<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>0dayNews</title><description>Independent coverage of CVEs, KEV catalog additions, and breach news.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Ray AI Framework Added to CISA KEV — Patch by Aug 21</title><link>https://0daynews.com/articles/2026-08-17-ray-framework-cve-2025-62593-cisa-kev/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-ray-framework-cve-2025-62593-cisa-kev/</guid><description>CISA confirmed active exploitation of CVE-2025-62593 in Ray and added it to the KEV catalog. Federal agencies must remediate by August 21. ML teams with exposed Ray dashboards should act now.</description><pubDate>Mon, 17 Aug 2026 16:00:00 GMT</pubDate><content:encoded>&lt;p&gt;CISA added &lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2025-62593&quot;&gt;CVE-2025-62593&lt;/a&gt;&lt;/strong&gt; to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;Known Exploited Vulnerabilities catalog&lt;/a&gt; on August 18, 2026, confirming active exploitation of a code injection flaw in &lt;a href=&quot;https://github.com/ray-project/ray&quot;&gt;Ray&lt;/a&gt; — the open-source distributed computing framework used widely for ML training, model serving, and data pipelines.&lt;/p&gt;
&lt;p&gt;The vulnerability enables remote code execution. Per CISA and the &lt;a href=&quot;https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v&quot;&gt;GitHub Security Advisory (GHSA-q279-jhrf-cc6v)&lt;/a&gt;, the attack surface includes exposure through Firefox and Safari, meaning Ray installations with reachable web interfaces are in scope.&lt;/p&gt;
&lt;p&gt;Under &lt;a href=&quot;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&quot;&gt;BOD 26-04&lt;/a&gt;, federal civilian agencies must remediate this entry by &lt;strong&gt;August 21, 2026&lt;/strong&gt; — three days from publication.&lt;/p&gt;
&lt;h2&gt;Who&apos;s exposed&lt;/h2&gt;
&lt;p&gt;Ray is deployed broadly in ML production: distributed training clusters, Ray Serve inference pipelines, large-scale data preprocessing, AutoML platforms, and reinforcement learning infrastructure. Organizations running Ray on anything with a network-reachable surface — dashboards, job submission APIs, cluster UIs — are the immediate concern.&lt;/p&gt;
&lt;p&gt;The default Ray dashboard runs on port 8265 and has shipped without authentication in many configurations. If your Ray instance is reachable beyond localhost — inside a corporate network, a cloud VPC, or exposed to the internet — that&apos;s the attack surface at issue here.&lt;/p&gt;
&lt;p&gt;Developer workstations running Ray locally, and cloud-based training jobs in isolated environments, have a lower but nonzero exposure depending on how the instance is bound.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;p&gt;Check the &lt;a href=&quot;https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v&quot;&gt;GitHub advisory for GHSA-q279-jhrf-cc6v&lt;/a&gt; for the patched version and the &lt;a href=&quot;https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09&quot;&gt;fix commit (70e7c72)&lt;/a&gt;. CISA&apos;s guidance when mitigations are unavailable: discontinue use of the product.&lt;/p&gt;
&lt;p&gt;Concrete steps:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Find Ray in your environment.&lt;/strong&gt; Check container images, ML training platforms (Anyscale, KubeRay, self-managed clusters), and any CI/CD pipelines that invoke Ray for distributed processing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Patch to the fixed release&lt;/strong&gt; per the GitHub advisory.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;If you can&apos;t patch immediately:&lt;/strong&gt; firewall port 8265 and any other exposed Ray ports to trusted networks. Do not leave the Ray dashboard bound to &lt;code&gt;0.0.0.0&lt;/code&gt; or publicly reachable.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check for unintentional exposure.&lt;/strong&gt; Review your network scan data or Shodan results for Ray dashboard fingerprints. Exposed, unauthenticated Ray dashboards have been a recurring cloud finding for years.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Priority call&lt;/h2&gt;
&lt;p&gt;This is a KEV — the &quot;do we patch it&quot; question is settled. The question is when.&lt;/p&gt;
&lt;p&gt;Federal agencies: August 21. That&apos;s the mandate.&lt;/p&gt;
