# Today's Top Stories
August 12, 2026
-
1The Hacker News general Aug 11Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft's August 2026 Patch Tuesday addressed 398 security vulnerabilities, including CVE-2026-68820 (CVSS 7.0), an actively exploited zero-day in a Windows kernel driver handling network socket operations (afd.sys) that allows local privilege escalation to SYSTEM. Two additional vulnerabilities were publicly disclosed prior to patching. Security teams should prioritize the kernel driver fix immediately given active exploitation.
-
2The Hacker News general Aug 11Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
A joint advisory from U.S. and South Korean agencies warns that the Gunra ransomware-as-a-service operation is targeting critical infrastructure — including healthcare, financial services, and government — by exploiting unpatched Fortinet firewall and Schneider Electric VPN flaws while also bypassing MFA. Gunra is built on leaked Conti code, giving it a mature capability set despite being a newer operation. Defenders running Fortinet or Schneider Electric perimeter devices should treat patching as urgent.
-
3The Hacker News general Aug 11DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The DeadLock ransomware group has adopted a blockchain-backed extortion infrastructure using Polygon smart contracts and the Session messaging network to store and deliver resources throughout the extortion process, making traditional law-enforcement takedowns of C2 infrastructure largely ineffective. Microsoft Threat Intelligence documented this novel resilience technique, which mirrors a similar blockchain-based approach observed in the Kimwolf botnet rebuild. This represents a significant operational security evolution for ransomware actors.
-
4The Hacker News general Aug 11Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Palo Alto Networks Unit 42 discovered Kimwolf v7 in February 2026, revealing that the Android/IoT botnet — previously disrupted by law enforcement — rebuilt itself with HTTP/2-based DDoS traffic that mimics legitimate Chrome browser activity and fetches command-and-control orders from the Ethereum blockchain. This dual-layer evasion (traffic disguise plus decentralized C2) directly counters both signature-based detection and infrastructure seizure tactics used in prior takedowns.
-
5The Hacker News general Aug 11Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Researchers disclosed CVE-2026-55040 (CVSS 9.1), an unauthenticated RCE vulnerability affecting Microsoft SharePoint Server Subscription Edition, 2019, and 2016, which was partially discovered using an AI agent. CISA has since confirmed (article 7434) that ransomware gangs are actively exploiting a related SharePoint RCE flaw flagged since early July, making immediate patching of all SharePoint Server deployments critical for defenders.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Aug 11Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Researchers discovered that Zoom's annotation feature — used for drawing and typing on shared screens — contained a zero-click code execution vulnerability allowing any meeting participant to execute code on another attendee's machine, including the presenter, with no user interaction beyond being present in the call. The flaw required no click, download, or visible prompt, making it particularly dangerous in enterprise environments where screen sharing is routine.
-
7The Hacker News general Aug 11Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers breached a Polish combined heat-and-power plant serving roughly 50,000 residents by pivoting through the private cellular APN network used to reach remote OT equipment, successfully shutting down a steam turbine and process-water treatment system. A second attack at a separate heat plant was also uncovered, occurring the same day as coordinated strikes on over 30 renewable energy installations in Poland. The incident underscores the risk of private cellular networks as an underprotected OT attack surface.
-
8The Hacker News general Aug 11Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
CERT-UA has linked a social engineering campaign running since at least May 2026 to UAC-0145, a Sandworm (APT44/GRU) subgroup, which poses as tech recruiters to deliver a trojanized WireGuard VPN client that can execute attacker commands on victim systems. The campaign specifically targets Ukrainian IT professionals and system administrators, exploiting trust in legitimate job recruitment workflows to gain persistent access.
-
9The Hacker News general Aug 11Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers created a fictitious cryptocurrency startup, advertised developer positions, and successfully hired three suspected North Korean IT workers, recording all activity on issued virtual machines. The sting exposed concrete identity fraud patterns useful to hiring teams: one suspect claimed a Texas address but submitted a California driver's license and New York bank account. The research provides actionable indicators for organizations to detect DPRK IT worker infiltration during onboarding.
-
10The Hacker News general Aug 11A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Researchers at the University of Birmingham and Fuzzware tested 26 phones and cellular modules, finding that a malicious SIM card can inject attacker-controlled commands directly into the modem firmware of devices — including EV chargers, industrial routers, and automotive telematics units — sufficient to achieve full device takeover. This supply-chain-level attack vector requires no network access from the attacker beyond physical or logical SIM insertion, posing significant risk to IoT deployments across critical infrastructure.