Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.
The wire
Friday, Aug 2113 stories
- SecurityWeekIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
CISA has added CVE-2025-62593 in Ray-Project Ray to its Known Exploited Vulnerabilities catalog after observing active abuse by the RondoDox botnet, prompting a mandate for federal agencies to prioritize remediation. This development sits alongside several other high-profile incidents, including GitHub's clarification that a vulnerability exploited by Wiz's AI agent was human-authored rather than generated by Copilot, and reports of T-Mobile physically cutting a router cable to halt an intrusion by Salt Typhoon. Additionally, FortiGuard Labs identified Evooo1Bot, a Linux botnet leveraging multiple CVEs, while Medusa ransomware groups are actively targeting unpatched vulnerabilities in Fortra GoAnywhere and BeyondTrust.
Reported exploitedRondoDox - Bishop FoxNo Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452
Bishop Fox has published a detection utility to help administrators verify the patch status of Citrix NetScaler ADC and Gateway appliances affected by CVE-2026-8452. This high-severity memory corruption vulnerability allows unauthenticated attackers to trigger remote code execution via SAML processing, requiring an upgrade to the latest 13.1 or 14.1 builds. The provided tool enables non-disruptive verification of the fix across virtual servers without crashing the appliance.
ResearchCitrix NetScaler ADC - BleepingComputerCISA orders feds to patch actively exploited TrueConf Server flaws
CISA has directed U.S. federal agencies to remediate two critical vulnerabilities in TrueConf Server, which are currently under active exploitation in the wild. The first flaw, CVE-2026-72529, permits unauthenticated remote code execution via an undocumented function on port 4307/TCP, while CVE-2026-72530 enables a sandbox escape through complex code injection. Kaspersky identifies the hacktivist group Head Mare as the actor leveraging these weaknesses since July 2026 to distribute trojanized client installers containing backdoor malware, primarily targeting Russian organizations. Federal civilian executive branch agencies must complete patches by September 3.
Reported exploitedTrueConf Server - Help Net SecurityCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)
Microsoft has addressed a critical remote code execution flaw identified as CVE-2026-69836 within its Entra ID cloud identity service, which is actively being exploited in the wild. Rated with the maximum CVSS score of 10.0, this vulnerability stems from the deserialization of untrusted data and permits unauthenticated attackers to execute code across the network without prior credentials. The issue was discovered by internal security engineer Robert Fitzpatrick and has already been fully mitigated by Microsoft, meaning no specific remediation steps are necessary for customers. Despite confirming active exploitation, the company has not yet disclosed details regarding the threat actors involved, the timeline of attacks, or the potential scope of compromised organizations.
Reported exploitedMicrosoft Entra ID - BleepingComputerMicrosoft warns of max severity Entra ID flaw exploited in attacksReported exploitedMicrosoft Entra ID
- BleepingComputerSickKids data breach exposes employee and job applicant info
The Hospital for Sick Children (SickKids) has revealed that personal data belonging to current and former employees, as well as job applicants, was accessed during a cybersecurity incident. The hospital attributes the breach to a vulnerability in an unspecified third-party application, which has since been remediated. While clinical systems and patient records remain secure, the incident prompted a temporary takedown of the institution's public Careers website. SickKids is currently reviewing the scope of the exposure with external experts and will notify affected individuals directly, offering complimentary credit monitoring services in the interim.
IncidentSickKids - The Hacker NewsCisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has issued security updates addressing nine vulnerabilities across its Crosswork and Secure Workload products, discovered during an internal security review. Four high-severity issues affect Crosswork Data Gateway, Network Controller, and Planning, including CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359, all of which are fixed in Release version 7.2.1-SP. Additionally, five vulnerabilities impact Secure Workload SaaS and on-premises deployments, such as CVE-2026-20315 and CVE-2026-20317, with fixes available in versions 3.10.9.1 and 4.0.4.16. Cisco states these flaws are not currently being actively exploited but urges administrators to apply the latest updates promptly to mitigate risk.
