{"date_iso":"2026-08-13","date_human":"Thursday, August 13, 2026","generated_utc":"2026-08-13 14:25 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor","link":"https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cisco Talos","Dark Reading","Infosecurity Magazine","Krebs On Security","Malwarebytes Labs","Rapid7 Blog","SANS Internet Storm Center","SecurityWeek","The Hacker News","The Record","The Register Security","Zero Day Initiative"],"coverage":14,"cve_ids":[],"summary":"The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting\u2026","source":"The Hacker News","date_rel":"19h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1jrzxrBozKDsDhAGM8SBKcqbTE4M0zWSJqfp709iguQU21GwUzshBdYSvKkicSkfQD1bNsYhROcsx5p5vAT3jyM90H6w6p8imCjtLbHySKnpGKlsQqfSS-BhcdHNuwJKFPZfBiVkh49xDvJbRI-rvfBKePL6CeHYIWOpwvGG0T-ha3x__xznmdsYybs9v/s1600/windows-shell.jpg","description":"The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and","related":[{"title":"SharePoint Vulnerability Exploited Shortly After PoC Release","link":"https://www.securityweek.com/sharepoint-vulnerability-exploited-shortly-after-poc-release/","source":"SecurityWeek","date_rel":"22h ago"},{"title":"Patch Tuesday: Update now to fix 421 flaws, including three zero-days","link":"https://www.malwarebytes.com/blog/bugs/2026/08/patch-tuesday-update-now-to-fix-421-flaws-including-three-zero-days","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Microsoft\u2019s massive Patch Tuesday releases continue as AI reshapes bug discovery","link":"https://therecord.media/microsoft-massive-patch-tuesday-releases-continue-ai","source":"The Record","date_rel":"12 Aug"},{"title":"Hackers leverage new Microsoft SharePoint exploit in attacks","link":"https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/","source":"Bleeping Computer","date_rel":"12 Aug"},{"title":"CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign","link":"https://therecord.media/cisa-gives-federal-agencies-two-weeks-to-patch-dprk-microsoft-bug","source":"The Record","date_rel":"12 Aug"},{"title":"New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges","link":"https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges/","source":"Bleeping Computer","date_rel":"12 Aug"}]},{"title":"Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks","link":"https://cybersecuritynews.com/kimwolf-v7-uses-chrome-browser/","reason":"Android","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Cyber Security News","CyberScoop","Malwarebytes Labs","Palo Alto Unit 42","The Hacker News"],"coverage":7,"cve_ids":[],"summary":"Kimwolf v7 is raising the stakes for attacks launched from everyday Android TV boxes and set-top devices. The latest version can make disruptive web traffic look more like a real visitor browsing a site, making\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Kimwolf-v7-Botnet-Uses-Chrome-Browser-Fingerprints-to-Hide-HTTP-2-DDoS-Attacks.webp","description":"Kimwolf v7 is raising the stakes for attacks launched from everyday Android TV boxes and set-top devices. The latest version can make disruptive web traffic look more like a real visitor browsing a site, making defensive filtering harder at a critical moment. The botnet has been active under related names since 2024, moving from Linux internet-connected devices to Android targets in 2025. It reaches exposed Android Debug Bridge services through residential proxy networks, allowing attackers to install malware without authentication. Unit 42 said in a report shared with Cyber Security News\u2026","related":[{"title":"New Android malware lets criminals use your bank card in real time","link":"https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time","source":"Malwarebytes Labs","date_rel":"1h ago"},{"title":"Android malware combo takes out loans and relays victims' credit cards","link":"https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/","source":"Bleeping Computer","date_rel":"14h ago"},{"title":"Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse","link":"https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/","source":"Bleeping Computer","date_rel":"12 Aug"},{"title":"Kimwolf botnet rebuilt to survive takedowns, researchers say","link":"https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/","source":"CyberScoop","date_rel":"12 Aug"},{"title":"Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing","link":"https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html","source":"The Hacker News","date_rel":"11 Aug"},{"title":"Mira Hormone Monitor, Mira Android App","link":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01","source":"CISA Alerts & Advisories","date_rel":"11 Aug"}]},{"title":"Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor","link":"https://cybersecuritynews.com/akira-uses-windows-safe-mode/","reason":"Windows","category":"News","sources":["Bleeping Computer","Cyber Security News","Fortinet PSIRT","Microsoft Security","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":["CVE-2026-62696","CVE-2026-62747","CVE-2026-70348"],"summary":"Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Akira-Ransomware-Uses-Windows-Safe-Mode-to-Shut-Down-EDR-Before-Launching-Encryptor.webp","description":"Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device connected while most third-party protections stayed offline. The operation