CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 10 of 36 · newest first · times in UTC

Friday, Aug 2113 stories

  1. SecurityWeek
    In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

    CISA has added CVE-2025-62593 in Ray-Project Ray to its Known Exploited Vulnerabilities catalog after observing active abuse by the RondoDox botnet, prompting a mandate for federal agencies to prioritize remediation. This development sits alongside several other high-profile incidents, including GitHub's clarification that a vulnerability exploited by Wiz's AI agent was human-authored rather than generated by Copilot, and reports of T-Mobile physically cutting a router cable to halt an intrusion by Salt Typhoon. Additionally, FortiGuard Labs identified Evooo1Bot, a Linux botnet leveraging multiple CVEs, while Medusa ransomware groups are actively targeting unpatched vulnerabilities in Fortra GoAnywhere and BeyondTrust.

    Reported exploitedRondoDox
  2. Bishop Fox
    No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452

    Bishop Fox has published a detection utility to help administrators verify the patch status of Citrix NetScaler ADC and Gateway appliances affected by CVE-2026-8452. This high-severity memory corruption vulnerability allows unauthenticated attackers to trigger remote code execution via SAML processing, requiring an upgrade to the latest 13.1 or 14.1 builds. The provided tool enables non-disruptive verification of the fix across virtual servers without crashing the appliance.

    ResearchCitrix NetScaler ADC
  3. BleepingComputer
    CISA orders feds to patch actively exploited TrueConf Server flaws

    CISA has directed U.S. federal agencies to remediate two critical vulnerabilities in TrueConf Server, which are currently under active exploitation in the wild. The first flaw, CVE-2026-72529, permits unauthenticated remote code execution via an undocumented function on port 4307/TCP, while CVE-2026-72530 enables a sandbox escape through complex code injection. Kaspersky identifies the hacktivist group Head Mare as the actor leveraging these weaknesses since July 2026 to distribute trojanized client installers containing backdoor malware, primarily targeting Russian organizations. Federal civilian executive branch agencies must complete patches by September 3.

    Reported exploitedTrueConf Server
  4. Help Net Security
    Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

    Microsoft has addressed a critical remote code execution flaw identified as CVE-2026-69836 within its Entra ID cloud identity service, which is actively being exploited in the wild. Rated with the maximum CVSS score of 10.0, this vulnerability stems from the deserialization of untrusted data and permits unauthenticated attackers to execute code across the network without prior credentials. The issue was discovered by internal security engineer Robert Fitzpatrick and has already been fully mitigated by Microsoft, meaning no specific remediation steps are necessary for customers. Despite confirming active exploitation, the company has not yet disclosed details regarding the threat actors involved, the timeline of attacks, or the potential scope of compromised organizations.

    Reported exploitedMicrosoft Entra ID
  5. BleepingComputer
  6. BleepingComputer
    SickKids data breach exposes employee and job applicant info

    The Hospital for Sick Children (SickKids) has revealed that personal data belonging to current and former employees, as well as job applicants, was accessed during a cybersecurity incident. The hospital attributes the breach to a vulnerability in an unspecified third-party application, which has since been remediated. While clinical systems and patient records remain secure, the incident prompted a temporary takedown of the institution's public Careers website. SickKids is currently reviewing the scope of the exposure with external experts and will notify affected individuals directly, offering complimentary credit monitoring services in the interim.

    IncidentSickKids
  7. The Hacker News
    Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

    Cisco has issued security updates addressing nine vulnerabilities across its Crosswork and Secure Workload products, discovered during an internal security review. Four high-severity issues affect Crosswork Data Gateway, Network Controller, and Planning, including CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359, all of which are fixed in Release version 7.2.1-SP. Additionally, five vulnerabilities impact Secure Workload SaaS and on-premises deployments, such as CVE-2026-20315 and CVE-2026-20317, with fixes available in versions 3.10.9.1 and 4.0.4.16. Cisco states these flaws are not currently being actively exploited but urges administrators to apply the latest updates promptly to mitigate risk.

