Skip to content

Morning Brief

Thursday, August 13, 2026 · generated 2026-08-13 14:25 UTC · ~6 min read

Top developments

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting…

Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

Kimwolf v7 is raising the stakes for attacks launched from everyday Android TV boxes and set-top devices. The latest version can make disruptive web traffic look more like a real visitor browsing a site, making…

Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor

Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device…

Passwords stored in public Google Doc then showed up in search results

PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Have a story about…

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File

WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with the Imagick extension and Ghostscript. The WordPress security…

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output…

Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code

Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute…

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy…

Researchers found a way to hijack devices through Zoom screen sharing

As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them , and even carry out autonomous hacking sprees , researchers offered a sobering new example on Tuesday…

Vulnerability watch

CVE-2026-73299 Microsoft · prompty CWE-94 CRITICAL 10.0

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled …

CVE-2024-27253 IBM · DOORS Next CWE-287 CRITICAL 10.0

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

CVE-2026-73263 Kubernetes · prowler CWE-78 CRITICAL 9.9

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth …

CVE-2026-73294 semaphoreui · semaphore CWE-78 CRITICAL 9.9

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{…

CVE-2026-16860 IBM · i CWE-427 CRITICAL 9.9

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

CVE-2026-19656 SCADA-LTS · ScadaLTS CWE-862 CRITICAL 9.9

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Suc…

CVE-2026-62420 Canonical · LXD CWE-863 CRITICAL 9.9

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via P…

CVE-2026-63293 Canonical · LXD CWE-59 CRITICAL 9.9

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symboli…

CVE-2026-63294 Canonical · LXD CWE-59 CRITICAL 9.9

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml fi…

CVE-2026-63296 Canonical · LXD CWE-863 CRITICAL 9.9

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without valid…

Full CVE Feed →

Worth reading

ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability

This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism…

ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability

This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →