🐛 COMMON VULNERABILITIES AND EXPOSURES 36[−]
9 AugCVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error pathInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=nInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64567 btrfs: reject free space cache with more entries than pagesInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages availableInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEARInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelpInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warningInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardownInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi objectInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memoryInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofsInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attackInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracleInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis clientInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached clientInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest stateInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-54876 Client-Side Memory Leak in OCSP Response CheckingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundariesInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio pathInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout returnInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64574 wifi: mac80211: tear down new links on vif update error pathInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parserInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest modeInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsertInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()Information published.MSRC.MICROSOFT.COM
9 AugCVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File LoadingInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() raceInformation published.MSRC.MICROSOFT.COM
9 AugCVE-2026-64542 ipv6: ndisc: fix NULL deref in accept_untracked_na()Information published.MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 4[−]
9 AugAlcon - 218,395 breached accountsIn August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including nam…HAVEIBEENPWNED.COM
9 AugRansomware gangs skip the CEO, head straight for the 40-something IT managerCarly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations c…DATABREACHES.NET
9 Aug KEVSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cy…SECURITYAFFAIRS.COM
9 AugKR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank AccountsPark Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s …DATABREACHES.NET
📋 SECURITY BULLETINS 1[−]
9 AugWeek in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent th…HELPNETSECURITY.COM
📢 SECURITY ADVISORIES 1[−]
9 AugThe AI safety test is becoming a safety riskAI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards and regulation can keep pace with increasingly powerful models.TECHCRUNCH.COM
🔥 INCIDENT REPORTING 1[−]
9 AugU.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled DataIEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability elec…SECURITYAFFAIRS.COM
🌐 CYBER THREAT LANDSCAPE 1[−]
9 AugSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: Ho…SECURITYAFFAIRS.COM
📰 CYBERSECURITY BRIEFINGS 1[−]
9 AugBuilding space in the AI era.This week on T-Minus: Space-Cyber Briefing: we look at how artificial intelligence (AI) is impacting the space sector and introducing new cybersecurity challenges that manufacturers have not fully realized.THECYBERWIRE.COM
🎙️ PODCASTS 1[−]
9 AugDesigning space systems for the AI era.As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured. In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Value Expert for Aerospace & Defense at Dassault Systems, t…THECYBERWIRE.COM
📡 INFOSEC NEWS 2[−]
9 AugWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsCSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that&…SECURITYAFFAIRS.COM
9 AugThis ‘adversarial’ pattern can prevent surveillance cameras from detecting youA security researcher has designed an algorithm that can create computer-generated patterns capable of hiding people, faces, and vehicles from detection by surveillance cameras.TECHCRUNCH.COM