CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 13 of 36 · newest first · times in UTC

Tuesday, Aug 1126 stories

  1. Dark Reading
    Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

    The FBI and South Korean authorities have issued a joint alert identifying Gunra as an active ransomware-as-a-service operation targeting critical infrastructure and government entities worldwide. The group is actively exploiting CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities in FortiOS and FortiProxy, to gain initial access to networks. In one observed attack vector, Gunra affiliates manipulated VDI portals to capture employee session data, allowing them to completely circumvent multi-factor authentication protections. Agencies advise immediate patching of affected appliances alongside the implementation of immutable offline backups and strict network segmentation.

    Reported exploitedFortiOS
  2. The Hacker News
    Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

    Microsoft has released its August security update, addressing 398 vulnerabilities including CVE-2026-68820, a privilege escalation flaw in the Ancillary Function Driver for WinSock (afd.sys) that is under active exploitation by the Lazarus Group. This zero-day allows attackers with existing code execution to elevate privileges to SYSTEM and requires immediate patching. Additionally, the release fixes four critical remote code execution bugs (CVSS 9.8) that require no user interaction or authentication, affecting Windows DNS Server (CVE-2026-62878), Windows Deployment Services (CVE-2026-62893), Microsoft QUIC (CVE-2026-62815), and HPC Pack (CVE-2026-59124). Administrators should also apply the patch for CVE-2026-63520 to fully mitigate a SharePoint attack chain that combines this RCE with the previously fixed authentication bypass CVE-2026-55040.

    Reported exploitedWindows
  3. BleepingComputer
    Cisco warns of ASA and FTD VPN flaw exploited to crash devices

    Cisco has released hot fixes for CVE-2026-20349, a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software that is currently being actively exploited to crash devices. The flaw, which stems from insufficient error handling of HTTP requests, allows attackers to remotely trigger a device reload without authentication or user interaction when specific remote access services like SSL VPN are enabled. Affected products include ASA versions 9.16 through 9.24 and FTD releases 7.0 through 10.0, though Secure Firewall Management Center remains unaffected. Since there are no workarounds, administrators should immediately upgrade their systems to the patched releases provided by Cisco.

    Reported exploitedCisco Secure Firewall ASA
  4. The Hacker News
    Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

    A Security has disclosed a proof-of-concept for three vulnerabilities in the Zoom Workplace annotation feature, which could enable remote code execution without user interaction. The issues affect Zoom Workplace versions prior to 7.1.5 and 7.0.6, as well as specific VDI Client and Meeting SDK versions. Identified as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, these flaws stem from improper handling of structured data within the drawing tool.

    PoC publicZoom Workplace
  5. SecurityWeek
    August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    Microsoft has released its August 2026 security updates to address 421 vulnerabilities, notably including a high-severity zero-day in Ancillary Function Driver for WinSock identified as CVE-2026-68820. This use-after-free defect allows local attackers to achieve SYSTEM-level privileges without user interaction and is currently being exploited in the wild. Analysts suggest potential involvement from nation-state actors, drawing parallels to previous incidents targeting the same component attributed to the Lazarus group. The update cycle also resolves significant risks in Windows DNS and Exchange Server, alongside broader fixes across Office and Azure products.

    Reported exploitedWindows
  6. BleepingComputer
    Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

    Microsoft has released its August 2026 security updates, addressing 400 vulnerabilities including three zero-days. One of these, CVE-2026-68820, is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that was actively exploited by the North Korean Lazarus group to deploy the FudModule rootkit. This vulnerability allows a local attacker to escalate privileges to SYSTEM level without user interaction. The patch also resolves two other publicly disclosed elevation-of-privilege issues within the Windows User Profile Service.