began with a credential-spraying attack against an exposed SonicWall SSL VPN that had no multi-factor authentication. A valid account opened the door, after which the intruder used remote desktop access, mapped the network, collected files, and prepared them for upload. This route echoes the risks described in\u2026","related":[{"title":"Nightmare Eclipse Drops Windows Zero-Day Exploit \u2018ShieldBreak\u2019","link":"https://www.securityweek.com/nightmare-eclipse-drops-windows-zero-day-exploit-shieldbreak/","source":"SecurityWeek","date_rel":"4h ago"},{"title":"Plug and Pwn attack uses fake USB devices for Windows SYSTEM access","link":"https://www.bleepingcomputer.com/news/security/plug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62696","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-70348 Windows Management Services Denial of Service Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Heap overflow in kernel driver due to missing size validation","link":"https://fortiguard.fortinet.com/psirt/FG-IR-26-156","source":"Fortinet PSIRT","date_rel":"12 Aug"}]},{"title":"Passwords stored in public Google Doc then showed up in search results","link":"https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Kaspersky Securelist","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"PWNED Welcome, once again, to PWNED, the weekly column where we highlight others\u2019 security failures. Hopefully, there\u2019s a lesson in all this, but it could just be \u201cstop shooting yourself in the foot.\u201d Have a story about\u2026","source":"The Register Security","date_rel":"5h ago","thumbnail":"https://image.theregister.com/?imageId=5287048&width=800","description":"PWNED Welcome, once again, to PWNED, the weekly column where we highlight others\u2019 security failures. Hopefully, there\u2019s a lesson in all this, but it could just be \u201cstop shooting yourself in the foot.\u201d Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi\u2019s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the\u2026","related":[{"title":"Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits","link":"https://www.malwarebytes.com/blog/privacy/2026/08/parents-take-on-meta-tiktok-google-and-snap-in-3000-youth-safety-lawsuits","source":"Malwarebytes Labs","date_rel":"2h ago"},{"title":"Google security advisory (AV26-806)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-806","source":"CCCS Alerts & Advisories","date_rel":"12 Aug"},{"title":"OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning","link":"https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html","source":"The Hacker News","date_rel":"12 Aug"},{"title":"Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection","link":"https://securelist.com/project-cav3rn-continues/120991/","source":"Kaspersky Securelist","date_rel":"11 Aug"}]},{"title":"Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA","link":"https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa","reason":"Fortinet","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.","source":"Dark Reading","date_rel":"11 Aug","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt468a31de0930ebef/6a7b87a0f0b097cbb1a7bb39/ransomware-jittawit.21-Getty-2178699306.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Fortinet Patches Authentication Flaws in FortiWeb and FortiManager","link":"https://www.securityweek.com/fortinet-patches-authentication-flaws-in-fortiweb-and-fortimanager/","source":"SecurityWeek","date_rel":"2h ago"},{"title":"Fortinet security advisory (AV26-812)","link":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-812","source":"CCCS Alerts & Advisories","date_rel":"19h ago"},{"title":"Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure","link":"https://www.infosecurity-magazine.com/news/gunra-ransomware-fortinet-flaws/","source":"Infosecurity Magazine","date_rel":"23h ago"},{"title":"Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks","link":"https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html","source":"The Hacker News","date_rel":"11 Aug"}]},{"title":"Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File","link":"https://cybersecuritynews.com/wordpress-imagick-rce-vulnerability/","reason":"Wordpress","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Infosecurity Magazine","Sophos Threat Research","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with the Imagick extension and Ghostscript. The WordPress security\u2026","source":"Cyber Security News","date_rel":"10h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/WordPress-Imagick-RCE-Vulnerability.webp","description":"WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with the Imagick extension and Ghostscript. The WordPress security team is urging site owners to update immediately, either through the Dashboard\u2019s Updates screen or by downloading the release directly from WordPress.org, since sites with automatic background updates should already be receiving the patch. The flaw, tracked as CVE-2026-65640 and detailed in GHSA-8vr3-7mxf-gx8w, was responsibly disclosed by researchers at pwn.ai and allows an\u2026","related":[{"title":"BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins","link":"https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html","source":"The Hacker News","date_rel":"11 Aug"},{"title":"ClickFix campaign abuses Deno runtime for infostealer delivery","link":"https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery","source":"Sophos Threat Research","date_rel":"11 Aug"},{"title":"WordPress Plugins Compromised Without a Single File Change","link":"https://www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/","source":"Infosecurity Magazine","date_rel":"10 Aug"},{"title":"WordPress security advisory (AV26-792)","link":"https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-792","source":"CCCS Alerts & Advisories","date_rel":"10 Aug"}]},{"title":"Shipping 10\u201350\u00d7 More Code? Watch This Webinar on Securing AI-Speed Development","link":"https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html","reason":"Teams","category":"News","sources":["Dark Reading","Microsoft Security","Microsoft Security Blog","SecurityWeek","The Hacker News"],"coverage":5,"cve_ids":["CVE-2026-65768"],"summary":"AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output\u2026","source":"The Hacker News","date_rel":"10 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy3fcUJacnxspYO1ssk2-ESCQ9QYb5BBCB0-3Jk8UyWQFmKZxt8RCeYemwUlJ08y_hnkyVm4LaAq6a_oyz5BPmpuwkmephJ0K7iy6cFvPjAe-b3pQ4Q28jh3KzNqLhZ6qtecuG9jenDpeVsjpUrG9ZBEwe2WStxgh6RiOwhI_rlsxYelFv2BD31o9rhd8/s1600/chain-webinar.jpg","description":"AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.","related":[{"title":"Walmart Takes a 'Trusted Agent' Approach to Purple Teaming","link":"https://www.darkreading.com/cybersecurity-operations/walmart-trusted-agent-approach-purple-teaming","source":"Dark Reading","date_rel":"20h ago"},{"title":"Mindgard Raises $30 Million to Protect AI Systems","link":"https://www.securityweek.com/mindgard-raises-30-million-to-protect-ai-systems/","source":"SecurityWeek","date_rel":"23h ago"},{"title":"CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768","source":"Microsoft Security","date_rel":"11 Aug"},{"title":"Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise","link":"https://www.microsoft.com/en-us/security/blog/2026/08/10/microsoft-named-a-leader-in-the-2026-idc-marketscape-for-mdr-mxdr-for-the-enterprise/","source":"Microsoft Security Blog","date_rel":"10 Aug"}]},{"title":"Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code","link":"https://cybersecuritynews.com/adobe-commerce-vulnerabilities/","reason":"Adobe","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-71362"],"summary":"Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Critical-Adobe-Commerce-Vulnerability-Allows-Hackers-to-Execute-arbitrary-code.webp","description":"Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute arbitrary code. The most serious issue is CVE-2026-71362, an incorrect authorization vulnerability rated 9.1 out of 10 under the CVSS scoring system. The flaw could allow an unauthenticated remote attacker to escalate privileges without requiring administrator access. Adobe classified the vulnerability as critical because it could expose sensitive data and allow attackers to make\u2026","related":[{"title":"Hackers exploit critical Adobe Commerce flaw to hijack customer accounts","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts/","source":"Bleeping Computer","date_rel":"15h ago"},{"title":"Adobe security advisory (AV26-808)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws","link":"https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html","source":"The Hacker News","date_rel":"12 Aug"}]},{"title":"737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One","link":"https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html","reason":"Chrome","category":"News","sources":["Ars Technica Security","Bleeping Computer","Malwarebytes Labs","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy\u2026","source":"The Hacker News","date_rel":"22h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjI8aMtoRcWh4THmHEumFrk1X_t6xuq3Z6RsJwVKoyozs0nuRDIc7ffcIFNr5dFuUgTeeKZ0KLdeFoeHRRSFgqcTvK4VaO54Js2FADwBztN4Qlf0L8viPKGCY7lVEHF50K2xOaopCphCPL0ooDKna2E3S_4R4UzOsuh9m8dK4XQMo98_b6GjKqHRi_lm38i/s1600/chrome-plugins.jpg","description":"A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66","related":[{"title":"Hundreds of fake Chrome VPN extensions route traffic through a proxy","link":"https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extensions-route-traffic-through-a-proxy/","source":"Bleeping Computer","date_rel":"17h ago"},{"title":"Chrome adopts what may be the best protection yet against account takeovers","link":"https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-account-takeovers/","source":"Ars Technica Security","date_rel":"11 Aug"},{"title":"Fake CCleaner installs GhostDesk Chrome spyware","link":"https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware","source":"Malwarebytes Labs","date_rel":"11 Aug"}]},{"title":"Researchers found a way to hijack devices through Zoom screen sharing","link":"https://arstechnica.com/security/2026/08/researchers-found-a-way-to-hijack-devices-through-zoom-screen-sharing/","reason":"Zoom","category":"Media","sources":["Ars Technica Security","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them , and even carry out autonomous hacking sprees , researchers offered a sobering new example on Tuesday\u2026","source":"Ars Technica Security","date_rel":"23h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2022/08/GettyImages-1233188488-500x500.jpg","description":"As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them , and even carry out autonomous hacking sprees , researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets\u2019 devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security\u2026","related":[{"title":"\u201cZoomsday\u201d flaws could let one Zoom participant attack another","link":"https://www.malwarebytes.com/blog/bugs/2026/08/zoomsday-flaws-could-let-one-zoom-participant-attack-another","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client","link":"https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html","source":"The Hacker News","date_rel":"11 Aug"}]}],"worth_reading":[{"title":"ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-538/","reason":"Exchange","category":"Research","sources":["Infosecurity Magazine","Microsoft Security","Zero Day Initiative"],"coverage":3,"cve_ids":["CVE-2026-62913"],"summary":"This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism\u2026","source":"Zero Day Initiative","date_rel":"11 Aug","thumbnail":"","description":"This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.","related":[{"title":"CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62913","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day","link":"https://www.infosecurity-magazine.com/news/lazarus-post-quantum-key-dream-job/","source":"Infosecurity Magazine","date_rel":"23h ago"},{"title":"ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-535/","source":"Zero Day Initiative","date_rel":"11 Aug"},{"title":"ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-534/","source":"Zero Day Initiative","date_rel":"11 Aug"}]},{"title":"ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-533/","reason":"Cisco","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has\u2026","source":"Zero Day Initiative","date_rel":"11 Aug","thumbnail":"","description":"This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-20316.","related":[{"title":"Cisco security advisory (AV26-807)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-807","source":"CCCS Alerts & Advisories","date_rel":"12 Aug"},{"title":"Cisco security advisory (AV26-794)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-794","source":"CCCS Alerts & Advisories","date_rel":"10 Aug"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-73299","vendor":"Microsoft","product":"prompty","severity":"CRITICAL","score":10.0,"description":"Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled \u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73299"},{"id":"CVE-2024-27253","vendor":"IBM","product":"DOORS Next","severity":"CRITICAL","score":10.0,"description":"IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2024-27253"},{"id":"CVE-2026-73263","vendor":"Kubernetes","product":"prowler","severity":"CRITICAL","score":9.9,"description":"Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth \u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73263"},{"id":"CVE-2026-73294","vendor":"semaphoreui","product":"semaphore","severity":"CRITICAL","score":9.9,"description":"Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73294"},{"id":"CVE-2026-16860","vendor":"IBM","product":"i","severity":"CRITICAL","score":9.9,"description":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.","cwe":"CWE-427","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16860"},{"id":"CVE-2026-19656","vendor":"SCADA-LTS","product":"ScadaLTS","severity":"CRITICAL","score":9.9,"description":"ScadaLTS 2.7.8.1\u00a0exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Suc\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19656"},{"id":"CVE-2026-62420","vendor":"Canonical","product":"LXD","severity":"CRITICAL","score":9.9,"description":"An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via P\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-62420"},{"id":"CVE-2026-63293","vendor":"Canonical","product":"LXD","severity":"CRITICAL","score":9.9,"description":"A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symboli\u2026","cwe":"CWE-59","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63293"},{"id":"CVE-2026-63294","vendor":"Canonical","product":"LXD","severity":"CRITICAL","score":9.9,"description":"A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml fi\u2026","cwe":"CWE-59","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63294"},{"id":"CVE-2026-63296","vendor":"Canonical","product":"LXD","severity":"CRITICAL","score":9.9,"description":"An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without valid\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63296"}],"vendor_spikes":[{"vendor":"IBM","count":68,"critical_count":6},{"vendor":"jfrog","count":25,"critical_count":0},{"vendor":"Unknown","count":24,"critical_count":0},{"vendor":"siyuan-note","count":22,"critical_count":0},{"vendor":"Red Hat","count":17,"critical_count":4},{"vendor":"Apache","count":17,"critical_count":0},{"vendor":"WordPress","count":16,"critical_count":0},{"vendor":"GitLab","count":13,"critical_count":0},{"vendor":"Palo Alto","count":12,"critical_count":0},{"vendor":"Microsoft","count":11,"critical_count":4}],"epss_risers":[],"developing_map":{"https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html":4},"trending_count":20,"new_cve_count":393,"has_news_data":true,"has_cve_data":true}