🚨 CISA KEV 1[−]
11 Aug KEVPatch Tuesday - August 2026Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch T…RAPID7.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 339[−]
11 AugCVE-2026-64581 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68258 drm/amdkfd: Check bounds on CRIU restore queue type and mqd sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68203 media: vivid: fix cleanup bugs in vivid_init()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversalInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68186 binfmt_misc: set have_execfd only once the interpreter is openedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68114 drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68183 firmware: stratix10-svc: fix memory leaks and list corruption bugsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68190 staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` outputInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68273 drm/amdgpu: Fix context pstate override handlingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68097 ksmbd: validate ACE size against SID sub-authoritiesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68412 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71497 jsoup: Cleaner may expose markup with custom raw-text elementsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injectionInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68235 drm/amd/display: dce100: skip non-DP stream encoders for DP MSTInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68407 wifi: nl80211: free RNR data on MBSSID mismatchInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71556 go-git: Worktree operations may follow symlinksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68323 tipc: serialize udp bearer replicast list updatesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-71557 go-git: Malicious reference names may modify files outside the reference storageInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68363 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware requestInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-65819 gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParserInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68288 net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOADInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68256 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink referenceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68242 drm/i915/gt: Fix NULL deref on sched_engine alloc failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68252 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68374 usb: core: sysfs: add lock to bos_descriptors_read()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68353 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handlerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68187 exec: fix unsigned loop counter wrap in transfer_args_to_stack()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68411 wifi: mac80211_hwsim: clamp virtio RX length before skb_putInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68152 amt: fix use-after-free in AMT delayed worksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68189 Bluetooth: hci_sync: Protect UUID list traversalInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68351 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB readInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68136 net: gro: fix double aggregation of flush-marked skbsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68083 ksmbd: fix path resolution in ksmbd_vfs_kern_path_createInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68352 wifi: ath6kl: fix OOB read from firmware IE lengths in connect eventInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68254 drm/i915/vrr: require valid min/max vfreq for VRRInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68238 drm/amdgpu: Release VFCT ACPI table referenceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68241 drm/i915/mst: limit DP MST ESI service loopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68362 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_beginInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68315 sctp: validate stream count in sctp_process_strreset_inreq()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-15534 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatchInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68272 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68197 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-operInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68148 fscrypt: Add missing superblock check in find_or_insert_direct_key()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68249 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68155 libceph: Reject monmaps advertising zero monitorsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68397 net/iucv: take a reference on the socket found in afiucv_hs_rcv()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68312 cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain pathsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-72522 libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68130 ksmbd: defer destroy_previous_session() until after NTLM authenticationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68350 wifi: carl9170: fix OOB read from off-by-two in TX status handlerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68337 bpf: Reject redirect helpers without a bpf_net_contextInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68395 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registeredInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68297 tipc: fix u16 MTU truncation in media and bearer MTU validationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68141 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68371 usb: musb: omap2430: Do not put borrowed of_node in probeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68110 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68206 media: v4l2-ctrls: validate HEVC active reference countsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68195 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68143 net: slip: serialize receive against buffer reallocationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68111 drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68355 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68125 mac802154: llsec: reject frames shorter than the authentication tagInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68176 tracing: Fix mmiotrace possible NULL dereferencing of