463Articles
10Categories
2026-08-11Date
🚨 CISA KEV 1[−]
11 Aug KEVPatch Tuesday - August 2026Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch T…RAPID7.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 339[−]
11 AugCVE-2026-68203 media: vivid: fix cleanup bugs in vivid_init()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68114 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68190 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68273 drm/amdgpu: Fix context pstate override handlingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68097 ksmbd: validate ACE size against SID sub-authoritiesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68407 wifi: nl80211: free RNR data on MBSSID mismatchInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71556 go-git: Worktree operations may follow symlinksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68323 tipc: serialize udp bearer replicast list updatesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68252 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68374 usb: core: sysfs: add lock to bos_descriptors_read()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68152 amt: fix use-after-free in AMT delayed worksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68189 Bluetooth: hci_sync: Protect UUID list traversalInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68136 net: gro: fix double aggregation of flush-marked skbsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68254 drm/i915/vrr: require valid min/max vfreq for VRRInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68238 drm/amdgpu: Release VFCT ACPI table referenceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68241 drm/i915/mst: limit DP MST ESI service loopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66486 Improper Output Encoding in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68249 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68155 libceph: Reject monmaps advertising zero monitorsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66484 Path Traversal in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68337 bpf: Reject redirect helpers without a bpf_net_contextInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68110 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68195 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68111 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68115 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68182 comedi: comedi_parport: deal with premature interruptInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68331 dpaa2-eth: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68118 tcp: challenge ACK for non-exact RST in SYN-RECEIVEDInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68129 gve: fix Rx queue stall on alloc failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68112 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68328 nfp: Check resource mutex allocationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68123 openvswitch: fix GSO userspace truncation underflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68218 media: pci: dm1105: Free allocated workqueueInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68250 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68165 mm/damon/core: validate ranges in damon_set_regions()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68406 wifi: cfg80211: validate PMSR FTM preamble rangeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68317 pds_core: fix auxiliary device add/del racesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68154 libceph: reject zero bucket types in crush_decodeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68417 RDMA/siw: publish QP after initializationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68303 drm/vc4: hvs/v3d: Fix null dereference in unbindInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68109 drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68192 wifi: brcmfmac: make release_scratchbuffers idempotentInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68419 RDMA/irdma: Prevent rereg_mr for non-mem regionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68157 libceph: guard missing CRUSH type name lookupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68354 firewire: net: Fix fragmented datagram reassemblyInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68180 intel_th: fix MSC output device reference leakInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68409 wifi: mac80211: defer link RX stats percpu free to RCUInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68113 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68310 wifi: mt76: mt7915: guard HE capability lookupsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68140 net/iucv: fix use-after-free of a severed iucv_pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68248 drm/i915: Return NULL on error in active_instanceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68246 drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68376 sctp: fix auth_hmacs array size in struct sctp_cookieInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68135 net: hip04: fix RX buffer leak on build_skb failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68151 binfmt_elf_fdpic: only honour the first PT_INTERPInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68247 drm/i915/bios: range check LFP Data Block panel_type2Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68381 ksmbd: pin conn during async oplock break notificationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68343 smb: client: validate DFS referral PathConsumedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68184 cdrom: fix stack out-of-bounds read in CDROMVOLCTRLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68214 media: rtl2832: fix use-after-free in rtl2832_remove()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68327 wan: wanxl: Only reset hardware after BAR mappingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68188 Bluetooth: RFCOMM: Fix session UAF in set_termiosInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68313 tipc: fix infinite loop in __tipc_nl_compat_dumpitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68121 pppoe: reload header pointer after dev_hard_header()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68102 drm/amdgpu: fix aperture mapping leakInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68325 iommu/amd: Bound the early ACPI HID mapInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68233 drm/vc4: Shut down BO cache timer before teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68304 wifi: brcmfmac: fix 802.1X-SHA256 call trace warningInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64563 rhashtable: clear stale iter->p on table restartInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68098 ksmbd: bound DACL dedup walk to copied ACEsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68399 bpf: Fix UAF in sock clone early bailoutsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68302 amt: re-read skb header pointers after every pullInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68333 dpaa2-switch: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66485 Uncontrolled Memory Allocation in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68161 sctp: close UDP tunnel sockets during netns teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68166 userfaultfd: prevent registration of special VMAsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68198 wifi: ath6kl: fix use-after-free in aggr_reset_state()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68194 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68108 drm/amdgpu/vce: fix integer overflow in image sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68226 media: cx23885: add ioremap return check and cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68107 drm/amdgpu/vcn4: avoid rereading IB param lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68236 drm/amd/display: set new_stream to NULL after releaseInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68340 hwmon: occ: validate poll response sensor blocksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68253 drm/i915/hdcp: check streams[] bounds before overflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68339 Bluetooth: btusb: validate Realtek vendor event lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68153 libceph: remove debugfs files before client teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68251 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64377 cpufreq: qcom-cpufreq-hw: Fix possible double freeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64388 smb/client: fix chown/chgrp with SMB3 POSIX ExtensionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtimeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messagesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57795 RDMA/rxe: Remove the direct link to net_deviceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MESInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcpInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
11 AugRapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script . Figure 1: …RAPID7.COM
11 AugVU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacksOverview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged…KB.CERT.ORG
11 AugNIST wants to overhaul its vulnerability database for the AI ageNIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop .CYBERSCOOP.COM
11 AugZoom zero-click flaw allowed RCE attacks during meetingsMultiple vulnerabilities in Zoom’s annotation engine could allow a malicious meeting participant to compromise another attendee’s device by sending specially crafted meeting data. The most serious issue, tracked as CVE-2026-53413, is a buffer overwrite that Zoom says could lead t…CYBERINSIDER.COM
11 AugResearchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCESecurity researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects Shar…THEHACKERNEWS.COM
11 Aug KEVMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)42 Critical 355 Important 1 Moderate 0 Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild. Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated …TENABLE.COM
11 AugZoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code ExecutionZoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-…SECURITYAFFAIRS.COM
11 AugCVE-2026-19137 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19140 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19138 Heap buffer overflow in CrashReportingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19139 Race in CredentialProviderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19145 Use after free in TranslateThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19142 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19144 Use after free in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19146 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19147 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19149 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19148 Out of bounds write in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19151 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19153 Insufficient validation of untrusted input in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19152 Inappropriate implementation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19155 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19158 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19157 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19156 Heap buffer overflow in BaseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19150 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19161 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19162 Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19160 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19163 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19159 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19164 Insufficient validation of untrusted input in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19165 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19167 Integer overflow in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19166 Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19170 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19169 Insufficient validation of untrusted input in Contextual TasksThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19173 Out of bounds write in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19172 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19168 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19174 Integer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19176 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19171 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19175 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19177 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugZoom zero-click RCE flaws allow attackers to compromise meeting participantsZoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them. Three of the vulnerabilities affect all Zoom…CSOONLINE.COM
