{"date_iso":"2026-08-20","date_human":"Thursday, August 20, 2026","generated_utc":"2026-08-20 15:22 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)","link":"https://unit42.paloaltonetworks.com/large-scale-credential-attacks/","reason":"Microsoft","category":"Threat Intel","sources":["Any.Run Malware Analysis","Ars Technica Security","Bleeping Computer","CCCS Alerts & Advisories","Dark Reading","Malwarebytes Labs","Palo Alto Unit 42","SANS Internet Storm Center","The Hacker News"],"coverage":9,"cve_ids":[],"summary":"In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks.","source":"Palo Alto Unit 42","date_rel":"18 Aug","thumbnail":"https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-1.jpg","description":"","related":[{"title":"Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)","link":"https://isc.sans.edu/diary/rss/33264","source":"SANS Internet Storm Center","date_rel":"18m ago"},{"title":"Microsoft says August Windows updates may cause gaming issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-august-windows-updates-may-cause-gaming-issues-reboots/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"Microsoft fixes known issue causing Windows Defender crashes","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-known-issue-causing-windows-defender-crashes/","source":"Bleeping Computer","date_rel":"19 Aug"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"18 Aug"},{"title":"Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps","link":"https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html","source":"The Hacker News","date_rel":"18 Aug"},{"title":"Microsoft Copilot reveals secret input that allowed it to be hacked","link":"https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/","source":"Ars Technica Security","date_rel":"18 Aug"}]},{"title":"NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology","link":"https://therecord.media/nsa-fbi-warns-of-hackers-using-ai-generated-tools-critical-infrastructure","reason":"Siemens","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","CISA ICS Advisories","CyberScoop","Infosecurity Magazine","SecurityWeek","The Record"],"coverage":7,"cve_ids":[],"summary":"The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by \u201cAI-assisted development\u201d alongside exploitation of known vulnerabilities.","source":"The Record","date_rel":"18h ago","thumbnail":"http://cms.therecord.media/uploads/chuttersnap_E_Fvj_Sgbw1c_unsplash_dbd93b061f.jpg","description":"","related":[{"title":"ICS Operators Warned of AI-Driven Attacks on Siemens PLCs","link":"https://www.infosecurity-magazine.com/news/ics-ai-attacks-siemens/","source":"Infosecurity Magazine","date_rel":"1h ago"},{"title":"Hackers Using AI to Target Siemens PLCs in Critical US Sectors","link":"https://www.securityweek.com/hackers-using-ai-to-target-siemens-plcs-in-critical-us-sectors/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"AI-fueled attacks pose \u2018active threat\u2019 to water, other sectors, U.S. agencies warn","link":"https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/","source":"CyberScoop","date_rel":"17h ago"},{"title":"US warns of AI-powered attacks on Siemens PLCs in critical infrastructure","link":"https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/","source":"Bleeping Computer","date_rel":"18h ago"},{"title":"Defending Against an Active Threat to Siemens S7 Series PLCs","link":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a","source":"CISA Alerts & Advisories","date_rel":"19 Aug"},{"title":"Siemens Simcenter Nastran","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02","source":"CISA Alerts & Advisories","date_rel":"18 Aug"}]},{"title":"ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud","link":"https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html","reason":"Android","category":"News","sources":["Bleeping Computer","Dark Reading","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with \"significant enhancements,\" including a set of 167 remote commands and expands its targeting footprint\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq19iWDNnvPUAAC2_MJN09g-1SHoPWQv82zvmQGTvrniDXm9BUWK73QrKCNCgxk0uGp6MrKF8cDQrigQCI3CW1G8V8GNltJ0GRc-yBjt69zPem4YW_b0XCZwsIFhWiOoul7eIhEOjb_F0X9A9B_DOmQNbCWHF6AzqDro4U0XjH_CgtJ_J0MVZjDPmyDL1p/s1600/android-banking-malware.jpg","description":"Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with \"significant enhancements,\" including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.","related":[{"title":"New Manic Android malware can exfiltrate data through