hiter->devInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68234 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reservedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68366 usb: gadget: uvc: clamp SEND_RESPONSE length to the response bufferInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68145 iomap: fix out-of-bounds bitmap_set() with zero-length rangeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68278 drm/dp/mst: fix buffer overflows in sideband chunk accumulationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68405 wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lockInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68255 drm/virtio: bound EDID block reads to the response bufferInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68100 ksmbd: validate num_subauth when copying ACE in set_ntacl_daclInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68277 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsersInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68115 drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68414 wifi: cfg80211: cancel sched scan results work on unregisterInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68158 libceph: Fix multiplication overflow in decode_new_up_state_weight()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68318 pds_core: fix use-after-free on workqueue during removeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68222 media: msi2500: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68413 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68182 comedi: comedi_parport: deal with premature interruptInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68280 drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68428 KVM: x86/mmu: Fix use-after-free on vendor module reloadInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68331 dpaa2-eth: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68231 media: airspy: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68131 rbd: Reset positive result codes to zero in object map update pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68118 tcp: challenge ACK for non-exact RST in SYN-RECEIVEDInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68129 gve: fix Rx queue stall on alloc failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68112 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68175 tracing: Fix resource leak on mmiotrace trace_pipe closeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68156 libceph: refresh auth->authorizer_buf{,_len} after authorizer updateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68217 media: pwc: Drain fill_buf on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68123 openvswitch: fix GSO userspace truncation underflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68218 media: pci: dm1105: Free allocated workqueueInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68250 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68422 btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68404 wifi: cfg80211: use wiphy work for socket owner autodisconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68284 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68408 wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlockInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68165 mm/damon/core: validate ranges in damon_set_regions()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68369 usb: gadget: printer: fix infinite loop in printer_read()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68406 wifi: cfg80211: validate PMSR FTM preamble rangeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68364 drm/amd/display: Fix ISM dc_lock deadlock during suspendInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68317 pds_core: fix auxiliary device add/del racesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68202 ALSA: seq: close a re-opened queue timer in the destructorInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68154 libceph: reject zero bucket types in crush_decodeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68417 RDMA/siw: publish QP after initializationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68223 media: meson: vdec: Fix memory leak in error path of vdec_openInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68303 drm/vc4: hvs/v3d: Fix null dereference in unbindInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68199 wifi: ath6kl: fix OOB access from firmware ADDBA window sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68320 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkidInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68109 drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68336 bonding: fix devconf_all NULL dereference when IPv6 is disabledInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68300 sctp: auth: verify auth requirement when auth_chunk is NULLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68192 wifi: brcmfmac: make release_scratchbuffers idempotentInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68116 vxlan: mdb: Fix source list corruption on a failed replaceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68257 drm/amdkfd: fix 32-bit overflow in CWSR total size calculationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68419 RDMA/irdma: Prevent rereg_mr for non-mem regionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68099 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68426 xfrm: fix stale skb->prev after async crypto steals a GSO segmentInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68157 libceph: guard missing CRUSH type name lookupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68425 IB/mad: Drop unmatched RMPP responses before reassemblyInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68354 firewire: net: Fix fragmented datagram reassemblyInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68180 intel_th: fix MSC output device reference leakInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68392 Bluetooth: mgmt: fix locking in unpair_device/disconnect_syncInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68409 wifi: mac80211: defer link RX stats percpu free to RCUInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68279 drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsersInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68357 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68113 drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68309 wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68368 usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68402 wifi: cfg80211: bound element ID read when checking