threat-intel Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 In July 2026, a significant wave of cybersecurity mergers and acquisitions occurred, with 21 deals announced. These transactions involved companies like Bank of America acquiring MDSec Consulting, Barracuda Networks acqu… SecurityWeek · Aug 13, 2026 Medium UNISTEmergersacquisitionscybersecurity
threat-intel Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? The rapid increase in vulnerability discovery, driven by advancements in AI models like Anthropic's Claude Mythos, is overwhelming cybersecurity teams and raising concerns about responsible disclosure. The sheer volume o… WeLiveSecurity · Aug 13, 2026 High aivulnerabilitydiscovery
vulnerability Adobe Commerce Bug Targeted Immediately After Disclosure A critical vulnerability in Adobe Commerce and Magento allowed unauthenticated attackers to gain access to other customer accounts immediately after its disclosure. Adobe swiftly released a patch, but threat actors were… SecurityWeek · Aug 13, 2026 Critical CVE-2026-71362vulnerabilityecommerceadobe
threat-intel AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS A new macOS information stealer, dubbed AmnesiaStealer, is targeting Chromium-based browsers to steal user credentials and provide live, interactive control over victim's web sessions. Developed by a Rust-based threat ac… The Hacker News · Aug 13, 2026 High CVE-2020-9771macosrustchromium
threat-intel Brazil orders Discord to suspend livestreaming after teen suicide Brazilian authorities have ordered Discord to suspend its livestreaming feature (Go Live) while they investigate whether the platform failed to adequately protect children from harmful content, following the death of a 1… The Record · Aug 13, 2026 High BRchild_safetycontent_moderationlivestreaming
threat-intel Trump taps cyber firms to go on offensive against criminals The Trump administration is expanding its efforts to combat cybercrime by allowing private cybersecurity firms to conduct offensive operations targeting transnational criminal networks. The initiative, outlined in a pres… The Record · Aug 13, 2026 High CHCAMYcybercrimeoffensive-cybercybersecurity
vulnerability WordPress 7.0.4 Patches Remote Code Execution Vulnerability WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability. This flaw, tracked as CVE-2026-65640, allows authenticated attackers to execute code by uploading malicious PostScript… SecurityWeek · Aug 13, 2026 High CVE-2026-65640wordpressvulnerabilityremote code execution
threat-intel Germany moves to give spy agencies hacking and sabotage powers Germany is poised to significantly expand the powers of its intelligence agencies, allowing them to conduct cyber operations, sabotage supply chains, and spread disinformation within the country. This legislation, a majo… The Record · Aug 13, 2026 High GERUcybersecurityintelligencesurveillance
vulnerability Siemens Parasolid Siemens Parasolid versions V38.0 and V38.1 are vulnerable to an out-of-bounds read vulnerability when parsing X_T files, potentially allowing an attacker to execute arbitrary code. Siemens has released updates to address… CISA Advisories · Aug 13, 2026 High CVE-2026-64629vulnerabilitysupply-chainindustrial-control-systems
vulnerability ANDRITZ HIPASE-250 and 250 SCALA ANDRITZ HIPASE-250 and 250 SCALA devices, versions <=7.20, are vulnerable to several security flaws that could allow an attacker to read stored passwords, access configuration endpoints without authentication, and gain V… CISA Advisories · Aug 13, 2026 High CVE-2026-65309CVE-2026-65310CVE-2026-65311vulnerabilitypasswordauthentication
vulnerability Flow Neuroscience FL-100 A critical vulnerability has been identified in Flow Neuroscience devices (FL-100 and Halo Neuroscience FL-100) due to a hard-coded credential that allows an attacker within Bluetooth range to manipulate brain stimulatio… CISA Advisories · Aug 13, 2026 Critical CVE-2026-18164bluetoothvulnerabilityhardcoded
vulnerability Hitachi Energy APM Edge Product Hitachi Energy is issuing a security advisory regarding critical vulnerabilities in its APM Edge product, specifically versions 6.10 and earlier. These vulnerabilities, including a write-what-where condition and an out-o… CISA Advisories · Aug 13, 2026 Critical CVE-2026-43284CVE-2026-43500SWvulnerabilitycvelinux
vulnerability Siemens Siveillance Video Siemens has released security advisories addressing a Remote Code Execution (RCE) vulnerability in its Siveillance Video Management Servers. Versions V2023 R3 through V2025 are affected, allowing users with edit permissi… CISA Advisories · Aug 13, 2026 High CVE-2026-3014rcecve-2026-3014industrial control systems
vulnerability Johnson Controls Inc. Airwall Johnson Controls Inc.'s Airwall software versions 4.0.4 and earlier contain critical vulnerabilities. A hardcoded cryptographic key allows attackers to decrypt sensitive data, bypass authentication, and access arbitrary… CISA Advisories · Aug 13, 2026 High CVE-2026-64887CVE-2026-34492vulnerabilityhardcoded keypath traversal
vulnerability Siemens Solid Edge Siemens Solid Edge versions 2025 and 2026 are vulnerable to multiple file parsing vulnerabilities, including out-of-bounds reads and writes, and use-after-free errors, when processing PAR, PSM, and DFT files. These vulne… CISA Advisories · Aug 13, 2026 High CVE-2026-50058CVE-2026-50059CVE-2026-50060vulnerabilityfile-parsingcad
vulnerability Siemens License Server (SLS) Siemens License Server (SLS) versions prior to 5.3 are vulnerable to two separate attacks: a local privilege escalation due to an insecure sudoers policy, allowing an attacker to execute arbitrary commands and plant mali… CISA Advisories · Aug 13, 2026 Critical CVE-2026-69108CVE-2026-69109vulnerabilitysudopath traversal
vulnerability Siemens LOGO! Soft Comfort Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These v… CISA Advisories · Aug 13, 2026 High CVE-2026-57262CVE-2026-57263GEencryptionpasswordhardcoded
vulnerability Johnson Controls Metasys A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject malicious code via a crafted URL, potentially leading to session hijacking and unauthorized access across multiple versions. The vulnerabi… CISA Advisories · Aug 13, 2026 Critical CVE-2026-34491cve-2026-34491xsscisa
vulnerability Siemens Simcenter Femap Siemens Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads BMP files. An attacker could exploit these flaws to execute code within the current process, potentiall… CISA Advisories · Aug 13, 2026 High CVE-2026-59700CVE-2026-59701vulnerabilitycontrol-systemfile-parsing
vulnerability Siemens Desigo DXR and PXC Controllers A denial-of-service vulnerability exists in Siemens Desigo DXR and PXC controllers, exploitable by sending malformed BACnet packets. This can cause the devices to stop responding to queries, requiring a device reset or r… CISA Advisories · Aug 13, 2026 High CVE-2026-59693industrial control systemsbacnetdenial of service