    PatchCrosswork Data Gateway
  8. SecurityWeek
    Microsoft Rolls Out 22 Fresh Security Patches

    Microsoft has distributed 22 new security updates to remediate critical and high-severity vulnerabilities across its portfolio, including Azure, Entra ID, Exchange Online, Fabric, and Partner Center. The release addresses several maximum-scoring flaws, such as remote code execution and elevation of privilege issues in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555, CVE-2026-65816), and Entra ID (CVE-2026-69836). For most of these defects, customers do not need to take action because Microsoft implemented the mitigations on the server side, though additional patches cover high-severity bugs in services like Copilot and Windows Remote Help Defense.

    PoC publicMicrosoft Azure SQL Database
  9. Help Net Security
    Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

    Citrix has issued urgent security updates for NetScaler ADC and NetScaler Gateway to address two newly disclosed vulnerabilities, with the primary threat being CVE-2026-19490. This critical flaw carries a CVSS v4.0 score of 9.3 and permits attackers to bypass authentication mechanisms under specific configuration conditions involving Gateway or AAA virtual servers. A secondary issue, CVE-2026-19489 (CVSS 8.8), involves a memory overflow that could lead to denial of service when SIP ALG is enabled on Large Scale NAT groups. While Rapid7 reports no evidence of active exploitation as of mid-August, Citrix advises immediate upgrades to supported builds, specifically versions 14.1-73.32 and 13.1-63.21, given the high likelihood of rapid opportunistic attacks against exposed infrastructure.

    PatchCitrix NetScaler ADC
  10. SecurityWeek
    CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    CISA has added two critical vulnerabilities affecting TrueConf Server, CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities catalog following reports of active use by the hacktivist group Head Mare. These flaws allow remote attackers with access to port 4307/TCP to execute arbitrary code on the host system, enabling the deployment of the PhantomCore malware. Federal agencies are urged to apply patches immediately, while all users of affected server versions should update to releases 5.3.9, 5.4.9, or 5.5.5 to mitigate the risk.

    Reported exploitedTrueConf Server
  11. The Hacker News
    GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

    WatchTowr has detected active in-the-wild exploitation of CVE-2026-19478, a critical code injection vulnerability affecting GitLab CE and EE shortly after its public disclosure. With a CVSS score of 9.4, this flaw allows unauthenticated attackers to manipulate or delete public projects via the GraphQL interface without needing credentials. Affected versions include GitLab 18.2 prior to 18.11.11, 19.0 before 19.0.8, 19.1 prior to 19.1.6, and 19.2 before 19.2.4. Organizations should upgrade to the patched releases immediately or mitigate risk by restricting unauthenticated access to /api/graphql while reviewing web logs for suspicious @glintroduced directives.

    Reported exploitedGitLab CE
  12. The Hacker News
    Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

    Microsoft has disclosed and fixed a critical remote code execution vulnerability in its cloud identity platform, Microsoft Entra ID. Tracked as CVE-2026-69836 with a maximum CVSS score of 10.0, the flaw stems from the deserialization of untrusted data, potentially allowing attackers to execute arbitrary code over the network. While reports confirm the vulnerability is being actively exploited in the wild, Microsoft states that it has fully mitigated the issue on their end and advises customers that no specific action is needed.

    Reported exploitedMicrosoft Entra ID
  13. Palo Alto Unit 42
    Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

    Palo Alto Networks' Unit 42 has published new research detailing how threat actors are shifting their focus from final software binaries to the foundational tools of the software development lifecycle (SDLC). The report highlights incidents such as the XZ Utils vulnerability (CVE-2024-3094) and the ChainDrop npm worm, which exploited preinstall hooks to harvest secrets from GitHub Actions runners and propagate via stolen tokens. By targeting un-sandboxed environments like developer endpoints, CI/CD pipelines, and cloud container runtimes, attackers can bypass traditional application scans. Key affected areas include npm, GitHub Actions, and VS Code, where malicious extensions or scripts operate with user-level privileges. To mitigate these risks, the team recommends strict execution controls, such as ignoring install scripts and limiting credential lifetimes.

    Researchnpm

Thursday, Aug 2019 stories

  1. The Hacker News
    ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

    Security researchers have disclosed critical remote code execution vulnerabilities in Gogs (CVE-2026-52813) and n8n (CVE-2026-33696), prompting immediate patch releases. Additionally, the U.S. Department of Justice has formally charged seventeen individuals affiliated with the Iran-based Mabna Institute for orchestrating a massive cyber-theft campaign targeting global academic institutions. Administrators should update Gogs to version 0.14.3 and n8n to versions 2.14.1, 2.13.3, or 1.123.27 to mitigate these risks. This week’s intelligence also highlights new exploitation techniques involving Microsoft Defender components and AI-assisted vulnerability discovery.