non-inheritanceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68310 wifi: mt76: mt7915: guard HE capability lookupsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68367 usb: gadget: f_tcm: synchronize delayed set_alt with teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68386 bpf, sockmap: Reject unhashed UDP sockets on sockmap updateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68140 net/iucv: fix use-after-free of a severed iucv_pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68219 media: nxp: imx8-isi: Fix potential out-of-bounds issuesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68329 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68396 scsi: core: wake eh reliably when using scsi_schedule_ehInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68248 drm/i915: Return NULL on error in active_instanceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68246 drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68376 sctp: fix auth_hmacs array size in struct sctp_cookieInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68269 drm/i915/gem: Add missing nospec on parallel submit slotInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68349 wifi: carl9170: fix buffer overflow in rx_stream failover pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68301 net: hsr: fix memory leak on slave unregistration by removing synced VLANsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68135 net: hip04: fix RX buffer leak on build_skb failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68326 wifi: mwifiex: bound uAP association event IEs to the event bufferInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68117 tipc: clear sock->sk on the failed-insert path in tipc_sk_create()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68106 drm/amdgpu: fix division by zero with invalid uvd dimensionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68294 net: qrtr: restrict socket creation to the initial network namespaceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68293 net/mlx5: Fix MCIA register buffer overflow on 32 dword readsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68149 fs: preserve ACL_DONT_CACHE state in forget_cached_acl()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68151 binfmt_elf_fdpic: only honour the first PT_INTERPInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68335 rds: drop incoming messages that cross network namespace boundariesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68410 wifi: libertas: fix memory leak in helper_firmware_cb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68212 media: saa7134: Fix a possible memory leak in saa7134_video_init1Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68418 RDMA/irdma: Prevent user-triggered null deref on QP createInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68361 hwmon: (corsair-psu) Stop device IO before calling hid_hw_stopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68090 debugobjects: Plug race against a concurrent OOM disableInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68126 mac802154: hold an interface reference across the scan workerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68416 mtd: fix double free and WARN_ON in add_mtd_device() error pathsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68247 drm/i915/bios: range check LFP Data Block panel_type2Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68245 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68377 net/sched: act_tunnel_key: Defer dst_release to RCU callbackInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68103 drm/amdgpu: reject mapping a reserved doorbell to a new queueInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68147 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68381 ksmbd: pin conn during async oplock break notificationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68343 smb: client: validate DFS referral PathConsumedInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68184 cdrom: fix stack out-of-bounds read in CDROMVOLCTRLInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68124 mctp: serial: handle zero-length frames to prevent rx buffer overflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68146 ftrace: Add global mutex to serialize trace_parser accessInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68401 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68322 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabledInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68373 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68214 media: rtl2832: fix use-after-free in rtl2832_remove()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68327 wan: wanxl: Only reset hardware after BAR mappingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68188 Bluetooth: RFCOMM: Fix session UAF in set_termiosInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68360 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68271 drm/nouveau: fix reversed error cleanup order in ucopy functionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68162 sctp: avoid auth_enable sysctl UAF during netns teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68229 media: cedrus: skip invalid H.264 reference list entriesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68359 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stopInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68313 tipc: fix infinite loop in __tipc_nl_compat_dumpitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68324 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68121 pppoe: reload header pointer after dev_hard_header()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68132 super: fix emergency thaw deadlock on frozen block devicesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68209 media: sun4i-csi: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20348 ClamAV XAR File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68325 iommu/amd: Bound the early ACPI HID mapInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68085 Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceledInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68196 wifi: wilc1000: validate assoc response length before subtracting headerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68370 usb: gadget: dummy_hcd: prevent fifo_req reuse during givebackInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68233 drm/vc4: Shut down BO cache timer before teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64654 GitHub CLI: Terminal escape sequence injection in multiple `gh` commandsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68304 wifi: brcmfmac: fix 802.1X-SHA256 call trace warningInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68243 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEUInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20339 ClamAV PESpin File Format Processing Integer Overflow VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20338 ClamAV ZIP File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20347 ClamAV Mach-O File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20337 ClamAV ZIP File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20346 ClamAV PDF File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64563 rhashtable: clear stale iter->p on table restartInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64655 GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN MatchingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68098 ksmbd: bound DACL dedup walk to copied ACEsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68104 drm/amdgpu: invoke pm_genpd_remove() before freeing genpdInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68210 media: stm32: dcmi: unregister notifier on probe failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68399 bpf: Fix UAF in sock clone early bailoutsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68127 ila: reload IPv6 header after pskb_may_pull in checksum adjustInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68244 drm/i915/gem: Do not leak siblings[] on proto context errorInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68171 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updatesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68289 tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68181 mei: bus: access mei_device under device_lock on cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68348 ASoC: tas2781: bound firmware description string parsingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68308 wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68365 USB: serial: io_edgeport: cap received transmit creditsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68391 Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmdsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68302 amt: re-read skb header pointers after every pullInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68286 drop_monitor: perform u64_stats updates under IRQ-disabled sectionInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68333 dpaa2-switch: put MAC endpoint device on disconnectInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68427 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappingsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-66485 Uncontrolled Memory Allocation in GNU cpioInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68161 sctp: close UDP tunnel sockets during netns teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68306 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68338 net/packet: avoid fanout hook re-registration after unregisterInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68185 LoongArch: Move jump_label_init() before parse_early_param()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68096 audit: fix recursive locking deadlock in audit_dupe_exe()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68287 drop_monitor: fix size calculations for 64-bit attributesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68403 wifi: brcmfmac: initialize SDIO data work before cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68220 media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68389 Bluetooth: hci_qca: Clear memdump state on invalid dump sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68166 userfaultfd: prevent registration of special VMAsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68198 wifi: ath6kl: fix use-after-free in aggr_reset_state()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68398 ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAFInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68194 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio busesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68215 media: radio-si476x: Unregister v4l2_device on probe failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68091 HID: wacom: stop hardware after post-start probe failuresInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68159 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZEInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68138 net/sched: serialize qdisc_rtab_list against concurrent get/putInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68299 vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packetsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68205 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68259 drm/amdkfd: Check bounds in allocate_event_notification_slotInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68207 media: ti: vpe: unwind v4l2 device registration on probe errorInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68088 usb: gadget: function: rndis: add length check to response queryInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68108 drm/amdgpu/vce: fix integer overflow in image sizeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68226 media: cx23885: add ioremap return check and cleanupInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68142 geneve: require CAP_NET_ADMIN in the device netns for changelinkInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68086 mm/khugepaged: write all dirty file folios when collapsingInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68164 mm/damon/core: disallow overlapping input ranges for damon_set_regions()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68107 drm/amdgpu/vcn4: avoid rereading IB param lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68204 media: vivid: check for vb2_is_busy() when toggling capsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68236 drm/amd/display: set new_stream to NULL after releaseInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68340 hwmon: occ: validate poll response sensor blocksInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68253 drm/i915/hdcp: check streams[] bounds before overflowInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68339 Bluetooth: btusb: validate Realtek vendor event lengthInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68169 mptcp: pm: userspace: fix use-after-free in get_local_idInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68093 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplugInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68153 libceph: remove debugfs files before client teardownInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68084 staging: vme_user: fix location monitor leak in tsi148 bridgeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-20345 ClamAV GPT File Format Processing Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-72568 Redis - Heap Out-of-Bounds Read in Cluster Bus PING Message HandlerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68105 drm/amdgpu: Fix kernel panic during driver load failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68216 media: pwc: Return queued buffers on start_streaming() failureInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-68251 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64523 net/handshake: Take a long-lived file reference at submitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64525 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64513 KVM: x86: Unconditionally recompute CR8 intercept on PPR updateInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64377 cpufreq: qcom-cpufreq-hw: Fix possible double freeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64388 smb/client: fix chown/chgrp with SMB3 POSIX ExtensionsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-64539 Bluetooth: eir: Fix stack OOB write when prepending the Flags ADInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-54332 GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoSInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtimeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messagesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM workerInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57795 RDMA/rxe: Remove the direct link to net_deviceInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-52005 The sideband payload is passed unfiltered to the terminal in gitInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packetsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systemsInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MESInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37842 spi: fsl-qspi: use devm function instead of driver removeInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creationInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create()Information published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37879 9p/net: fix improper handling of bogus negative read/write repliesInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcpInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2025-37980 block: fix resource leak in blk_register_queue() error pathInformation published.MSRC.MICROSOFT.COM
11 AugCVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
11 AugRapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script . Figure 1: …RAPID7.COM
11 AugVU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacksOverview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged…KB.CERT.ORG
11 AugNIST wants to overhaul its vulnerability database for the AI ageNIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop .CYBERSCOOP.COM
11 AugZoom zero-click flaw allowed RCE attacks during meetingsMultiple vulnerabilities in Zoom’s annotation engine could allow a malicious meeting participant to compromise another attendee’s device by sending specially crafted meeting data. The most serious issue, tracked as CVE-2026-53413, is a buffer overwrite that Zoom says could lead t…CYBERINSIDER.COM
11 AugResearchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCESecurity researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects Shar…THEHACKERNEWS.COM
11 Aug KEVMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)42 Critical 355 Important 1 Moderate 0 Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild. Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated …TENABLE.COM
11 AugZoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code ExecutionZoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-…SECURITYAFFAIRS.COM
11 AugCVE-2026-19137 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19140 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19138 Heap buffer overflow in CrashReportingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19139 Race in CredentialProviderThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19145 Use after free in TranslateThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19142 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19144 Use after free in HTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19146 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19147 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19149 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19148 Out of bounds write in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19151 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19153 Insufficient validation of untrusted input in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19152 Inappropriate implementation in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19155 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19158 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19157 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19156 Heap buffer overflow in BaseThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19150 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19161 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19162 Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19160 Uninitialized Use in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19163 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19159 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19164 Insufficient validation of untrusted input in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19165 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19167 Integer overflow in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19166 Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19170 Use after free in WebGLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19169 Insufficient validation of untrusted input in Contextual TasksThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19173 Out of bounds write in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19172 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19168 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19174 Integer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19176 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19171 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19175 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugCVE-2026-19177 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 AugZoom zero-click RCE flaws allow attackers to compromise meeting participantsZoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them. Three of the vulnerabilities affect all Zoom…CSOONLINE.COM
