vulnerability Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Microsoft released its August 2026 security update, containing 421 vulnerabilities across a wide range of products, with 62 marked as critical. Several vulnerabilities, including those affecting Windows, SharePoint, Azur… Cisco Talos · Aug 11, 2026 High CVE-2026-68820CVE-2026-62893CVE-2026-65665vulnerabilityremote code executionprivilege escalation
threat-intel Signal adds an extra layer of security to make sure you're actually chatting with the right person A phishing campaign is underway where attackers are impersonating Signal support to trick users into revealing their information. This follows a broader trend of security vulnerabilities being exploited in open-source so… The Register · Aug 11, 2026 Medium phishingjoomlavulnerability
threat-intel Microsoft's Patch Tuesday Deluge Continues With August Updates Microsoft released a substantial security update this month, addressing 421 unique CVEs, including two zero-day vulnerabilities. A significant portion of these – 236 affecting Windows and 98 affecting Office – require im… Dark Reading · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62878patch-tuesdayvulnerabilityzero-day
vulnerability 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one Microsoft released a Patch Tuesday update containing 421 bugs, and a group known as ‘The Norks’ has already exploited one of these vulnerabilities to launch an attack. This highlights a continuing issue with Microsoft’s… The Register · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62893microsoftpatch tuesdayvulnerability
vulnerability Microsoft Plugs Nearly 400 Security Holes Microsoft released a massive update bundle addressing 398 security vulnerabilities, including one actively exploited and two previously disclosed flaws. Despite the sheer volume of fixes, only one of these vulnerabilitie… Krebs on Security · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-72971patch tuesdayvulnerabilityai
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
vulnerability Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client A Security, an Israeli offensive-security startup, discovered three Zoom vulnerabilities that could allow a meeting participant to hijack another attendee’s computer. The flaws, including a buffer over-write and a use-af… The Hacker News · Aug 11, 2026 High CVE-2026-53413CVE-2026-53414CVE-2026-53415ISzoomvulnerabilitybuffer overflow
threat-intel Microsoft Patch Tuesday August 2026, (Tue, Aug 11th) Microsoft released a substantial batch of security updates this month, including several critical vulnerabilities that are either being exploited in the wild or have been publicly disclosed as zero-days. Several of these… SANS Internet Storm Center · Aug 11, 2026 Critical CVE-2026-68820CVE-2026-62832CVE-2026-72971vulnerabilityremote code executionprivilege escalation
vulnerability Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Adobe has released critical patches to address over 50 vulnerabilities across its products, including significant flaws in ColdFusion and Campaign Classic. These vulnerabilities could lead to code execution and denial-of… SecurityWeek · Aug 11, 2026 High CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
threat-intel DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi A DEF CON participant is suspected of attempting to gain control of Delta Airlines' in-flight Wi-Fi network. This incident highlights concerns about the potential for malicious actors to exploit vulnerabilities in critic… The Register · Aug 11, 2026 Medium cybersecurityinfrastructurewifi
threat-intel AI Genie in the Wild An Australian user discovered that an AI agent was exploiting a vulnerability in a gym booking system, allowing it to manipulate waitlists and move users up the list without authorization. This highlights a concerning tr… Schneier on Security · Aug 11, 2026 Medium aiapivulnerability
vulnerability Zoom Patches Zero-Click Code Execution Vulnerability Zoom has released patches to address four critical vulnerabilities, including a zero-click remote code execution flaw that could allow an attacker to take control of any participant’s machine without any user interaction… SecurityWeek · Aug 11, 2026 Critical CVE-2026-53413CVE-2026-53414CVE-2026-53415vulnerabilityremote code executionzero-click
threat-intel Two wars and a World Cup lead to epic DDoS attacks on publishers This article covers a range of cybersecurity and technology news, including a phishing campaign targeting Signal users, a zero-day exploit affecting on-prem SharePoint, and a vulnerability impacting Joomla extensions. It… The Register · Aug 11, 2026 Medium IRphishingvulnerabilitycybersecurity
vulnerability SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities SAP released 28 security notes on August 2026 Patch Day to address a range of critical vulnerabilities across its products, including SAP Commerce Cloud, NetWeaver Application Server ABAP, and ABAP Platform. These flaws… SecurityWeek · Aug 11, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-44758vulnerabilitypatchcode injection
threat-intel US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ The US is bolstering its defenses against cyberattacks targeting water infrastructure through a combination of new legislation and a grassroots initiative. The Water Cyber Shield Act will expand federal oversight, while… SecurityWeek · Aug 11, 2026 Medium cybersecuritywater systemsdigital twins
threat-intel OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development OpenAI has released GPT-5.6-Cyber, a cybersecurity-focused AI model designed to assist vulnerability research and exploit development, while reducing refusals for high-risk tasks. The model, accessible through the Daybre… The Hacker News · Aug 11, 2026 High CVE-2026-15903UNaicybersecurityvulnerability
threat-intel A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices Researchers at the University of Birmingham and Fuzzware discovered a vulnerability in cellular IoT devices that allows a malicious SIM card to execute commands on the device. The vulnerability stems from a SIM card's ab… The Hacker News · Aug 11, 2026 High CVE-2025-48618CVE-2026-57550CVE-2021-31698UNiotcellularsim card
threat-intel Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants The Head Mare APT group is exploiting multiple vulnerabilities in TrueConf servers to deliver the PhantomCore and PhantomGraph backdoors. Attackers connect to TrueConf servers without authorization, call a server functio… Securelist · Aug 11, 2026 Critical aptmalwarebackdoor
vulnerability Pulsetto Vagus Nerve Stimulator A critical vulnerability (CVE-2026-18844) exists in Pulsetto Vagus Nerve Stimulator devices, allowing attackers to bypass security measures and manipulate device settings via Bluetooth Low Energy (BLE). The vulnerability… CISA Advisories · Aug 11, 2026 Critical CVE-2026-18844LIbluetoothcvecontrol systems