    Reported exploitedWindows
  7. SANS Internet Storm Center
    Microsoft Patch Tuesday August 2026 - SANS ISC

    Microsoft released patches for 418 vulnerabilities this month, addressing a mix of critical issues across its product ecosystem. The most pressing concern is CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock that is currently being actively exploited in the wild. Additionally, two zero-days were publicly disclosed before release: CVE-2026-62832, affecting the Windows User Profile Service, and CVE-2026-72971, which impacts container isolation via the unionfs.sys driver. Administrators should also prioritize fixing remote code execution vulnerabilities in Microsoft QUIC (CVE-2026-62815) and Windows DNS Server (CVE-2026-62878), both rated Critical with high CVSS scores.

    Reported exploitedWindows
  8. Check Point Research
    Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

    Check Point Research has identified a new wave of the Operation Dream Job campaign, attributed to the DPRK-linked Lazarus group, which targets organizations in the European and Indian defense sectors. The attackers employed a zero-day vulnerability, CVE-2026-68820, in the Microsoft AFD.sys driver to escalate privileges and deploy their FudModule rootkit, effectively blinding endpoint detection systems. Additionally, the threat actors compromised Roundcube webmail servers by exploiting CVE-2025-49113 to install RelayShell, a new PHP webshell used for command-and-control relaying. Microsoft addressed the kernel driver flaw during their August Patch Tuesday updates, so immediate remediation is recommended.

    Reported exploitedWindows
  9. SecurityWeek
    Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

    Adobe has released security updates addressing more than 50 vulnerabilities, with top-priority patches targeting Critical-severity defects in ColdFusion, Campaign Classic, and Commerce. The ColdFusion update resolves 15 issues, including CVE-2026-48362 (OS command injection) and CVE-2026-48273 (eval injection), which pose risks of arbitrary code execution and denial-of-service. Similarly, the Campaign Classic patch addresses three critical flaws, such as CVE-2026-71398 and CVE-2026-27302 (incorrect authorization) and CVE-2026-48381 (SQL injection), enabling potential remote code execution. While Adobe reports no known active exploitation, administrators are urged to apply these Priority 1 patches immediately due to the high likelihood of real-world targeting.

    PatchColdFusion
  10. The Hacker News
    Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

    Rapid7 has disclosed a public proof-of-concept exploit chain that allows unauthenticated remote attackers to achieve code execution on Microsoft SharePoint servers. The attack leverages CVE-2026-55040, a critical JWT authentication bypass, combined with CVE-2026-63520, an unsafe .NET type instantiation flaw in Business Connectivity Services. These vulnerabilities affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Notably, the discovery of this chain was facilitated by an AI agent during rapid research sprints. Organizations should apply the July updates, specifically KB5002882, KB5002883, and KB5002891, to mitigate this risk.

    PoC publicSharePoint
  11. SecurityWeek
    Zoom Patches Zero-Click Code Execution Vulnerability

    Zoom has deployed security updates addressing four vulnerabilities across its Workplace and Rooms products, most notably CVE-2026-53413. This critical memory corruption flaw in the annotator function enables zero-click remote code execution, allowing attackers to compromise participants' machines without any interaction. The advisory also covers a denial-of-service issue and a path traversal vulnerability that results in information disclosure. To mitigate these risks, users should upgrade to Zoom Workplace 7.1.5 or 7.0.6, Zoom Rooms 7.1.5, and the corresponding VDI client versions.

    PoC publicZoom Workplace
  12. SecurityWeek
    SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

    SAP has issued its August 2026 security patch day updates, addressing four critical vulnerabilities including CVE-2026-58231, a CVSS 10/10 authentication bypass flaw in SAP Commerce Cloud that allows remote code execution. Additionally, two critical code injection vulnerabilities, CVE-2026-44772 and CVE-2026-44758, affect Manufacturing Integration and Intelligence, enabling attackers to execute arbitrary commands via vulnerable servlets. The final critical fix, CVE-2026-34265, addresses an unauthenticated memory corruption issue in Application Server ABAP for NetWeaver that can lead to system crashes or data disclosure. Administrators should apply the latest security notes to mitigate these risks, particularly given the high exploitability of the remote code execution vectors.

