CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 11 of 36 · newest first · times in UTC

Wednesday, Aug 193 stories

  1. BleepingComputer
    Critical RCE flaw in Windows IKE Extension now actively exploited

    CISA has confirmed that threat actors are actively exploiting a critical remote code execution vulnerability in the Windows IKE Service Extensions component, tracked as CVE-2026-33824. This double-free flaw affects all supported versions of Windows 10, Windows 11, and Windows Server, allowing unauthenticated attackers to achieve code execution by sending maliciously crafted packets over UDP ports 500 or 4500. Microsoft addressed the issue during the April 2026 Patch Tuesday cycle, and security teams should apply the relevant updates immediately or restrict inbound traffic on those UDP ports if immediate patching is not possible.

    Reported exploitedWindows
  2. Help Net Security
    Google’s AI security agents found 100+ critical software vulnerabilities in just two days

    Google’s Mandiant unit revealed that its internal Agentic Vulnerability Discovery Harness (AVDH) leverages multiple AI agents to detect security issues in source code efficiently. During a specific incident involving stolen corporate repositories, the system successfully identified more than 100 verified, high-severity vulnerabilities within a 48-hour period. This rapid detection capability led to the assignment of twelve official Common Vulnerabilities and Exposures identifiers, notably CVE-2026-13242 and CVE-2026-55803, with further disclosures currently underway. The findings underscore the growing effectiveness of specialized agentic pipelines in automating complex code reviews compared to traditional scanning methods.

    ResearchGoogle
  3. The Hacker News
    Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

    ReliaQuest researchers have identified a bespoke JavaServer Pages (JSP) web shell associated with the Clop ransomware operation, targeting PTC Windchill and FlexPLM servers. This implant exploits CVE-2026-12569, a critical vulnerability allowing remote code execution, to establish persistent access within the application. Unlike generic shells, this tool is specifically engineered to interact with PLM software, enabling attackers to decrypt administrative and LDAP credentials directly from the Windchill keystore. By leveraging the application's own database identities, the malware facilitates the rapid exfiltration of sensitive engineering data and product designs while evading standard signature-based detection.

    Reported exploitedWindchill

Tuesday, Aug 1812 stories

  1. Dark Reading
    Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

    GitLab has issued an out-of-band security update to address CVE-2026-19478, a critical code-injection vulnerability with a CVSS score of 9.4 that affects self-managed instances of GitLab Community Edition and Enterprise Edition. This flaw allows unauthenticated remote attackers to manipulate or delete public projects and user data via the platform's GraphQL interface without requiring any login credentials or user interaction. While GitLab.com and GitLab Dedicated users are already protected, organizations running self-hosted versions between 18.2 and prior 19.2.4 must immediately upgrade to fixed releases such as 18.11.11, 19.0.8, 19.1.6, or 19.2.4. The disclosure also includes a secondary CSRF bug, CVE-2026-19650, rated 7.1, which carries similar version constraints and can enable unauthorized changes via crafted requests.

    PatchGitLab CE/EE
  2. Dark Reading
    'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture

    Varonis Threat Labs disclosed a series of vulnerabilities in Microsoft Copilot Personal, collectively dubbed "CoSnitch," which enable threat actors to extract internal architectural details and exfiltrate sensitive data. The attack chain relies on a technique called "meta-hacking" to map the system's behavior, followed by the use of specially crafted URLs containing an undocumented ?autorun=1 parameter to trigger automatic prompt execution within a victim's authenticated session. This allows attackers to access connected services such as Gmail and Google Drive without further user interaction. Microsoft assigned the flaw as CVE-2026-24301, rating it 8.8 on CVSS 3.1, and deployed a patch on August 18, 2025. While enterprise customers are reportedly unaffected and no in-the-wild exploitation has been observed, researchers warn that personal instances linked to corporate accounts pose a significant risk.