⚠️ VULNERABILITY DISCLOSURE 38[−]
11 AugBdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress AdminsCybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero so…THEHACKERNEWS.COM
11 AugThe future of AI security research isn’t autonomous, it’s human-amplifiedMeet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was guided…CSOONLINE.COM
11 AugUsing LLMs for Vuln Discovery - Rishi Sharma - ASW #395Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective wa…YOUTUBE.COM
11 AugRansomware gangs don’t need control system access to disrupt industrial productionDisrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industr…HELPNETSECURITY.COM
11 AugGPT-5.6-Cyber refuses security researchers’ requests far less oftenGPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program fo…HELPNETSECURITY.COM
11 AugPreviously unseen entry vector used to breach Polish energy plantThe December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator …HELPNETSECURITY.COM
11 AugYour security vendor gets the frontier cyber model, you get the findingsSelected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Program, which OpenAI expanded on …HELPNETSECURITY.COM
11 AugMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate SecretsA malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: …THEHACKERNEWS.COM
11 AugGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach NetworksCybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government ser…THEHACKERNEWS.COM
11 AugCuba's Spies, Defectors, and the Ex-FBI Agent Who Met Them AllFor decades, Cuban intelligence has been seen as a force that punches above its weight. Shaped during the Cold War through cooperation with the Soviet Union, its intelligence officers received extensive training by the KGB. But where does Cuba’s spy service stand today, especiall…THECYBERWIRE.COM
11 AugAI for Military SupportInteresting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a hi…SCHNEIER.COM
11 AugGitHub already has an EDR. You just have to listen to itMany of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said. At their Black Hat USA 2026 presentation, researchers Yossi Weizman of Microsoft and Mor Weinberger of Echo argued the ca…CSOONLINE.COM
11 AugOpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response windowOpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats. Daybreak now has two access levels. Blue give…CSOONLINE.COM
11 AugHead Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participantsKaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.SECURELIST.COM
11 AugCisco warns of high-severity ClamAV flaws with public exploitsCisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVCISA: Microsoft SharePoint flaw now exploited in ransomware attacksCISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]BLEEPINGCOMPUTER.COM
11 AugOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit DevelopmentOpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks …THEHACKERNEWS.COM
11 AugVague Task, Total Access: When AI Delegation Becomes a Security RiskAI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to d…BLEEPINGCOMPUTER.COM
11 AugUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugMozilla rotates Firefox and Thunderbird signing key after GitHub exposureMozilla has replaced a GPG subkey used to sign some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. The organization says its audit records show no evidence that an unauthorized person acces…CYBERINSIDER.COM
11 AugZoom Patches Zero-Click Code Execution VulnerabilityImpacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugAdobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic FlawsThe security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugThe inconvenient truth about AI pentesting: someone has to check all the workAI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, lo…SECURITYAFFAIRS.COM
11 AugCisco Warns of Seven ClamAV Flaws, Two With Public PoCsCisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-sour…SECURITYAFFAIRS.COM
11 AugDeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to DisruptThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-back…THEHACKERNEWS.COM
11 Aug KEVMicrosoft Patch Tuesday August 2026, (Tue, Aug 11th)This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execut…ISC.SANS.EDU
11 AugHow Trail of Bits helps verify the integrity of your Signal chatsEvery Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt me…TRAILOFBITS.COM
11 AugShattering the Dream – When a Job Offer Becomes a Zero-Day AttackKey Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. …RESEARCH.CHECKPOINT.COM
11 AugExfilSquad Targets New Victims, Shares Data via TorrentsExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime gro…SECURITYAFFAIRS.COM
11 Aug KEVMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysToday is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
11 AugAugust 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DayA use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugStolen Change Healthcare data gets new handling rules in court orderNaomi Diaz reports: A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit. Magistrate Judge Dulce J. Foster approved the plan, reviewed by Becker’s, Aug. 7. It…DATABREACHES.NET
11 AugStop Building a 2003 SOC with AI: Triage Must Die (Part 2)(with key ideas from Augusto Barros ) In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic horse p…MEDIUM.COM
11 AugNSA installs DHS lawyer as new general counselKerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News.THERECORD.MEDIA
11 Aug KEVCisco warns of ASA and FTD VPN flaw exploited to crash devicesCisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVMicrosoft Plugs Nearly 400 Security HolesMicrosoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.KREBSONSECURITY.COM
11 AugSquirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-606YOUTUBE.COM
11 AugGunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFAThe ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.DARKREADING.COM
📋 SECURITY BULLETINS 3[−]
11 AugMicrosoft releases Windows 10 KB5120249 extended security updateMicrosoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. [...]BLEEPINGCOMPUTER.COM
11 AugMicrosoft's Patch Tuesday Deluge Continues With August UpdatesSecurity experts say prioritization should be the main focus for the August updates, not the massive CVE volume.DARKREADING.COM
11 AugMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."TALOSINTELLIGENCE.COM
📢 SECURITY ADVISORIES 15[−]
11 Aug KEVSecurity leaders’ rogue AI confidence could actually be disastrousA large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope. Nine in 10 IT and security leaders surveyed by IT o…CSOONLINE.COM
11 AugKids’ online safety bill faces dim prospects of passage this session despite progressProponents of the Kids Online Safety Act are cheering recent progress but acknowledge a long road ahead for legislation that, despite mounting political pressure, may be difficult to pass this session.THERECORD.MEDIA
11 AugArctera enhances Unified Platform for evidence-driven compliance workflowsArctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and response workflows across the compliance lifecycle. These capabilities help organizations create a more comp…HELPNETSECURITY.COM
11 AugLanding Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS ArtifactOrganizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landin…AWS.AMAZON.COM
11 AugSandworm hackers target IT pros with trojanized WireGuard VPN clientHackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. [...]BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 17[−]
11 AugHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut TurbineAttackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recover…THEHACKERNEWS.COM
11 AugOnly Half of UK Manufacturers Have a Cyber Incident Response PlanMake UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidentsINFOSECURITY-MAGAZINE.COM
11 AugUS and South Korea warn of Gunra ransomware targeting govt agenciesU.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]BLEEPINGCOMPUTER.COM
11 AugLogistics Giant Ceva Suffers Data Breach Impacting European ClientsSupply chain attack and data breach at Ceva Logistics appears to have a large blast radiusINFOSECURITY-MAGAZINE.COM
11 AugSuisan City, California, Responds to Cyber Incident Amid Wave of US Local Government AttacksPolice and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week alsoINFOSECURITY-MAGAZINE.COM
11 AugFBI warns Gunra ransomware targets critical sectors and governmentsUS authorities are warning organizations about Gunra, an emerging ransomware operation that has attacked victims worldwide, stolen as much as tens of terabytes of data in individual incidents, and opened ransom negotiations at amounts exceeding tens of millions of dollars. The gr…CYBERINSIDER.COM
11 AugMalicious SIMs can hijack smartphones, steal files, and lock them onto 2GResearchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr Lisowsk…HELPNETSECURITY.COM
11 AugLocal governments in four states dealing with cyberattacks that have shut down servicesMunicipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.THERECORD.MEDIA
11 AugThreat Hunting Case Study: The GentlemenAnalyzing The Gentlemen ransomware group's attack chain and how to hunt for their privileged group manipulation technique before they spread through the NETLOGON share folder on Windows domain controllers.INTEL471.COM
11 AugDelta investigating after someone set up fake Wi-Fi network mid-flightThe Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.TECHCRUNCH.COM
11 AugPoland’s CERT describes winter cyberattack against heat-and-power plant.US and South Korea warn of "Gunra" ransomware gang with North Korean ties. Chinese IP connections spark security review in UK Navy drones.THECYBERWIRE.COM
11 AugCyberattack on logistics giant Ceva hits retailers and Steam customers across EuropeOperations at eight European warehouses belonging to France's CEVA Logistics have reportedly been disrupted by a cyberattack, and several other companies are feeling the effects.THERECORD.MEDIA
11 AugWesco confirms security incident after ExfilSquad claims data theftGlobal supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]BLEEPINGCOMPUTER.COM
11 AugIran-Linked Hackers Target More US Water Infrastructure in New Jersey and AlabamaIran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to a…SECURITYAFFAIRS.COM
11 AugRansomware group hijacks hospital system’s Facebook page amid ongoing cyberattack falloutThe hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents.THERECORD.MEDIA
11 AugA private route to public risk.Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North …THECYBERWIRE.COM
11 AugDeadLock ransomware uses blockchain to resist infrastructure takedownThe DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 23[−]
11 AugHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to RedemptionMarcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugOpenAI Unveils New Cybersecurity Model GPT-5.6-CyberOpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugMozilla Issues New Firefox GPG Key Following ExposureThe previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugLocking your ssh-agent exposed local-only keys until OpenSSH 10.5Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection from a remote server. The fi…HELPNETSECURITY.COM
11 AugWho will be the Stanislav Petrov in your organization?The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear m…HELPNETSECURITY.COM
11 AugAn AI tool found 84 flaws in 5G network software and 23 of them still have no fixResearchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The …HELPNETSECURITY.COM
11 AugCybersecurity jobs available right now: August 11, 2026CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection logic, deploying and tuning an…HELPNETSECURITY.COM
11 AugKimwolf v7: An Evolution of the Kimwolf BotnetDiscover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
11 AugCorma Raises $60 Million for Defensive Cybersecurity AI ModelCorma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue. The post Corma Raises $60 Million for Defensive Cybersecurity AI Model appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugExtension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesThe extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugResearchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT WorkersSecurity researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire c…THEHACKERNEWS.COM
11 AugCitrix expands Platform Flex with observability and secure developer servicesCitrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience Insights Flex, a Citrix-managed observability ser…HELPNETSECURITY.COM
11 AugNorth Korean remote IT staffer worked for US government agency, says FBIThe investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges.TECHCRUNCH.COM
11 AugLLMs Can Find Business Logic BugsBusiness-logic vulnerabilities have traditionally been difficult to automate. Finding them often required manual penetration testing, bug bounty researchers, or experienced internal security engineers. Rishi argues that LLMs can change that by identifying and chaining complex, mu…YOUTUBE.COM