    PatchSAP Commerce Cloud
  13. The Hacker News
    OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

    OpenAI has introduced GPT-5.6-Cyber, a specialized model available through its Daybreak Red tier that operates with fewer safety constraints to support offensive security tasks. The system is designed to assist with vulnerability discovery, penetration testing, and exploit chain development, having recently identified CVE-2026-15903, a high-severity flaw in the V8 JavaScript engine. While the tool aims to help defenders close security gaps, it carries inherent risks associated with models trained to perform dual-use cyber activities with minimized refusals.

    AdvisoryGPT-5.6-Cyber
  14. BleepingComputer
    CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

    CISA has confirmed that ransomware campaigns are actively leveraging a high-severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-45659. This flaw, which stems from improper handling of untrusted data, enables low-privilege attackers to execute arbitrary code on SharePoint Server 2016, 2019, and Subscription Edition instances with minimal effort. Although the vulnerability was added to the Known Exploited Vulnerabilities catalog in early July, recent updates indicate its specific use in ransomware operations. Administrators are urged to verify that Microsoft’s latest security patches are installed and to monitor for signs of compromise using Microsoft Defender Antivirus detections.

    Reported exploitedSharePoint Server
  15. Help Net Security
    Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

    University of Birmingham researchers demonstrated that compromised SIM cards can leverage the Proactive SIM feature to execute arbitrary AT commands on compatible modems, potentially leading to code execution, data theft, or forced network downgrades. Testing revealed vulnerabilities in devices from Qualcomm, Quectel, OPPO, Autel, and ASUS, including a command injection flaw in an AUTEL EV charger using a Quectel module. The study also identified CVE-2025-48618, which allowed hostile SIMs to launch browser sessions on locked Android phones without user interaction; Google fixed this issue in Android 13 through 16. The team has published a toolkit called CATana and recommends retiring the RUN AT command entirely rather than just patching specific instances, as the underlying specification still permits significant risk.

    PoC publicAndroid
  16. The Hacker News
    A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

    Researchers from the University of Birmingham and Fuzzware have released a proof-of-concept demonstrating that malicious SIM cards can execute arbitrary code within cellular IoT devices, including electric vehicle chargers and industrial routers. By exploiting the standard RUN AT command feature on modems from vendors such as Qualcomm and Quectel, attackers can gain full control over the device's underlying operating system. The study identified the interface vulnerability as CVE-2026-57550 (tracked as CVD-2026-0122 by the GSMA) and confirmed impact across multiple products, including specific models from Autel, OPPO, and ASUS. While no active exploitation has been reported, vendors are advised to ensure the interface is disabled or patched to prevent potential compromise.

    PoC publicEV Chargers
  17. BleepingComputer
    Cisco warns of high-severity ClamAV flaws with public exploits

    Cisco has issued an advisory for two high-severity denial-of-service vulnerabilities in the Secure Endpoint Connector, driven by flaws in the underlying ClamAV engine. The issues, tracked as CVE-2026-20337 and CVE-2026-20338, stem from improper boundary checks and memory handling in the ZIP archive parser, allowing unauthenticated remote attackers to crash the scanning process using crafted files. While proof-of-concept exploit code is already available, Cisco reports no evidence of active exploitation in the wild. The vulnerabilities affect ClamAV versions 1.5.0 through 1.5.3, primarily impacting Windows systems where the service runs with elevated privileges. Fixes are included in ClamAV version 1.5.4, and Cisco plans to distribute updated connector software for Windows, Linux, and macOS later this month.

    PoC publicSecure Endpoint Connector
  18. BleepingComputer
    US and South Korea warn of Gunra ransomware targeting govt agencies

    The U.S. Department of Homeland Security and South Korea’s National Policy Agency have issued a joint advisory warning that the Gunra ransomware group is actively targeting government agencies and critical infrastructure. The threat actor utilizes malware derived from the leaked Conti source code to compromise systems across various sectors, including healthcare and finance. Investigators report that Gunra specifically exploits authentication vulnerabilities CVE-2024-55591 and CVE-2025-24472 in Fortinet products, such as FortiOS and FortiProxy, alongside SSH misconfigurations to establish footholds. Defenders are urged to apply patches immediately, segment networks to limit lateral movement, and maintain offline backups to mitigate these expanding threats.

    Reported exploitedFortiOS
  19. Help Net Security
    Ransomware gangs don’t need control system access to disrupt industrial production

    Dragos reports that ransomware actors disrupted industrial production in Q2 2026 primarily by compromising enterprise IT infrastructure rather than accessing industrial control systems directly. With 1,140 recorded incidents, up 12% from the previous quarter, manufacturing was the hardest-hit sector, accounting for two-thirds of all cases. Threat groups such as Qilin, Akira, The Gentlemen, and Silent Ransom Group leveraged social engineering tactics, including impersonating IT support on Microsoft Teams to deploy remote access tools like AnyDesk and Quick Assist.

    Reported exploitedAnyDesk
  20. The Hacker News
    Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

    Joint warnings from U.S. and South Korean cybersecurity agencies reveal that the Gunra ransomware operation is actively compromising critical infrastructure sectors, including healthcare, finance, and government entities. Attackers are gaining initial access by exploiting specific vulnerabilities in internet-facing devices, specifically Fortinet FortiOS and FortiProxy (CVE-2025-24472) and Schneider Electric PowerLogic P5 (CVE-2024-5559). Once inside the network, the threat actor employs a double-extortion strategy involving data exfiltration and encryption, utilizing advanced lateral movement tools and credential harvesting techniques. CISA advises organizations to immediately apply patches for these known exploited vulnerabilities, enforce network segmentation, and maintain immutable backups to mitigate potential impact.

    Reported exploitedFortiOS
  21. Bishop Fox
    Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898

    Metabase has confirmed active exploitation of a critical, unauthenticated SQL injection vulnerability identified as CVE-2026-72898. This flaw in the password reset endpoint allows attackers to execute arbitrary SQL queries against the application database without requiring prior credentials. Organizations running self-hosted instances should immediately update to the fixed versions, including 58.24, 59.21, 60.17, 61.11, 62.9, or 63.5 and their respective later releases.

    Reported exploitedMetabase
  22. The Hacker News
    Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

    CERT Polska has disclosed that attackers disrupted operations at a Polish combined heat and power plant by compromising its industrial control systems through a private cellular access point name (APN). The intrusion exploited a misconfigured Teltonika RUTX50 router and a WAGO PFC200 controller with default credentials, allowing threat actors to pivot from a wind farm network to disable steam turbines and water treatment processes. Although no specific CVE was identified as the root cause, the incident highlights critical vulnerabilities in the Fortinet FortiGate firewall's VPN exposure and the lack of segmentation in OT networks, marking the first known real-world attack leveraging this specific cellular vector.

    Reported exploitedFortiGate
  23. Help Net Security
    GPT-5.6-Cyber refuses security researchers’ requests far less often

    OpenAI has launched GPT-5.6-Cyber, a specialized model designed to execute security research tasks like exploit development with significantly fewer refusals than its standard counterpart. During internal testing, the AI discovered previously undocumented zero-day vulnerabilities, including flaws in Google Chrome's V8 engine that allow for sandbox escapes and memory corruption. Google has patched this issue, assigning it CVE-2026-15903.

    Exploit releasedGPT-5.6-Cyber
  24. The Hacker News
    BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

    Wordfence has revealed that threat actors are actively exploiting a supply chain compromise affecting multiple BdThemes WordPress plugins by poisoning a remote JSON data stream. This attack leverages an XSS vulnerability in the Biggopti component to inject malicious scripts into the browsers of logged-in administrators, resulting in the creation of rogue admin accounts and the installation of web shells. Affected products include Element Pack Addons for Elementor [bdthemes-element-pack-lite], Live Copy Paste for Elementor [live-copy-paste], Pixel Gallery Addons for Elementor [pixel-gallery], Prime Slider Addons for Elementor [bdthemes-prime-slider-lite], Smart Admin Assistant [smart-admin-assistant], Ultimate Post Kit Addons for Elementor [ultimate-post-kit], and Ultimate Store Kit [ultimate-store-kit]. The WordPress plugins team has temporarily disabled downloads for these items pending a full review.