nearby devices","link":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps","link":"https://www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/","source":"Infosecurity Magazine","date_rel":"2h ago"},{"title":"Sideloading on Android: What it is, why it\u2019s risky, and how to do it more safely","link":"https://www.malwarebytes.com/blog/how-to/2026/08/sideloading-on-android-what-it-is-why-its-risky-and-how-to-do-it-more-safely","source":"Malwarebytes Labs","date_rel":"21h ago"},{"title":"Video Call Exploit Chains Two Flaws in Unisoc Modems","link":"https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems","source":"Dark Reading","date_rel":"17 Aug"}]},{"title":"CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway","link":"https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway","reason":"Citrix","category":"Research","sources":["Bleeping Computer","CCCS Alerts & Advisories","Rapid7 Blog","SecurityWeek"],"coverage":4,"cve_ids":["CVE-2026-19490"],"summary":"Overview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS\u2026","source":"Rapid7 Blog","date_rel":"19h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS\u2026","related":[{"title":"Citrix urges admins to patch new NetScaler flaws as soon as possible","link":"https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/","source":"Bleeping Computer","date_rel":"13m ago"},{"title":"Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler","link":"https://www.securityweek.com/exploitation-expected-for-critical-authentication-bypass-patched-in-citrix-netscaler/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"Citrix security advisory (AV26-833)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-833","source":"CCCS Alerts & Advisories","date_rel":"17h ago"},{"title":"Citrix security advisory (AV26-645) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-645","source":"CCCS Alerts & Advisories","date_rel":"17 Aug"}]},{"title":"Hackers Hide Malware Code Inside English Words to Infect Windows Users","link":"https://cybersecuritynews.com/hackers-hide-malware-code/","reason":"Windows","category":"News","sources":["Cyber Security News","Malwarebytes Labs","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-42912","CVE-2026-49798","CVE-2026-50383"],"summary":"A new Windows malware campaign is hiding malicious code inside ordinary English words, making the payload look less suspicious during analysis. The technique is being used to deliver Amatera Stealer, an\u2026","source":"Cyber Security News","date_rel":"47m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Hide-Malware-Code-Inside-English-Words-to-Infect-Windows-Users.webp","description":"A new Windows malware campaign is hiding malicious code inside ordinary English words, making the payload look less suspicious during analysis. The technique is being used to deliver Amatera Stealer, an information-stealing threat that targets sensitive data stored on infected systems. The campaign relies on ClearFake, a long-running operation that compromises legitimate websites and places fake CAPTCHA checks over real pages. Visitors are told to complete a verification step, but the prompt actually guides them into running a malicious command through the Windows Run dialog. Analysts at\u2026","related":[{"title":"41 deceptive download sites show a real link, then send you somewhere else","link":"https://www.malwarebytes.com/blog/threat-intel/2026/08/41-deceptive-download-sites-show-a-real-link-then-send-you-somewhere-else","source":"Malwarebytes Labs","date_rel":"18h ago"},{"title":"CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50383","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49798","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912","source":"Microsoft Security","date_rel":"22h ago"},{"title":"16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets","link":"https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html","source":"The Hacker News","date_rel":"18 Aug"}]},{"title":"UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities","link":"https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/","reason":"Linux","category":"Threat Intel","sources":["Cisco Talos","Dark Reading","Infosecurity Magazine"],"coverage":3,"cve_ids":[],"summary":"UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with\u2026","source":"Cisco Talos","date_rel":"2h ago","thumbnail":"https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/08/Fig-0-.jpg","description":"UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques. The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality. The