vulnerability Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Fortinet has released patches for eight security vulnerabilities across its products, including critical authentication flaws in FortiWeb and FortiManager. These vulnerabilities could allow attackers to gain unauthorized… SecurityWeek · Aug 13, 2026 Critical CVE-2026-26035CVE-2026-70468CVE-2026-70465vulnerabilityauthenticationpatch
threat-intel White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs The White House has launched a program allowing vetted US cybersecurity firms to conduct offensive operations against foreign cybercrime gangs, under strict federal oversight. These firms will execute cyber surveillance… SecurityWeek · Aug 13, 2026 Medium cybercrimeoffensive operationscyber intelligence
threat-intel Critical VMware vCenter Vulnerability in Attackers’ Crosshairs A critical vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited by an advanced persistent threat (APT) group, leading to remote code execution and persistent access for attackers. The vulnerabilit… SecurityWeek · Aug 13, 2026 Critical CVE-2026-59310DEUSTRvulnerabilityremote code executionssh
vulnerability Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ A disgruntled security researcher, Nightmare Eclipse, released a new zero-day exploit called ShieldBreak targeting Microsoft Defender, allowing users to escalate privileges on Windows 11 and Server 2025. This exploit lev… SecurityWeek · Aug 13, 2026 High CVE-2026-50656zero-daydefenderprivilege escalation
vulnerability SharePoint Vulnerability Exploited Shortly After PoC Release A SharePoint vulnerability, patched last month, is now being actively exploited in the wild, with attackers leveraging a publicly released proof-of-concept. This follows a series of similar vulnerabilities discovered thi… SecurityWeek · Aug 12, 2026 High CVE-2026-55040CVE-2026-63520CVE-2026-50522sharepointvulnerabilityexploitation
threat-intel Mindgard Raises $30 Million to Protect AI Systems AI security startup Mindgard secured $30 million in Series A funding to bolster its platform for identifying and mitigating vulnerabilities in AI systems. The company’s platform proactively tests AI models and applicatio… SecurityWeek · Aug 12, 2026 Medium aisecurityvulnerability
threat-intel WhatsApp Unveils New Scam Alert Feature WhatsApp is rolling out a limited beta feature called Scam Alert, designed to identify potentially scam messages on users' devices *before* they are sent. The feature uses on-device machine learning, doesn't send message… SecurityWeek · Aug 12, 2026 Medium GERUmachine learningencryptionprivacy
threat-intel Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset A sophisticated and innovative campaign, dubbed ‘City-Forum,’ is targeting Salesforce and ServiceNow using a custom multi-platform toolset. The attackers are exploiting unauthenticated guest user access to gather data, p… SecurityWeek · Aug 12, 2026 High guest userunauthenticated accessdata exfiltration
threat-intel Ceva Logistics Operations Disrupted by Cyberattack Ceva Logistics, a major shipping and logistics firm, has experienced a significant cyberattack that disrupted operations across eight European warehouses. The attack has impacted numerous downstream customers, including… SecurityWeek · Aug 12, 2026 High NLdata breachcyberattacklogistics
vulnerability Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined Intel and AMD released patches addressing over 80 vulnerabilities across their products, including fixes for privilege escalation, denial-of-service attacks, and information disclosure. The updates cover a wide range of… SecurityWeek · Aug 12, 2026 High patch tuesdayvulnerabilitiessecurity
supply-chain Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner,… SecurityWeek · Aug 12, 2026 High supply chainaicredentials
threat-intel Fresh Windows Zero-Day Exploited in North Korean Cyberattacks North Korean hackers, operating under the Lazarus Group, are exploiting a recently patched Windows zero-day vulnerability (CVE-2026-68820) to conduct targeted attacks against defense, aerospace, and aviation organization… SecurityWeek · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daylazarus groupcyber espionage
vulnerability Ivanti EPM Update Patches Remotely Exploitable Flaws Ivanti has released patches to address four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. Two of the EPM flaws are remotely exploitable, allowing attackers to steal credentials and gain cont… SecurityWeek · Aug 12, 2026 High CVE-2026-18129CVE-2026-18125CVE-2026-18127vulnerabilitypatchremote
vulnerability ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Several major industrial automation vendors – Siemens, Schneider Electric, and Phoenix Contact – released security patches to address critical vulnerabilities in their ICS products. These flaws could allow attackers to e… SecurityWeek · Aug 12, 2026 High icsindustrial control systemspatch tuesday
vulnerability SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform SonicWall has released patches to address eight critical vulnerabilities in its discontinued GMS platform and Email Security products. These flaws, including remote code execution and command injection, could allow attac… SecurityWeek · Aug 12, 2026 Critical CVE-2026-66147CVE-2026-66145CVE-2026-66149vulnerabilitypatchrce
vulnerability Cisco Patches Firewall Zero-Day Exploited for DoS Attacks Cisco has released patches to address a zero-day vulnerability (CVE-2026-20349) in its firewall software, which allows unauthenticated attackers to cause a denial-of-service attack. Cisco detected active exploitation of… SecurityWeek · Aug 12, 2026 High CVE-2026-20349zero-dayvulnerabilityasa
vulnerability August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Microsoft released a substantial update addressing 421 vulnerabilities, including a critical zero-day exploit in a kernel-mode driver (afd.sys). Threat actors, potentially including nation-state actors like those linked… SecurityWeek · Aug 11, 2026 High CVE-2026-68820CVE-2025-32709CVE-2025-21418zero-daykernel-modeprivilege escalation
vulnerability Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Adobe has released critical patches to address over 50 vulnerabilities across its products, including significant flaws in ColdFusion and Campaign Classic. These vulnerabilities could lead to code execution and denial-of… SecurityWeek · Aug 11, 2026 High CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability Zoom Patches Zero-Click Code Execution Vulnerability Zoom has released patches to address four critical vulnerabilities, including a zero-click remote code execution flaw that could allow an attacker to take control of any participant’s machine without any user interaction… SecurityWeek · Aug 11, 2026 Critical CVE-2026-53413CVE-2026-53414CVE-2026-53415vulnerabilityremote code executionzero-click
threat-intel The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It The article argues that AI governance needs proactive leadership oversight, not waiting for finalized regulations. Many C-suite executives are delaying addressing AI governance, leading to significant risks due to fragme… SecurityWeek · Aug 11, 2026 High ai governanceai regulationcybersecurity