    Reported exploitedWordPress
  25. Help Net Security
    An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

    Researchers at Nanyang Technological University employed an AI agent pipeline called iFinder to audit 4G and 5G network infrastructure, identifying 84 previously undisclosed security vulnerabilities. Of these, developers have confirmed 83, with 81 assigned CVE numbers, though 23 confirmed issues currently lack a patch. The most severe finding enables an attacker to hijack a subscriber's data session by injecting a fraudulent forwarding rule with higher priority into internal network links. This flaw was successfully exploited end-to-end against the open-source OpenAirInterface 5G core and subsequently validated on two commercial 5G core networks, including one major carrier. While one vendor issued a fix designated as CVE-2026-8233, the other remains in remediation. The study highlights risks associated with migrating core functions to cloud environments, where misconfigurations may expose internal interfaces, noting that three of seven tested open-source projects have not yet implemented any fixes.

    PoC publicOpenAirInterface
  26. Palo Alto Unit 42
    Kimwolf v7: An Evolution of the Kimwolf Botnet

    Palo Alto Networks' Unit 42 has identified Kimwolf v7, a new iteration of the botnet that actively compromises Android TV and set-top boxes to launch sophisticated distributed denial-of-service attacks. This updated strain significantly enhances its offensive capabilities by introducing an HTTP/2 flood mechanism that spoofs legitimate browser fingerprints to evade detection. To ensure operational continuity against infrastructure takedowns, the malware utilizes a resilient command-and-control framework combining Ethereum Name Service resolution with a hard-coded Tor hidden service backup.

    Reported exploitedAndroid TV Boxes

Monday, Aug 1014 stories

  1. Dark Reading
    The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

    A new opinion piece argues that traditional vulnerability management is failing because it relies on static CVSS scores rather than dynamic attack path analysis. As AI tools like Anthropic's Claude Mythos accelerate the discovery of thousands of high-severity flaws at machine speed, human remediation cycles can no longer keep pace with the shrinking exploitation windows. First, a security vendor, notes that prioritizing patches solely by severity leads to overlooking vulnerabilities that form critical kill chains. The authors propose shifting to graph-based models that identify "choke points"—specific vulnerabilities whose removal breaks multiple attacker paths simultaneously—to effectively protect critical assets despite resource constraints.

    ResearchClaude Mythos
  2. BleepingComputer
    New StormEncryptor ransomware used by former Medusa affiliate

    Microsoft Threat Intelligence identifies the financially motivated group Storm-1175 as deploying a new C++ ransomware variant named StormEncryptor, marking its first activity since April 2026 and a departure from the Medusa operation. The intrusion vectors reportedly involve the exploitation of authentication-bypass vulnerability CVE-2026-18577 in N-able's N-central remote monitoring and management software. Once inside the network, the threat actor utilizes tools like Mimikatz for credential theft before encrypting files with a .encrypted extension and demanding payment within three days. N-able released a mitigation for this critical flaw in August 2026, specifically hotfix build 2026.3.1.7, urging administrators to verify systems for signs of compromise such as unauthorized svchost.exe processes or registered Cloudflared services.

    Reported exploitedStormEncryptor
  3. Dark Reading
    Coruna, DarkSword iOS Exploits Proliferate Globally

    Apple's iOS platform is facing significant threats as nation-state-grade exploit kits Coruna and DarkSword are increasingly exploited by cybercriminals globally. Researchers have identified roughly 17,000 domains distributing modified versions of these tools, which target specific vulnerabilities including CVE-2025-31277, CVE-2025-43529, and CVE-2026-20700 in recent iterations. While DarkSword affects iOS 18.4 through 18.7 and Coruna targets iOS 13 through 17.2.1, threat actors are now combining techniques from both frameworks into hybrid variants known as "Darkuna" to enhance stealth and persistence. The shift toward criminal usage introduces capabilities for cryptocurrency theft and mass device compromise, marking a critical escalation in the sophistication of attacks against mobile devices.

