Security Round-Up

Monday

2026-08-10
Your source for daily security alerts from some of the best experts in the world.
Find the problems, secure your systems now!
Get these alerts in your inbox every morning. Subscribe

CONTENTS

MSRC Unclassified ( 7 )
Hacker News ( 19 )
Bleeping Computer ( 7 )
CISA ( 2 )
Cisco Advisories ( 2 )
DataBreaches.net ( 10 )
CVEMon Intruder ( 10 )
Graham Cluley
Publications | Hacking Lab ( 2 )
Schneier on Security ( 2 )
Securelist ( 2 )
Talos – Vulnerability Reports
Microsoft-Sentinel ( 3 )


MSRC Unclassified

08/09 TOC Mariner – ipv6: ndisc: fix NULL deref in accept_untracked_na() CVE-202…
08/09 TOC Mariner – wifi: mac80211: tear down new links on vif update error path…
08/09 TOC Mariner – Bluetooth: qca: fix NVM tag length underflow in TLV parser C…
08/09 TOC Mariner – ipv4: fib: free fib_alias with kfree_rcu() on insert error p…
08/09 TOC Mariner – mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_…
08/09 TOC Mariner – btrfs: reject free space cache with more entries than pages …
08/09 TOC Mariner – gtp: check skb_pull_data() return in gtp1u_send_echo_resp() …

Hacker News

08/10 TOC Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Cr…
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository
08/10 TOC OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to …
OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it’s implementing security controls for higher-capability models and associated activities, such as isolated
08/08 TOC Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to…
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was
08/08 TOC New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Toke…
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth
08/08 TOC Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authen…
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain
08/08 TOC N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems an…
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. “This is not a duplicate of our
08/08 TOC Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
08/07 TOC Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infos…
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,” OpenSourceMalware researcher Paul
08/07 TOC ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture. “
08/07 TOC UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via
08/07 TOC New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch AS…
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity
08/07 TOC Growing Up The Hard Way
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral. Then,
08/07 TOC 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape…
A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.
08/07 TOC New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating …
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and
08/07 TOC Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Fi…
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. “The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
08/07 TOC AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apa…
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where
08/07 TOC Malware Can Abuse Windows Hello for Business Keys for Persistent Entra…
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim’s Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies
08/07 TOC Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow …
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor’s agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.
08/07 TOC TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply C…
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. “The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure,

Bleeping Computer

08/10 TOC Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. […]
08/08 TOC Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. […]
08/07 TOC Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. […]
08/07 TOC Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. […]
08/07 TOC Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. […]
08/07 TOC Real emails, hijacked payments: Two H1 2026 attack chains
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. […]
08/07 TOC North Carolina Ports confirms cyberattack disrupting operations
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. […]

CISA

08/07 TOC CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  

  • CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

 

08/07 TOC CPDLC over ATN-B1 Vulnerabilities

View CSAF

Summary

ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness.

The following versions of CPDLC over ATN-B1 Vulnerabilities are affected:

  • ATN-B1 CPDLC vers:all/* (CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413)
CVSS Standard Equipment Vulnerabilities
v3 7.1 Advisory Circular 90-117 Data Link Communications CPDLC over ATN-B1 Vulnerabilities Missing Authentication for Critical Function, Allocation of Resources Without Limits or Throttling, Improper Check for Unusual or Exceptional Conditions

Background

  • Critical Infrastructure Sectors: Transportation Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Global

Vulnerabilities

Expand All +

CVE-2025-71409

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

View CVE Details


Affected Products

CPDLC over ATN-B1 Vulnerabilities
Standard:
Advisory Circular 90-117 Data Link Communications
Product Version:
Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*
Product Status:
known_affected
Remediations

None available
Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.

Mitigation
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.

Mitigation
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

Mitigation
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.

Relevant CWE: CWE-306 Missing Authentication for Critical Function


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.1 HIGH CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
4.0 7.1 HIGH CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L

CVE-2025-71410

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out remotely over radio frequency.

View CVE Details


Affected Products

CPDLC over ATN-B1 Vulnerabilities
Standard:
Advisory Circular 90-117 Data Link Communications
Product Version:
Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*
Product Status:
known_affected
Remediations

None available
Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.

Mitigation
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.

Mitigation
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

Mitigation
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.

Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
4.0 6 MEDIUM CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVE-2025-71411

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

View CVE Details


Affected Products

CPDLC over ATN-B1 Vulnerabilities
Standard:
Advisory Circular 90-117 Data Link Communications
Product Version:
Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*
Product Status:
known_affected
Remediations

None available
Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.

Mitigation
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.

Mitigation
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

Mitigation
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.

Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
4.0 6 MEDIUM CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVE-2025-71412

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.

View CVE Details


Affected Products

CPDLC over ATN-B1 Vulnerabilities
Standard:
Advisory Circular 90-117 Data Link Communications
Product Version:
Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*
Product Status:
known_affected
Remediations

None available
Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.

Mitigation
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.

Mitigation
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

Mitigation
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.

Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.1 HIGH CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
4.0 7.1 HIGH CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L

CVE-2025-71413

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remotely over radio frequency.

View CVE Details


Affected Products

CPDLC over ATN-B1 Vulnerabilities
Standard:
Advisory Circular 90-117 Data Link Communications
Product Version:
Advisory Circular 90-117 Data Link Communications ATN-B1 CPDLC: vers:all/*
Product Status:
known_affected
Remediations

None available
Currently, there is no mitigation available for CVE-2025-71409, CVE-2025-71410, CVE-2025-71411, CVE-2025-71412, CVE-2025-71413.

Mitigation
These vulnerabilities in the CPDLC protocol stack are exploitable in a lab environment. However, they require very specific conditions to be met and are unlikely to be exploited outside of a lab setting.

Mitigation
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

Mitigation
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities have a high attack complexity.

Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
4.0 6 MEDIUM CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Acknowledgments

  • Martin Strohmeier of Armasuisse reported these vulnerabilities to CISA

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Revision History

  • Initial Release Date: 2026-08-07
Date Revision Summary
2026-08-07 1 Initial Publication

Legal Notice and Terms of Use


Cisco Advisories

08/07 TOC Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.

This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe


Security Impact Rating: Medium
CVE: CVE-2026-20294
08/07 TOC ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. 

For more information about these vulnerabilities, see the Details section of this advisory.

For additional information on these vulnerabilities in ClamAV, see the ClamAV blog.

Cisco plans to release software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities.

Notes:

  • The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV scanning process in a privileged security context. The platforms that are highly impacted include Cisco Secure Endpoint Connector for Windows.
  • The SIR for these vulnerabilities is Medium on other platforms, including Linux and Mac platforms, because those platforms run the ClamAV scanning process in a lower-privileged security context. The affected platforms include Secure Endpoint Connector for Linux and Mac.
  • Cisco Secure Endpoint Private Cloud itself is not impacted by these vulnerabilities. However, the Cisco Secure Endpoint Connector software that is distributed from the device is impacted.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26


Security Impact Rating: High
CVE: CVE-2026-20337,CVE-2026-20338,CVE-2026-20339,CVE-2026-20345,CVE-2026-20346,CVE-2026-20347,CVE-2026-20348

DataBreaches.net

08/09 TOC KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank …
Park Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s website saying it had confirmed that “an external actor illegally accessed the…

Source

08/09 TOC Ransomware gangs skip the CEO, head straight for the 40-something IT m…
Carly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data…

Source

08/08 TOC City of Suisun declares local emergency after cyberattack downs 911 di…
Katie Chavez reports: Suisun City officials declared a state of emergency Saturday, Aug. 8, after a cyberattack took out the city’s emergency dispatch line and other key systems. City officials said that “malicious software infected and compromised IT systems” at about 5:45 a.m. on Friday. The cybersecurity issue forced the city to shut down its…

Source

08/08 TOC City of Coweta refuses to pay ransom after system-wide cyberattack
An update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who don’t keep their word do spoil it for…

Source

08/07 TOC US cloud kill switch is as dangerous as ransomware, European businesse…
Emma Woollacott reports: European firms are more concerned about a potential US government-imposed ‘kill switch’ for cloud services than almost anything else. In a survey of 1,500 businesses in the UK, France, and Germany, Proton found that with many having built their operations around a small number of US-based providers, they’re worried that access to those platforms could be…

Source

08/07 TOC New York State Department of Financial Services Secures Cybersecurity …
A press release from the NYS DFS: August 5, 2026 New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulation (23 NYCRR Part 500). DFS investigators identified deficiencies in the company’s cybersecurity program…

Source

08/07 TOC City of Coweta hit with system-wide ransomware attack, has backup
KTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity professionals to secure their systems to prevent any further intrusion and to begin a recovery…

Source

08/07 TOC Boston Childrens Hospital named in North Korean hacking operation
Naomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached, saying the issue traced to a former contractor’s personal device. Mr. Stykas, chief technology officer at…

Source

08/07 TOC AU: Hackers leak sensitive Victorian court data to dark web
Kristian Silva and Danny The personal information of Victorian court users has been posted on the dark web, sparking a police investigation. Names, emails and job titles of people who attended online hearings in regional courts were posted on an underground hacking forum in July. A user has claimed responsibility in a post. […] Court…

Source

08/07 TOC What Canvas learned from a massive cyberattack
Alcino Donadel reports: …. Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher ed. Higher education’s more meditative, governed approach to technological change is useful for reviewing rigor and long-term quality assurance, Pendleton…

Source


CVEMon Intruder

08/10 TOC CVE-2024-6100
Currently trending CVE – Hype Score: 16 – Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
08/10 TOC CVE-2026-64638
Currently trending CVE – Hype Score: 7 – WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers …
08/10 TOC CVE-2026-27912
Currently trending CVE – Hype Score: 5 – Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
08/10 TOC CVE-2026-11331
Currently trending CVE – Hype Score: 5 – An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an …
08/10 TOC CVE-2026-63077
Currently trending CVE – Hype Score: 2 – In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
08/10 TOC CVE-2025-14500
Currently trending CVE – Hype Score: 2 – IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The specific flaw exists …
08/10 TOC CVE-2024-1939
Currently trending CVE – Hype Score: 2 – Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
08/10 TOC CVE-2026-71320
Currently trending CVE – Hype Score: 2 – Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro …
08/10 TOC CVE-2025-3248
Currently trending CVE – Hype Score: 1 – Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
08/10 TOC CVE-2026-18577
Currently trending CVE – Hype Score: 1 – An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Graham Cluley

08/07 TOC Beware cut-price AI services that read your every word
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

Publications | Hacking Lab

09/30 TOC Prism: A Multi-Team Orchestration of LLM Agents for Automatic Program …
08/31 TOC QueryHouse: Cross-DBMS Differential Testing with LLM and Query Transpi…

Schneier on Security

08/07 TOC Friday Squid Blogging: Arctic Bobtail Squid Video

Nice video of the Arctic bobtail squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

08/07 TOC ICE Is Buying Access to Credit Card Records

Through data brokers, ICE is buying the information you provided to open a credit card.


Securelist

08/10 TOC IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
08/10 TOC IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.

Talos – Vulnerability Reports

08/09 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteReq…

Microsoft-Sentinel

08/07 TOC AI-powered playbook generator, now available to more customers

We’re excited to announce we’re making it easier than ever to go from intent to action with the AI-powered playbook generator now available to more customers. 

What’s new 

All Microsoft Sentinel customers in Defender portal can now create AI-generated playbooks directly in their automation workflow. As part of this change, Security Copilot enablement is no longer required: playbook generator is now available to more teams out of the box and without any extra cost. 

What playbook generator does 

Playbook generator uses AI to turn what you want to automate into a working playbook. Instead of hand-building automation in python code, describe the response you need in natural language and get an editable playbook, its tests and documentation generated for you right inside the Microsoft Defender portal. 

  • Faster response automation: go from idea to playbook in minutes. 
  • Built into your workflow: find it under Automation › + Create › Playbook Generator. 
  • Fully editable: generated playbooks are code-based, complete with tests, documentation and visual flow, that you can review and refine. 

Who is it for 

If you’re using Microsoft Sentinel in your Defender portal, the playbook generator is now within reach. This expansion brings AI-assisted playbook creation to significantly more security teams.

How to get started 

Ensure you have the right permissions 

To build and deploy generated playbooks, make sure You have the Automation Playbooks Unified RBAC permission with Read and Write access. 

 

  1. Open Microsoft Defender Portal and go to Automation. 
  2. Select + Create › Playbook Generator. 
  3. Describe the playbook you want to create. 
  4. Review, edit, and deploy. 
Automatically created visual diagram of the playbook.Phyton code created by playbook generator.

 

Availability 
  • General availability: Already available. 
  • Cost: Included with Microsoft Sentinel – no additional charge.  