actor\u2026","related":[{"title":"UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations","link":"https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/","source":"Cisco Talos","date_rel":"2h ago"},{"title":"Exclusive: Linux Foundation's Akrites to Go Live in September","link":"https://www.infosecurity-magazine.com/news/linux-foundations-akrites-go-live/","source":"Infosecurity Magazine","date_rel":"20h ago"},{"title":"Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS","link":"https://www.darkreading.com/cyber-risk/linux-botnet-evooo1bot-mirai-capabilities-beyond-ddos","source":"Dark Reading","date_rel":"17 Aug"}]},{"title":"Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code","link":"https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html","reason":"Wordpress","category":"News","sources":["Check Point Research","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitKWjeNJOL_DEahUmMAYpH9qh94s2iFi8igtfSlAzOVWiUBU-EIM0MWMsFYPmA5NDL6Rs9E-w9vvCmw3Cc6Og0q-TDt87Q2hwYIePNAQ0xQ3OJYHzgCizDFm-YK9SxW4ncWnuVLaOzgb3SPO7Qpx17zHMaFzBQfYllgz5IP-p1jMALgWlasRkj1nV3Tq3G/s1600/wordpress.jpg","description":"Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. \"The flaw lives in the Forms module's File","related":[{"title":"StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data","link":"https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html","source":"The Hacker News","date_rel":"19 Aug"},{"title":"Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect","link":"https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/","source":"Check Point Research","date_rel":"18 Aug"},{"title":"Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads","link":"https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html","source":"The Hacker News","date_rel":"17 Aug"},{"title":"WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover","link":"https://www.infosecurity-magazine.com/news/wordpress-plugin-flaw-40000-sites/","source":"Infosecurity Magazine","date_rel":"17 Aug"}]},{"title":"Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic","link":"https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html","reason":"Google","category":"News","sources":["Graham Cluley","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian\u2026","source":"The Hacker News","date_rel":"17 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu-MyaPNuRr2_NJ_TMqLf7OYW5AzCqgHpQ6HMfxlc-qsMzwSkfWlZDbHfecZ3IRp639FVDelhMZgpbnN87Fdchoh-g08R-cAiXxr7RvfdGy_ihvMxg152HK-rbOTIOnEueRTnPT-wU0eID3vplpIN1GBClvJC5e0egCGpDb_H0ykwH1x6a4zOvpW8V-Ssy/s1600/google.jpg","description":"Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the","related":[{"title":"Smashing Security podcast #481: Never say this to a robot dog","link":"https://grahamcluley.com/smashing-security-podcast-481/","source":"Graham Cluley","date_rel":"13h ago"},{"title":"Be careful what you put in \u201canyone with the link\u201d Google Docs","link":"https://www.malwarebytes.com/blog/news/2026/08/be-careful-what-you-put-in-anyone-with-the-link-google-docs","source":"Malwarebytes Labs","date_rel":"18 Aug"}]},{"title":"Meta Ran Ads for an App That Promised to Nudify Female Politicians","link":"https://www.wired.com/story/meta-ran-ads-for-an-app-promising-to-nudify-female-politicians/","reason":"Apple","category":"Media","sources":["CCCS Alerts & Advisories","Malwarebytes Labs","SANS Internet Storm Center","Wired Security"],"coverage":4,"cve_ids":[],"summary":"One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.","source":"Wired Security","date_rel":"18 Aug","thumbnail":"https://media.wired.com/photos/6a7b83f8c77bf6fe1feeaecb/master/pass/Politics_An%20NSFW%20Ad%20Featuring%20a%20Deepfaked%20Elisa%20Slotkin%20Is%20Running%20on%20Meta%20Platforms_v1.jpg","description":"","related":[{"title":"Apple security advisory (AV26-823) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823","source":"CCCS Alerts & Advisories","date_rel":"18 Aug"},{"title":"Apple fixes another image-processing flaw that could allow code execution","link":"https://www.malwarebytes.com/blog/bugs/2026/08/apple-fixes-another-image-processing-flaw-that-could-allow-code-execution","source":"Malwarebytes Labs","date_rel":"18 Aug"},{"title":"Apple Patches iOS and macOS, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33254","source":"SANS Internet Storm Center","date_rel":"17 Aug"},{"title":"Apple Screen Sharing Security, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33252","source":"SANS Internet Storm Center","date_rel":"17 