Security Round-Up

Thursday

2026-08-06
Your source for daily security alerts from some of the best experts in the world.
Find the problems, secure your systems now!
Get these alerts in your inbox every morning. Subscribe

CONTENTS

TLDR InfoSec ( 2 )
Hacker News ( 38 )
Check Point Research
Cisco Talos ( 2 )
Bleeping Computer ( 15 )
CISA ( 5 )
MS-ISAC CYBERSECURITY ADVISORY
Advisories ( 15 )
DataBreaches.net ( 9 )
Artificial truth
CVEMon Intruder ( 10 )
Embrace The Red
Graham Cluley ( 3 )
PortSwigger Research ( 2 )
Publications | Hacking Lab ( 2 )
Schneier on Security ( 5 )
Securelist ( 2 )
Talos – Vulnerability Reports
Troy Hunt
Zero Day Initiative-Published ( 3 )
Microsoft-Core Infrastructure
Microsoft-Defender Cloud
Veeam ( 6 )


TLDR InfoSec

08/04 TOC macOS Root Access Bug , Rusty UEFI Bootkit , DPRK NPM Attacks
08/03 TOC Claude Models Hack 3 Organizations , CareCloud Breach , $88M BTC Walle…

Hacker News

08/06 TOC Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windo…
Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,
08/06 TOC AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Withou…
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent’s tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon
08/06 TOC Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthentic…
Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese
08/06 TOC Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware…
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.
08/06 TOC CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation …
A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity server
08/06 TOC Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Mi…
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from
08/05 TOC Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Mal…
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft
08/05 TOC OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Frau…
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive
08/05 TOC Poison Claude Sells Discounted Claude Access While Its Operator Sees E…
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. “Advertisements for Poison Claude
08/05 TOC Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent…
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes
08/05 TOC Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cr…
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused for later users’
08/05 TOC Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP fro…
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by
08/05 TOC New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwi…
A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim
08/05 TOC Kali365 Weaponizes Microsoft Authentication Against US Companies: New …
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,
08/05 TOC Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files vi…
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its
08/05 TOC Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896
08/05 TOC Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Develo…
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
08/05 TOC Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testin…
An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for
08/05 TOC CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Explo…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows – CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote
08/05 TOC QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Wi…
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a
08/04 TOC Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Toke…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and
08/04 TOC Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code …
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages
08/04 TOC Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remot…
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat
08/04 TOC When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Alwa…
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as “script kiddies,” sat at the other end, running public
08/04 TOC Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could T…
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied
08/04 TOC New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Databa…
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects
08/04 TOC DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and Dev…
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second
08/04 TOC CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compro…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows
08/03 TOC 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool U…
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package
08/03 TOC Google Password Manager Attacks Could Let Malware Hijack Passkey-Prote…
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
08/03 TOC INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000…
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
08/03 TOC Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attack…
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from
08/03 TOC FOMO in the SOC: Where AI Platforms like Claude Actually Fit
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers the most value. With so many new AI
08/03 TOC Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on…
An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit
08/03 TOC PNLD Breach Exposes U.K. Police and Government Contact Details on Dark…
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names
08/03 TOC Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly U…
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it
08/03 TOC N-able Says Attackers Take Over N-central Servers After Initial Fix Pr…
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform
08/03 TOC Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbi…
Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. “These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the

Check Point Research

08/03 TOC 3rd August Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported […]

The post 3rd August – Threat Intelligence Report appeared first on Check Point Research.


Cisco Talos

08/04 TOC Keep going, bro. Youve got this! A data-driven look at how adversaries…
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we’ve seen bad actors leveraging cloud-based AI.
08/03 TOC [Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incid…
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.

Bleeping Computer

08/05 TOC Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. […]
08/05 TOC Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. […]
08/05 TOC Hackers run khunt post-exploitation toolkit from Oracle database
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. […]
08/05 TOC COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. […]
08/05 TOC CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat fl…
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. […]
08/05 TOC Google Blogger locks hundreds of blogs in malware false positive
Google has locked hundreds of Blogger websites after a false positive claimed they violated its “Malware and Similar Malicious Content” policy, with some sites deleted from the platform. […]
08/05 TOC How AI-powered phishing killed blocklists for good
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense than relying on domains, signatures, and other known-bad indicators. […]
08/04 TOC OpenAI, Anthropic AI agents targeted real people and systems in cyber …
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. […]
08/04 TOC TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). […]
08/04 TOC Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. […]
08/04 TOC New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. […]
08/04 TOC 77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. […]
08/04 TOC Massive ChainDrop npm supply-chain attack infects hundreds of packages…
Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. […]
08/04 TOC Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user’s intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. […]
08/03 TOC Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 account…
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. […]

CISA

08/05 TOC CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  

  • CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

08/04 TOC Thermo Fisher Applied Biosystems Genetic Analyzers

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results.

The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected:

  • Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2 
  • Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2 
  • Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software <=1.2.5 
  • Applied Biosystems SeqStudio Flex Series Instrument Software <=1.2.0 
  • Applied Biosystems GeneMapper ID-X Software <=v1.7.3 
  • Applied Biosystems 3130 Series Data Collection Software <=4.1 
  • ABI PRISM 3100/3100-Avant Data Collection Software <=2.0 
  • ABI PRISM 310 Data Collection Software <=3.1 
CVSS Vendor Equipment Vulnerabilities
v3 8.4 Thermo Fisher Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check

Background

  • Critical Infrastructure Sectors: Healthcare and Public Health
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities

Expand All +

CVE-2026-17583

The affected product is vulnerable because its .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.

View CVE Details


Affected Products

Thermo Fisher Applied Biosystems Genetic Analyzers
Vendor:
Thermo Fisher
Product Version:
Thermo Fisher Applied Biosystems 3500/3500xL Series Data Collection Software: <=4.0.2, Thermo Fisher Applied Biosystems 3730/3730xL Series Data Collection Software: <=5.0.2, Thermo Fisher Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: <=1.2.5, Thermo Fisher Applied Biosystems SeqStudio Flex Series Instrument Software: <=1.2.0, Thermo Fisher Applied Biosystems GeneMapper ID-X Software: <=v1.7.3, Thermo Fisher Applied Biosystems 3130 Series Data Collection Software: <=4.1, Thermo Fisher ABI PRISM 3100/3100-Avant Data Collection Software: <=2.0, Thermo Fisher ABI PRISM 310 Data Collection Software: <=3.1
Product Status:
known_affected
Remediations

Mitigation
Thermo Fisher has developed security updates to address the vulnerability. The security updates implement the use of digital signatures on the instrument software that adds an extralayer of protection. Moving forward, this will help users verify that data files have not been modified.

Vendor fix
Applied Biosystems 3500/3500xL Series Data Collection Software: Update to version 4.0.3
https://downloads.thermofisher.com/3500_DCS_v4.0.3_Patch/v4.0.3_Patch_Installer.exe

Vendor fix
Applied Biosystems 3730/3730xL Series Data Collection Software: Update to version 5.0.3
https://downloads.thermofisher.com/3730xl_UDC_v5.0.3_Patch/3730xl_UDC_v5.0.3_Patch.exe

Vendor fix
Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software: Update to version 1.2.6
https://downloads.thermofisher.com/SeqStudio/1.2.6/SeqStudio-1.2.6.abpkg

Vendor fix
Applied Biosystems SeqStudio Flex Series Instrument Software: Update to version 1.2.1
https://downloads.thermofisher.com/SeqStudioFlex/1.2.1/SeqStudioFlex-1.2.1.abpkg

Vendor fix
Applied Biosystems GeneMapper ID-X Software: Update to version 1.7.4
https://downloads.thermofisher.com/GeneMapperID-Xv1.7.4_Patch/GMIDX_v1.7.4_Patch.exe

Vendor fix
Applied Biosystems 3130 Series Data Collection Software: Product is End of Life (EoL), no update provided

Vendor fix
ABI PRISM 3100/3100-Avant Data Collection Software: Product is End of Life (EoL), no update provided

Vendor fix
ABI PRISM 310 Data Collection Software: Product is End of Life (EoL), no update provided

Mitigation
For users who are unable to immediately implement all applicable security updates, Thermo Fisher Scientific recommends implementing the following interim mitigation measures until the applicable updates have been installed: 

-Maintain a secure chain of custody for files generated by the HID instrumentation throughout the analysis workflow.
-Store generated files on encrypted, password-protected storage media (for example, encrypted USB drives or encrypted hard drives).
-Restrict access to generated files to authorized personnel in accordance with your laboratory’s access control policies.
-Apply the principle of least privilege by limiting user permissions on systems operating the HID instrumentation or hosting associated data analysis and secondary analysis software.
-Leverage firewall rules and network access control lists (NACLs) to restrict internet connectivity to only trusted sources.

Mitigation
For more information, refer to Thermo Fisher’s security bulletin.
https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf

Relevant CWE: CWE-353 Missing Support for Integrity Check


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0 8.2 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

Acknowledgments

  • Nathaniel Adams, Laura Gaydosh-Combs, and Kevin Dyer reported this vulnerability to CISA

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.

When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.


Revision History

  • Initial Release Date: 2026-08-04
Date Revision Summary
2026-08-04 1 Initial Publication

Legal Notice and Terms of Use

08/04 TOC Acrisure KARR BT and DR-100

View CSAF

Summary

Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations.

The following versions of Acrisure KARR BT and DR-100 are affected:

  • KARR BT firmware
  • DR-100 firmware
CVSS Vendor Equipment Vulnerabilities
v3 8.1 Acrisure Acrisure KARR BT and DR-100 Use of Hard-coded Cryptographic Key

Background

  • Critical Infrastructure Sectors: Transportation Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities

Expand All +

CVE-2026-18411

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.

View CVE Details


Affected Products

Acrisure KARR BT and DR-100
Vendor:
Acrisure
Product Version:
Acrisure KARR BT firmware:
Product Status:
known_affected
Remediations

Vendor fix
Acrisure Protection Group released a firmware update on July 20, 2026, to address this vulnerability. They recommend that affected users should follow the directions found here: https://www.karrsecurity.com/karr-security-firmware-update-instructions.
https://www.karrsecurity.com/karr-security-firmware-update-instructions

Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
4.0 7.2 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Acknowledgments

  • Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, Nishant Bhaskar of UC San Diego team reported this vulnerability to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.

Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.

Locate control system networks and remote devices behind firewalls and isolating them from business networks.

When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

Do not click web links or open attachments in unsolicited email messages.

Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.

Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-08-04
Date Revision Summary
2026-08-04 1 Initial Publication

Legal Notice and Terms of Use

08/04 TOC CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  

  • CVE-2026-9198 IBM Langflow Code Injection Vulnerability
  • CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
  • CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

08/03 TOC CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  

  • CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.


MS-ISAC CYBERSECURITY ADVISORY

08/03 TOC Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for A…

Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain access. This does require the SAML 2.0 authentication method to be enabled. 


Advisories

08/05 TOC Cisco Advance Notification for Publication of August 5, 2026, Security…

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:

<
Security Impact Rating: Informational08/05TOCCisco IOS XE Software Web-Based Management Interface Denial of Service…

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-PtAODAWW


Security Impact Rating: Medium
CVE: CVE-2026-20311
08/05TOCCisco Integrated Management Controller Cross-Site Scripting Vulnerabil…

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-7EhBFxBp


Security Impact Rating: Medium
CVE: CVE-2026-20198
08/05TOCCisco RoomOS Logging Subsystem Information Disclosure Vulnerability

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information.

This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm


Security Impact Rating: Medium
CVE: CVE-2026-20289
08/05TOCCisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Se…

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.

Cisco has released software updates that address this vulnerability. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd


Security Impact Rating: High
CVE: CVE-2026-20263
08/05TOCCisco IOS XE Software SNMP Denial of Service Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. There is a mitigation that addresses this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD


Security Impact Rating: High
CVE: CVE-2026-20124
08/05TOCCisco IOS Software and IOS XE Software Extensible Messaging Client Pro…

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. There is a mitigation that addresses this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t


Security Impact Rating: High
CVE: CVE-2026-20301
08/05TOCCisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.