    PoC publicWindows Defender
  2. SecurityWeek
    Hackers Target Zimbra Servers in Active Exploitation Campaign

    CERT Polska has confirmed that attackers are actively exploiting a high-severity vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. The flaw allows unauthenticated attackers to execute arbitrary OS commands when the optional zimbra-snmp package is installed and SNMP notifications are enabled. This critical risk was addressed in version 10.1.20, released on July 20, so administrators should apply the patch immediately to prevent full server compromise, credential harvesting, and lateral movement.

    Reported exploitedZimbra Collaboration Suite
  3. BleepingComputer
    Critical Elementor Pro bug exposes WordPress sites to RCE attacks

    A critical remote code execution flaw identified as CVE-2026-32475 affects versions of Elementor Pro prior to 4.2.2, allowing unauthenticated attackers to upload executable files to WordPress servers. The vulnerability arises from a mismatch between file validation and processing loops in the File Upload module, specifically when handling empty filename entries within multipart uploads. Researchers at Patchstack disclosed that the exploit requires only a published Elementor form with a file upload field, enabling adversaries to place PHP payloads in public directories where they can be executed by the server. While no active exploitation has been observed yet, a proof-of-concept is available, urging administrators to immediately update to the fixed version and manually inspect their upload directories for malicious content.

    PoC publicElementor Pro
  4. Qualys Security Blog
    CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

    A public proof-of-concept has surfaced for ShieldBreak (CVE-2026-69414), a zero-day elevation-of-privilege flaw in the Microsoft Malware Protection Engine underlying Microsoft Defender. This vulnerability enables low-privileged local attackers to achieve full SYSTEM access by manipulating how Defender processes cloud-hydrated files via the Cloud Filter API. The exploit affects Windows 11 25H2 and Windows Server 2025, where attackers can abuse privileged processing paths to execute arbitrary code under high-trust contexts.

    PoC publicMicrosoft Defender
  5. The Hacker News
    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    Citrix has issued security updates for NetScaler ADC and NetScaler Gateway to remediate two vulnerabilities, including a high-severity authentication bypass. The critical flaw, identified as CVE-2026-19490 with a CVSS score of 9.3, allows attackers to bypass authentication on devices configured as Gateway or AAA servers under specific conditions. Additionally, CVE-2026-19489 (CVSS 8.8) introduces a memory overflow risk that could lead to denial-of-service when SIP ALG is enabled. Administrators are advised to upgrade to NetScaler ADC and NetScaler Gateway version 14.1-73.32 or later, or version 13.1-63.21 or later, to mitigate these risks, though no active exploitation has been confirmed.

    PatchNetScaler ADC
  6. The Hacker News
    Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

    CERT Polska has confirmed active in-the-wild exploitation of CVE-2026-73570, a high-severity command injection vulnerability in Zimbra Collaboration Suite versions prior to 10.1.20. The flaw affects installations where the zimbra-snmp package is present and allows unauthenticated attackers to execute arbitrary OS commands by sending crafted SMTP requests that bypass input sanitization during SNMP notification handling. While Zimbra released a patch for this issue in July, the recent confirmation of real-world attacks underscores the urgent need for organizations to verify they have upgraded to version 10.1.20 and should inspect system logs for signs of compromise.

    Reported exploitedZimbra Collaboration Suite
  7. SecurityWeek
    Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

    A threat actor known for Operation CameraSwarm has compromised over 14,000 Dahua IP cameras across Ukraine and Russia between mid-June and late July. The attacker leveraged a brute-force engine alongside authentication bypass techniques involving CVE-2021-33044, CVE-2021-33045, and CVE-20244-39943 to gain unauthorized administrative access. This exploit chain allowed the deployment of a persistent backdoor account using the credentials p2pwn/p2password via RPC, which remains effective even after password changes or factory resets on many firmware versions. Hunt.io discovered that the operator had prepared this infrastructure long in advance and utilized a toolkit combining proprietary code with modified scripts from other developers. While the specific motivation behind the mass compromise is unclear, the presence of enterprise-format export tools suggests the data may have been intended for transfer to a third party.

