Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.
Tag: Vulnerability
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog,…
SharePoint CVE-2026-55040 Under Active Exploit
A critical authentication bypass vulnerability in Microsoft SharePoint Server Subscription Edition is under active exploitation following the public…
Cisco sees network refresh surge from AI vulnerability disco
Cisco is experiencing a surge in network equipment sales as customers rush to replace unsupported devices following the emergence of Anthropic’s Mythos AI…
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.
CISA Adds Actively Exploited Windows WinSock Vulnerability to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft Windows vulnerability to its Known Exploited…
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators.…
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has…
Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed…
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check…
WordPress RCE Vulnerability Lets Authenticated Authors Execute Remote Code
WordPress has released version 7.0.4 to address a high-impact authenticated remote code execution (RCE) vulnerability. This flaw could allow users with…
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with…
Meccha Chameleon Vulnerability Allowed Malware to Spread Through Steam Workshop Maps
A security vulnerability in the game Meccha Chameleon enabled malicious custom maps stored on Steam Workshop to infect users with malware. The…
Hidden SIM Card Vulnerability Affecting Smartphones, EV Chargers and IoT Devices
Security researchers from Birmingham University unveiled research at USENIX WOOT Conference 2026 on Offensive Technologies, demonstrating how a…
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft…
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
No, no nasties to see here, guv…
Framework loses customer data in Metabase zero-day attack
Repairable hardware is little comfort when personal details escape
Cisco says software vulnerability could let hackers crash firewalls
Threat actors have already begun exploiting the flaw, according to the U.S. government.