This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe


Security Impact Rating: Medium
CVE: CVE-2026-20294
08/05TOCCisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.


Security Impact Rating: Critical
CVE: CVE-2026-20267,CVE-2026-20268,CVE-2026-20269,CVE-2026-20270,CVE-2026-20271,CVE-2026-20272,CVE-2026-20273
08/05TOCCisco Integrated Management Controller Argument Injection Vulnerabilit…

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. 

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU


Security Impact Rating: High
CVE: CVE-2026-20200,CVE-2026-20288
08/05TOCCisco Terminal Services Agent Firewall Rules Bypass Vulnerability

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.

This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ts-agent-fw-bypass-MYBTMrev


Security Impact Rating: Medium
CVE: CVE-2026-20028
08/05TOCCisco Catalyst SD-WAN Software Security Hardening Release: August 2026…

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K


Security Impact Rating: Critical
CVE: CVE-2026-20303,CVE-2026-20304,CVE-2026-20310,CVE-2026-20312,CVE-2026-20313
08/05TOCCisco IOS XE Software Web-Based Management Interface Denial of Service…

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.

This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3


Security Impact Rating: Medium
CVE: CVE-2026-20308
08/05TOCCisco Secure Firewall Management Center Software Static Credential Vul…

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. 

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  

Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh


Security Impact Rating: High
CVE: CVE-2026-20316
08/05TOCCisco Secure Firewall Management Center Software Authentication Bypass…

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. 

This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2

This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication.


Security Impact Rating: Critical
CVE: CVE-2026-20079

DataBreaches.net

08/05TOCCanadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and …
Connor Riley Moucka, aka “Waifu” and “Judishe,” was scheduled to stand trial in January 2027. Today, he changed his “not guilty” plea to a guilty plea, and pleaded guilty to four counts of the multi-count indictment.   Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in…

Source

08/05TOCAU: Updoc patients notified of security breach where personal informat…
Emma Kirk reports: Updoc patients have been notified their personal information may have been accessed in a security breach. The website is used for 24/7 telehealth services across Australia. Customers were advised there was a “brief period of unauthorised access to a third party system” where hackers had access to names, email and postal addresses…

Source

08/04TOCSage Water Resources says Utah saltwater disposal controller intrusion…
Dysruption reports on a critical infrastructure attack in Utah that could have caused more damage than some other recent attacks: Sage Water Resources said workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah, before the March 15 intrusion caused equipment failure or environmental damage. In an Aug….

Source

08/04TOCFlorida Man Sentenced for Conspiracy to Commit Wire Fraud
Stolen wallets are still a thing.  From the U.S. Attorney’s Office, Eastern District of Kentucky: July 31, 2026 LEXINGTON, Ky. – An Orlando, Fl., man, Ivory Joe Pruitt, 61, was sentenced on Friday to 63 months imprisonment by U.S. District Judge Robert Wier for conspiracy to commit wire fraud. Pruitt was also ordered to pay $137,392.74…

Source

08/04TOCRepublican attorneys general urge OpenAI to preserve records on Huggin…
Miranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO Sam Altman, 15 attorneys general wrote the ChatGPT-maker may have…

Source

08/04TOCSwiss federal IT office hit by cyberattack
SwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration. Around 200 accounts were compromised in the incident. There are no indications of any further data breaches. The unknown attackers are…

Source

08/03TOCKR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-…
The Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seoul Metropolitan Council member Im Gyu-ho of the Democratic Party of Korea…

Source

08/03TOCUK: Details of 100,000 police staff leaked on the dark web after hack
Bill Curtis reports: The full names and contact details for more than 100,000 police officers and staff have been leaked on the dark web after a hack, The Times can reveal. As part of a major security breach, hackers compromised data belonging to the Ministry of Defence (MoD), the Home Office, National Crime Agency (NCA),…

Source

08/03TOCCyberattack hits Liechtenstein, with 31,000 records stolen
DPA reports: The tiny principality of Liechtenstein has fallen victim to a major cyberattack in which the data of 31,000 people were stolen, the government said on Sunday. The country, which lies between Switzerland and Austria, has a population of around 41,000. The government said it had convened a crisis team led by Prime Minister…

Source


Artificial truth

08/04TOCmat2 0.15.0

There is a new version of mat2: 0.15.0, this is a big one, with two new added formats, and a bunch of fixes:

  • Be more upfront about the limited HEIC support. As mat2 can’t remove embedded ICC profile, HEIC files can now only be cleaned in lightweight mode.
  • Remove setup.py and fully embrace pyproject.toml, it’s apparently the present and future of python packaging. One more packaging method bro, one more and it’ll fix everything, just one more.
  • Add integration with Cinnamon‘s file manager Nemo.
  • Improve compatibility with modern Python
  • Don’t change the PDF version of cleaned files
  • Remove APEv2 and ID3v1 tags appended to mp3, ogg and flac files
  • Add avif support
  • Add jpeg xl (jxl) support
  • Improve odt support
  • Improve startup performances on modern python thanks to PEP0810
  • Stop reordering elements in office files, only sort their attributes. This improves compatibility with MS Office.

I’m super happy that metadatacleaner, a GUI for mat2, is kept alive by a handful of people, as it’s likely the easiest way to use mat2.

Many thanks to Cole “munzzyy” Munz for his contributions!

As usual, if you know some python help is welcome.


CVEMon Intruder

08/06TOCCVE-2026-58073
Currently trending CVE – Hype Score: 23 – A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent’s credentials.
08/06TOCCVE-2026-58072
Currently trending CVE – Hype Score: 23 – A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.
08/06TOCCVE-2025-31207
Currently trending CVE – Hype Score: 19 – A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user’s installed apps.
08/06TOCCVE-2026-9198
Currently trending CVE – Hype Score: 17 – IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
08/06TOCCVE-2026-18556
Currently trending CVE – Hype Score: 15 – Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
08/06TOCCVE-2026-34486
Currently trending CVE – Hype Score: 14 – Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or …
08/06TOCCVE-2026-67191
Currently trending CVE – Hype Score: 7 – Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop’s …
08/06TOCCVE-2026-67192
Currently trending CVE – Hype Score: 7 – Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length …
08/06TOCCVE-2026-66014
Currently trending CVE – Hype Score: 7 – JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
08/06TOCCVE-2026-65617
Currently trending CVE – Hype Score: 7 – A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

Embrace The Red

08/03TOCLLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and …

LiteLLM is a popular AI gateway. It provides a unified interface to LLMs and simplifies governance. It also has access to the backend LLM provider keys.

All of that makes it a high-value target. Not only for IP and data theft, but also for response modification and tool invocation.

LLM Heist

This post walks through a set of TTPs that red teams can integrate into authorized operations to demonstrate rerouting, interception, and modification of LLM traffic. We also cover things defenders can look out for.


Graham Cluley

08/06TOCApples bug bounty program is drowning in so much AI slop, it is in dan…
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist. Read more in my article on the Hot for Security blog.
08/05TOCSmashing Security podcast #479: How a fake police officer nearly stole…
Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There’s just one small problem: what they really want is the 24-word seed key to Graham’s cryptocurrency wallet. Meanwhile, if you’ve stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of “Captive Crunch” for a Russian intelligence-linked hacking group. And a group calling itself the “ExFilSquad” has walked off with 600,000 records of the UK’s teachers and head teachers from the Department for Education — sending an unusually polite ransom demand. All this and more in episode 479 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.
08/04TOCFake IRS letters target cryptocurrency holders
Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called “Digital Asset Compliance Portal”? If so, it’s time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Hot for Security blog.

PortSwigger Research

08/05TOCCRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
08/05TOCCan AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi

Publications | Hacking Lab

09/30TOCPrism: A Multi-Team Orchestration of LLM Agents for Automatic Program …
08/31TOCQueryHouse: Cross-DBMS Differential Testing with LLM and Query Transpi…

Schneier on Security

08/05TOCVulnerabilities in Car Anti-Theft Device

This is disturbing:

…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.

08/04TOCIran Cyberattacks Against Minnesota Water Systems

Attribution is preliminary, and so far it seems no real damage.

And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.

“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”…

08/04TOCSome Claude Chats Are Searchable on Google

And it’s personal information (alternate link):

The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses.

What seems to be the issue is a user setting about data sharing. Anthropic’s position is that it’s not their problem:

“We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,” the company said in a statement. “These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”…

08/03TOCMore on the OpenAI Agents Attack on Hugging Face

Hugging Face has published a detailed timeline of the attack. From the summary:

The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark’s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own…

08/03TOCThe OpenAI Hack Shows the Genie Is Out of the Bottle

This essay originally appeared in Foreign Policy.

Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.

Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to …


Securelist

08/04TOCHow legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
08/03TOCAn analysis of incidents at Brazilian educational institutions
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.

Talos – Vulnerability Reports

08/05TOCMicrosoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteReq…

Troy Hunt

08/03TOCWelcoming the Nepalese Government to Have I Been Pwned

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and


Zero Day Initiative-Published

08/05TOCZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature …
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
08/05TOCZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following …
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
08/05TOCZDI-26-524: (0Day) PAX Technology Q80 XCB Daemon Missing Authenticatio…
This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1.

Microsoft-Core Infrastructure

08/03TOCCheck This Out! (CTO!) Guide (August 2026)

Member: TysonPaul | Microsoft Community Hub

Enhanced host pool management for Azure Virtual Desktop is now generally available

Team Blog: Azure Virtual Desktop

Author: NeoCai

Published: 07/09/2026

Summary: Azure Virtual Desktop has introduced enhanced host pool management, now generally available, featuring session host configuration and update, dynamic autoscale, and ephemeral OS disks. These improvements streamline management, reduce operational overhead, and support secure, reliable, and scalable virtual environments. Session host configuration enables centralized settings and easy updates, ephemeral OS disks improve performance and rapid refresh for stateless workloads, and dynamic autoscale optimizes resource allocation and cost efficiency based on demand. Administrators can easily configure these features through the Azure portal for more efficient and consistent host pool management.

Embedded Image

How SCBX built AI literacy at scale and made AI part of daily work

Team Blog: Microsoft Learn

Author: ToddMinor

Published: 07/30/2026

Summary: SCBX partnered with Trainocate and Microsoft to boost AI literacy and embed AI in daily work across thousands of employees. Through a phased, role-based training approach—combining foundational learning, practical application, and advanced technical tracks—SCBX ensured adoption at scale while maintaining governance standards. Over 15,000 participants engaged, with measurable gains in productivity and satisfaction as teams automated repetitive tasks and applied AI in their roles. SCBX’s experience highlights the value of structured, outcome-focused skilling to drive AI readiness and business transformation across a regulated enterprise.

Embedded Image

New Microsoft 365 Certified: AI Services Administrator Associate Certification

Team Blog: Microsoft Learn

Author: LibertyMunson

Published: 07/28/2026

Summary: Microsoft has launched the Microsoft 365 Certified: AI Services Administrator Associate certification, validating skills to configure, manage, secure, and optimize Microsoft 365 and AI services like Copilot at enterprise scale. Candidates must pass Exam AB-650 (beta), which is discounted 80% for the first 300 test-takers before August 18, 2026, using code AB-650SkyClub. The certification is designed for experienced Microsoft 365 administrators with knowledge of Entra ID, Defender XDR, and Microsoft Graph PowerShell. Preparation resources and exam details are available online, with general availability expected in October 2026.

Embedded Image

Hunting Local AI Tools on macOS with Microsoft Defender for Endpoint

Team Blog: Core Infrastructure and Security

Author: Vytas_Boyev

Published: 07/14/2026

Summary: The article discusses emerging security challenges as developers increasingly run AI tools locally on macOS, expanding the attack surface for organizations. It outlines how Microsoft Defender for Endpoint (MDE) can detect and inventory local AI agents, such as Ollama and OpenClaw, using advanced KQL queries for process, file, and network telemetry. Recommendations include establishing a baseline inventory, monitoring new AI tool usage, skill file changes, suspicious behaviors, and external network connections. The article emphasizes a layered, tuned detection strategy, practical limitations, and the importance of visibility over default blocking to manage AI risks effectively.

Embedded Image

Azure Database Security Newsletter – July 2026

Team Blog: Core Infrastructure and Security

Author: PieterVanhove

Published: 07/07/2026

Summary: **Summary:** The July 2026 Azure Database Security Newsletter highlights the evolving impact of AI agents on database security, emphasizing identity-first access, least privilege, data-aware protection, and continuous monitoring. Key updates include support for AES keys in Transparent Data Encryption, Microsoft Entra server principals for Azure SQL Database, cross-tenant key management for PostgreSQL, and Defender security posture assessments. Best practices urge secure-by-default configurations, data classification, and ongoing vulnerability assessments. The newsletter also features recent blogs, events, and calls to review agent access as AI-driven workloads increase, stressing proactive database security adaptation.

Embedded Image

Agent governance is organizational readiness

Team Blog: FastTrack

Author: AuzinAhmadi

Published: 07/30/2026

Summary: The article emphasizes that effective agent governance is essential for scaling AI in healthcare organizations. It argues that success depends less on technology and more on readiness—specifically, whether governance structures ensure agents fit clinical workflows, assign clear accountability, manage risk, and secure stakeholder trust. A governance triad (IT, Legal, Business) is needed to vet, approve, and monitor agents before deployment. A checklist ensures readiness by confirming ownership, data access, measurable outcomes, and shutdown conditions. Ultimately, strong governance—not just technical capability—determines whether AI agents are safely and successfully integrated into healthcare operations.

Embedded Image

Understanding Copilot Risk: Mapping Exposure Across Zero Trust Pillars

Team Blog: FastTrack

Author: AuzinAhmadi

Published: 07/06/2026

Summary: The article examines Microsoft 365 Copilot’s impact on organizational data security, highlighting how Copilot accelerates data discovery based on existing user permissions. It maps Copilot-related risks across four Zero Trust pillars—identity, endpoints, apps, and data—emphasizing the importance of access governance, permission hygiene, and data protection. Copilot doesn’t grant new access but amplifies the exposure of overshared or poorly governed content. Organizations should assess who can access Copilot and what data it surfaces, using Zero Trust strategies to identify and mitigate risks before scaling deployments.

Embedded Image

Azure Arc Server June Forum

Team Blog: Azure Arc

Author: Aurnov_Chattopadhyay

Published: 07/29/2026

Summary: The June 2026 Azure Arc Server Forum covered updates on Arc Server AI Agent integration, new multicloud connectors for GCP and EKS clusters, and ESU timelines for Windows Server 2016 and SQL Server 2016. Attendees received guidance on enrollment and licensing, and were informed about upcoming end-of-support dates. The forum will pause for July and August, resuming in September. Leadership of the community calls is transitioning to Mason Torres, Yunis Hussein, and Meagan McCrory. Registration and agent release notes are available online.

Embedded Image

Plan for Upcoming Changes to Extended Security Updates on Azure Local

Team Blog: Azure Arc

Author: sydbruck

Published: 07/09/2026

Summary: Starting April 1, 2026, Microsoft will implement a uniform pricing model for Extended Security Updates (ESU) for SQL Server and Windows products, regardless of deployment location or purchasing channel. This affects new ESU offerings, such as Windows 10 Enterprise LTSB 2016 and Windows Server 2016, but not existing ESUs. Customers are encouraged to upgrade to newer versions before end of support; further ESU pricing and availability details will be announced. Existing ESUs remain free on Azure Local via Azure Verification for VMs.

Embedded Image

Beyond the Canvas: The Azure Architecture Diagram Builder Becomes Agent-Ready

Team Blog: Azure Architecture

Author: arturoqu

Published: 07/10/2026

Summary: The Azure Architecture Diagram Builder has evolved from a click-based app to an agent-ready platform. Key updates include Architecture Chat for iterative, conversational design, Blueprint Diagrams for whiteboard-style visuals, and support for 14 AI models. The tool now operates as a Model Context Protocol (MCP) server, enabling agents to generate, validate, estimate costs, and render Azure architectures programmatically. Enhancements include deployment guides grounded in Microsoft Learn, cost badges, theme options, and metadata panels. The platform remains open-source, offering evidence-based model comparison and integration for both human users and AI agents.

Embedded Image

Skill or Sub-Agent. Choosing AI Capabilities You Will Actually Reuse

Team Blog: Azure Architecture

Author: KishoreKumarPattabiraman

Published: 07/30/2026

Summary: The article advises cloud architects and engineering leaders to prioritize choosing the right AI capability shape—skill or sub-agent—over model selection. Skills are iterative, voice-driven, and require ongoing human involvement, ideal for craft and subjective tasks. Sub-agents handle structured, repeatable work with one-off outputs and minimal human gating. The recommended approach is to match the capability to the work’s nature, sometimes combining both, to maximize reuse and effectiveness. Teams should assess iteration, output, blast radius, and frequency before building, avoiding the mistake of forcing all tasks into a single delivery shape.

Embedded Image

Introducing Kubernetes-Native Policy Validation with CEL and VAP in Azure Policy

Team Blog: Azure Governance and Management

Author: stevenbucher

Published: 07/23/2026

Summary: Azure Policy for Kubernetes now supports Kubernetes-native policy validation using Common Expression Language (CEL) and Validating Admission Policy (VAP) with Gatekeeper integration. This enables faster, in-process policy enforcement directly in the Kubernetes API server, improving reliability and latency over previous OPA Rego-based webhook methods. Users write CEL constraint templates, package them as Azure Policy definitions, and deploy them for governance, audit, and enforcement. This approach enhances compliance tracking and centralized management for AKS clusters running Kubernetes v1.30+, combining native validation logic with Azure Policy’s robust governance capabilities.

Embedded Image

Introducing Compliance Substate for Azure Policy Exemptions!

Team Blog: Azure Governance and Management

Author: stevenbucher

Published: 07/28/2026

Summary: Azure Policy now introduces a compliance substate for exempted resources, revealing their underlying compliance status even when exemptions are applied. Previously, exemptions hid whether a resource was compliant or not, making audits difficult. Now, resources show “Exempt” plus a substate (“Compliant” or “Non-compliant”), enabling easier exemption management and cleanup. The compliance substate can be viewed in the Azure Policy blade, added as a column, and queried across subscriptions using Azure Resource Graph, improving governance visibility and confidence in policy enforcement.

Embedded Image

Reservation exchanges for Azure services covered by savings plans end starting Feb. 1, 2027

Team Blog: FinOps

Author: kyleikeda

Published: 07/30/2026

Summary: Starting February 1, 2027, Azure reservation exchanges will no longer be available for services covered by savings plans, aligning policies for greater clarity. Impacted services include several compute and database offerings. Existing reservations purchased before this date retain one final exchange right. Reservations remain available for stable workloads, while savings plans offer flexibility for dynamic needs. Instance size flexibility and cancellation policies are unchanged. Customers should review their reservation portfolios and consider savings plans for future flexibility. Policy details may evolve as savings plan coverage expands.

Embedded Image

Introducing Cost Management and Pricing Toolsets in Azure Resource Manager MCP Server

Team Blog: FinOps

Author: demiajayi

Published: 07/29/2026

Summary: Microsoft has integrated Cost Management and Pricing toolsets into Azure Resource Manager MCP, allowing AI agents to access and analyze Azure cost, pricing, budget, and optimization data directly within cloud workflows. This enables users to estimate costs before deployment, track and explain spending, manage budgets, identify savings, and analyze AKS workloads without switching tools. The release provides APIs for querying costs, managing budgets, reviewing savings opportunities, and retrieving pricing details, making cloud operations more cost-aware and efficient. Installation requires VS Code, an Azure account, and specific configuration steps. Future enhancements and feedback opportunities are planned.

Embedded Image

From hours to minutes: Rethinking Microsoft Intune compliance reporting with the Export API

Team Blog: Intune Customer Success

Author: Intune_Support_Team

Published: 07/24/2026

Summary: The article explains how Microsoft Intune’s Export API dramatically improves compliance reporting for large device fleets. By replacing thousands of per-device Graph API calls with a single bulk export, reporting jobs drop from ~100,000 calls and 2.5 hours runtime to ~15 calls and 15 minutes. The Export API delivers identical data in one file, simplifying maintenance, reducing failure points, and enabling scalability without downstream changes. It’s ideal for scheduled, bulk reports, while traditional endpoints remain best for real-time, single-device queries. Overall, the Export API offers faster, more reliable, and scalable compliance reporting.

Embedded Image

Build a patch strategy for today’s threat pace with Microsoft

Team Blog: Intune Customer Success

Author: Intune_Support_Team

Published: 07/09/2026

Summary: Microsoft outlines a modern patch strategy to address today’s fast-paced threat landscape, leveraging AI and integrated tools like Intune and Microsoft Defender. The approach focuses on three stages: automating updates for quick mitigation, prioritizing remediation based on risk and exposure, and enforcing compliance to contain unpatched vulnerabilities. Intune centralizes management for Windows, Apple, and Android devices, supporting automated updates, risk assessment dashboards, and compliance controls. This operational discipline helps organizations reduce risk, accelerate response times, and maintain secure, up-to-date endpoints across diverse device fleets. Licensing requirements for advanced features vary by Microsoft 365 subscription.

Embedded Image

Azure Elastic SAN: Pooled, Cloud-Native Block Storage That Actually Acts Like a SAN

Team Blog: ITOps Talk

Author: Pierre_Roman

Published: 07/17/2026

Summary: Azure Elastic SAN is Azure’s fully managed, cloud-native SAN storage, offering pooled block storage accessible via iSCSI. It enables IT pros to provision combined capacity and performance, dynamically sharing resources across multiple workloads, reducing over-provisioning and costs. Supporting up to petabyte-scale, millions of IOPS, and high throughput, Elastic SAN integrates with Azure VMs, Kubernetes, VMware, and container storage. It provides familiar SAN resource hierarchy, network isolation, encryption, snapshots, and cost-effective scaling. Best suited for consolidating many IO-intensive workloads, Elastic SAN delivers significant TCO savings and simplifies migration from on-prem SANs.

Embedded Image

Premium SSD v2 and Instant Access Snapshots: A Better, Faster, Cheaper Disk for Your Azure VMs

Team Blog: ITOps Talk

Author: Pierre_Roman

Published: 07/20/2026

Summary: Premium SSD v2 (PV2) for Azure VMs offers significant improvements over Premium SSD v1, delivering up to 4x more IOPS, 2x more throughput, and 42% lower costs. Key features include independent scaling of capacity, IOPS, and throughput, sub-millisecond latency, and live resizing without VM downtime. Instant Access Snapshots enable near-instant restores and faster, lower-latency hydration. PV2 is ideal for I/O-intensive workloads like SQL, SAP, and analytics, and supports efficient scaling, rapid recovery, and cost optimization. However, it cannot be used as an OS disk or with host caching.

Embedded Image

Microsoft Discovery: Where HPC meets agentic AI for the next era of EDA

Team Blog: Azure High Performance Computing (HPC)

Author: richpaw

Published: 07/21/2026

Summary: Microsoft Discovery is an enterprise agentic AI platform designed to enhance electronic design automation (EDA) by combining high-performance computing (HPC) with intelligent orchestration. Built on Azure, it coordinates specialized AI agents to reason, plan, execute, and learn across complex engineering workflows, optimizing tasks such as simulation, analysis, and documentation. Discovery integrates seamlessly with Azure HPC, storage, and automation tools, enabling hybrid workflows and improving engineering productivity. Its human-in-the-loop approach ensures transparency and validation through established EDA practices, allowing engineers to focus on creative problem-solving while repetitive tasks are automated.

Embedded Image

Connecting Microsoft Discovery App to Azure HPC with Azure NetApp Files and CycleCloud

Team Blog: Azure High Performance Computing (HPC)

Author: richpaw

Published: 07/21/2026

Summary: The article outlines how to integrate Microsoft Discovery, an AI platform for R&D, with traditional Azure HPC environments using Azure NetApp Files and CycleCloud. By running Discovery on a Windows VM within the Azure network, mapping shared storage, and utilizing SSH for job submission, users can bridge AI-native and HPC workflows. This enables Discovery agents to manage files, submit jobs, and interact securely with HPC clusters, leveraging AI to automate and enhance engineering workloads without disrupting existing processes, while maintaining security, performance, and operational best practices.

Embedded Image

Move a live GitLab project between groups without breaking Terraform state or CI/CD

Team Blog: Azure Infrastructure

Author: HimanshuYadav

Published: 07/31/2026

Summary: Moving a live GitLab project between groups can disrupt Terraform state, CI/CD variables, runners, and cloud authentication if paths are hardcoded or inherited resources aren’t handled. The project ID remains unchanged, but group-level variables and runners must be recreated or reconfigured. Key the Terraform backend to the project ID, not the project path, and update any cloud credentials mapped to the old namespace. Thorough inventory, backups, and a freeze window ensure a safe transfer and rollback. Validate everything post-move to avoid drift or broken pipelines. Proper preparation and verification prevent common pitfalls.

Embedded Image

Azure Cobalt: Workload-Aware Power Management for More Efficient Datacenters

Team Blog: Azure Infrastructure

Author: redsa

Published: 07/16/2026

Summary: Microsoft’s Azure Cobalt CPUs introduce industry-first, per-VM power monitoring and capping, achieved through hardware/software co-design. This enables fine-grained, workload-aware power management, selectively throttling non-critical VMs while preserving performance for priority workloads. The approach allows up to 20% more power oversubscription and 24% higher performance compared to software-only capping, supporting more efficient datacenter operations and sustainability. End-to-end integration across Azure infrastructure enables optimized VM placement and real-time telemetry, demonstrating the benefits of deep hardware/software collaboration for balancing performance, efficiency, and sustainability in cloud environments.

Embedded Image

Microsoft is headed to VMware Explore 2026 in Las Vegas

Team Blog: Azure Migration and Modernization

Author: KirstenMegahan

Published: 07/28/2026

Summary: Microsoft will participate in VMware Explore 2026 in Las Vegas, offering breakout sessions and expert roundtables focused on Azure and its partnership with VMware by Broadcom. Attendees can learn about streamlined migration of VMware workloads to Azure, maximizing on-premises investments, and leveraging AI innovation. Sessions will cover migration best practices, security, and unlocking data and AI capabilities, along with enticing migration offers. The event aims to help businesses gain a competitive edge by transitioning from on-premises to Azure.

Embedded Image

Azure Front Door edge actions: programmable compute for a secure, resilient, AI-ready edge

Team Blog: Azure Networking

Author: AbhishekTiwari

Published: 07/30/2026

Summary: Azure Front Door edge actions introduces programmable compute at Microsoft’s global edge, enabling customer-defined logic for secure, low-latency web experiences. Its architecture prioritizes hyperscale performance, strong security, tenant isolation, and resiliency using Hyperlight micro-VMs for hardware-backed isolation. Edge actions maintains local execution to minimize latency, employs fast-fail and circuit-breakers for stability, and continuously validates resiliency through Game Days. Designed for current and future intelligent workloads, it ensures programmability without compromising Azure Front Door’s reliability, security, or performance, making edge programmability a foundational capability for modern applications.

Embedded Image

Scale limits in network security perimeter

Team Blog: Azure Networking

Author: shashankamalladi

Published: 07/31/2026

Summary: The article outlines updated hard limits for network security perimeters in PaaS deployments, including 1,000 perimeters per subscription, 200 profiles per perimeter, 200 rule elements per profile, and 2,500 associated PaaS resources. Rule elements per profile are now capped at 200 for new customers. Existing customers exceeding 200 can edit or reduce rules until October 31, 2026; after that, only reductions are allowed. These changes aim to enforce consistent security scalability and operational boundaries.

Embedded Image

Secure Native Access to Azure Kubernetes Service (AKS) Private Clusters with Azure Bastion

Team Blog: Azure Network Security

Author: saikishor

Published: 07/09/2026

Summary: The article explains how Azure Bastion’s native client tunneling (now in public preview) enables secure, simplified access to private Azure Kubernetes Service (AKS) clusters without needing VPNs or jump hosts. Bastion establishes an encrypted tunnel from engineers’ local machines to the private AKS API server, maintaining strong network isolation. It supports modern authentication methods, including Microsoft Entra ID and Azure RBAC, for centralized, auditable access control. This approach streamlines cluster management while enhancing security by removing public endpoints and reducing exposure to credential theft or infrastructure compromise.

Embedded Image

Optimize Oracle workloads on Azure with Azure NetApp Files

Team Blog: Azure Storage

Author: GeertVanTeylingen

Published: 07/09/2026

Summary: The article details recent advancements in Azure NetApp Files that optimize Oracle workloads on Azure, focusing on predictable performance, flexible scaling, and enhanced data protection. Key features include flexible service level capacity pools, automated application volume group deployment, availability zone-aware volume placement, integrated migration tools, space-efficient short-term clones, cool access tiering, and rapid backup and test/dev refreshes. These improvements enable easier Oracle environment sizing, deployment, protection, and scaling, reducing costs and complexity while supporting business continuity and modernization of Oracle workloads in the Azure cloud.

Embedded Image

Terraform AzureRM provider 5.0 now generally available

Team Blog: Azure Tools

Author: stevenjma

Published: 07/29/2026

Summary: Terraform AzureRM Provider 5.0 is now generally available, offering major improvements for managing Azure infrastructure as code. Key updates include greater control over Azure Resource Provider registration, optional Azure preflight validation to catch issues earlier, and removal of deprecated resources and properties. Users are advised to carefully review their configurations before upgrading due to breaking changes. The release aims to provide clearer provider behavior, faster feedback during workflows, and a cleaner foundation for future Azure features. Detailed migration guidance and changelog are available to assist with upgrading.

Embedded Image

Microsoft-Defender Cloud

08/03TOCMicrosoft Defender for Cloud Customer Newsletter

*This will be the last monthly MDC newsletter. To keep up with the latest, please visit: What’s new in MDC

What’s new in Defender for Cloud?

Multiple container security features are now Generally Available: Container-level misconfiguration recommendations for Kubernetes, Upgrade AKS version recommendations, VA for runtime-discovered container images on EKS and GKE, Kubernetes notes VA for EKS and GKE, scanning support for Docker hardened container images. For more information, see this page here. 

Database-level recommendations for SQL VA now GA

The SQL vulnerability assessment recommendations created as part of the transition from grouped to individual recommendations are now generally available. Each SQL vulnerability assessment rule is surfaced as its own recommendation, reported directly on the affected SQL database resource. 

For more details, please refer to this documentation . 

Blogs of the month

In July, our team published the following blog posts we would like to share:

1. Built to Protect: The Architecture Behind Codename MDASH

Customer journey

Discover how other organizations successfully use Microsoft Defender for Cloud to protect their cloud workloads. This month we are featuring NTT Data. NTT Data, a top global IT services provider, leverages Azure, OpenAI and Microsoft Defender to launch their AI agents, adopting secure by design principles, to help enhance, competitiveness organization change and data usage. Defender for AI, and Defender CSPM, as part of the Defender family, address the emerging risks and threats like prompt injection and data poisoning that come with generative AI.

Join our community!

We offer several customer connection programs within our private communities. By signing up, you can help us shape our products through activities such as reviewing product roadmaps, participating in co-design, previewing features, and staying up-to-date with announcements. Sign up at aka.ms/JoinCCP.

We greatly value your input on the types of content that enhance your understanding of our security products. Your insights are crucial in guiding the development of our future public content. We aim to deliver material that not only educates but also resonates with your daily security challenges. Whether it’s through in-depth live webinars, real-world case studies, comprehensive best practice guides through blogs, or the latest product updates, we want to ensure our content meets your needs. Please submit your feedback on which of these formats do you find most beneficial and are there any specific topics you’re interested in https://aka.ms/PublicContentFeedback.

Note: If you want to stay current with Defender for Cloud and receive updates in your inbox, please consider subscribing to our monthly newsletter: https://aka.ms/MDCNewsSubscribe

Veeam

08/04TOCRelease Information for Veeam Recovery Orchestrator 13 and Updates
Release information for Veeam Recovery Orchestrator 13, including release notes, build history, and download links for each released build and update.
08/04TOCStandalone Veeam Agent for Unix Fails to Connect to Veeam Backup Serve…
A standalone Veeam Agent for IBM AIX or Veeam Agent for Oracle Solaris cannot connect to its Veeam Backup Server and reports a self-signed certificate error after the backup server’s SSL certificate has been changed twice since the agent last connected. This article explains why the agent no longer trusts the certificate and provides the steps to delete and recreate the connection.
08/03TOCVulnerabilities Resolved in Veeam Service Provider Console 9.3
Veeam has resolved four security vulnerabilities in Veeam Service Provider Console, two rated Critical and two rated High, all affecting version 9.2 and earlier. This article documents each CVE with its severity, CVSS v4.0 score, and the build in which it was fixed.
08/03TOCVeeam Backup for Salesforce Backend Service Fails to Start After Upgra…
After Veeam Backup for Salesforce is upgraded from version 2.1.1 or earlier to version 3.2.1 or later, the vbsf-backend service fails to start because the server continues to use OpenJDK 11 rather than the required OpenJDK 21. This article explains how to check which Java version is active and how to make OpenJDK 21 the active version so that the backend service starts.
08/03TOCList of Security Fixes and Improvements in Veeam Service Provider Cons…
This article describes all security-related fixes and improvements introduced in each release or update of Veeam Service Provider Console.
08/03TOCList of Security Fixes and Improvements in Veeam ONE
This article describes all security-related fixes and improvements introduced in each release or update of Veeam ONE.



Content on this page is collected from remote sources by IPWorX but is not created by IPWorX. The contents belong to the creators and should be considered theirs for all legal purposes, we have no editorial control or responsibility over them. IPWorX does not represent or endorse the accuracy or reliability of any opinion, statement, or other information provided by any third party.

This page contains links to third-party websites. These links are provided solely for your convenience. IPWorX does not control, maintain, or endorse the content, accuracy, or reliability of any third-party resources, and you access them at your own risk.

Scripts and tools to help manage your network found, managed and
happily shared with documentation on usage at the IP WORk eXchange.
https://www.IPWorX.com

Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303
CVE-2026-20304
CVE-2026-20310
CVE-2026-20312
CVE-2026-20313
Critical 9.9
Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267
CVE-2026-20268
CVE-2026-20269
CVE-2026-20270
CVE-2026-20271
CVE-2026-20272
CVE-2026-20273
Critical 9.8
Cisco Integrated Management Controller Argument Injection Vulnerabilities CVE-2026-20200
CVE-2026-20288
High 8.8
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability CVE-2026-20301 High 8.6
Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability CVE-2026-20263 High 8.6
Cisco IOS XE Software SNMP Denial of Service Vulnerability CVE-2026-20124 High 7.7
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability CVE-2026-20294 Medium 6.5
Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability CVE-2026-20311 Medium 6.3
Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability CVE-2026-20289 Medium 5.7
Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability CVE-2026-20028 Medium 5.0
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability CVE-2026-20198 Medium 4.8
About
Buy Me A CoffeeStore

Copyright © 2026 IPWorX.com. All rights reserved.

Static port by NoPress