CRITICAL
The Hacker News
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe released patches for three CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic that enable arbitrary code execution and privilege escalation. Immediate patching is required for all affected systems.
▸ countermeasure Immediately apply Adobe security updates to all ColdFusion and Campaign Classic instances
CRITICAL
BleepingComputer
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Critical vulnerability CVE-2026-71362 in Adobe Commerce/Magento enables account hijacking attacks. Immediate patching and account monitoring required for all e-commerce deployments.
▸ countermeasure Apply Adobe security patches immediately to all Commerce/Magento instances
CRITICAL
BleepingComputer
Android malware combo takes out loans and relays victims' credit cards
WindRelay Android malware combined with SpyNote RAT enables real-time NFC card data theft and fraudulent loan applications. Immediate detection and containment of infected devices is critical to prevent financial fraud and identity theft.
▸ countermeasure Block known WindRelay/SpyNote command and control domains at network perimeter
CRITICAL
The Hacker News
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus Group exploits Windows zero-day to achieve SYSTEM-level access and deploy novel backdoor against defense/aerospace sectors in France, Germany, Brazil, and India. Immediate patching and threat hunting required for vulnerable systems.
▸ countermeasure Apply latest Windows security patches immediately, prioritizing defense and aerospace organizations
CRITICAL
BleepingComputer
DeadLock ransomware uses blockchain to resist infrastructure takedown
DeadLock ransomware employs blockchain-based infrastructure to evade traditional takedown methods and maintain resilient command-and-control communications. Organizations must implement enhanced detection and response capabilities against decentralized threat infrastructure.
▸ countermeasure Monitor network traffic for blockchain-related domains and cryptocurrency transaction patterns associated with ransom payments
CRITICAL
BleepingComputer
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]
▸ countermeasure Confirm exposure, apply vendor patches, add temporary WAF/IPS rules, and run post-patch vulnerability validation.
HIGH
BleepingComputer
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Plug and Play feature can be exploited via malicious USB devices to force installation of vulnerable drivers, leading to SYSTEM privilege escalation. Organizations must restrict USB device installation and monitor driver loading.
▸ countermeasure Disable or restrict Plug and Play device installation via Group Policy (Computer Configuration > Administrative Templates > System > Device Installation)
HIGH
BleepingComputer
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Threat actors are actively exploiting misconfigured Salesforce Experience Cloud and ServiceNow portals to steal data exposed to anonymous users. Organizations must audit portal access controls and data exposure settings immediately.
▸ countermeasure Audit all Salesforce Experience Cloud and ServiceNow portal configurations to identify data accessible to anonymous users
HIGH
CISA News
Mira Hormone Monitor, Mira Android App
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The following versions of Mira Hormone Monitor, Mira Android App are affected: Mira Monitor Firmware 1.7.1.47 (C
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
CISA News
Pulsetto Vagus Nerve Stimulator
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Nerve Stimulator are affected: Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844) CVSS Vendor Equipment Vulnerabilities v3 8.1 Pulsetto Pulsetto Vagus Ner
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
CISA News
Johnson Controls C-CURE 9000 and Victor application server (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected: C-CURE 9000 <=v3.10.1 (CVE-2026-21655) victor Application Server <=v4.10 (CVE-2026-21655) victor <=v7.0 (CVE-2026-21655) victor Web vict
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
The Hacker News
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
The Hacker News
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
The Hacker News
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
BleepingComputer
Critical VMware vCenter RCE flaw exploited for reverse SSH access
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
BleepingComputer
Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
CISA News
Siemens Parasolid
View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
CISA News
Johnson Controls Inc. Airwall
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
CISA News
Johnson Controls Metasys
View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) M
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
The Hacker News
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
HIGH
SANS ISC
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the d
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
MEDIUM
BleepingComputer
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. [...]
▸ countermeasure Apply security updates, prioritize domain controllers and internet-facing Windows services, then monitor authentication anomalies.
MEDIUM
CISA News
Siemens License Server (SLS)
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version. The following versions of Siemens License Server (SLS) are affected: Siemens License Server (SLS) vers:intdot/<5.1, vers:int
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
MEDIUM
CISA News
Siemens Desigo DXR and PXC Controllers
View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DX
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.