⚠️ VULNERABILITY DISCLOSURE 38[−]
11 AugBdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress AdminsCybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero so…THEHACKERNEWS.COM
11 AugThe future of AI security research isn’t autonomous, it’s human-amplifiedMeet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was guided…CSOONLINE.COM
11 AugUsing LLMs for Vuln Discovery - Rishi Sharma - ASW #395Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective wa…YOUTUBE.COM
11 AugRansomware gangs don’t need control system access to disrupt industrial productionDisrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industr…HELPNETSECURITY.COM
11 AugGPT-5.6-Cyber refuses security researchers’ requests far less oftenGPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program fo…HELPNETSECURITY.COM
11 AugPreviously unseen entry vector used to breach Polish energy plantThe December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator …HELPNETSECURITY.COM
11 AugYour security vendor gets the frontier cyber model, you get the findingsSelected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Program, which OpenAI expanded on …HELPNETSECURITY.COM
11 AugMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate SecretsA malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: …THEHACKERNEWS.COM
11 AugGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach NetworksCybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government ser…THEHACKERNEWS.COM
11 AugCuba's Spies, Defectors, and the Ex-FBI Agent Who Met Them AllFor decades, Cuban intelligence has been seen as a force that punches above its weight. Shaped during the Cold War through cooperation with the Soviet Union, its intelligence officers received extensive training by the KGB. But where does Cuba’s spy service stand today, especiall…THECYBERWIRE.COM
11 AugAI for Military SupportInteresting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a hi…SCHNEIER.COM
11 AugGitHub already has an EDR. You just have to listen to itMany of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said. At their Black Hat USA 2026 presentation, researchers Yossi Weizman of Microsoft and Mor Weinberger of Echo argued the ca…CSOONLINE.COM
11 AugOpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response windowOpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats. Daybreak now has two access levels. Blue give…CSOONLINE.COM
11 AugHead Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participantsKaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.SECURELIST.COM
11 AugCisco warns of high-severity ClamAV flaws with public exploitsCisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVCISA: Microsoft SharePoint flaw now exploited in ransomware attacksCISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]BLEEPINGCOMPUTER.COM
11 AugOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit DevelopmentOpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks …THEHACKERNEWS.COM
11 AugVague Task, Total Access: When AI Delegation Becomes a Security RiskAI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to d…BLEEPINGCOMPUTER.COM
11 AugUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugMozilla rotates Firefox and Thunderbird signing key after GitHub exposureMozilla has replaced a GPG subkey used to sign some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. The organization says its audit records show no evidence that an unauthorized person acces…CYBERINSIDER.COM
11 AugZoom Patches Zero-Click Code Execution VulnerabilityImpacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugAdobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic FlawsThe security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugThe inconvenient truth about AI pentesting: someone has to check all the workAI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, lo…SECURITYAFFAIRS.COM
11 AugCisco Warns of Seven ClamAV Flaws, Two With Public PoCsCisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-sour…SECURITYAFFAIRS.COM
11 AugDeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to DisruptThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-back…THEHACKERNEWS.COM
11 Aug KEVMicrosoft Patch Tuesday August 2026, (Tue, Aug 11th)This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execut…ISC.SANS.EDU
11 AugHow Trail of Bits helps verify the integrity of your Signal chatsEvery Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt me…TRAILOFBITS.COM
11 AugShattering the Dream – When a Job Offer Becomes a Zero-Day AttackKey Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. …RESEARCH.CHECKPOINT.COM
11 AugExfilSquad Targets New Victims, Shares Data via TorrentsExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime gro…SECURITYAFFAIRS.COM
11 Aug KEVMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysToday is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
11 AugAugust 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DayA use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugStolen Change Healthcare data gets new handling rules in court orderNaomi Diaz reports: A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit. Magistrate Judge Dulce J. Foster approved the plan, reviewed by Becker’s, Aug. 7. It…DATABREACHES.NET
11 AugStop Building a 2003 SOC with AI: Triage Must Die (Part 2)(with key ideas from Augusto Barros ) In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic horse p…MEDIUM.COM
11 AugNSA installs DHS lawyer as new general counselKerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News.THERECORD.MEDIA
11 Aug KEVCisco warns of ASA and FTD VPN flaw exploited to crash devicesCisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. [...]BLEEPINGCOMPUTER.COM
11 Aug KEVMicrosoft Plugs Nearly 400 Security HolesMicrosoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.KREBSONSECURITY.COM
11 AugSquirrel Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and more - SWN #606Squirrel (and other) Soup, Ghostjacking, OpenSource, Gunra, Beesafe, AI threats, SBOMS, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-606YOUTUBE.COM
11 AugGunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFAThe ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.DARKREADING.COM
📋 SECURITY BULLETINS 3[−]
11 AugMicrosoft releases Windows 10 KB5120249 extended security updateMicrosoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. [...]BLEEPINGCOMPUTER.COM
11 AugMicrosoft's Patch Tuesday Deluge Continues With August UpdatesSecurity experts say prioritization should be the main focus for the August updates, not the massive CVE volume.DARKREADING.COM