&lt;p&gt;Everyone else with Ray in network-reachable production: this week. KEV listing means active exploitation is confirmed, not theoretical. Opportunistic scanning against new KEV additions moves fast.&lt;/p&gt;
&lt;p&gt;Isolated local dev installs with no network exposure: lower urgency, but schedule the update on your next regular cycle regardless.&lt;/p&gt;
&lt;p&gt;Track this and all current CISA KEV entries at the &lt;a href=&quot;/kev-tracker&quot;&gt;0dayNews KEV Tracker&lt;/a&gt;. For another recent AI/ML platform RCE, see &lt;a href=&quot;/articles/2026-08-15-mindsdb-cvss10-unauthenticated-rce&quot;&gt;MindsDB CVSS 10.0 unauthenticated RCE&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><category>ray-project</category><category>cve-2025-62593</category><category>cisa-kev</category><category>remote-code-execution</category><category>machine-learning</category><category>patch</category></item><item><title>Clop Claims GE and Philips; Both Investigating</title><link>https://0daynews.com/articles/2026-08-17-clop-ransomware-ge-philips-data-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-clop-ransomware-ge-philips-data-theft/</guid><description>General Electric and Philips confirm they are investigating data theft claims from the Clop ransomware gang. Neither company has confirmed exfiltration scope, affected systems, or breach date.</description><pubDate>Mon, 17 Aug 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Clop named both General Electric and Philips on its extortion site. Both companies confirmed they are investigating. Neither has validated the claim.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/&quot;&gt;BleepingComputer reports&lt;/a&gt; the acknowledgments came in response to Clop&apos;s public posting — standard Clop pressure mechanics, designed to force a response or accelerate settlement negotiations. GE and Philips are not the only organizations named in this campaign period. Breach date, attack vector, data volume, and affected divisions: none of these have been confirmed from either company.&lt;/p&gt;
&lt;h2&gt;Confidence labels&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Confirmed (high):&lt;/strong&gt; GE and Philips are actively investigating Clop&apos;s claims. Both companies issued statements to that effect.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Confirmed (medium):&lt;/strong&gt; This is part of a wider Clop campaign. The language of each company&apos;s statement — and the simultaneous naming on Clop&apos;s site — is consistent with a mass-exploitation event targeting a common platform across multiple organizations. Specific co-victims: unconfirmed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unconfirmed:&lt;/strong&gt; Attack vector, breach timeline, data categories affected, whether data has been published or previewed. These details originate from Clop&apos;s own site — treat as adversary-sourced until independently corroborated.&lt;/p&gt;
&lt;h2&gt;Who is Clop&lt;/h2&gt;
&lt;p&gt;Financially motivated extortion group, active since at least 2019. Their model: exploit a widely deployed enterprise platform (file transfer software, collaboration tools), harvest data from dozens or hundreds of organizations simultaneously, then post victim names publicly to force payment. They do not typically encrypt systems — data exfiltration and the threat of public exposure is the lever.&lt;/p&gt;
&lt;p&gt;GE spans aerospace, power generation, and healthcare. Philips is primarily healthcare technology and consumer electronics. The sectors matter: regulated personal data, intellectual property, and operational technology environments may be involved depending on which divisions were exposed. Nothing in the current reporting confirms which assets Clop claims to hold.&lt;/p&gt;
&lt;h2&gt;What to watch&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Official breach notifications from GE or Philips (regulatory filings or SEC disclosures if material).&lt;/li&gt;
&lt;li&gt;Clop adding data previews to its leak site — a tactic the group uses to increase payment pressure.&lt;/li&gt;
&lt;li&gt;Additional named victims in this campaign.&lt;/li&gt;
&lt;li&gt;Any identification of the exploited platform.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Developing story. Updated as confirmed details emerge.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-17-clop-ransomware-ge-philips-data-theft/cover.jpg" medium="image" width="1200" height="675"/><category>clop</category><category>ransomware</category><category>general electric</category><category>philips</category><category>data theft</category><category>breach investigation</category><category>extortion</category></item><item><title>Microsoft Patch Underway for Defender ShieldBreak Zero-Day</title><link>https://0daynews.com/articles/2026-08-17-shieldbreak-defender-patch-update/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-shieldbreak-defender-patch-update/</guid><description>Microsoft confirms a patch is in development for CVE-2026-69414, a zero-day EoP in Defender&apos;s Malware Protection Engine (ShieldBreak). No patch yet. No exploitation confirmed.</description><pubDate>Mon, 17 Aug 2026 10:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Patch status: in progress. Not shipped.&lt;/p&gt;
&lt;p&gt;Microsoft has confirmed it is developing a security update for &lt;a href=&quot;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414&quot;&gt;CVE-2026-69414&lt;/a&gt;, the unpatched elevation-of-privilege vulnerability in the Defender Malware Protection Engine (&lt;code&gt;MsMpEng.exe&lt;/code&gt;), tracked publicly as &quot;ShieldBreak.&quot; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/&quot;&gt;BleepingComputer reports&lt;/a&gt; the disclosure is attributed to security researcher &quot;Nightmare Eclipse&quot; — identity not independently confirmed.&lt;/p&gt;
&lt;p&gt;No patch is available as of August 17, 2026. No ship date has been announced. No active exploitation in the wild is confirmed.&lt;/p&gt;
&lt;h2&gt;What changed&lt;/h2&gt;
&lt;p&gt;CVE-2026-69414 dropped August 14 with an MSRC advisory and no fix. &lt;a href=&quot;/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine/&quot;&gt;Initial coverage here&lt;/a&gt;: the flaw sits in &lt;code&gt;MsMpEng.exe&lt;/code&gt;, which runs as SYSTEM on Windows hosts with real-time protection enabled. An attacker with local code execution access can escalate to SYSTEM through this EoP path.&lt;/p&gt;
&lt;p&gt;Three days in, the patch remains in development. The interval is not unusual — Microsoft ships Malware Protection Engine updates out-of-band, outside the monthly Patch Tuesday cycle, as standalone engine builds when they are ready. The MSRC advisory will carry the engine build number when that happens.&lt;/p&gt;
&lt;p&gt;This is distinct from &lt;a href=&quot;/articles/2026-08-12-shieldbreak-defender-cve-2026-50656-patch-bypass/&quot;&gt;CVE-2026-50656&lt;/a&gt;, a separately tracked ShieldBreak flaw that shipped in August Patch Tuesday and had a bypass circulating within 24 hours. Same &quot;ShieldBreak&quot; label, different CVE, different component.&lt;/p&gt;
&lt;h2&gt;What to do now&lt;/h2&gt;
&lt;p&gt;Nothing new since August 14.&lt;/p&gt;
&lt;p&gt;Keep Defender Security Intelligence (definition) updates current. Microsoft ships these continuously and independently of engine builds; behavioral mitigations for unpatched engine flaws can arrive via signature updates before the binary patch. Confirm definitions are current via &lt;code&gt;Get-MpComputerStatus&lt;/code&gt; in PowerShell or the Defender version panel under Windows Security.&lt;/p&gt;
&lt;p&gt;Watch the MSRC advisory linked above. The engine build version will appear there when the patch ships — that is the authoritative signal, not third-party reporting.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-17-shieldbreak-defender-patch-update/cover.jpg" medium="image" width="1200" height="675"/><category>shieldbreak</category><category>CVE-2026-69414</category><category>microsoft defender</category><category>zero-day</category><category>elevation of privilege</category><category>windows</category><category>malware protection engine</category></item><item><title>Fortune 500 Firms Named in Azure Data Theft Claim</title><link>https://0daynews.com/articles/2026-08-17-fortune-500-azure-data-theft-campaign/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-fortune-500-azure-data-theft-campaign/</guid><description>Threat actor claims mass exfiltration from McDonald&apos;s, TCS, Vodafone, and other Fortune 500 firms via Azure. Named companies have not confirmed. Story developing.</description><pubDate>Mon, 17 Aug 2026 07:30:00 GMT</pubDate><content:encoded>&lt;p&gt;Claim unverified. A threat actor is publicly asserting mass data exfiltration from McDonald&apos;s, Tata Consultancy Services (TCS), Vodafone, and additional unnamed large organizations through Azure infrastructure, &lt;a href=&quot;https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/&quot;&gt;per SecurityWeek reporting published Monday morning&lt;/a&gt;. Stated volume: millions of records. No named company has confirmed unauthorized access at time of writing. Microsoft has not attributed the claimed exfiltration to a specific Azure vulnerability or misconfiguration.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Confidence breakdown:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Confirmed&lt;/em&gt;: SecurityWeek has reported the claim. A threat actor is publicly advertising this dataset.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Unconfirmed&lt;/em&gt;: Record authenticity. The specific Azure service, attack vector, or credential path involved. Whether the named organizations were aware before this disclosure.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Unknown&lt;/em&gt;: Threat actor identity. Whether samples have been validated by any of the named targets or an independent party.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The public advertising of claimed datasets — especially against high-profile targets — is consistent with extortion staging or data brokerage operations, where actors market access or records to create leverage or generate buyer interest before companies can respond.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Context.&lt;/strong&gt; Azure-hosted environments have been persistent targets for credential-based intrusion chains throughout 2026. &lt;a href=&quot;/articles/2026-08-01-device-code-phishing-industrial-scale/&quot;&gt;OAuth device-code phishing at industrial scale&lt;/a&gt; and &lt;a href=&quot;/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft/&quot;&gt;misconfigured anonymous-access endpoints in enterprise cloud portals&lt;/a&gt; have both driven large-scale data harvesting with no CVE required. Whether this incident follows a similar pattern — or involves a distinct Azure service vulnerability — is unestablished.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What to watch:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Statements from McDonald&apos;s, TCS, or Vodafone security teams&lt;/li&gt;
&lt;li&gt;Microsoft MSRC or Azure Security Advisory response&lt;/li&gt;
&lt;li&gt;Sample validation or forensic confirmation by an independent third party&lt;/li&gt;
&lt;li&gt;Whether additional named organizations surface in follow-up reporting&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Treat the named targets as claimed, not confirmed. This story is developing. Further reporting will follow as details are verified.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Source: &lt;a href=&quot;https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/&quot;&gt;SecurityWeek — Fortune 500 Companies Hit in Azure Data Theft Campaign&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-17-fortune-500-azure-data-theft-campaign/cover.jpg" medium="image" width="1200" height="675"/><category>azure</category><category>data breach</category><category>fortune 500</category><category>cloud security</category><category>threat actor</category><category>data theft</category><category>exfiltration</category></item><item><title>GL.iNet 4.9.0 Fixes Five RCE Flaws in Wi-Fi Routers</title><link>https://0daynews.com/articles/2026-08-17-gl-inet-490-rce-flaws-routers/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-gl-inet-490-rce-flaws-routers/</guid><description>GL.iNet confirmed five high-severity RCE and auth bypass vulnerabilities across its 4.8.x firmware line. Version 4.9.0 is the fix for all affected devices.</description><pubDate>Mon, 17 Aug 2026 06:00:00 GMT</pubDate><content:encoded>&lt;p&gt;GL.iNet has confirmed and patched five vulnerabilities in firmware 4.8.x — four remote code execution flaws and one authorization bypass — all with public proof-of-concept code. The fix is firmware 4.9.0, available now. If you&apos;re running 4.8.x on any of the affected models, this is a straightforward call: update and move on.&lt;/p&gt;
&lt;h2&gt;The five CVEs&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-19983/&quot;&gt;CVE-2026-19983&lt;/a&gt; — CVSS 8.3, High&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The most severe of the batch. An unauthenticated host-header manipulation in the NAS command service (&lt;code&gt;/usr/bin/gl_nas_sys&lt;/code&gt;) allows remote code execution as root with no credentials required. Affected models: A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000. &lt;a href=&quot;https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/NAS%20Host-header%20bypass%20to%20unauthenticated%20root%20RCE.md&quot;&gt;Vendor advisory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-19979/&quot;&gt;CVE-2026-19979&lt;/a&gt; — CVSS 8.3, High&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Authorization bypass in the WebDAV service&apos;s COPY and MOVE operations. An attacker can redirect file operations outside the intended public-share scope without authentication. Affects the widest device list of the five: A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000. &lt;a href=&quot;https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/WebDAV%20Public-Share%20Destination%20Authorization%20Bypass.md&quot;&gt;Vendor advisory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-19982/&quot;&gt;CVE-2026-19982&lt;/a&gt; — CVSS 7.4, High&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;OS command injection via &lt;code&gt;dest_port&lt;/code&gt;/&lt;code&gt;dest_ip&lt;/code&gt; arguments in the firewall-management RPC. Affects the BE9300 and MT6000. &lt;a href=&quot;https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Firewall%20Cleanup%20RCE.md&quot;&gt;Vendor advisory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-19981/&quot;&gt;CVE-2026-19981&lt;/a&gt; — CVSS 7.4, High&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;OS command injection via &lt;code&gt;switch_power&lt;/code&gt;/&lt;code&gt;restore_power&lt;/code&gt; arguments in the Wi-Fi Timer Power-Schedule feature. Affects seventeen models across the product line. &lt;a href=&quot;https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Wi-Fi%20Timer%20Power-Schedule%20Cron%20RCE.md&quot;&gt;Vendor advisory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-19980/&quot;&gt;CVE-2026-19980&lt;/a&gt; — CVSS 7.4, High&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Code injection through &lt;code&gt;hour&lt;/code&gt;/&lt;code&gt;min&lt;/code&gt;/&lt;code&gt;week&lt;/code&gt; arguments in the language auto-update scheduler (&lt;code&gt;ui.update_langs&lt;/code&gt;). Same broad device list as CVE-2026-19981. &lt;a href=&quot;https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Language%20Auto-Update%20Cron%20RCE.md&quot;&gt;Vendor advisory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;None of these are currently on the &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt;. That can change — public PoC exists for all five, which is the condition that typically precedes opportunistic exploitation.&lt;/p&gt;
&lt;h2&gt;Affected devices&lt;/h2&gt;
&lt;p&gt;Across all five CVEs, the vulnerable firmware line (4.8.x) covers:&lt;/p&gt;
&lt;p&gt;A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000.&lt;/p&gt;
&lt;p&gt;Not every device is in scope for every CVE — the NAS RCE (CVE-2026-19983) and firewall RCE (CVE-2026-19982) have narrower device lists, while the WebDAV bypass and the scheduler flaws hit the full range above.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;p&gt;Update to &lt;strong&gt;GL.iNet firmware 4.9.0&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Log in to the admin panel, go to &lt;strong&gt;System → Upgrade&lt;/strong&gt;, and apply the update. GL.iNet&apos;s mobile app also supports firmware upgrades. The vendor&apos;s &lt;a href=&quot;https://dl.gl-inet.com/&quot;&gt;4.9.0 release page&lt;/a&gt; lists firmware packages by device.&lt;/p&gt;
&lt;p&gt;Check your admin panel exposure at the same time. The unauthenticated NAS RCE (CVE-2026-19983) doesn&apos;t require LAN position — it&apos;s remotely exploitable. If your router&apos;s admin interface is reachable from the WAN, restrict it to the LAN interface only (under &lt;strong&gt;System → Administration → Access Methods&lt;/strong&gt; in most GL.iNet firmware versions).&lt;/p&gt;
&lt;h2&gt;Priority call&lt;/h2&gt;
&lt;p&gt;CVE-2026-19983 tops the list — unauthenticated root RCE is as bad as it gets, and with a public PoC, the window between &quot;vulnerability disclosed&quot; and &quot;actively scanned&quot; is short. The four remaining flaws at CVSS 7.4 are all remotely exploitable with public PoC as well.&lt;/p&gt;
&lt;p&gt;Patch now. This is not a maintenance-window situation for any device that sits at a network edge or handles traffic from untrusted sources.&lt;/p&gt;
&lt;p&gt;For context on other router-class vulnerabilities patched recently, see &lt;a href=&quot;/articles/2026-08-15-openwrt-luci-critical-root-rce&quot;&gt;OpenWRT LuCI critical root RCE&lt;/a&gt; and the &lt;a href=&quot;/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay&quot;&gt;Evooo1Bot botnet targeting routers for SOCKS5 relay&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-17-gl-inet-490-rce-flaws-routers/cover.jpg" medium="image" width="1200" height="675"/><category>GL.iNet</category><category>router</category><category>remote-code-execution</category><category>firmware</category><category>CVE-2026-19979</category><category>CVE-2026-19983</category><category>patch</category></item><item><title>Wireshark 4.6.8 Patches 28 Vulnerabilities</title><link>https://0daynews.com/articles/2026-08-17-wireshark-468-28-vulnerabilities-patched/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-wireshark-468-28-vulnerabilities-patched/</guid><description>Wireshark 4.6.8 is out with patches for 28 security vulnerabilities and 25 bugs. Update any instance used for packet capture or PCAP analysis.</description><pubDate>Mon, 17 Aug 2026 05:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Wireshark 4.6.8 dropped August 16 with patches for &lt;strong&gt;28 security vulnerabilities&lt;/strong&gt; and fixes for 25 bugs. If you&apos;re running any earlier version in a packet capture or protocol analysis role — analyst workstations, capture probes, automated pipelines that parse PCAP files — this is a week-window update.&lt;/p&gt;
&lt;p&gt;Specific CVE IDs and CVSS scores are enumerated in &lt;a href=&quot;https://www.wireshark.org/docs/relnotes/wireshark-4.6.8.html&quot;&gt;Wireshark&apos;s official release notes&lt;/a&gt;. SANS Internet Storm Center &lt;a href=&quot;https://isc.sans.edu/diary/rss/33248&quot;&gt;confirmed the release&lt;/a&gt; Monday morning.&lt;/p&gt;
&lt;p&gt;No active exploitation of the patched vulnerabilities has been publicly reported as of publication. The release is not currently listed on the CISA Known Exploited Vulnerabilities catalog.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;p&gt;Update to 4.6.8. The path depends on your deployment:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Debian/Ubuntu:&lt;/strong&gt; &lt;code&gt;sudo apt update &amp;#x26;&amp;#x26; sudo apt upgrade wireshark&lt;/code&gt; once 4.6.8 reaches your distribution&apos;s repos&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;macOS (Homebrew):&lt;/strong&gt; &lt;code&gt;brew upgrade wireshark&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Windows:&lt;/strong&gt; download the installer from &lt;a href=&quot;https://www.wireshark.org/download.html&quot;&gt;wireshark.org/download.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enterprise (SCCM/Intune):&lt;/strong&gt; check your software catalog; the new version should appear in the Wireshark MSI feed&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Wireshark&apos;s dissector stack handles the parsing of hundreds of protocol types. The majority of historical CVEs in Wireshark have been dissector-level bugs — malformed packets in a capture file triggering a heap overflow or NULL dereference. With 28 issues addressed in one release, the patch surface is wide enough to take seriously even without active exploitation.&lt;/p&gt;
&lt;h2&gt;Priority call&lt;/h2&gt;
&lt;p&gt;Wireshark typically runs on analyst workstations and in testing environments, not in a production data path. That limits immediate blast radius. Standard priority: schedule it during your next maintenance window, not an emergency after-hours patch.&lt;/p&gt;
&lt;p&gt;One exception: if you&apos;re feeding untrusted PCAP files into Wireshark or TShark as part of an automated analysis or CI/CD pipeline, move this up the queue. Dissector bugs are the exact class of flaw that activates when processing attacker-controlled network captures — a scenario more common in security tooling pipelines than it sounds.&lt;/p&gt;