    ResearchMicrosoft Copilot Personal
  3. Qualys Security Blog
    CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

    CISA has added the actively exploited Windows vulnerability CVE-2026-68820 to its Known Exploited Vulnerabilities (KEV) catalog, enforcing strict remediation timelines under Binding Operational Directive 26-04. This use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) allows local privilege escalation to SYSTEM without user interaction, impacting both internal and internet-facing systems. Microsoft released fixes in cumulative updates KB5121003 and KB5120249 on August 11, 2026, but organizations must ensure affected endpoints are rebooted to complete remediation, as the vulnerable driver remains active until a restart occurs.

    Reported exploitedWindows
  4. The Hacker News
    Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    Varonis Threat Labs identified three vulnerabilities, dubbed CoSnitch, in Microsoft Copilot Personal that permit attackers to silently extract data from connected services through a single malicious link click. The flaws, tracked as CVE-2026-24301, exploit an undocumented URL parameter to execute prompts within the victim's authenticated session without user interaction. Although no evidence of real-world exploitation was found, the issue allowed access to emails, calendar entries, and file metadata linked to the user's account. Microsoft deployed patches on August 18, 2026, addressing these issues which included the ability to persistently inject instructions into the assistant's memory store.

    ResearchMicrosoft Copilot Personal
  5. The Hacker News
    Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

    Active exploitation has been observed against two distinct open-source platforms: MLflow, an AI lifecycle tool, and FUXA, a web-based SCADA/HMI solution for industrial automation. Threat actors are leveraging CVE-2026-64849 in MLflow versions prior to 3.15.0 to execute unauthenticated Server-Side Request Forgery attacks, allowing them to proxy requests to internal cloud metadata endpoints and exfiltrate sensitive credentials. Concurrently, vulnerabilities identified as CVE-2026-25895 in FUXA versions up to 1.2.9 are being scanned by attackers seeking to perform path traversal operations that could lead to remote code execution by overwriting critical system files.

    Reported exploitedMLflow
  6. BleepingComputer
    Clop created custom web shell for Windchill data theft attacks

    ReliaQuest identified a custom-built Java web shell attributed to the Clop ransomware gang, specifically engineered for PTC Windchill and FlexPLM servers. This implant leverages the critical remote code execution vulnerability CVE-2026-12569 to decrypt stored credentials and exfiltrate files from application vaults. Because the tool integrates directly with Windchill's internal APIs, database queries run under the application's service identity, potentially evading standard detection methods. Organizations running affected versions are urged to apply patches immediately and investigate any unusual JSP files referencing the 'X-windchill-req' header.

    Reported exploitedPTC Windchill
  7. OX Security
    Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive

    GitLab released version 19.2.4, along with updates for older branches, to address two significant vulnerabilities in its GraphQL API. The primary issue, CVE-2026-19478, is a critical code injection flaw that enables unauthenticated attackers to modify or delete public project and user data by exploiting a specific directive. Additionally, CVE-2026-19650 allows cross-site request forgery attacks against logged-in users through improper validation of multiplexed queries. Self-managed instances running versions between 18.2 and 19.2 should upgrade immediately to the latest patched releases.

    PatchGitLab CE/EE
  8. Help Net Security
    Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

    GitLab has deployed urgent fixes for two security issues affecting Community Edition and Enterprise Edition versions prior to specific release thresholds. The primary concern is a critical vulnerability identified as CVE-2026-19478, which enables unauthenticated remote attackers to execute code via a GraphQL directive, potentially compromising public project integrity and user data. A secondary high-severity flaw, CVE-2026-19650, involves cross-site request forgery risks within the GraphQL multiplex query handler. Self-managed instances must be updated immediately to versions 18.11.11, 19.0.8, 19.1.6, or 19.2.4 to mitigate these risks, while hosted GitLab.com and Dedicated environments are already protected.

    PatchGitLab CE/EE
  9. SecurityWeek
    300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

    Security researcher Defiant identified a critical remote code execution vulnerability, tracked as CVE-2026-15748, within the Forminator Forms plugin for WordPress. With a CVSS score of 9.8, this flaw allows unauthenticated users to execute arbitrary code by exploiting insufficient file type validation in the handlefileupload function. The issue stems from a combination of weaknesses that let attackers forge record configurations and bypass the plugin's dangerous extension blocklist using pipe-alternative MIME types. While default settings restrict PHP execution to protected directories, custom storage roots remain vulnerable, potentially leading to full site compromise via webshells. The plugin has over 600,000 installations, with approximately half running affected versions, leaving more than 300,000 websites at risk unless updated to version 1.56.2, which was released on July 31.

    AdvisoryWordPress Forminator Forms Plugin
  10. BleepingComputer
    CISA: Windows Task Host flaw now exploited by ransomware gangs

    CISA has confirmed that ransomware groups are actively leveraging CVE-2025-60710, a high-severity privilege escalation flaw in the Windows Task Host component. This vulnerability, which stems from a link-following weakness, was patched by Microsoft in November 2025 but remained under active attack until CISA added it to the Known Exploited Vulnerabilities catalog on April 13. The bug impacts Windows 11 and Windows Server 2025 systems, allowing local attackers with basic user permissions to elevate their privileges to SYSTEM level. Agencies were directed to apply mitigations within two weeks to prevent further compromise.

    Reported exploitedWindows Task Host
  11. SecurityWeek
    GitLab Patches Critical Code Injection Vulnerability

    GitLab has released urgent patches for two security flaws affecting recent versions of its platform, with the most severe being an unauthenticated code injection vulnerability identified as CVE-2026-19478. This critical defect, carrying a CVSS score of 9.4, permits attackers to modify or delete data through GraphQL directives without needing login credentials. Additionally, CVE-2026-19650 addresses a cross-site request forgery issue in the GraphQL multiplex query handler that could allow unauthorized mutations via GET requests. All self-managed instances of GitLab Community Edition and Enterprise Edition from versions 18.2, 19.0, 19.1, and 19.2 onward are impacted and should be updated immediately to versions 18.11.11, 19.0.8, 19.1.6, or 19.2.4. While GitLab.com and Dedicated users have already received automatic updates, administrators of self-hosted environments must act quickly to mitigate these risks.

    PatchGitLab
  12. The Hacker News
    CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

    CISA has added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a critical flaw in Ray. This vulnerability allows attackers to achieve remote code execution through browsers like Firefox and Safari by leveraging DNS rebinding attacks against unauthenticated endpoints. The issue primarily affects developers using Ray for testing or local environments, potentially exposing adjacent internal network instances if victims visit malicious sites. A fix for this high-severity weakness is available in version 2.52.0 of the Python package.

    Reported exploitedRay

Monday, Aug 1717 stories

  1. The Hacker News
    Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

    GitLab has issued an out-of-cycle security patch for Community Edition and Enterprise Edition to fix critical vulnerability CVE-2026-19478. Rated 9.4 by the vendor, this flaw allows unauthenticated attackers to remotely modify or delete public projects and user data through a specific GraphQL directive. Self-managed administrators should update immediately to versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, as GitLab.com and Dedicated customers are already protected. No active exploitation or public exploit code was detected at the time of the release.

    PatchGitLab CE
  2. SANS Internet Storm Center
    Apple Patches iOS and macOS - SANS Internet Storm Center

    Apple has issued security updates for iOS and macOS to remediate a broad set of vulnerabilities affecting multiple system components. The release addresses numerous flaws, including kernel memory corruption that could allow privilege escalation, WebKit bugs enabling data exfiltration or crashes, and ImageIO defects leading to arbitrary code execution. Key risks include potential remote exploitation through crafted web content or media files, as well as local sandbox escape vectors in frameworks like libc and MediaRemote. Users are advised to install the latest operating system updates to mitigate these threats.

    PatchiOS
  3. The Hacker News
    Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

    Wordfence has disclosed a critical vulnerability, designated CVE-2026-15748, in the Forminator Forms WordPress plugin that allows unauthenticated attackers to achieve remote code execution. This flaw stems from insufficient file type validation in the handlefileupload() function, enabling malicious users to upload executable PHP files if specific form fields are present. The issue affects all versions prior to and including 1.56.1 and carries a CVSS score of 9.8. A separate authentication bypass vulnerability, CVE-2026-15826, was also identified in the User Profile Builder plugin, allowing unauthorized administrative access under certain configurations.

    AdvisoryForminator Forms
  4. Dark Reading
    Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

    FortiGuard Labs has identified a new Mirai-derived Linux botnet named Evooo1Bot that is actively targeting internet-facing hardware from manufacturers including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. The malware leverages a wide array of historical vulnerabilities, spanning from CVE-2007-3010 to CVE-2020-10987, to gain initial access and deploy a modular framework that goes far beyond standard DDoS attacks. Notably, the botnet includes an SSH brute-force scanner, credential sniffing capabilities, and a reverse SOCKS relay module that allows attackers to use compromised edge devices as stealthy proxies for further network infiltration. This evolution highlights the growing sophistication of Mirai-based threats, turning simple flood tools into comprehensive attack platforms that exploit even years-old unpatched software.

    Reported exploitedAlcatel
  5. BleepingComputer
    Certighost and the Privilege Hiding in Your Certificate Authority

    Researchers have made a proof-of-concept available for "Certighost" (CVE-2026-54121), a vulnerability in Microsoft Active Directory Certificate Services that enables privilege escalation. By exploiting a defect in the "chase" enrollment process, standard domain users can coerce an Enterprise CA into issuing valid authentication certificates for a Domain Controller, granting full control over the domain's identity infrastructure. Microsoft resolved this issue on July 14, 2026, assigning it a CVSS score of 8.8. Organizations are urged to apply the patch immediately and also review their default configuration, particularly by setting the MachineAccountQuota to zero, to mitigate further reliance on insecure defaults.

    PoC publicActive Directory Certificate Services
  6. Check Point Research
    17th August – Threat Intelligence Report

    Microsoft released its August 2026 patch updates to address 421 vulnerabilities, critically including CVE-2026-68820, a Windows Ancillary Function Driver for WinSock zero-day that is currently being exploited by Lazarus-linked actors to achieve SYSTEM privileges via local privilege escalation. Simultaneously, Adobe deployed an urgent fix for CVE-2026-71362 in Adobe Commerce and Magento Open Source, reporting immediate attacks shortly after public disclosure that allow unauthorized session switching and account takeover. Additionally, Zoom issued patches for three critical flaws, such as CVE-2026-53413, which permit remote code execution without user interaction through meeting annotations.

    Reported exploitedWindows
  7. The Hacker News
    ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

    This week's security landscape was dominated by active exploitation of critical vulnerabilities, including a severe directory traversal flaw in VMware vCenter identified as CVE-2026-59310. A suspected China-linked APT group leveraged this bug to deploy backdoors and Babuk-derived ransomware, which researchers assess served primarily as a distraction for forensic evasion rather than the final objective. Concurrently, North Korea’s Lazarus Group targeted defense and aerospace sectors across Europe, South America, and Asia using a zero-day privilege escalation vulnerability in Microsoft Windows, tracked as CVE-2026-68820. The actor delivered new malware strains, ForestTiger and Troy, under the guise of their long-running “Dream Job” social engineering campaign. Additional notable developments include the release of patches for a critical SQL injection issue in GeoServer (fixed in versions 3.0.1, 2.28.5, and 2.27.6), the discovery of GhostSplice, an attack technique that fragments malicious prompts to evade AI coding assistant guardrails, and the emergence of Amnesia Stealer, a macOS tool capable of live-controlling victim browsers via the Chrome DevTools Protocol.

    Reported exploitedLazarus Group
  8. Help Net Security
    Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

    Apple's recently patched vulnerability, tracked as CVE-2026-65400, is currently under active attack, allowing malicious actors to bypass authentication in macOS Screen Sharing and deploy cryptominers. The Dutch National Cyber Security Centre (NCSC) confirmed that root access was gained on multiple systems with port 5900 exposed to the internet, leading to the installation of a Monero miner. Apple has released fixes for this issue through macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1). Users should immediately apply these updates; alternatively, manually disabling Screen Sharing in System Settings can mitigate the risk until patching is complete.

    Reported exploitedmacOS
  9. The Hacker News
    How MCP Servers Can Expose Enterprise Secrets

    Recent analysis from Keeper Security highlights significant security gaps in the adoption of the Model Context Protocol (MCP), originally introduced by Anthropic. The study identifies several mechanisms through which MCP servers can inadvertently expose enterprise credentials, including storing plaintext tokens in configuration files and failing to enforce the principle of least privilege during deployment. A critical concern involves the "mcp-remote" OAuth proxy, where vulnerabilities such as CVE-2025-6514 allow for operating system command injection and remote code execution. This specific flaw could enable attackers to steal credentials directly from the client machine running the proxy. To mitigate these risks, the authors recommend centralizing secret management, using short-lived rotating credentials, and maintaining strict visibility over all MCP servers operating within an enterprise environment.

    ResearchModel Context Protocol (MCP)
  10. BleepingComputer
    Philips and GE investigating Clop ransomware data theft claims

    General Electric, Philips, and Shell are currently investigating reports that the Clop ransomware group accessed their networks and exfiltrated data. These breaches stem from active exploitation of CVE-2026-12569, a critical input validation vulnerability affecting Internet-exposed instances of PTC Windchill and PTC FlexPLM. While Philips has stated its response contained the incident without impacting customer environments, GE is still assessing the scope of the potential compromise. This campaign involves Clop deploying JSP webshells to steal sensitive assets such as blueprints and project plans from enterprises relying on these PLM platforms. As CISA has added this flaw to its Known Exploited Vulnerabilities catalog, organizations should apply available patches and audit their systems for signs of intrusion.

    Reported exploitedPTC Windchill
  11. The Hacker News
    Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

    Security researchers have released a public proof-of-concept for a two-stage attack chain targeting Unisoc modem firmware that achieves full Android kernel access. By combining a previously disclosed remote code execution flaw in SIP video handling with a new privilege-escalation bug classified as CWE-1189, attackers can bypass hardware boundaries to map and modify kernel memory. The vulnerability affects devices utilizing the Unisoc T606, T612, and T7250 chipsets, including the Motorola E13, Realme C33, and Xiaomi Redmi A5. Exploiting the chain requires an attacker-controlled private 4G network and victim interaction, specifically answering a malicious video call. As of the August 2026 disclosure, no CVE ID has been assigned, and neither UNISOC nor the device manufacturers have issued patches or confirmed mitigation plans.

    PoC publicUnisoc T606
  12. The Hacker News
    Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    Fortinet FortiGuard Labs identified Evooo1Bot, a newly documented Linux botnet derived from Mirai source code that has been actively compromising internet-facing devices since July 2026. The malware employs an integrated exploit arsenal targeting multiple known vulnerabilities, including CVE-2007-3010 in Alcatel OmniPCX Enterprise, CVE-2016-6277 in NETGEAR routers, and command injection flaws such as CVE-2018-14558 in Tenda AC7/AC9/AC10 models. Beyond standard DDoS capabilities, Evooo1Bot introduces encrypted C2 communication over port 443, credential sniffing, and a distinct feature that converts infected hosts into SOCKS5 proxies. This infrastructure allows threat actors to route malicious traffic through compromised edge devices, effectively using victim IPs to mask their origin and access internal networks.

    Reported exploitedAlcatel OmniPCX Enterprise
  13. BleepingComputer
    Microsoft working on Defender patch for ShieldBreak zero-day

    Microsoft has confirmed it is developing a security update for CVE-2026-69414, a privilege escalation vulnerability in the Microsoft Malware Protection Engine known as "ShieldBreak." This flaw enables local attackers with limited permissions to gain SYSTEM-level access on fully patched versions of Windows 10, Windows 11, and Windows Server. Disclosed by security researcher Nightmare Eclipse alongside a working proof-of-concept, ShieldBreak functions as a complete bypass for the previously addressed RoguePlanet vulnerability (CVE-2026-50656). While the exploit requires Microsoft Defender to be active, independent verification has confirmed its 100% success rate across modern Windows environments. Microsoft stated that it is actively working on a high-quality fix and will release further details once the patch becomes available.

    PoC publicMicrosoft Defender
  14. SecurityWeek
    Recent macOS Screen Sharing Vulnerability Exploited in Attacks

    Attackers are actively leveraging CVE-2026-65400, a high-severity authentication bypass in Apple's macOS Screen Sharing feature, to seize root privileges and deploy cryptocurrency miners. The vulnerability allows remote adversaries to authenticate without valid credentials by simply specifying an existing account name, a method made easier by public proof-of-concept exploits. Apple addressed this defect in updates released on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, alongside other fixes for the screensharingd daemon. The Dutch NCSC confirmed in-the-wild abuse targeting systems with port 5900 open to the internet, warning that approximately 40,000 exposed devices remain vulnerable. Administrators should ensure all macOS instances are patched and restrict unnecessary external access to Screen Sharing ports.

    Reported exploitedmacOS Screen Sharing
  15. SecurityWeek
    Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

    Threat intelligence firms have confirmed active exploitation of CVE-2026-58231, a critical vulnerability in SAP Commerce Cloud, beginning just three days after the patch release on August 11. This flaw involves inadequate authorization checks and input validation, enabling attackers to execute arbitrary code and compromise internal systems with a perfect CVSS score of 10. While CISA has not yet added this specific ID to its Known Exploited Vulnerabilities catalog, independent sensors have detected attack attempts since August 14.

    Reported exploitedSAP Commerce Cloud
  16. The Hacker News
    Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

    A suspected Chinese state-aligned APT group is actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in Broadcom's VMware vCenter Server, to establish root-level control over victim infrastructure. The campaign, which began shortly after the July 29, 2026 patch release, has compromised hundreds of servers across 47 countries, with researchers observing distinct Chinese-language artifacts and operational timing consistent with UTC+08:00. Upon gaining access via the unauthenticated code execution flaw, attackers deploy a custom Linux implant and create backdoor accounts to maintain persistence. The intrusion culminates in the deployment of a Babuk-derived ransomware variant targeting ESXi hosts, although analysts suggest this may serve as a distraction to obscure broader espionage or sabotage activities.

    Reported exploitedVMware vCenter
  17. Help Net Security
    Windows 11’s strongest security defenses can be bypassed without a screwdriver

    University researchers identified a method to circumvent Virtualization-Based Security and Hypervisor-Enforced Code Integrity on Windows 11 by exploiting unprotected Serial Presence Detect (SPD) chips in DDR4 and DDR5 memory modules. The attack allows privileged users to rewrite memory configuration data, effectively aliasing physical memory to access isolated kernel regions and disable security tools like EDR and blocklisted drivers. Microsoft addressed the issue as CVE-2026-23670 through mitigations released in its April 2026 security updates, though systems without Secure Boot remain vulnerable if using affected RAM.

    ResearchWindows 11

Sunday, Aug 161 story

  1. Help Net Security
    Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

    A long-running campaign dubbed City-Forum has been extracting data from Salesforce and ServiceNow portals globally for 17 months without triggering traditional breach alerts. Meanwhile, Framework confirmed a data breach stemming from an exploited zero-day vulnerability in the Metabase business intelligence platform. N-able released a second hotfix for N-central to counter active exploitation of CVE-2026-18577, while Cisco addressed CVE-2026-20349, a high-severity flaw currently being used to disrupt firewall operations.

    Reported exploitedSalesforce

Saturday, Aug 152 stories

  1. The Hacker News
    SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

    SAP Commerce Cloud is facing active exploitation attempts for CVE-2026-58231, a critical vulnerability rated 10.0 on the CVSS scale. The flaw allows unauthenticated attackers to bypass authorization checks and send invalid input to specific functions, potentially enabling arbitrary code execution and compromising internal components. Although no public proof-of-concept was previously available, threat intelligence firm Defused Cyber detected attacks beginning just three days after the patch was released. SAP advises customers to update to the fixed release levels or configure IP filters as a temporary mitigation.

    Reported exploitedSAP Commerce Cloud
  2. The Hacker News
    Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

    The Dutch National Cyber Security Centre (NCSC) has confirmed that CVE-2026-65400, a critical authentication bypass in Apple macOS Screen Sharing, is being actively exploited to deploy cryptocurrency mining software. This flaw, rated 9.8 on the CVSS scale, permits attackers to gain unauthorized root access to remote desktop services without valid credentials, particularly affecting Macs with port 5900 exposed to the internet. Apple released emergency patches for this vulnerability in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Users should immediately apply these updates or disable Screen Sharing via System Settings to mitigate the risk of compromise.

    Reported exploitedmacOS

Friday, Aug 145 stories

  1. Rapid7 Blog
    Metasploit Wrap Up: Lot of summer shells and fit http profiles

    Rapid7's Metasploit framework has released a major update featuring thirteen new modules that provide working proof-of-concepts for recent vulnerabilities in popular platforms such as WordPress, Ghost CMS, Joomla, and the Linux kernel. Notable additions include exploit paths for CVE-2026-60137 in WordPress core, unauthenticated remote code execution in Joomla JCE via CVE-2026-48907, and a local privilege escalation module for the Fragnesia Linux kernel tracked as CVE-2026-46300. This release also introduces new AArch64 payloads for Windows on ARM and enhanced HTTP malleable profiles, significantly expanding the offensive capabilities available to security teams.

    PoC publicMetasploit
  2. Ars Technica (Security)
    Vulnerability giving attackers full control of Macs is under active exploitation

    Dutch cyber officials have confirmed active exploitation of a high-severity vulnerability in macOS that grants attackers full system control. Known as CVE-2026-65400, the flaw exists within the operating system's screen sharing feature and allows unauthorized remote execution of malicious code. Attackers have successfully obtained root access to compromised machines, often deploying Monero cryptocurrency miners. Apple has released patches for macOS Tahoe, Sequoia, and Sonoma to address this issue.

    Reported exploitedmacOS
  3. BleepingComputer
    Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

    The Netherlands' National Cyber Security Centre (NCSC) reports active exploitation of an authentication bypass in macOS Screen Sharing, specifically affecting TCP port 5900. This vulnerability, identified as CVE-2026-65400, allows unauthenticated remote access to the system. Threat actors have leveraged the flaw to obtain root privileges and deploy a Monero cryptocurrency miner. Apple addressed the issue in recent updates, including macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

    Reported exploitedmacOS
  4. BleepingComputer
    Max severity SAP Commerce Cloud flaw now targeted in attacks

    Threat intelligence firm Defused reports that a critical remote code execution vulnerability in SAP Commerce Cloud is being actively targeted despite having only recently been patched. Tracked as CVE-2026-58231 with a maximum CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code by abusing a default authentication client within the Data Hub Adapter extension. Although SAP has not yet updated its official advisory to confirm widespread exploitation, shadow server data indicates over 4,200 internet-exposed instances remain vulnerable across Europe and North America. Organizations should apply the latest security fixes immediately to mitigate the risk of system compromise.

    Reported exploitedSAP Commerce Cloud
  5. BleepingComputer
    Shell investigates 'potential incident' after Clop data theft claims

    Major energy firm Shell has begun investigating a potential security incident following claims by the Clop ransomware group that they exfiltrated 89GB of sensitive data, including engineering drawings and facility reports. The theft is attributed to active exploitation of CVE-2026-12569, a critical input validation flaw in internet-facing instances of PTC Windchill and FlexPLM. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging organizations to apply patches released by PTC and check for indicators of compromise.

    Reported exploitedPTC Windchill

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store