PatchCrosswork Data Gateway - SecurityWeekMicrosoft Rolls Out 22 Fresh Security Patches
Microsoft has distributed 22 new security updates to remediate critical and high-severity vulnerabilities across its portfolio, including Azure, Entra ID, Exchange Online, Fabric, and Partner Center. The release addresses several maximum-scoring flaws, such as remote code execution and elevation of privilege issues in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555, CVE-2026-65816), and Entra ID (CVE-2026-69836). For most of these defects, customers do not need to take action because Microsoft implemented the mitigations on the server side, though additional patches cover high-severity bugs in services like Copilot and Windows Remote Help Defense.
PoC publicMicrosoft Azure SQL Database - Help Net SecurityCitrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has issued urgent security updates for NetScaler ADC and NetScaler Gateway to address two newly disclosed vulnerabilities, with the primary threat being CVE-2026-19490. This critical flaw carries a CVSS v4.0 score of 9.3 and permits attackers to bypass authentication mechanisms under specific configuration conditions involving Gateway or AAA virtual servers. A secondary issue, CVE-2026-19489 (CVSS 8.8), involves a memory overflow that could lead to denial of service when SIP ALG is enabled on Large Scale NAT groups. While Rapid7 reports no evidence of active exploitation as of mid-August, Citrix advises immediate upgrades to supported builds, specifically versions 14.1-73.32 and 13.1-63.21, given the high likelihood of rapid opportunistic attacks against exposed infrastructure.
PatchCitrix NetScaler ADC - SecurityWeekCISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
CISA has added two critical vulnerabilities affecting TrueConf Server, CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities catalog following reports of active use by the hacktivist group Head Mare. These flaws allow remote attackers with access to port 4307/TCP to execute arbitrary code on the host system, enabling the deployment of the PhantomCore malware. Federal agencies are urged to apply patches immediately, while all users of affected server versions should update to releases 5.3.9, 5.4.9, or 5.5.5 to mitigate the risk.
Reported exploitedTrueConf Server - The Hacker NewsGitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
WatchTowr has detected active in-the-wild exploitation of CVE-2026-19478, a critical code injection vulnerability affecting GitLab CE and EE shortly after its public disclosure. With a CVSS score of 9.4, this flaw allows unauthenticated attackers to manipulate or delete public projects via the GraphQL interface without needing credentials. Affected versions include GitLab 18.2 prior to 18.11.11, 19.0 before 19.0.8, 19.1 prior to 19.1.6, and 19.2 before 19.2.4. Organizations should upgrade to the patched releases immediately or mitigate risk by restricting unauthenticated access to /api/graphql while reviewing web logs for suspicious @glintroduced directives.
Reported exploitedGitLab CE - The Hacker NewsMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft has disclosed and fixed a critical remote code execution vulnerability in its cloud identity platform, Microsoft Entra ID. Tracked as CVE-2026-69836 with a maximum CVSS score of 10.0, the flaw stems from the deserialization of untrusted data, potentially allowing attackers to execute arbitrary code over the network. While reports confirm the vulnerability is being actively exploited in the wild, Microsoft states that it has fully mitigated the issue on their end and advises customers that no specific action is needed.
Reported exploitedMicrosoft Entra ID - Palo Alto Unit 42Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Palo Alto Networks' Unit 42 has published new research detailing how threat actors are shifting their focus from final software binaries to the foundational tools of the software development lifecycle (SDLC). The report highlights incidents such as the XZ Utils vulnerability (CVE-2024-3094) and the ChainDrop npm worm, which exploited preinstall hooks to harvest secrets from GitHub Actions runners and propagate via stolen tokens. By targeting un-sandboxed environments like developer endpoints, CI/CD pipelines, and cloud container runtimes, attackers can bypass traditional application scans. Key affected areas include npm, GitHub Actions, and VS Code, where malicious extensions or scripts operate with user-level privileges. To mitigate these risks, the team recommends strict execution controls, such as ignoring install scripts and limiting credential lifetimes.
Researchnpm
Thursday, Aug 2019 stories
- The Hacker NewsThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
Security researchers have disclosed critical remote code execution vulnerabilities in Gogs (CVE-2026-52813) and n8n (CVE-2026-33696), prompting immediate patch releases. Additionally, the U.S. Department of Justice has formally charged seventeen individuals affiliated with the Iran-based Mabna Institute for orchestrating a massive cyber-theft campaign targeting global academic institutions. Administrators should update Gogs to version 0.14.3 and n8n to versions 2.14.1, 2.13.3, or 1.123.27 to mitigate these risks. This week’s intelligence also highlights new exploitation techniques involving Microsoft Defender components and AI-assisted vulnerability discovery.
PoC publicWindows Defender - SecurityWeekHackers Target Zimbra Servers in Active Exploitation Campaign
CERT Polska has confirmed that attackers are actively exploiting a high-severity vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. The flaw allows unauthenticated attackers to execute arbitrary OS commands when the optional zimbra-snmp package is installed and SNMP notifications are enabled. This critical risk was addressed in version 10.1.20, released on July 20, so administrators should apply the patch immediately to prevent full server compromise, credential harvesting, and lateral movement.
Reported exploitedZimbra Collaboration Suite - BleepingComputerCritical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical remote code execution flaw identified as CVE-2026-32475 affects versions of Elementor Pro prior to 4.2.2, allowing unauthenticated attackers to upload executable files to WordPress servers. The vulnerability arises from a mismatch between file validation and processing loops in the File Upload module, specifically when handling empty filename entries within multipart uploads. Researchers at Patchstack disclosed that the exploit requires only a published Elementor form with a file upload field, enabling adversaries to place PHP payloads in public directories where they can be executed by the server. While no active exploitation has been observed yet, a proof-of-concept is available, urging administrators to immediately update to the fixed version and manually inspect their upload directories for malicious content.
PoC publicElementor Pro - Qualys Security BlogCVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
A public proof-of-concept has surfaced for ShieldBreak (CVE-2026-69414), a zero-day elevation-of-privilege flaw in the Microsoft Malware Protection Engine underlying Microsoft Defender. This vulnerability enables low-privileged local attackers to achieve full SYSTEM access by manipulating how Defender processes cloud-hydrated files via the Cloud Filter API. The exploit affects Windows 11 25H2 and Windows Server 2025, where attackers can abuse privileged processing paths to execute arbitrary code under high-trust contexts.
PoC publicMicrosoft Defender - The Hacker NewsCritical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has issued security updates for NetScaler ADC and NetScaler Gateway to remediate two vulnerabilities, including a high-severity authentication bypass. The critical flaw, identified as CVE-2026-19490 with a CVSS score of 9.3, allows attackers to bypass authentication on devices configured as Gateway or AAA servers under specific conditions. Additionally, CVE-2026-19489 (CVSS 8.8) introduces a memory overflow risk that could lead to denial-of-service when SIP ALG is enabled. Administrators are advised to upgrade to NetScaler ADC and NetScaler Gateway version 14.1-73.32 or later, or version 13.1-63.21 or later, to mitigate these risks, though no active exploitation has been confirmed.
PatchNetScaler ADC - The Hacker NewsAttackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
CERT Polska has confirmed active in-the-wild exploitation of CVE-2026-73570, a high-severity command injection vulnerability in Zimbra Collaboration Suite versions prior to 10.1.20. The flaw affects installations where the zimbra-snmp package is present and allows unauthenticated attackers to execute arbitrary OS commands by sending crafted SMTP requests that bypass input sanitization during SNMP notification handling. While Zimbra released a patch for this issue in July, the recent confirmation of real-world attacks underscores the urgent need for organizations to verify they have upgraded to version 10.1.20 and should inspect system logs for signs of compromise.
Reported exploitedZimbra Collaboration Suite - SecurityWeekThreat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
A threat actor known for Operation CameraSwarm has compromised over 14,000 Dahua IP cameras across Ukraine and Russia between mid-June and late July. The attacker leveraged a brute-force engine alongside authentication bypass techniques involving CVE-2021-33044, CVE-2021-33045, and CVE-20244-39943 to gain unauthorized administrative access. This exploit chain allowed the deployment of a persistent backdoor account using the credentials p2pwn/p2password via RPC, which remains effective even after password changes or factory resets on many firmware versions. Hunt.io discovered that the operator had prepared this infrastructure long in advance and utilized a toolkit combining proprietary code with modified scripts from other developers. While the specific motivation behind the mass compromise is unclear, the presence of enterprise-format export tools suggests the data may have been intended for transfer to a third party.
Reported exploitedDahua IP Cameras - BleepingComputerCitrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has issued a security update addressing two newly disclosed vulnerabilities in its NetScaler ADC and NetScaler Gateway products. The most severe flaw, CVE-2026-19490, allows unauthenticated remote attackers to bypass authentication mechanisms under specific configuration conditions, while CVE-2026-19489 permits denial-of-service attacks via a memory overflow when SIP ALG is enabled. Although there is no evidence of active exploitation yet, the vendor strongly recommends that administrators apply the relevant patches immediately to secure their environments.
PatchNetScaler ADC - SecurityWeekMLflow Vulnerability Exploited for Cloud Credential Theft
Threat actors are actively leveraging an unauthenticated server-side request forgery (SSRF) flaw in MLflow, tracked as CVE-2026-64849, to exfiltrate cloud credentials and secrets. The vulnerability stems from the MLflow Tracking Server exposing model-registry webhook APIs without proper authentication, allowing attackers to bypass SSRF protections introduced in version 3.10.0 and directly access cloud metadata services. With a CVSS score of 9.3, this defect affects all MLflow versions prior to 3.15.0 and has been added to the CISA Known Exploited Vulnerabilities catalog, prompting urgent remediation across affected systems.
Reported exploitedMLflow - SecurityWeekCisco Patches Critical Crosswork, Secure Workload Vulnerabilities
Cisco has issued security updates to address 15 vulnerabilities, highlighting critical defects in its Crosswork and Secure Workload platforms. The latest release for Crosswork resolves four high-severity issues, including CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, which enable risks such as SQL injection and remote code execution, alongside CVE-2026-20359 involving credential protection failures. Secure Workload versions 4.0.4.16 and 3.10.9.1 fix five similar critical-class vulnerabilities covering access control, command injection, and buffer overflow concerns. While no active exploitation has been reported, the vendor advises users to apply these patches promptly to mitigate potential unauthorized system access.
PatchCrosswork - The Hacker NewsCDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Security researchers have identified two denial-of-service vectors, collectively termed "CDN Tsunami," that exploit the conversion of HTTP/3 traffic to HTTP/1.1 by major content delivery networks. By leveraging mismatches in header compression and connection handling, attackers can amplify bandwidth or exhaust origin server connections, with factors reaching up to 350x on platforms like Alibaba, Baidu, and Tencent. Although no CVE has been assigned and no wild exploitation is currently reported, the study indicates significant potential for disruption across six prominent providers. Affected services include Cloudflare, Amazon CloudFront, and Fastly, prompting recommendations for stricter CDN-side limits on header sizes and backend connection multiplicity.
ResearchCDN Services - BleepingComputerCISA warns of hackers exploiting critical MLflow vulnerability
CISA has identified active real-world attacks targeting a critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849. This unauthenticated DNS-rebinding bypass affects the outbound webhook delivery mechanism and enables attackers to steal cloud credentials, such as AWS IAM keys, from internal services. The vulnerability is resolved in MLflow 3.15.0, and federal agencies have been ordered to apply the patch within two weeks under Binding Operational Directive 26-04.
Reported exploitedMLflow - The Hacker NewsNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Researchers at Cycode revealed that vulnerabilities in AIT-GUI, the browser-based console for NASA/JPL's AMMOS Instrument Toolkit, allowed unauthenticated actors to send arbitrary commands to spacecraft instruments. Identified as GHSA-p9r8-2q67-fp86 with a CVSS score of 9.4, the flaw impacted versions up to 2.5.1 because the server bound to all interfaces without requiring credentials or CSRF protection. Version 2.5.2 resolves these issues by restricting network bindings and enforcing origin checks on state-changing requests, though related records like CVE-2026-60112 highlight ongoing discrepancies regarding full authentication enforcement.
PatchAIT-GUI - Cisco TalosUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Cisco Talos has published analysis of a new cross-platform implant named SPECTRE, which is actively being deployed by the threat actor UAT-10147 against Windows and Linux environments. The malware integrates advanced capabilities including process injection, credential theft, and Bring Your Own Vulnerable Driver (BYOVD) techniques to neutralize endpoint detection and response solutions by exploiting known vulnerabilities such as CVE-2019-16098 and CVE-2021-21551. Notably, the research highlights emerging patterns in offensive security tooling, with indicators suggesting that UAT-10147 utilized AI-assisted workflows to develop parts of the SPECTRE implant and the associated Specter Linux rootkit. This evolution underscores the increasing sophistication of commodity intrusion tooling and its impact on modern enterprise defenses.
Reported exploitedWindows OS - Cisco TalosUAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsReported exploitedWindows Server
- BleepingComputerCritical Zimbra RCE flaw now actively exploited in attacks
CERT Polska has confirmed that attackers are actively exploiting a critical remote code execution vulnerability identified as CVE-2026-73570 in the Zimbra Collaboration Suite. This flaw stems from insufficient input sanitization in the SNMP monitoring component, allowing unauthenticated users to execute arbitrary operating system commands when SNMP notifications are enabled. To remediate this issue, Zimbra released version 10.1.20 on July 20. Administrators should urgently apply this update and review system logs for signs of compromise, such as unexpected service restarts or unauthorized file creations within specific Jetty webapp directories.
Reported exploitedZimbra Collaboration Suite - SecurityWeekExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Citrix has released security updates for NetScaler ADC and NetScaler Gateway to remediate two distinct vulnerabilities, the most severe being an authentication bypass tracked as CVE-2026-19490 with a CVSS score of 9.3. This critical flaw allows remote, unauthenticated attackers to circumvent access controls on gateways configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA services without any user interaction. A second high-severity issue, CVE-2026-19489, involves a memory overflow in SIP ALG configurations that can result in denial-of-service conditions. Organizations should urgently apply the fixes available in NetScaler versions 14.1-73.32, 13.1-63.21, and other specified builds, as Rapid7 predicts imminent exploitation attempts given the widespread deployment of these appliances in enterprise perimeters.
PatchNetScaler ADC - SecurityWeekCritical GitLab Flaw Exploited Shortly After Disclosure
WatchTowr has confirmed that threat actors began actively exploiting CVE-2026-19478, a critical code injection flaw in GitLab Community Edition (CE) and Enterprise Edition (EE), just two days after its public disclosure. The vulnerability allows unauthenticated attackers to remotely manipulate public projects, including deleting repositories and forging merge records, without requiring any prior credentials. Users are urged to update to fixed versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, or mitigate risk by restricting access to the /api/graphql endpoint.
Reported exploitedGitLab CE - The Hacker NewsElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Researchers have identified a critical vulnerability in the Elementor Pro WordPress plugin that allows unauthenticated attackers to achieve remote code execution through file upload manipulation. Tracked as CVE-2026-32475 with a CVSS score of 9.0, the flaw exists in the Forms module's File Upload field, where discrepancies in extension checking and file handling permit the bypass of security restrictions. This issue affects all versions of Elementor Pro up to 4.2.1, but has been resolved in the recently released version 4.2.2.
PatchElementor Pro
Wednesday, Aug 198 stories
- BleepingComputerHackers compromise 14,500 Dahua web cameras in 35-day campaign
Threat intelligence firm Hunt.io has identified a 35-day attack campaign dubbed CameraSwarm that compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia. The operation utilized a combination of brute-force attacks against TCP port 37777, exploitation of CVE-2021-33044 and CVE-2021-33045 to install persistent backdoors, and unauthorized cloud-relay access via serial numbers. Researchers recovered extensive operational data, including source code and credentials, from an unprotected server directory left open by the attackers. Administrators are advised to check devices for the malicious 'p2pwn' account, apply firmware updates per Dahua SA-2021-0130, and disable P2P services when not in use.
Reported exploitedDahua IP Cameras - PatchstackCritical Unauthenticated File Upload to RCE in Elementor Pro Plugin
A critical unauthenticated remote code execution vulnerability (CVE-2026-32475) affecting the Elementor Pro plugin for WordPress has been patched in version 4.2.2, following the release of a public proof-of-concept. The flaw resides in the Forms module's File Upload field, where a logic discrepancy between validation and processing loops allows attackers to bypass extension blocklists by submitting empty file entries alongside malicious PHP payloads. This issue enables unauthenticated visitors to place executable scripts in public directories if a form with an optional file upload is present, leading to full server compromise. Site administrators are urged to update immediately and review the wp-content/uploads/elementor/forms/ directory for any unexpected PHP files that may have been deployed prior to the patch.
PoC publicElementor Pro - Qualys Security BlogOracle Critical Patch Update, August 2026 Security Update Review
Oracle has distributed its August 2026 Critical Patch Update, resolving a total of 943 security vulnerabilities across its portfolio. The release places significant emphasis on Oracle Fusion Middleware and Oracle Hyperion, each receiving 262 individual patches, while Oracle Database components addressed 17 specific issues. Notable high-severity fixes include CVE-2026-60782 and CVE-2026-70926 in Oracle E-Business Suite, both rated with a CVSS base score of 9.8 and permitting remote code execution without authentication. Administrators should prioritize deploying these updates to mitigate exposure in network-accessible services such as Oracle Siebel CRM and Oracle Commerce.
RoundupOracle Fusion Middleware - The Hacker NewsHackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Researchers at Hunt.io identified a campaign dubbed Operation CameraSwarm that exploited over 14,500 Dahua devices between June and July 2026. The attackers utilized credential stuffing, the authentication bypass vulnerabilities CVE-2021-33044 and CVE-2021-33045, and peer-to-peer relay techniques to gain unauthorized access, with significant impacts reported in Ukraine and Russia. These flaws allow bypass of device identity checks and enable connections to devices behind NAT without initial authentication. Affected users are advised to apply firmware updates from Dahua’s official site, disable unnecessary P2P features, and audit credentials to mitigate these risks.
Reported exploitedDahua IP Cameras - SecurityWeekCl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware group has published the full names of over 40 organizations allegedly targeted through a campaign exploiting CVE-2026-12569, a critical vulnerability in PTC’s Windchill and FlexPLM product lifecycle management platforms. This improper input validation flaw allows unauthenticated remote attackers to execute arbitrary code, marking the first time a Windchill defect has been exploited in the wild. ReliaQuest noted that Cl0p deployed a custom implant to steal credentials and exfiltrate vast amounts of data, including engineering documents and databases, from victims such as Shell, Philips, and Fiserv.
Reported exploitedPTC - The Hacker NewsCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA has updated its Known Exploited Vulnerabilities catalog to include four high-severity flaws currently being targeted by threat actors. These vulnerabilities affect Apple macOS (CVE-2026-65400), Microsoft SharePoint (CVE-2026-55040), VMware vCenter (CVE-2026-59310), and Microsoft IKE (CVE-2026-33824). Active attacks range from cryptocurrency mining via the macOS flaw to ransomware deployment through the vCenter path traversal bug, with victims reported across 47 countries. Federal agencies are required to apply the vendor-provided patches by August 21, 2026, to mitigate these risks.
Reported exploitedmacOS - SecurityWeekCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
CISA has mandated immediate remediation for four active vulnerabilities across Microsoft, VMware, and Apple systems, adding them to the Known Exploited Vulnerabilities catalog. The alert covers CVE-2026-33824 in Windows IKE, CVE-2026-55040 in SharePoint, CVE-2026-59310 in VMware vCenter, and CVE-2026-65400 in macOS Screen Sharing. Federal agencies are required to apply patches by August 21 to mitigate these in-the-wild threats.
Reported exploitedWindows IKE - Help Net SecurityMedusa ransomware gang has hit over 500 organizations, CISA warns
FBI, CISA, and HHS have issued an updated joint advisory revealing that the Medusa ransomware group has compromised more than 500 organizations since 2021. The agencies report that victims span critical sectors including healthcare, defense, manufacturing, and finance, with many organizations affected through unpatched vulnerabilities in products such as ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust. Medusa operates via an affiliate model where operators deploy newly disclosed exploits within 24 hours of announcement rather than developing zero-days. To mitigate risk, defenders should immediately patch internet-facing systems, segment networks to restrict lateral movement, and block unauthorized remote access traffic.
Reported exploitedScreenConnect