# Archive

Browse past daily curated stories

Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19 Jul 18 Jul 17 Jul 16 Jul 15 Jul 14 Jul 12 Jul 11

Thursday, August 13, 2026

  1. 1
    0
    BleepingComputer general
    Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

    Microsoft's August 2026 Patch Tuesday addresses 400 vulnerabilities including one actively exploited zero-day (a use-after-free in afd.sys Windows kernel-mode driver enabling SYSTEM privilege escalation) and two publicly disclosed zero-days. The sheer volume — roughly five times typical monthly patch volumes — is attributed to AI-assisted vulnerability discovery, making prioritization critical for security teams. Defenders should immediately focus on the actively exploited kernel flaw and the Lazarus-linked CVE-2026-68820.

  2. 2
    0
    BleepingComputer general
    Lazarus hackers exploited Windows zero-day to target defense firms

    North Korea's Lazarus Group exploited Windows zero-day CVE-2026-68820 as part of Operation Dream Job to deploy the previously unknown ForestTiger backdoor against defense and aerospace companies in France, Germany, Brazil, and India. CISA issued a two-week remediation deadline for federal agencies. Check Point Research attributed the campaign, which used fake job offer lures targeting IT professionals.

  3. 3
    0
    The Hacker News general
    Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    Two malicious LiteLLM releases were pushed to PyPI in March 2026 via the Trivy supply chain hack, remaining available for approximately 40 minutes before removal — yet credential-stealing code captured data from 434,000 files across 2,100+ organizations. Stolen data included cloud API keys, SSH keys, Kubernetes tokens, and database passwords, making this one of the most impactful AI-toolchain supply chain attacks to date.

  4. 4
    0
    The Hacker News general
    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    Threat actors are actively exploiting CVE-2026-59310 (CVSS 9.8), a directory-traversal vulnerability in Broadcom VMware vCenter Server, to execute arbitrary code and establish persistent remote access. The critical flaw was recently patched, but active exploitation means unpatched vCenter instances in network-accessible environments face immediate compromise risk.

  5. 5
    0
    The Hacker News general
    Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

    Adobe's August 2026 patch batch includes three CVSS 10.0 vulnerabilities: CVE-2026-48362, an OS command injection in ColdFusion; a critical flaw in Campaign Classic; and CVE-2026-71362 in Adobe Commerce/Magento, which attackers are already exploiting to hijack customer accounts. Security teams running ColdFusion or Magento storefronts should treat these as emergency patches given active exploitation.

  6. 6
    0
    The Hacker News general
    Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

    Cisco disclosed CVE-2026-20349 (CVSS 8.6), a zero-day in Secure Firewall ASA and FTD software being actively exploited in the wild to trigger remote denial-of-service crashes via malformed HTTP requests — no authentication required. Organizations relying on Cisco ASA/FTD for perimeter defense should apply patches immediately, as this flaw can be exploited remotely against internet-facing firewall management interfaces.

  7. 7
    0
    The Hacker News general
    SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

    SAP patched CVE-2026-58231 (CVSS 10.0), a maximum-severity flaw in Commerce Cloud's Data Hub Adapter stemming from insufficient authorization checks and input validation that allows unauthenticated remote code execution. The August SAP Security Patch Day included 28 new notes, with four addressing critical-severity bugs across multiple enterprise products.

  8. 8
    0
    BleepingComputer general
    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Russian threat actor Sandworm has been targeting system administrators and IT professionals with fake job offers since at least May 2026, distributing a trojanized WireGuard VPN client as part of the lure. The campaign mirrors Lazarus Group's Operation Dream Job TTPs, underscoring a trend of nation-state actors exploiting IT professionals' trust in open-source tooling.

  9. 9
    0
    BleepingComputer general
    DeadLock ransomware uses blockchain to resist infrastructure takedown

    The DeadLock ransomware operation has adopted blockchain-backed decentralized infrastructure for victim communications and data leak operations, making law enforcement takedowns significantly harder by eliminating centralized C2 servers. This mirrors the rebuilt Kimwolf botnet's use of the Ethereum blockchain for command distribution, signaling a broader ransomware ecosystem shift toward decentralized resilience.

  10. 10
    0
    Dark Reading general
    Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

    The Gunra ransomware-as-a-service operation is actively targeting critical infrastructure using leaked Conti source code while exploiting known Fortinet firewall and VPN appliance vulnerabilities to bypass MFA. The group's success against high-value targets using old, unpatched flaws reinforces the persistent risk of delayed patching in OT and critical infrastructure environments.