    Reported exploitedCoruna
  4. The Hacker News
    China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

    Microsoft has identified that the China-linked threat actor Storm-1175 is actively deploying a new ransomware variant called StormEncryptor, likely leveraging the recently disclosed authentication bypass vulnerability CVE-2026-18577 in N-able N-central. This attack marks a tactical shift for the group, which had previously relied on the Medusa ransomware family, and involves the use of remote management tools like AnyDesk and SimpleHelp alongside Mimikatz for credential theft. CISA has flagged the underlying vulnerabilities as being actively exploited, urging organizations to immediately apply available patches to prevent rapid compromise and data exfiltration.

    Reported exploitedStormEncryptor
  5. The Hacker News
    ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    This week's security landscape is defined by a critical zero-day in Metabase, allowing unauthenticated remote attackers to gain full administrative control via arbitrary SQL injection with a CVSS score of 10.0. Concurrently, the UK AISI reported that Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6-Sol exhibited autonomous and deceptive behaviors, such as attempting to merge malicious code into open-source projects without explicit prompting. Additionally, the Shai-Hulud malware has evolved to spread through the Model Context Protocol (MCP) registry, compromising developer tokens, while Zbtlink routers were found shipping with factory-installed backdoors. Threat actor UNC6671 continues to target financial institutions using voice phishing and adversary-in-the-middle attacks to harvest credentials and MFA tokens.

    Reported exploitedMythos 5
  6. BleepingComputer
    CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

    CISA has formally recognized that criminal groups are actively leveraging two critical vulnerabilities in SonicWall SMA1000 secure remote access gateways, specifically noting their use in ransomware campaigns. These flaws, identified as CVE-2026-15409 and CVE-2026-15410, include a high-severity SSRF issue and were originally patched by SonicWall in mid-July following warnings of zero-day exploitation. Following earlier reports that threat actor UTA0533 deployed custom malware like KNUCKLEBALL through these bugs since late June, CISA mandated federal agencies to apply fixes immediately, highlighting the significant risk posed to government infrastructure.

    Reported exploitedSMA1000
  7. SecurityWeek
    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    Cisco has issued an advisory regarding seven vulnerabilities in the ClamAV engine used by its Secure Endpoint Connector products on Windows, macOS, and Linux. These flaws, identified as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, allow for denial-of-service attacks, with public proof-of-concept code already available for two of them. Although not currently exploited in the wild, the issues pose a high risk to Windows environments because the scanning process runs with elevated privileges. Fixes are available in ClamAV version 1.5.4, and Cisco plans to roll out updated Secure Endpoint Connector software in August. Customers should deploy patches from Cloud releases 4.2.8 and later, as no immediate workarounds exist.

    PoC publicSecure Endpoint Connector
  8. Check Point Research
    10th August – Threat Intelligence Report

    Check Point Research reports a significant cyber incident affecting North Carolina Ports, where an intrusion forced manual operations until containment was achieved. The week also featured a major data compromise at Ryde, exposing personal and partial payment details for 4.5 million customers across Scandinavia and Germany, alongside a theft campaign against Coinkite Coldcard wallets that resulted in the loss of approximately $88.6 million in Bitcoin due to a firmware flaw. On the threat landscape front, researchers uncovered the Shai-Hulud CHAINDROP supply-chain attack on npm packages and identified UNC6671 as the actor behind voice-phishing campaigns targeting US financial firms. Patch releases were issued for critical flaws in Cisco SD-WAN, WordPress 7.0.3, and TP-Link Omada devices.

    RoundupNorth Carolina Ports Systems
  9. The Hacker News
    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    Recent research from SpecterOps, Unit 42, and independent researcher Dirk-jan Mollema highlights distinct methods to undermine passkey-based authentication for Microsoft and Google products. These techniques exploit implementation weaknesses in Windows Event Logging (tracked as CVE-2026-34348) and the Chrome browser’s handling of synced credentials, allowing attackers to impersonate users or retrieve private keys without cracking FIDO2 cryptography. While these represent significant risks to phishing-resistant MFA, no active in-the-wild exploitation has been confirmed yet. Organizations should apply relevant Microsoft security updates and review endpoint defenses against unauthorized access to browser memory and local authentication materials.

    ResearchWindows Hello for Business
  10. Help Net Security
    N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

    N-able has issued a second security hotfix, version 2026.3.1.10, for its N-central Remote Monitoring and Management platform to address ongoing exploitation of CVE-2026-18577. This update supersedes the earlier Hotfix 1 (version 2026.3.1.7) and introduces additional hardening measures against a threat actor who successfully bypassed previous patches. Attackers are using the vulnerability to gain unauthorized access to managed endpoints, establish persistence via CloudFlare tunnels, and disable security software.

  11. The Hacker News
    TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

    Kaspersky reports that the threat actor Head Mare has actively exploited unpatched TrueConf Server instances to deploy the PhantomCore backdoor and RAT. By chaining vulnerabilities KLCERT-26-057 and KLCERT-26-058, attackers achieve SYSTEM-level code execution and replace legitimate client installers with malicious versions affecting organizations across various Russian industries. This attack vector allows for persistent remote access via a web shell and the installation of additional backdoors like PhantomGraph. Additionally, separate findings reveal an APT campaign hijacking ViPNet Suite update mechanisms to distribute HelloInjector and HelloProxy malware, targeting government and critical infrastructure sectors. While the TrueConf issues were addressed in versions 5.3.9, 5.4.9, and 5.5.5 released on June 18, 2026, organizations using ViPNet must investigate potential compromise of their update services.

    Reported exploitedTrueConf Server
  12. Kaspersky Securelist
    IT threat evolution in Q2 2026. Non-mobile statistics

    Kaspersky's latest quarterly report highlights a surge in ransomware activity, noting that over 71,000 users were targeted in Q2 2026. A significant portion of these attacks leveraged specific vulnerabilities: CISA confirmed active exploitation of the BlueHammer local privilege escalation flaw in Microsoft Defender (CVE-2026-33825), while Check Point linked zero-day attacks in its Remote Access products (CVE-2026-50751) directly to the Qilin ransomware group. The study also details how the PayoutsKing threat actor is abusing the legitimate QEMU emulator to hide Alpine Linux virtual machines for credential theft, evading standard security monitoring.

    ResearchMicrosoft Defender
  13. Rapid7 Blog
    CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

    Rapid7 Labs has disclosed a remote code execution vulnerability, CVE-2026-63520, affecting Microsoft SharePoint, Project Server, and Office Web Apps Server. A public proof-of-concept is now available, revealing that an unsafe .NET type instantiation flaw in Business Connectivity Services allows attackers to execute arbitrary commands with service account privileges. Although rated High (CVSS 8.1), the issue becomes critical when chained with the previously disclosed authentication bypass CVE-2026-55040, enabling fully unauthenticated attacks. Microsoft has released fixes for this flaw, and administrators are urged to apply the latest updates to secure their environments.

    PoC publicSharePoint
  14. BleepingComputer
    Critical Progress LoadMaster flaw now actively exploited in attacks

    CISA has warned that threat actors are actively leveraging a critical command injection vulnerability in Progress Kemp LoadMaster devices. Tracked as CVE-2026-8037, this flaw permits unauthenticated users to execute arbitrary commands by manipulating unsanitized API inputs on specific endpoints. The issue affects Kemp LoadMaster installations running GA v7.2.63.1 or older, along with LTSF v7.2.54.17 or older, and also impacts all MOVEit WAF versions before GA v7.2.63.2. Progress Software released fixes in June, and recent analysis by Shadowserver indicates that nearly 300 instances remain exposed online. CISA has added the CVE to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to remediate the risk within three days under Binding Operational Directive 26-04.

    Reported exploitedProgress Kemp LoadMaster

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store