Try Playbook Generator in your Microsoft Defender Portal today. 

08/07 TOC Smarter signals, broader coverage: UEBA anomalies on top of Behaviors …

Co-authors: Ron Shlomo and Ryan Smith

Security teams don’t struggle with a lack of security signals. The real challenge is understanding which activity matters, why it stands out, and where to focus first. 

Microsoft Sentinel’s Behaviors layer already helps analysts transform raw security events into meaningful behavioral patterns. Today, we’re making that experience both smarter and broader. 

What if every behavior could immediately tell you not only what happened, but why it matters? We’re bringing UEBA anomaly intelligence directly into the Behaviors layer, so every behavior now includes anomaly insights together with explainable context. At the same time, UEBA expands beyond identity signals to support network and cloud data sources, enabling richer behavioral insights across more of your environment and helping security teams detect suspicious activity wherever it occurs. 

If you’re new to these capabilities, we recommend reviewing our previous announcements on the UEBA expansion and the Behaviors public preview, which provide additional background on the Behaviors layer and its underlying UEBA capabilities. 

What’s new in Sentinel UEBA and Behaviors layer 

Microsoft Sentinel’s Behaviors layer aggregates and sequences individual events into meaningful behavioral patterns, giving SOC teams the security context of who did what to whom and why it matters in one place, instead of sifting through raw telemetry in separated tables. 

With this release, we’re expanding the Behaviors layer. It now includes UEBA Anomalies and contextual enrichments directly within each behavior. In addition, the Behaviors layer now supports Fortinet logs via the CommonSecurityLog table. We’re also expanding Classical UEBA beyond identity signals by adding support for network and cloud data sources: AWS GuardDuty, Check Point, Zscaler and Fortinet (via CommonSecurityLog). Together, these enhancements allow the SOC to receive a richer context and explainable anomaly detection for every behavior across a broader portion of the environment. 

Adding context to every behavior—use case 

The following example illustrates how UEBA Anomalies on Behaviors help analysts quickly identify suspicious activity by adding context to every behavior. 

Scenario: Detecting a compromised FortiGate device  

An attacker gains administrative access to a FortiGate firewall and begins making configuration changes to establish persistence and enable future access. Individually, each action may appear legitimate. Together, however, they form a potentially suspicious behavioral pattern. UEBA then layers anomaly insights and explainability on top of these Behaviors, providing the additional context needed to identify suspicious activity. 

Examples of observed behaviors include: 
  • Firewall administrator signs in from a new geographic location. 
  • Configuration changes occur outside normal maintenance windows. 
  • A new administrator account is created. 
  • VPN settings or firewall rules are modified to enable new access paths. 
  • Unusual outbound traffic is detected through the FortiGate device. 

Rather than presenting these as isolated events, UEBA enriches each behavior with anomaly insights and explainable context. Analysts can immediately understand why the activity stands out. For example, because the administrator has never performed this combination of actions before, the changes occurred at an unusual time, and multiple high-risk modifications happened within a short period. This helps security teams quickly identify high-risk activity, reduce investigation time, and respond before attackers can expand their access within the environment. 

KQL examples
//Query 1: Logon and Configuration Change by user for the first time BehaviorInfo | where Timestamp > ago(30d) | where ActionType == “BehaviorFortiGateReconfiguration” | where Insights has “FirstSeen” | extend AdditionalFields = todynamic(AdditionalFields) | extend Hostname = AdditionalFields.ApplianceId | extend User = AdditionalFields.ChangedBy[0] | extend uebaEnrichments = AdditionalFields [“ueba.enrichments”] | extend uebaInsights = todynamic(Insights).Explainability | project ActionType, Description, Categories, AttackTechniques, ServiceSource, DataSources, User, Hostname, AdditionalFields, uebaInsights, uebaEnrichments //Query 2: get HighVolumeAnomaly behaviors to detect high traffic for the suspicious host / IP BehaviorInfo | where Timestamp > ago(30d) | where DataSources has “CommonSecurityLog” | invoke GetAnomalousBehaviorsByValue( ““, //Extracted from Hostname in query 1 “HighVolumeAnomaly”)

Expanding visibility scross the environment—use cases 

The following examples show how the new network data sources extend Behavioral analytics and UEBA Anomalies, helping uncover suspicious activity across more of your environment. 