11 AugMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."TALOSINTELLIGENCE.COM
📢 SECURITY ADVISORIES 15[−]
11 Aug KEVSecurity leaders’ rogue AI confidence could actually be disastrousA large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope. Nine in 10 IT and security leaders surveyed by IT o…CSOONLINE.COM
11 AugKids’ online safety bill faces dim prospects of passage this session despite progressProponents of the Kids Online Safety Act are cheering recent progress but acknowledge a long road ahead for legislation that, despite mounting political pressure, may be difficult to pass this session.THERECORD.MEDIA
11 AugArctera enhances Unified Platform for evidence-driven compliance workflowsArctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and response workflows across the compliance lifecycle. These capabilities help organizations create a more comp…HELPNETSECURITY.COM
11 AugLanding Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS ArtifactOrganizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landin…AWS.AMAZON.COM
11 AugSandworm hackers target IT pros with trojanized WireGuard VPN clientHackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. [...]BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 17[−]
11 AugHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut TurbineAttackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recover…THEHACKERNEWS.COM
11 AugOnly Half of UK Manufacturers Have a Cyber Incident Response PlanMake UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidentsINFOSECURITY-MAGAZINE.COM
11 AugUS and South Korea warn of Gunra ransomware targeting govt agenciesU.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]BLEEPINGCOMPUTER.COM
11 AugLogistics Giant Ceva Suffers Data Breach Impacting European ClientsSupply chain attack and data breach at Ceva Logistics appears to have a large blast radiusINFOSECURITY-MAGAZINE.COM
11 AugSuisan City, California, Responds to Cyber Incident Amid Wave of US Local Government AttacksPolice and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week alsoINFOSECURITY-MAGAZINE.COM
11 AugFBI warns Gunra ransomware targets critical sectors and governmentsUS authorities are warning organizations about Gunra, an emerging ransomware operation that has attacked victims worldwide, stolen as much as tens of terabytes of data in individual incidents, and opened ransom negotiations at amounts exceeding tens of millions of dollars. The gr…CYBERINSIDER.COM
11 AugMalicious SIMs can hijack smartphones, steal files, and lock them onto 2GResearchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr Lisowsk…HELPNETSECURITY.COM
11 AugLocal governments in four states dealing with cyberattacks that have shut down servicesMunicipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.THERECORD.MEDIA
11 AugThreat Hunting Case Study: The GentlemenAnalyzing The Gentlemen ransomware group's attack chain and how to hunt for their privileged group manipulation technique before they spread through the NETLOGON share folder on Windows domain controllers.INTEL471.COM
11 AugDelta investigating after someone set up fake Wi-Fi network mid-flightThe Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.TECHCRUNCH.COM
11 AugPoland’s CERT describes winter cyberattack against heat-and-power plant.US and South Korea warn of "Gunra" ransomware gang with North Korean ties. Chinese IP connections spark security review in UK Navy drones.THECYBERWIRE.COM
11 AugCyberattack on logistics giant Ceva hits retailers and Steam customers across EuropeOperations at eight European warehouses belonging to France's CEVA Logistics have reportedly been disrupted by a cyberattack, and several other companies are feeling the effects.THERECORD.MEDIA
11 AugWesco confirms security incident after ExfilSquad claims data theftGlobal supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]BLEEPINGCOMPUTER.COM
11 AugIran-Linked Hackers Target More US Water Infrastructure in New Jersey and AlabamaIran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to a…SECURITYAFFAIRS.COM
11 AugRansomware group hijacks hospital system’s Facebook page amid ongoing cyberattack falloutThe hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents.THERECORD.MEDIA
11 AugA private route to public risk.Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North …THECYBERWIRE.COM
11 AugDeadLock ransomware uses blockchain to resist infrastructure takedownThe DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 23[−]
11 AugHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to RedemptionMarcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugOpenAI Unveils New Cybersecurity Model GPT-5.6-CyberOpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugMozilla Issues New Firefox GPG Key Following ExposureThe previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugLocking your ssh-agent exposed local-only keys until OpenSSH 10.5Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection from a remote server. The fi…HELPNETSECURITY.COM
11 AugWho will be the Stanislav Petrov in your organization?The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear m…HELPNETSECURITY.COM
11 AugAn AI tool found 84 flaws in 5G network software and 23 of them still have no fixResearchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The …HELPNETSECURITY.COM
11 AugCybersecurity jobs available right now: August 11, 2026CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection logic, deploying and tuning an…HELPNETSECURITY.COM
11 AugKimwolf v7: An Evolution of the Kimwolf BotnetDiscover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
11 AugCorma Raises $60 Million for Defensive Cybersecurity AI ModelCorma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue. The post Corma Raises $60 Million for Defensive Cybersecurity AI Model appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugExtension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesThe extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugResearchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT WorkersSecurity researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire c…THEHACKERNEWS.COM
11 AugCitrix expands Platform Flex with observability and secure developer servicesCitrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience Insights Flex, a Citrix-managed observability ser…HELPNETSECURITY.COM
11 AugNorth Korean remote IT staffer worked for US government agency, says FBIThe investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges.TECHCRUNCH.COM
11 AugLLMs Can Find Business Logic BugsBusiness-logic vulnerabilities have traditionally been difficult to automate. Finding them often required manual penetration testing, bug bounty researchers, or experienced internal security engineers. Rishi argues that LLMs can change that by identifying and chaining complex, mu…YOUTUBE.COM
11 AugAnthropic adds invisible watermarks to Claude-generated textAnthropic is introducing machine-readable watermarks in Claude-generated text, allowing supported AI output to carry an invisible signal that can be detected even after the text is copied elsewhere. The system is part of Anthropic’s implementation of the European Union AI Act’s A…CYBERINSIDER.COM
11 AugThe AI Governance Gap Is a Leadership Problem: Waiting Won’t Close ItOrganizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugSAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesSAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
11 AugAI Genie in the WildWhen I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it had discovered a way to book …SCHNEIER.COM
11 Aug KEVFormer BlackFile affiliates linked to extortion campaign targeting private equityResearchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.CYBERSECURITYDIVE.COM
11 AugInput Validation Is Often WrongMike challenges a common AppSec recommendation: treating input validation as a first-line solution for vulnerabilities such as SQL injection, XSS, and prompt injection. His argument is that these problems fundamentally involve separating code from data. Simply pattern-matching in…YOUTUBE.COM
11 AugDelta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las VegasThe airline deactivated the network after the crew realized someone was messing with the in-flight system. The feds are investigating. The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop .CYBERSCOOP.COM
11 AugWhat Happens When AI Ignores RulesAn Australian man reportedly asked an AI agent to book a spot in a local gym class. Instead of simply waiting for an opening, the agent manipulated the wait list and interfered with other reservations. The story highlights a basic problem with autonomous agents: completing the re…YOUTUBE.COM
11 AugFederal judge issues second order blocking Trump mail-in voting directiveThe U.S. Supreme Court temporarily reversed an earlier decision through the shadow docket. The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
11 AugA Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT DevicesA malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University…THEHACKERNEWS.COM
11 AugFake CCleaner installs GhostDesk Chrome spywareA convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome.MALWAREBYTES.COM
🎙️ PODCASTS 1[−]
11 AugInside the Media Minds of Byron Tau: ProPublicaOn this episode of #IMM, Christine and Madison sit down with Byron Tau as he transitions from the Associated Press to ProPublica.THECYBERWIRE.COM
📡 INFOSEC NEWS 24[−]
11 AugBetween Two Nerds: The cyber resistance!In this edition of Between Two Nerds Tom Uren and The Grugq talk about examples of cyber resistance and whether they achieve their goals. This epsiode is also available on YouTube.RISKY.BIZ
11 AugWatch out for fake TikTok Shops trying to steal your moneyTikTok Shop is huge, so it's no wonder that impersonation shops have popped up. Here's how to stay safe.MALWAREBYTES.COM
11 AugFake popular sites offer a free app, instead take over PCsFake branded download pages are tricking Windows users into installing legitimate remote-access software that's being abused by attackers.MALWAREBYTES.COM
11 AugProject CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectionProject CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.SECURELIST.COM
11 AugOpenAI Pauses Some Development of Astra Model on Security ConcernsOpenAI is tightening restrictions on testing of its upcoming Astra model due to security concernsINFOSECURITY-MAGAZINE.COM
11 AugResearchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop wi…THEHACKERNEWS.COM
11 AugOpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 CyberDaybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI modelsINFOSECURITY-MAGAZINE.COM
11 AugMozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private RepoMozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, con…THEHACKERNEWS.COM
11 AugLove/hate relationship: The AI affair. Young people love AI, but it’s breaking their trustThe same technology making our lives easier is also making it harder. How are young people navigating this new world?MALWAREBYTES.COM
11 AugA Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a CallResearchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.WIRED.COM
11 AugSexual predators targeting online accounts for intimate images, FBI warnsThe FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.MALWAREBYTES.COM
11 AugMozilla updates GPG signing key for Firefox releases after exposureMozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]BLEEPINGCOMPUTER.COM
11 AugDDoS attacks over 1 Tbps surged fivefold in the second quarterCloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]BLEEPINGCOMPUTER.COM
11 AugSix npm Packages Read C2 Addresses From Ethereum WalletSix npm packages queried an Ethereum wallet to locate C2 infrastructureINFOSECURITY-MAGAZINE.COM
11 AugCursor Security Bug Allowed Repositories to Execute Commands Before Trust VerificationCursor fixed a pre-trust code execution path in three days then closed the report as informativeINFOSECURITY-MAGAZINE.COM
11 AugAWS successfully completed its 2025-26 NHS DSPT assessmentAmazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their pe…AWS.AMAZON.COM
11 AugValve warns Steam hardware buyers: Expect fake delivery scamsThe warning affects recent buyers of Steam hardware, including the hugely popular Steam Deck.MALWAREBYTES.COM
11 AugSocial media platforms crack down on drone factory recruiting gameResearchers found that games and major US social media platforms were used to lure young people into jobs in Russia's drone industry.MALWAREBYTES.COM
11 AugWindows 11 KB5121003 & KB5120240 cumulative updates releasedMicrosoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
11 AugSummer 2026 SOC 1 report is now available with 185 services in scopeAmazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 12-month period from July 1, 2025–June 30, 2026, giving customers a full year of assurance. These report…AWS.AMAZON.COM
11 AugDelta probes Wi-Fi deauth attack on flight carrying DEF CON attendeesDelta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. [...]BLEEPINGCOMPUTER.COM
11 AugFBI says cybercriminals are hacking into victims’ online accounts to steal their intimate picturesIn a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns.TECHCRUNCH.COM
11 AugGoogle says Chrome cuts 7 billion unwanted Android notifications a day to fight abuseGoogle says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]BLEEPINGCOMPUTER.COM