    Reported exploitedDahua IP Cameras
  8. BleepingComputer
    Citrix urges admins to patch new NetScaler flaws as soon as possible

    Citrix has issued a security update addressing two newly disclosed vulnerabilities in its NetScaler ADC and NetScaler Gateway products. The most severe flaw, CVE-2026-19490, allows unauthenticated remote attackers to bypass authentication mechanisms under specific configuration conditions, while CVE-2026-19489 permits denial-of-service attacks via a memory overflow when SIP ALG is enabled. Although there is no evidence of active exploitation yet, the vendor strongly recommends that administrators apply the relevant patches immediately to secure their environments.

    PatchNetScaler ADC
  9. SecurityWeek
    MLflow Vulnerability Exploited for Cloud Credential Theft

    Threat actors are actively leveraging an unauthenticated server-side request forgery (SSRF) flaw in MLflow, tracked as CVE-2026-64849, to exfiltrate cloud credentials and secrets. The vulnerability stems from the MLflow Tracking Server exposing model-registry webhook APIs without proper authentication, allowing attackers to bypass SSRF protections introduced in version 3.10.0 and directly access cloud metadata services. With a CVSS score of 9.3, this defect affects all MLflow versions prior to 3.15.0 and has been added to the CISA Known Exploited Vulnerabilities catalog, prompting urgent remediation across affected systems.

    Reported exploitedMLflow
  10. SecurityWeek
    Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

    Cisco has issued security updates to address 15 vulnerabilities, highlighting critical defects in its Crosswork and Secure Workload platforms. The latest release for Crosswork resolves four high-severity issues, including CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, which enable risks such as SQL injection and remote code execution, alongside CVE-2026-20359 involving credential protection failures. Secure Workload versions 4.0.4.16 and 3.10.9.1 fix five similar critical-class vulnerabilities covering access control, command injection, and buffer overflow concerns. While no active exploitation has been reported, the vendor advises users to apply these patches promptly to mitigate potential unauthorized system access.

    PatchCrosswork
  11. The Hacker News
    CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

    Security researchers have identified two denial-of-service vectors, collectively termed "CDN Tsunami," that exploit the conversion of HTTP/3 traffic to HTTP/1.1 by major content delivery networks. By leveraging mismatches in header compression and connection handling, attackers can amplify bandwidth or exhaust origin server connections, with factors reaching up to 350x on platforms like Alibaba, Baidu, and Tencent. Although no CVE has been assigned and no wild exploitation is currently reported, the study indicates significant potential for disruption across six prominent providers. Affected services include Cloudflare, Amazon CloudFront, and Fastly, prompting recommendations for stricter CDN-side limits on header sizes and backend connection multiplicity.

    ResearchCDN Services
  12. BleepingComputer
    CISA warns of hackers exploiting critical MLflow vulnerability

    CISA has identified active real-world attacks targeting a critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849. This unauthenticated DNS-rebinding bypass affects the outbound webhook delivery mechanism and enables attackers to steal cloud credentials, such as AWS IAM keys, from internal services. The vulnerability is resolved in MLflow 3.15.0, and federal agencies have been ordered to apply the patch within two weeks under Binding Operational Directive 26-04.

    Reported exploitedMLflow
  13. The Hacker News
    NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

    Researchers at Cycode revealed that vulnerabilities in AIT-GUI, the browser-based console for NASA/JPL's AMMOS Instrument Toolkit, allowed unauthenticated actors to send arbitrary commands to spacecraft instruments. Identified as GHSA-p9r8-2q67-fp86 with a CVSS score of 9.4, the flaw impacted versions up to 2.5.1 because the server bound to all interfaces without requiring credentials or CSRF protection. Version 2.5.2 resolves these issues by restricting network bindings and enforcing origin checks on state-changing requests, though related records like CVE-2026-60112 highlight ongoing discrepancies regarding full authentication enforcement.