Scenario: Identifying suspicious web access with Zscaler telemetry  

A user attempts to access a URL categorized as phishing, malware, spyware, or command-and-control. On its own, the event may appear as just another web-proxy log among thousands generated every day. 

With Zscaler telemetry incorporated into behavioral analytics, UEBA identifies that the user has never accessed this high-risk URL category before and enriches the activity with user, destination, source IP, location, ISP, and threat intelligence context, helping analysts immediately understand why the event stands out. Rather than investigating an isolated web access event, analysts can quickly determine whether the activity indicates a phishing attempt or attacker-controlled infrastructure and respond before the compromise spreads. 

KQL example 
//Query 3: First-time high-risk web category access from an unusual location or ISP Returns phishing, malware, spyware, or C2 category hits that are new for the user and come from an unusual location or network. Check RequestURL and UrlCategory for the destination. BehaviorAnalytics | where TimeGenerated > ago(7d) | where EventSource == “CommonSecurityLog” | where ActivityType == “UnusualHighRiskWebCategoryAccess” | where ActivityInsights.DeviceVendor == “Zscaler” | where ActivityInsights.DeviceProduct == “NSSWeblog” | extend UrlCategory = ActivityInsights.UrlCategory | extend RequestURL = ActivityInsights.RequestURL | extend ISP = DevicesInsights.ISP | extend ThreatIntel = DevicesInsights.ThreatIntelIndicatorType | extend RiskyCategory = ActivityInsights.FirstTimeUserAccessedHighRiskUrlCategory == True or ActivityInsights.FirstTimeHighRiskUrlCategoryObservedInTenant == True | extend UnusualLocation = ActivityInsights.FirstTimeUserConnectedFromCountry == True or ActivityInsights.FirstTimeConnectionFromCountryObservedInTenant == True or ActivityInsights.CountryUncommonlyConnectedFromByUser == True | extend UnusualISP = ActivityInsights.FirstTimeUserConnectedViaISP == True or ActivityInsights.ISPUncommonlyUsedByUser == True or ActivityInsights.IPRegOrgUncommonlyUsedByUser == True | where RiskyCategory and (UnusualLocation or UnusualISP or isnotempty(ThreatIntel))

 

The following example illustrates how Behaviors built on top of new network data source help analysts identify sensitive administrative activity that might otherwise appear routine. 

Scenario: Identifying suspicious FortiGate configuration backups  

A network administrator exports a FortiGate configuration backup. On its own, this action is common during maintenance, upgrades, or disaster recovery and is unlikely to trigger immediate investigation. 

With Behaviors built on top of Fortinet telemetry, Microsoft Sentinel transforms this raw administrative event into a meaningful security context. Analysts can immediately see who performed the backup, which device was involved, how it was executed (GUI, API, RESTAPI, ssh or CLI), and whether the activity deviates from the user’s normal behavior or occurred alongside other suspicious activity. 

Instead of reviewing isolated firewall events, analysts can quickly determine whether the configuration export is part of legitimate administration or an early indicator of compromise, reconnaissance, or preparation for persistence. 

KQL example
// Query 4: FortiGate configuration backup activity BehaviorInfo | where ActionType == “BehaviorFortiGateBackup” | extend ParsedData = parse_json(AdditionalFields) | extend Device = tostring(ParsedData.ApplianceId), User = tostring(ParsedData.Account), SourceIP = tostring(ParsedData.LoginSourceIP) | project TimeGenerated, Device, User, SourceIP, Description, AdditionalFields | order by TimeGenerated

Getting started 

 

UEBA user interface.

 We’d love to hear how your team is using these capabilities. Share your feedback to help us improve and expand coverage. 

Why it matters 

These updates represent another step in our commitment to making Behaviors and UEBA in Microsoft Sentinel more powerful, more explainable, and more broadly applicable across the environments your security team defends. 

08/07 TOC Public Preview: Nested API Support Comes to Microsoft Sentinel CCF

Microsoft Sentinel continues to evolve its capabilities to support an expanding ecosystem of partners and data integrations. Recent innovations include the Codeless Connector Framework (CCF) Push feature, the new Sentinel connector builder agent, and the CCF expansion to pull data from Azure Storage Blob. Each of these reflects our ongoing investment in making it easier for ISVs and developers to build scalable, high-fidelity data connectors that bring telemetry into Sentinel data lake.

Today, we are excited to announce another advancement in this journey – the public preview for Nested API support in CCF.

What is Nested API support and Why it Matters

Nested API support enables a pattern common across many ISV log sources, where a single polling cycle spans multiple dependent API calls: an initial call returns a list of records (such as alert IDs or case references), and one or more follow-up calls fetch the full detail for each record in that list.

This support allows CCF to accommodate the list-then-detail API pattern as it exists in many API designs, so that partners don’t need to restructure or adapt their endpoints. The result is broader integration coverage that allows partners to connect data sources whose APIs are naturally paginated across multiple calls, and then to ingest complete records into Microsoft Sentinel without building custom middleware.

Support for Nested API in the Microsoft Sentinel VS Code extension

This pattern is also available through the Visual Studio Code (VS Code) extension for Microsoft Sentinel connectors. The extension is an agentic tool that helps ISVs and partners build, test, and package data connectors more efficiently, providing a guided experience for bringing data into Microsoft Sentinel.

As part of its design, the extension enables developers to implement Nested API workflows, allowing connectors to orchestrate multi-step API calls and support APIs that require chained or dependent requests. To learn more, see the Sentinel connector builder agent blog and the Microsoft Learn documentation for implementation guidance.

Real-world adoption: Early ISV implementations

A growing set of solutions are already leveraging Nested API support to enable multi-step data retrieval scenarios. These early implementations demonstrate how partners are using this capability to structure connector workflows around their existing APIs. Some of the early adopters and their solutions are listed below.

 

 

 BigID


BigID integrates with Microsoft Sentinel to extend data security posture management (DSPM) insights into security operations workflows. The solution brings visibility into sensitive, regulated, and critical data across cloud, SaaS, and on‑premises environments, helping security teams understand data‑related risk and exposure. Built on the Codeless Connector Framework (CCF), the integration can leverage capabilities such as Nested API retrieval to ingest more detailed, context‑rich records through multi‑step API calls, supporting more informed investigation and prioritization.

 

 

Cisco Email Threat Defense

Cisco Email Threat Defense integrates with Microsoft Sentinel to bring email‑borne threat detections into centralized security operations. The connector ingests all information that can be used as security signals, such as phishing and malware indicators, enabling teams to correlate email activity with broader incidents and improve investigation and response. Built on the Codeless Connector Framework (CCF), the integration supports advanced patterns like Nested API retrieval, allowing more detailed event context to be ingested through multi‑step API calls without requiring changes to the underlying data source.

 

 

 

Idira Audit

Idira® Audit by Palo Alto Networks integrates with Microsoft Sentinel to centralize visibility into privileged identity and access activity. By streaming detailed audit logs—covering system events, user actions, and administrative activity—into Sentinel, security teams can correlate identity‑driven risks with broader security telemetry. Built on the Codeless Connector Framework (CCF), the integration can leverage capabilities such as Nested Application Programming Interface retrieval to ingest more detailed, context‑rich records, supporting faster investigation and more effective response. 

 

 

In addition to these early third-party adopters, some Microsoft-built connectors that also leverage this pattern are listed below:

Build with Nested APIs in Microsoft Sentinel

Developers and partners can begin leveraging Nested API support today as part of the Codeless Connector Framework. To get started, review the Microsoft Learn documentation for implementation guidance and explore existing connector configurations that demonstrate this pattern. You can also jump right in and explore building with mock data using our Nested API Lab.

As Microsoft Sentinel continues to expand its ecosystem, App Assure works closely with partners to help onboard and optimize integrations. If you are building or extending a connector and would like support, the App Assure team is available to help you get started. Reach out to us via our intake form.

Additional Sentinel Feature Public Preview Announcements




Content on this page is collected from remote sources by IPWorX but is not created by IPWorX. The contents belong to the creators and should be considered theirs for all legal purposes, we have no editorial control or responsibility over them. IPWorX does not represent or endorse the accuracy or reliability of any opinion, statement, or other information provided by any third party.

This page contains links to third-party websites. These links are provided solely for your convenience. IPWorX does not control, maintain, or endorse the content, accuracy, or reliability of any third-party resources, and you access them at your own risk.

Scripts and tools to help manage your network found, managed and
happily shared with documentation on usage at the IP WORk eXchange.
https://www.IPWorX.com