MediumAI-Ready PAM: When Your Identity Security Solution Talks Back
MediumOpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
MediumScans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)
MediumPython Now Has a Post-Quantum Encryption Library
InformationalISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th)
LowWhatsApp Begins Limited Test of AI Scam Alerts for Unknown Senders
InformationalAmid AI-Driven Bug Tsunami, NIST Looks to…AI
InformationalI tested an Android app that lets anyone fight censorship - and shows your impact in real time
InformationalISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)
InformationalA10 Networks introduces AI Gateway to secure and manage enterprise AI
InformationalOligo Raises $60M to Extend Runtime Security to AI Agents
LowAndroid can now tap to share for contact info, photos, and more - which phones get it first
InformationalJuly 2026 Cyber Attacks Statistics
InformationalUsing Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)
InformationalISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)
InformationalSearchlight Cyber combines exposure and threat intelligence in new PTEM platform
InformationalWalmart's "Trusted Agent" Approach to Purple Teaming
InformationalISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)
InformationalISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)
InformationalObsidian Secures $85M to Control AI Agents in SaaS Apps

Vulnerability (142)

CriticalWindows 11’s strongest security defenses can be bypassed without a screwdriver
CriticalGeoServer Zero-Day Is Already Being Probed. That’s the Problem
CriticalmacOS Screen Sharing Flaw Exploited to Deploy Monero Miners
CriticalSAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
CriticalShield Breaks: Microsoft Faces Fresh Nightmare Eclipse Zero-Day
CriticalZDI-26-573: Linux Kernel KSMBD Response Header Out-Of-Bounds Read Information Disclosure Vulnerability
CriticalU.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
CriticalAdobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
CriticalGlobal Threat Campaign Hits Critical VMware vCenter Flaw
CriticalAttackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
CriticalCritical VMware vCenter RCE flaw exploited for reverse SSH access
CriticalMicrosoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack
CriticalHaiwell IoT Cloud HMI Gateway
CriticalSiemens Siveillance Video
CriticalNorth Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
CriticalSharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
CriticalBelgium's eID Authentication Opens Citizen Accounts to RCE
CriticalAttackers Exploit SharePoint Authentication Bypass After Public PoC Release
CriticalMultiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
CriticalHackers leverage new Microsoft SharePoint exploit in attacks
CriticalHackers exploit critical Adobe Commerce flaw to hijack customer accounts
CriticalZoom Zero-Click RCE: AI Helped Build an Exploit in Under 24 Hours
CriticalMicrosoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
CriticalZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
CriticalZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability
CriticalZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability
CriticalZDI-26-546: Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability
CriticalSAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
CriticalAttackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
CriticalAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
CriticalNew Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
CriticalZoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Critical[remote] mcp-server-kubernetes 3.8.x - Argument Injection
Critical[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
Critical[webapps] Blocksy Companion 2.1.46 - RCE
CriticalResearchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
CriticalZoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
CriticalCISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CriticalMira Hormone Monitor, Mira Android App
CriticalResearchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
CriticalAn AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Critical[webapps] Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
Critical[webapps] CorgetGpsDget 2_3.2 - OS Command Injection
Critical[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
CriticalChina-Linked Hackers Exploit N-able Flaw in Ransomware Attacks
CriticalCritical Progress LoadMaster flaw now actively exploited in attacks
HighSecurity Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION
HighZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
HighZDI-26-565: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability
HighZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability
HighZDI-26-568: Linux Kernel Net Scheduler Race Condition Local Privilege Escalation Vulnerability
HighZDI-26-569: Linux Kernel Net Scheduler True Link Equalizer Race Condition Local Privilege Escalation Vulnerability
HighZDI-26-570: Linux Kernel IGMP Subsystem Race Condition Local Privilege Escalation Vulnerability
HighZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability
HighZDI-26-572: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability
HighZDI-26-574: Linux Kernel Net Scheduler Connection Tracking Race Condition Local Privilege Escalation Vulnerability
HighZDI-26-575: Linux Kernel Net Scheduler Packet Classifier API Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
HighZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability
HighZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
HighZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability
HighZDI-26-579: Cisco Identity Services Engine zipFiles Directory Traversal Remote Code Execution Vulnerability
HighZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability
HighZDI-26-581: Cisco Identity Services Engine invokeScript Command Injection Remote Code Execution Vulnerability
HighZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability
HighZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability
HighMicrosoft patches LegacyHive Windows zero-day vulnerability
HighHitachi Energy APM Edge Product
HighSiemens Simcenter Femap
HighSiemens Solid Edge
HighANDRITZ HIPASE-250 and 250 SCALA
HighSiemens LOGO! Soft Comfort
HighFlow Neuroscience FL-100
HighJohnson Controls Metasys
HighJohnson Controls Inc. Airwall
HighSiemens License Server (SLS)
HighSiemens Parasolid
HighZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
HighZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
HighWireshark 4.6.8 patches 28 security bugs, nine in file parsers
HighCisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
HighPatch Tuesday: Update now to fix 421 flaws, including three zero-days
High“Zoomsday” flaws could let one Zoom participant attack another
HighMultiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution
HighLazarus hackers exploited Windows zero-day to target defense firms
HighMicrosoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP
HighMicrosoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
HighCISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
HighShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
HighZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability
HighZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability
HighZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability
HighZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability
HighZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability
HighZDI-26-536: (Pwn2Own) Microsoft Windows http.sys Integer Overflow Local Privilege Escalation Vulnerability
HighZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability
HighZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
HighZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability
HighZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerability
HighZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability
HighZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability
HighZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
HighZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability
HighZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
HighZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
HighZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
HighZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
HighCisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
HighShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
HighMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
HighCisco Warns of Seven ClamAV Flaws, Two With Public PoCs
High[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion
High[webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
High[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
High[webapps] Apache Gravitino 1.2.1 - SSRF
HighMicrosoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
HighMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
HighMicrosoft Patch Tuesday, August 2026 Security Update Review
HighMicrosoft Patch Tuesday August 2026, (Tue, Aug 11th)
HighHead Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
HighMalicious SIMs can hijack smartphones, steal files, and lock them onto 2G
HighPulsetto Vagus Nerve Stimulator
HighCisco warns of high-severity ClamAV flaws with public exploits
HighMetabase SQL Zero-Day Attacks Could Have Wide Blast Radius
High⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
HighN-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
MediumZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability
MediumSiemens RUGGEDCOM APE1808
MediumZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability
MediumZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability
MediumZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability
MediumZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability
MediumZDI-26-540: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Information Disclosure Vulnerability
LowSiemens Desigo DXR and PXC Controllers

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests