# Today's Top Stories
August 13, 2026
-
1BleepingComputer general Aug 11Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Microsoft's August 2026 Patch Tuesday addresses 400 vulnerabilities including one actively exploited zero-day (a use-after-free in afd.sys Windows kernel-mode driver enabling SYSTEM privilege escalation) and two publicly disclosed zero-days. The sheer volume — roughly five times typical monthly patch volumes — is attributed to AI-assisted vulnerability discovery, making prioritization critical for security teams. Defenders should immediately focus on the actively exploited kernel flaw and the Lazarus-linked CVE-2026-68820.
-
2BleepingComputer general Aug 12Lazarus hackers exploited Windows zero-day to target defense firms
North Korea's Lazarus Group exploited Windows zero-day CVE-2026-68820 as part of Operation Dream Job to deploy the previously unknown ForestTiger backdoor against defense and aerospace companies in France, Germany, Brazil, and India. CISA issued a two-week remediation deadline for federal agencies. Check Point Research attributed the campaign, which used fake job offer lures targeting IT professionals.
-
3The Hacker News general Aug 12Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases were pushed to PyPI in March 2026 via the Trivy supply chain hack, remaining available for approximately 40 minutes before removal — yet credential-stealing code captured data from 434,000 files across 2,100+ organizations. Stolen data included cloud API keys, SSH keys, Kubernetes tokens, and database passwords, making this one of the most impactful AI-toolchain supply chain attacks to date.
-
4The Hacker News general Aug 12Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors are actively exploiting CVE-2026-59310 (CVSS 9.8), a directory-traversal vulnerability in Broadcom VMware vCenter Server, to execute arbitrary code and establish persistent remote access. The critical flaw was recently patched, but active exploitation means unpatched vCenter instances in network-accessible environments face immediate compromise risk.
-
5The Hacker News general Aug 12Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe's August 2026 patch batch includes three CVSS 10.0 vulnerabilities: CVE-2026-48362, an OS command injection in ColdFusion; a critical flaw in Campaign Classic; and CVE-2026-71362 in Adobe Commerce/Magento, which attackers are already exploiting to hijack customer accounts. Security teams running ColdFusion or Magento storefronts should treat these as emergency patches given active exploitation.
-
ADSponsoredPenetration Testing
Comprehensive security assessments by certified professionals. Find vulnerabilities before attackers do.
Learn More → -
6The Hacker News general Aug 12Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco disclosed CVE-2026-20349 (CVSS 8.6), a zero-day in Secure Firewall ASA and FTD software being actively exploited in the wild to trigger remote denial-of-service crashes via malformed HTTP requests — no authentication required. Organizations relying on Cisco ASA/FTD for perimeter defense should apply patches immediately, as this flaw can be exploited remotely against internet-facing firewall management interfaces.
-
7The Hacker News general Aug 12SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP patched CVE-2026-58231 (CVSS 10.0), a maximum-severity flaw in Commerce Cloud's Data Hub Adapter stemming from insufficient authorization checks and input validation that allows unauthenticated remote code execution. The August SAP Security Patch Day included 28 new notes, with four addressing critical-severity bugs across multiple enterprise products.
-
8BleepingComputer general Aug 11Sandworm hackers target IT pros with trojanized WireGuard VPN client
Russian threat actor Sandworm has been targeting system administrators and IT professionals with fake job offers since at least May 2026, distributing a trojanized WireGuard VPN client as part of the lure. The campaign mirrors Lazarus Group's Operation Dream Job TTPs, underscoring a trend of nation-state actors exploiting IT professionals' trust in open-source tooling.
-
9BleepingComputer general Aug 11DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation has adopted blockchain-backed decentralized infrastructure for victim communications and data leak operations, making law enforcement takedowns significantly harder by eliminating centralized C2 servers. This mirrors the rebuilt Kimwolf botnet's use of the Ethereum blockchain for command distribution, signaling a broader ransomware ecosystem shift toward decentralized resilience.
-
10Dark Reading general Aug 11Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The Gunra ransomware-as-a-service operation is actively targeting critical infrastructure using leaked Conti source code while exploiting known Fortinet firewall and VPN appliance vulnerabilities to bypass MFA. The group's success against high-value targets using old, unpatched flaws reinforces the persistent risk of delayed patching in OT and critical infrastructure environments.