    PatchAIT-GUI
  14. Cisco Talos
    UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

    Cisco Talos has published analysis of a new cross-platform implant named SPECTRE, which is actively being deployed by the threat actor UAT-10147 against Windows and Linux environments. The malware integrates advanced capabilities including process injection, credential theft, and Bring Your Own Vulnerable Driver (BYOVD) techniques to neutralize endpoint detection and response solutions by exploiting known vulnerabilities such as CVE-2019-16098 and CVE-2021-21551. Notably, the research highlights emerging patterns in offensive security tooling, with indicators suggesting that UAT-10147 utilized AI-assisted workflows to develop parts of the SPECTRE implant and the associated Specter Linux rootkit. This evolution underscores the increasing sophistication of commodity intrusion tooling and its impact on modern enterprise defenses.

    Reported exploitedWindows OS
  15. Cisco Talos
  16. BleepingComputer
    Critical Zimbra RCE flaw now actively exploited in attacks

    CERT Polska has confirmed that attackers are actively exploiting a critical remote code execution vulnerability identified as CVE-2026-73570 in the Zimbra Collaboration Suite. This flaw stems from insufficient input sanitization in the SNMP monitoring component, allowing unauthenticated users to execute arbitrary operating system commands when SNMP notifications are enabled. To remediate this issue, Zimbra released version 10.1.20 on July 20. Administrators should urgently apply this update and review system logs for signs of compromise, such as unexpected service restarts or unauthorized file creations within specific Jetty webapp directories.

    Reported exploitedZimbra Collaboration Suite
  17. SecurityWeek
    Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

    Citrix has released security updates for NetScaler ADC and NetScaler Gateway to remediate two distinct vulnerabilities, the most severe being an authentication bypass tracked as CVE-2026-19490 with a CVSS score of 9.3. This critical flaw allows remote, unauthenticated attackers to circumvent access controls on gateways configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA services without any user interaction. A second high-severity issue, CVE-2026-19489, involves a memory overflow in SIP ALG configurations that can result in denial-of-service conditions. Organizations should urgently apply the fixes available in NetScaler versions 14.1-73.32, 13.1-63.21, and other specified builds, as Rapid7 predicts imminent exploitation attempts given the widespread deployment of these appliances in enterprise perimeters.

    PatchNetScaler ADC
  18. SecurityWeek
    Critical GitLab Flaw Exploited Shortly After Disclosure

    WatchTowr has confirmed that threat actors began actively exploiting CVE-2026-19478, a critical code injection flaw in GitLab Community Edition (CE) and Enterprise Edition (EE), just two days after its public disclosure. The vulnerability allows unauthenticated attackers to remotely manipulate public projects, including deleting repositories and forging merge records, without requiring any prior credentials. Users are urged to update to fixed versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, or mitigate risk by restricting access to the /api/graphql endpoint.

    Reported exploitedGitLab CE
  19. The Hacker News
    Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

    Researchers have identified a critical vulnerability in the Elementor Pro WordPress plugin that allows unauthenticated attackers to achieve remote code execution through file upload manipulation. Tracked as CVE-2026-32475 with a CVSS score of 9.0, the flaw exists in the Forms module's File Upload field, where discrepancies in extension checking and file handling permit the bypass of security restrictions. This issue affects all versions of Elementor Pro up to 4.2.1, but has been resolved in the recently released version 4.2.2.

    PatchElementor Pro

Wednesday, Aug 198 stories

  1. BleepingComputer
    Hackers compromise 14,500 Dahua web cameras in 35-day campaign

    Threat intelligence firm Hunt.io has identified a 35-day attack campaign dubbed CameraSwarm that compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia. The operation utilized a combination of brute-force attacks against TCP port 37777, exploitation of CVE-2021-33044 and CVE-2021-33045 to install persistent backdoors, and unauthorized cloud-relay access via serial numbers. Researchers recovered extensive operational data, including source code and credentials, from an unprotected server directory left open by the attackers. Administrators are advised to check devices for the malicious 'p2pwn' account, apply firmware updates per Dahua SA-2021-0130, and disable P2P services when not in use.

    Reported exploitedDahua IP Cameras
  2. Patchstack
    Critical Unauthenticated File Upload to RCE in Elementor Pro Plugin

    A critical unauthenticated remote code execution vulnerability (CVE-2026-32475) affecting the Elementor Pro plugin for WordPress has been patched in version 4.2.2, following the release of a public proof-of-concept. The flaw resides in the Forms module's File Upload field, where a logic discrepancy between validation and processing loops allows attackers to bypass extension blocklists by submitting empty file entries alongside malicious PHP payloads. This issue enables unauthenticated visitors to place executable scripts in public directories if a form with an optional file upload is present, leading to full server compromise. Site administrators are urged to update immediately and review the wp-content/uploads/elementor/forms/ directory for any unexpected PHP files that may have been deployed prior to the patch.

    PoC publicElementor Pro
  3. Qualys Security Blog
    Oracle Critical Patch Update, August 2026 Security Update Review

    Oracle has distributed its August 2026 Critical Patch Update, resolving a total of 943 security vulnerabilities across its portfolio. The release places significant emphasis on Oracle Fusion Middleware and Oracle Hyperion, each receiving 262 individual patches, while Oracle Database components addressed 17 specific issues. Notable high-severity fixes include CVE-2026-60782 and CVE-2026-70926 in Oracle E-Business Suite, both rated with a CVSS base score of 9.8 and permitting remote code execution without authentication. Administrators should prioritize deploying these updates to mitigate exposure in network-accessible services such as Oracle Siebel CRM and Oracle Commerce.

    RoundupOracle Fusion Middleware
  4. The Hacker News
    Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

    Researchers at Hunt.io identified a campaign dubbed Operation CameraSwarm that exploited over 14,500 Dahua devices between June and July 2026. The attackers utilized credential stuffing, the authentication bypass vulnerabilities CVE-2021-33044 and CVE-2021-33045, and peer-to-peer relay techniques to gain unauthorized access, with significant impacts reported in Ukraine and Russia. These flaws allow bypass of device identity checks and enable connections to devices behind NAT without initial authentication. Affected users are advised to apply firmware updates from Dahua’s official site, disable unnecessary P2P features, and audit credentials to mitigate these risks.

    Reported exploitedDahua IP Cameras
  5. SecurityWeek
    Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

    The Cl0p ransomware group has published the full names of over 40 organizations allegedly targeted through a campaign exploiting CVE-2026-12569, a critical vulnerability in PTC’s Windchill and FlexPLM product lifecycle management platforms. This improper input validation flaw allows unauthenticated remote attackers to execute arbitrary code, marking the first time a Windchill defect has been exploited in the wild. ReliaQuest noted that Cl0p deployed a custom implant to steal credentials and exfiltrate vast amounts of data, including engineering documents and databases, from victims such as Shell, Philips, and Fiserv.

    Reported exploitedPTC
  6. The Hacker News
    Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

    CISA has updated its Known Exploited Vulnerabilities catalog to include four high-severity flaws currently being targeted by threat actors. These vulnerabilities affect Apple macOS (CVE-2026-65400), Microsoft SharePoint (CVE-2026-55040), VMware vCenter (CVE-2026-59310), and Microsoft IKE (CVE-2026-33824). Active attacks range from cryptocurrency mining via the macOS flaw to ransomware deployment through the vCenter path traversal bug, with victims reported across 47 countries. Federal agencies are required to apply the vendor-provided patches by August 21, 2026, to mitigate these risks.

    Reported exploitedmacOS
  7. SecurityWeek
    CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

    CISA has mandated immediate remediation for four active vulnerabilities across Microsoft, VMware, and Apple systems, adding them to the Known Exploited Vulnerabilities catalog. The alert covers CVE-2026-33824 in Windows IKE, CVE-2026-55040 in SharePoint, CVE-2026-59310 in VMware vCenter, and CVE-2026-65400 in macOS Screen Sharing. Federal agencies are required to apply patches by August 21 to mitigate these in-the-wild threats.

    Reported exploitedWindows IKE
  8. Help Net Security
    Medusa ransomware gang has hit over 500 organizations, CISA warns

    FBI, CISA, and HHS have issued an updated joint advisory revealing that the Medusa ransomware group has compromised more than 500 organizations since 2021. The agencies report that victims span critical sectors including healthcare, defense, manufacturing, and finance, with many organizations affected through unpatched vulnerabilities in products such as ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust. Medusa operates via an affiliate model where operators deploy newly disclosed exploits within 24 hours of announcement rather than developing zero-days. To mitigate risk, defenders should immediately patch internet-facing systems, segment networks to restrict lateral movement, and block unauthorized remote access traffic.

    Reported exploitedScreenConnect

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store