11 AugAnthropic adds invisible watermarks to Claude-generated textAnthropic is introducing machine-readable watermarks in Claude-generated text, allowing supported AI output to carry an invisible signal that can be detected even after the text is copied elsewhere. The system is part of Anthropic’s implementation of the European Union AI Act’s A…CYBERINSIDER.COM
11 AugThe AI Governance Gap Is a Leadership Problem: Waiting Won’t Close ItOrganizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugSAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesSAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugAI Genie in the WildWhen I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it had discovered a way to book …SCHNEIER.COM
11 Aug KEVFormer BlackFile affiliates linked to extortion campaign targeting private equityResearchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.CYBERSECURITYDIVE.COM
11 AugInput Validation Is Often WrongMike challenges a common AppSec recommendation: treating input validation as a first-line solution for vulnerabilities such as SQL injection, XSS, and prompt injection. His argument is that these problems fundamentally involve separating code from data. Simply pattern-matching in…YOUTUBE.COM
11 AugDelta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las VegasThe airline deactivated the network after the crew realized someone was messing with the in-flight system. The feds are investigating. The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop .CYBERSCOOP.COM
11 AugWhat Happens When AI Ignores RulesAn Australian man reportedly asked an AI agent to book a spot in a local gym class. Instead of simply waiting for an opening, the agent manipulated the wait list and interfered with other reservations. The story highlights a basic problem with autonomous agents: completing the re…YOUTUBE.COM
11 AugFederal judge issues second order blocking Trump mail-in voting directiveThe U.S. Supreme Court temporarily reversed an earlier decision through the shadow docket. The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
11 AugA Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT DevicesA malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University…THEHACKERNEWS.COM
11 AugFake CCleaner installs GhostDesk Chrome spywareA convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome.MALWAREBYTES.COM
🎙️ PODCASTS 1[−]
11 AugInside the Media Minds of Byron Tau: ProPublicaOn this episode of #IMM, Christine and Madison sit down with Byron Tau as he transitions from the Associated Press to ProPublica.THECYBERWIRE.COM
📡 INFOSEC NEWS 24[−]
11 AugBetween Two Nerds: The cyber resistance!In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals. This epsiode is also available on YouTube.RISKY.BIZ
11 AugWatch out for fake TikTok Shops trying to steal your moneyTikTok Shop is huge, so it's no wonder that impersonation shops have popped up. Here's how to stay safe.MALWAREBYTES.COM
11 AugFake popular sites offer a free app, instead take over PCsFake branded download pages are tricking Windows users into installing legitimate remote-access software that's being abused by attackers.MALWAREBYTES.COM
11 AugProject CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectionProject CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.SECURELIST.COM
11 AugOpenAI Pauses Some Development of Astra Model on Security ConcernsOpenAI is tightening restrictions on testing of its upcoming Astra model due to security concernsINFOSECURITY-MAGAZINE.COM
11 AugResearchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop wi…THEHACKERNEWS.COM
11 AugOpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 CyberDaybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI modelsINFOSECURITY-MAGAZINE.COM
11 AugMozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private RepoMozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, con…THEHACKERNEWS.COM
11 AugLove/hate relationship: The AI affair. Young people love AI, but it’s breaking their trustThe same technology making our lives easier is also making it harder. How are young people navigating this new world?MALWAREBYTES.COM
11 AugA Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a CallResearchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.WIRED.COM
11 AugSexual predators targeting online accounts for intimate images, FBI warnsThe FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.MALWAREBYTES.COM
11 AugMozilla updates GPG signing key for Firefox releases after exposureMozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]BLEEPINGCOMPUTER.COM
11 AugDDoS attacks over 1 Tbps surged fivefold in the second quarterCloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]BLEEPINGCOMPUTER.COM
11 AugSix npm Packages Read C2 Addresses From Ethereum WalletSix npm packages queried an Ethereum wallet to locate C2 infrastructureINFOSECURITY-MAGAZINE.COM
11 AugCursor Security Bug Allowed Repositories to Execute Commands Before Trust VerificationCursor fixed a pre-trust code execution path in three days then closed the report as informativeINFOSECURITY-MAGAZINE.COM
11 AugAWS successfully completed its 2025-26 NHS DSPT assessmentAmazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their pe…AWS.AMAZON.COM
11 AugValve warns Steam hardware buyers: Expect fake delivery scamsThe warning affects recent buyers of Steam hardware, including the hugely popular Steam Deck.MALWAREBYTES.COM
11 AugSocial media platforms crack down on drone factory recruiting gameResearchers found that games and major US social media platforms were used to lure young people into jobs in Russia's drone industry.MALWAREBYTES.COM
11 AugWindows 11 KB5121003 & KB5120240 cumulative updates releasedMicrosoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
11 AugSummer 2026 SOC 1 report is now available with 185 services in scopeAmazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 12-month period from July 1, 2025–June 30, 2026, giving customers a full year of assurance. These report…AWS.AMAZON.COM
11 AugDelta probes Wi-Fi deauth attack on flight carrying DEF CON attendeesDelta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. [...]BLEEPINGCOMPUTER.COM
11 AugFBI says cybercriminals are hacking into victims’ online accounts to steal their intimate picturesIn a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns.TECHCRUNCH.COM
11 AugGoogle says Chrome cuts 7 billion unwanted Android notifications a day to fight abuseGoogle says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]BLEEPINGCOMPUTER.COM