vulnerability August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Microsoft released a substantial update addressing 421 vulnerabilities, including a critical zero-day exploit in a kernel-mode driver (afd.sys). Threat actors, potentially including nation-state actors like those linked… SecurityWeek · Aug 11, 2026 High CVE-2026-68820CVE-2025-32709CVE-2025-21418zero-daykernel-modeprivilege escalation
threat-intel Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Russian state-sponsored threat actors, linked to the Sandworm group, are using fake recruitment campaigns to trick IT professionals in Ukraine into installing malware. They impersonate IT companies like Sopra Steria Bulg… The Hacker News · Aug 11, 2026 High RUUKsocial engineeringvpnrecruitment
vulnerability Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Adobe has released critical patches to address over 50 vulnerabilities across its products, including significant flaws in ColdFusion and Campaign Classic. These vulnerabilities could lead to code execution and denial-of… SecurityWeek · Aug 11, 2026 High CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
threat-intel Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe A cyberattack on logistics giant Ceva Logistics has impacted major European retailers, including Bol, De Bijenkorf, and Steam’s hardware business in Europe. The attack disrupted shipments, potentially exposed customer da… The Record · Aug 11, 2026 High FRNEUKcyberattacksupply-chaindata-breach
threat-intel The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It The article argues that AI governance needs proactive leadership oversight, not waiting for finalized regulations. Many C-suite executives are delaying addressing AI governance, leading to significant risks due to fragme… SecurityWeek · Aug 11, 2026 High ai governanceai regulationcybersecurity
threat-intel OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development OpenAI has released GPT-5.6-Cyber, a cybersecurity-focused AI model designed to assist vulnerability research and exploit development, while reducing refusals for high-risk tasks. The model, accessible through the Daybre… The Hacker News · Aug 11, 2026 High CVE-2026-15903UNaicybersecurityvulnerability
threat-intel Local governments in four states dealing with cyberattacks that have shut down services Local governments across four states – California, Oklahoma, South Dakota, Texas, and Wisconsin – are experiencing a surge in cyberattacks, leading to service disruptions and shutdowns. These attacks have impacted critic… The Record · Aug 11, 2026 High UScyberattacklocal governmentransomware
threat-intel Kids’ online safety bill faces dim prospects of passage this session despite progress The Kids Online Safety Act (KOSA), a landmark bill aimed at increasing online safety for children, faces significant obstacles in Congress, particularly regarding a ‘duty of care’ provision requiring companies to take re… The Record · Aug 11, 2026 High UNonline safetychildrenfirst amendment
threat-intel A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices Researchers at the University of Birmingham and Fuzzware discovered a vulnerability in cellular IoT devices that allows a malicious SIM card to execute commands on the device. The vulnerability stems from a SIM card's ab… The Hacker News · Aug 11, 2026 High CVE-2025-48618CVE-2026-57550CVE-2021-31698UNiotcellularsim card
vulnerability Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird downloads for Linux after an unencrypted copy was accidentally committed to a private repository. This affects older downloads and requires man… The Hacker News · Aug 11, 2026 High gpgkey revocationgithub breach
vulnerability Mira Hormone Monitor, Mira Android App Multiple vulnerabilities in the Mira Hormone Monitor and Mira Android App allow an attacker to access unauthorized health profile information, make changes to health data, cause denial-of-service conditions, and potentia… CISA Advisories · Aug 11, 2026 High CVE-2026-66875CVE-2026-66098CVE-2026-67558bleauthenticationwebview
threat-intel Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Mozilla has revoked a signing key for Firefox after an unencrypted copy of the key was accidentally uploaded to GitHub. This significantly increases the risk of malicious actors creating fake Firefox installations. The i… The Register · Aug 11, 2026 High key-managementfirefoxvulnerability
threat-intel Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers Security researchers simulated a cryptocurrency startup and hired three individuals they believe were North Korean operatives to test recruitment processes and identify potential risks. The operation involved sophisticat… The Hacker News · Aug 11, 2026 High USNOnorth korearecruitmentidentity theft
threat-intel Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities A Chrome extension, initially banned for stealing AI chat conversations, has returned to the Chrome Web Store and is now targeting enterprise browsers through Google's CDN. The extension employs a sophisticated affiliate… SecurityWeek · Aug 11, 2026 High chromeextensionaffiliate
supply-chain Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Researchers have discovered a method to leverage Windows Plug and Play to achieve SYSTEM-level access on Windows 11 machines. By emulating USB devices and exploiting a vulnerability in the driver installation process, an… The Hacker News · Aug 11, 2026 High usbremotedriver
threat-intel Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets A malicious tool server leveraging the Model Context Protocol (MCP) can silently exfiltrate sensitive data – including SSH keys, source code, and customer data – from AI coding assistants. The attack works by splitting r… The Hacker News · Aug 11, 2026 High aimodel context protocolghostsplice
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection Project CAV3RN, a modular espionage framework used against targets in Israel, continues to evolve, utilizing a sophisticated multi-transport C2 communication module. The framework now leverages DNS A-record responses to… Securelist · Aug 11, 2026 High
threat-intel Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption Marcus Hutchins, a cybersecurity professional, rose to prominence in 2017 for his role in stopping the WannaCry ransomware attack. Initially involved in a cybercrime forum and creating a blog (MalwareTech) that inadverte… SecurityWeek · Aug 11, 2026 High USUKneurodiversitywannacrymalwaretech