Aug"}]},{"title":"Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000","link":"https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html","reason":"Exchange","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-33824"],"summary":"A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging\u2026","source":"The Hacker News","date_rel":"18 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo_eOapavOiIGXF7klCQPyN0-Qg2nWk9KlUYzPHuLwAyMKM75P3E2jciQR3v9gt2UBmez3XRSC57e5Fe9Oowm2brtgRXz5nJMPN8iQnBYddnTI4DyffnBAh4iLQFSOhA-8RhbbwuXqbJQOkhiXo5asFku1kFfmQd-UsHT6ulzdvRvw7WXwFKYFBTU_Q9nB/s1600/ransom.jpg","description":"A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. \"In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,\" GuidePoint Research","related":[{"title":"Critical RCE flaw in Windows IKE Extension now actively exploited","link":"https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"19 Aug"},{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"18 Aug"}]}],"worth_reading":[{"title":"Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs","link":"https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves","reason":"Oracle","category":"Research","sources":["CCCS Alerts & Advisories","Tenable Blog"],"coverage":2,"cve_ids":[],"summary":"Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925\u2026","source":"Tenable Blog","date_rel":"19 Aug","thumbnail":"","description":"Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates 154 issues (16.3% of all patches) were assigned a critical severity rating Oracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patches Background On August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026 . Beginning in May 2026, Oracle introduced CSPUs as a monthly\u2026","related":[{"title":"Oracle Corporation security advisory (AV26-831)","link":"https://cyber.gc.ca/en/alerts-advisories/oracle-corporation-security-advisory-av26-831","source":"CCCS Alerts & Advisories","date_rel":"18h ago"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-20030","vendor":"Cisco","product":"Cisco Crosswork Planning","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20030"},{"id":"CVE-2026-20315","vendor":"Cisco","product":"Cisco Secure Workload","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that ad\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20315"},{"id":"CVE-2026-20317","vendor":"Cisco","product":"Cisco Secure Workload","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that ad\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20317"},{"id":"CVE-2026-20357","vendor":"Cisco","product":"Cisco Crosswork Planning","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20357"},{"id":"CVE-2026-20358","vendor":"Cisco","product":"Cisco Crosswork Planning","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20358"},{"id":"CVE-2026-22306","vendor":"Microsoft","product":"OZOLS","severity":"CRITICAL","score":10.0,"description":"Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext \ntransmission of sensitive information vulnerability in Ozols Grupa OZOLS\n on Windows caused by an\u00a0abandoned auto-update domai\u2026","cwe":"CWE-319","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-22306"},{"id":"CVE-2026-15068","vendor":"IBM","product":"AIX","severity":"CRITICAL","score":9.9,"description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15068"},{"id":"CVE-2026-16816","vendor":"IBM","product":"AIX","severity":"CRITICAL","score":9.9,"description":"IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16816"},{"id":"CVE-2026-20231","vendor":"Cisco","product":"Cisco Secure Workload","severity":"CRITICAL","score":9.9,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that ad\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20231"},{"id":"CVE-2026-20359","vendor":"Cisco","product":"Cisco Crosswork Planning","severity":"CRITICAL","score":9.9,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse\u2026","cwe":"CWE-522","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20359"}],"vendor_spikes":[{"vendor":"Splunk","count":110,"critical_count":4},{"vendor":"IBM","count":107,"critical_count":21},{"vendor":"Wireshark Foundation","count":25,"critical_count":0},{"vendor":"Dell","count":23,"critical_count":0},{"vendor":"Unknown","count":19,"critical_count":0},{"vendor":"Microsoft","count":17,"critical_count":1},{"vendor":"WordPress","count":16,"critical_count":1},{"vendor":"getgrav","count":16,"critical_count":0},{"vendor":"Cisco","count":15,"critical_count":8},{"vendor":"thorsten","count":13,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":634,"has_news_data":true,"has_cve_data":true}