Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 07:59 12/08/2026 UTC
Last updated: 16:08 11/08/2026 UTC

Latest updates

Browse →

SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 patch release

Security Patch Release

Updated: 12.08.2026 10:31 · First: 12.08.2026 10:31 · 📰 1 src / 1 articles · H score: 37

SAP released patches for Commerce Cloud (Data Hub Adapter) to fix CVE-2026-58231, a CVSS 10.0 flaw that could let an unauthenticated attacker reach arbitrary code execution. The issue stems from insufficient authorization checks and input validation failures in vulnerable functions. Onapsis urged customers to move to a fixed Commerce Cloud release and re-deploy the updated version. A temporary IP Filter Set workaround can restrict access to the vulnerable endpoint until patching is complete.

Microsoft security patch release for CVE-2026-62832

Security Patch Release

Updated: 12.08.2026 09:41 · First: 12.08.2026 09:41 · 📰 2 src / 2 articles · H score: 5

Microsoft shipped patches for 421 security flaws, including 236 flaws in Windows, as part of a broad update that also remediates multiple named CVEs. The release covers CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. CVE-2026-68820 is marked actively exploited and was added to CISA KEV, with federal agencies required to apply the fix by August 25, 2026.

CISA adds CVE-2026-68820 to KEV catalog

Public Sector Action

Updated: 12.08.2026 09:41 · First: 12.08.2026 09:41 · 📰 1 src / 1 articles · H score: 3

CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply fixes by August 25, 2026. The action formalizes the vulnerability as an official remediation priority and sets a concrete compliance deadline. It affects federal defenders responsible for Windows patching and vulnerability response.

Google Chrome expands Android notification anti-abuse controls with automatic permission revocation and rate limiting

Security Tool/Service

Updated: 12.08.2026 04:15 · First: 12.08.2026 04:15 · 📰 1 src / 1 articles · H score: 14

Google Chrome expanded its anti-abuse systems for Android notifications, reducing unwanted notification volume by more than 7 billion per day in Q1 2026. The controls now include automatic notification permission revocation for stale or suspicious sites and rate limiting for disruptive senders, cutting off deceptive notification traffic before it reaches users. The changes also target abuse tied to scams, malware, phishing attempts, and fraudulent payment requests.

Microsoft security patch release for CVE-2026-68820

Security Patch Release

Updated: 12.08.2026 00:28 · First: 12.08.2026 00:28 · 📰 2 src / 2 articles · H score: 35

Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing 398 vulnerabilities and an actively exploited zero-day. The bundle includes CVE-2026-68820, a privilege-escalation flaw in afd.sys that can help an attacker move from a low-privilege foothold to broader control. Microsoft also flagged CVE-2026-62832 as likely to be exploited, while CVE-2026-72971 was publicly disclosed but assessed as lower impact.

Cisco Secure Firewall ASA and FTD active DoS exploitation denial-of-service flaw (CVE-2026-20349)

Vulnerability

Updated: 11.08.2026 22:45 · First: 11.08.2026 22:45 · 📰 2 src / 2 articles · H score: 31

CVE-2026-20349 is being actively exploited against Cisco Secure Firewall ASA and FTD software, enabling crafted HTTP requests to trigger a remote denial of service on devices with certain remote access services enabled. Cisco has released hot fixes for affected releases and says there is no workaround other than upgrading to a fixed version.

Zoom annotation tool flaws (multiple vulnerabilities)

Vulnerability

Updated: 11.08.2026 22:08 · First: 11.08.2026 22:08 · 📰 1 src / 1 articles · H score: 24

Zoom's annotation tool flaws could let one meeting participant compromise another attendee's client across supported Zoom Workplace, Zoom Workplace VDI Client for Windows, Zoom Rooms, and Zoom Meeting SDK builds. The issues are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, covering a buffer over-write, a buffer over-read, and a use-after-free condition. Fixes shipped in June and July 2026 before the public disclosure, and the company says no exploitation has been reported. The affected flows rely on annotation messages in shared-screen meetings, where the receiver trusts the sender enough to rebuild the object in full.

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign

Updated: 11.08.2026 21:36 · First: 11.08.2026 21:36 · 📰 2 src / 2 articles · H score: 32

CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine since at least May 2026. The operation moves targets from job sites to Telegram and Zoom interviews, then pushes a poisoned WireGuard-based client and SourceForge lures tied to SopraVPN and Sopra Steria lookalikes. The malicious client can decrypt and run embedded PowerShell on Windows and fetch another executable through the VPN on Linux, creating a path to malware installation and unauthorized access.

Poisoned WireGuard-derived VPN client used to run commands on victim hosts

Malware Activity

Updated: 11.08.2026 21:36 · First: 11.08.2026 21:36 · 📰 1 src / 1 articles · H score: 20

A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct malware delivery. The modified client is distributed as SopraVPN through fake SourceForge projects and a bogus website. Its configuration handling adds a non-standard SymmetricKey option that decrypts embedded PowerShell before execution. The Windows build can create a scheduled task, while the Linux build uses cURL to fetch a secondary executable.

Delta Air Lines Flight 591 in-flight Wi-Fi disruption

Service Disruption

Updated: 11.08.2026 21:34 · First: 11.08.2026 21:34 · 📰 1 src / 1 articles · H score: 3

Delta Air Lines Flight 591 lost onboard Wi-Fi for nearly 30 minutes after an unauthorized wireless network appeared during the flight from Las Vegas to Atlanta, interrupting passenger connectivity. Delta said the issue did not affect safety or aircraft operating systems. The carrier is investigating the event with federal law enforcement and aviation regulators.

Windows 10 KB5120249 cumulative update (August 2026 Patch Tuesday)

Security Patch Release

Updated: 11.08.2026 21:26 · First: 11.08.2026 21:26 · 📰 1 src / 1 articles · H score: 26

Microsoft released Windows 10 KB5120249 for versions 22H2 and 21H2, making it a mandatory Patch Tuesday update for supported systems. The release fixes security vulnerabilities and bugs and also addresses a File History backup failure on SMB network shares. It additionally expands rollout of new Secure Boot certificates and moves systems to OS Builds 19045.7663 and 19044.7663 after installation.

Microsoft August 2026 Patch Tuesday security updates (3 zero-days)

Security Patch Release

Updated: 11.08.2026 21:08 · First: 11.08.2026 21:08 · 📰 2 src / 2 articles · H score: 56

Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in afd.sys that is under active exploitation and can let a local attacker escalate to SYSTEM. The release also includes four unauthenticated 9.8 RCEs in Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack, which need no account, password, or click from the victim. It also closes the August half of a SharePoint RCE chain that follows the July fix for CVE-2026-55040. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign.

Windows Ancillary Function Driver for WinSock zero-day privilege escalation (CVE-2026-68820)

Vulnerability

Updated: 11.08.2026 21:08 · First: 11.08.2026 21:08 · 📰 1 src / 1 articles · H score: 29

CVE-2026-68820 in Windows Ancillary Function Driver for WinSock (AFD.sys) was patched after active exploitation in zero-day attacks, leaving affected Windows systems exposed to SYSTEM privilege escalation. Microsoft said a locally authenticated attacker could run a specially crafted application to trigger a race condition and elevate privileges. The flaw was used in intrusions to deploy FudModule, making it a high-risk local escalation issue for Windows administrators.

Adobe security patch release for CVE-2026-71398

Security Patch Release

Updated: 11.08.2026 19:50 · First: 11.08.2026 19:50 · 📰 1 src / 1 articles · H score: 37

Adobe released a priority 1 update for Campaign Classic on Tuesday. The patch fixes three critical flaws that could enable arbitrary code execution, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. Adobe told users to apply the update immediately.

Adobe security patch release for CVE-2026-48362

Security Patch Release

Updated: 11.08.2026 19:50 · First: 11.08.2026 19:50 · 📰 1 src / 1 articles · H score: 37

Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application DoS. The release names CVE-2026-48362, CVE-2026-48273, and CVE-2026-71384 among the critical issues. Adobe says it is not aware of exploits in the wild and tells users to apply the patches immediately.

SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability

Updated: 11.08.2026 19:47 · First: 11.08.2026 19:47 · 📰 1 src / 1 articles · H score: 37

CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an administrator, on affected on-premises systems. Researchers also chained it to CVE-2026-63520 to reach code execution without credentials. SharePoint Server Subscription Edition, 2019, and 2016 are affected, while SharePoint Online is not listed, and the July update is said to break the chain.

Wesco CRM data leak claimed by ExfilSquad

Data Leak

Updated: 11.08.2026 18:59 · First: 11.08.2026 18:59 · 📰 1 src / 1 articles · H score: 50

ExfilSquad claimed it stole and leaked Wesco CRM data, putting customer and employee records and related account information at risk of public exposure. Wesco said it is investigating the cloud CRM environment involved and reported no business disruption. The claim centers on 2.6 million records and a leak-site publication that could expose sensitive business and identity data.

NullReceiver trojanized npm packages C2 via Ethereum recipient address

Malware Activity

Updated: 05.08.2026 16:41 · First: 05.08.2026 16:41 · 📰 2 src / 2 articles · H score: 3

NullReceiver is a malware activity that hides C2 infrastructure inside Ethereum recipient addresses, letting trojanized npm packages decode a server location from a blockchain transfer instead of using a smart contract or calldata. In the broader activity, bianira-ui and fluid-type-ui were published on July 28, 2026 and later removed from npm after limited downloads, while researchers tied the technique to the DPRK-linked Contagious Interview campaign associated with the Lazarus group. New reporting adds six npm packages identified by Sonatype Research Labs on August 10, all carrying the same payload and tracked as sonatype-2026-005899 and sonatype-2026-005901. Sonatype said the loader queried an attacker-controlled Ethereum wallet to recover C2 addresses, and the six packages split between three hijacked publishing accounts and three purpose-built packages.

Cursor command-line coding agent pre-trust command execution security flaw

Vulnerability

Updated: 11.08.2026 17:30 · First: 11.08.2026 17:30 · 📰 1 src / 1 articles · H score: 26

A Cursor vulnerability in the command-line coding agent lets a cloned repository run arbitrary commands before trust verification, creating sandbox-bypassing code-execution risk for developers. Cursor shipped a fix on July 23 after a July 20 report, but the submission was later closed as informative and no advisory was published. The flaw was found in the isolated worktree feature, and affected users should move to build 2026.07.23-e383d2b or later.

Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)

Vulnerability

Updated: 11.08.2026 15:05 · First: 11.08.2026 15:05 · 📰 1 src / 1 articles · H score: 10

CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code execution. Researchers found the capability enabled on 9 of 26 devices and demonstrated takeover on a commercial Autel EV charger. The affected surface includes Quectel EC25/EG25/RM52xN modules and some phones that accepted RUN AT. No attacks have been reported, and vendors are relying on mitigation and hardened defaults rather than a single universal patch.

Mozilla revokes and replaces Firefox and Thunderbird Linux signing key after private repo exposure

Security Tool/Service

Updated: 11.08.2026 15:04 · First: 11.08.2026 15:04 · 📰 2 src / 2 articles · H score: 11

Mozilla revoked and replaced the Firefox and Thunderbird Linux signing key, disrupting verification of older signed downloads and some RPM package installs until the new key is installed. The change matters because the retired key is used to confirm Linux tarballs came from Mozilla and were not tampered with. Users who verify signatures manually, and some Linux distribution package flows, must switch to the replacement key to restore trust checks.

Mozilla Firefox and Thunderbird Linux signing key remediation

Advisory/Mitigation

Updated: 11.08.2026 15:04 · First: 11.08.2026 15:04 · 📰 1 src / 1 articles · H score: 18

Mozilla's Firefox and Thunderbird Linux signing key revocation leaves some Linux verification and RPM updates dependent on importing the new key and removing trust in the old one. Users who verify signatures manually or install from Mozilla RPM packages may need manual remediation to restore successful verification and updates.

Suisan City hit by ransomware attack

Incident

Updated: 11.08.2026 15:00 · First: 11.08.2026 15:00 · 📰 1 src / 1 articles · H score: 25

Suisan City in California is still dealing with an ongoing cyber incident that disrupted 911 call routing, police and fire dispatch, and municipal services. The city declared a state of emergency after malicious software infected its IT network at about 5:45 am on August 7. Officials shut down the entire IT network to contain the threat and preserve evidence for a federal investigation, leaving online services and internal operations temporarily unavailable. The incident is being treated as possibly ransomware-related, but no attacker or malware family has been officially confirmed.

Repeated cyber-attacks on US local authorities in recent weeks

Trend

Updated: 11.08.2026 15:00 · First: 11.08.2026 15:00 · 📰 1 src / 1 articles · H score: 26

Several US local authorities have faced cyber-attacks in recent weeks, signaling a recurring threat pattern against municipal and county governments. The pattern raises the likelihood of service disruptions and ransomware-related incidents across local government networks. Resource-constrained public-sector IT teams remain especially exposed when attacks cluster across multiple jurisdictions.

ClamAV ZIP archive parser DoS flaws (multiple vulnerabilities)

Vulnerability

Updated: 11.08.2026 14:03 · First: 11.08.2026 14:03 · 📰 1 src / 1 articles · H score: 32

Cisco disclosed CVE-2026-20337 and CVE-2026-20338 in the ClamAV ZIP archive parser used by Secure Endpoint Connector. A crafted zip file can crash the scanning process and trigger a denial-of-service condition on affected systems. Cisco says public PoC exploit code is already available, but it has no evidence of in-the-wild exploitation. The flaws affect ClamAV 1.5.0 through 1.5.3 and are most serious on Windows because scanning runs in a privileged security context.

Cisco security patch release for CVE-2026-20337

Security Patch Release

Updated: 11.08.2026 14:03 · First: 11.08.2026 14:03 · 📰 1 src / 1 articles · H score: 30

Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. The update closes ZIP archive parser flaws that can let an unauthenticated attacker crash the scanning process by submitting a crafted zip file. Cisco said Secure Endpoint Connector updates for Windows, Linux, and Mac will follow later this month. The company also said there are no workarounds for the two bugs, although it has no evidence of in-the-wild exploitation.

Windows Plug and Play auto-install abuse reaches SYSTEM code execution on Windows 11

Technical Analysis

Updated: 11.08.2026 13:48 · First: 11.08.2026 13:48 · 📰 1 src / 1 articles · H score: 26

Researchers showed that Windows Plug and Play auto-install can be abused to reach SYSTEM code execution on Windows 11, turning a privileged device-install path into a local takeover vector under specific redirection conditions.

CEVA Logistics hit by cyberattack

Incident

Updated: 10.08.2026 14:47 · First: 10.08.2026 14:47 · 📰 2 src / 2 articles · H score: 33

CEVA Logistics faced a cyberattack that disrupted operations at eight European warehouses, forcing the shipping provider to isolate affected systems and bring in outside investigators. The incident affected logistics operations for Europe-based customers and remained under active review after the attack window of July 29 to August 1, 2026. The disclosure increases the risk of operational disruption and supply-chain fallout for affected retailers and shipment recipients.

GhostSplice MCP split-instruction prompt-injection against AI coding agents

Technical Analysis

Updated: 11.08.2026 13:24 · First: 11.08.2026 13:24 · 📰 1 src / 1 articles · H score: 23

GhostSplice shows that MCP-connected AI coding agents can be tricked into exfiltrating SSH keys, environment secrets, source code, and customer data by stitching together harmless-looking instruction fragments. The technique splits malicious intent across tool descriptions, tool results, and sometimes server-initiated sampling, so no single message looks overtly dangerous. Controlled tests found compliance rising from 42% to 82% when the request was split, making client-side trust boundaries and tool-output handling a concrete security concern.

Gunra launches RaaS affiliate program and recruits initial access brokers

Threat Actor Meta

Updated: 11.08.2026 12:47 · First: 11.08.2026 12:47 · 📰 2 src / 2 articles · H score: 30

Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform, increasing affiliate reach and lowering the barrier to intrusion. The group began recruiting initial access brokers and adopted the Golden Community branding alias to support the expansion. The shift strengthens its ability to scale extortion operations across enterprise networks and widen access to victims.