&lt;p&gt;For broader patch context from this week, see the &lt;a href=&quot;/articles/2026-08-11-microsoft-patch-tuesday-august-2026&quot;&gt;August 2026 Patch Tuesday roundup&lt;/a&gt; and &lt;a href=&quot;/articles/2026-08-13-fortinet-fortiweb-fortimanager-aug-patches&quot;&gt;Fortinet&apos;s August advisory batch&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-17-wireshark-468-28-vulnerabilities-patched/cover.jpg" medium="image" width="1200" height="675"/><category>wireshark</category><category>packet-capture</category><category>protocol-analyzer</category><category>vulnerability</category><category>patch</category><category>security-update</category></item><item><title>SafePal Breach: 39,798 Customers&apos; Order Data for Sale</title><link>https://0daynews.com/articles/2026-08-17-safepal-breach-40k-customers-data-for-sale/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-safepal-breach-40k-customers-data-for-sale/</guid><description>SafePal warns ~39,798 customers their order data was stolen via an exploited flaw. A threat actor is now selling the records. Hardware wallets unaffected.</description><pubDate>Mon, 17 Aug 2026 02:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Confirmed: SafePal, a cryptocurrency hardware wallet provider, is warning approximately 39,798 customers that their order information was stolen following exploitation of a flaw in company systems. A threat actor is actively claiming to sell the stolen data. Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/&quot;&gt;BleepingComputer&lt;/a&gt;, 2026-08-16.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Confirmed:&lt;/strong&gt; ~39,798 customers affected. Order information stolen. SafePal has issued customer notifications. Stolen data now listed for sale by a threat actor.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unconfirmed — treat accordingly:&lt;/strong&gt; The specific vulnerability class exploited. The precise data fields in the stolen set beyond &quot;order information.&quot; Threat actor identity. When the breach occurred and how long unauthorized access persisted.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Critical distinction for SafePal device owners:&lt;/strong&gt; This is not a wallet compromise. SafePal hardware wallets store private keys locally on the device — a breach of order and customer data systems does not expose those keys or on-chain funds. If you hold cryptocurrency in a SafePal hardware wallet, your on-chain assets are not at risk from this specific incident.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What&apos;s exposed:&lt;/strong&gt; Customer order records. The exact field set hasn&apos;t been published; order databases typically contain names, shipping addresses, purchase history, and contact details. Intersection with credentials used elsewhere, or with other crypto service accounts, expands the risk surface.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For affected SafePal customers:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Watch for phishing targeting SafePal owners specifically — verified crypto hardware wallet buyers are a high-value phishing demographic.&lt;/li&gt;
&lt;li&gt;Be alert to SIM-swap attempts if phone numbers are in the breached dataset.&lt;/li&gt;
&lt;li&gt;If the same email and password were used for SafePal as for exchange accounts or other crypto services, rotate those credentials now.&lt;/li&gt;
&lt;li&gt;SafePal&apos;s official channels are the authoritative source on breach scope and remediation — do not rely on unofficial summaries.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Analysis&lt;/strong&gt; (speculative — no attribution evidence at publication): Crypto hardware wallet company order databases are a recurring target. The payload is the customer list — verified crypto holders with physical shipping addresses and purchase history. A 39,798-record scope is modest by volume; data quality over quantity is the likely objective, consistent with commercially motivated actors. No evidence linking this to a known APT. Attribution unknown — treat accordingly.&lt;/p&gt;
&lt;p&gt;This follows &lt;a href=&quot;/articles/2026-08-13-trezor-shipmonk-breach-14k-customers/&quot;&gt;Trezor&apos;s breach via shipping partner ShipMonk in August&lt;/a&gt;, which exposed 14,000 customers through a supply-chain compromise. The reported vector here appears direct rather than third-party — but specifics remain unconfirmed as of publication.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-17-safepal-breach-40k-customers-data-for-sale/cover.jpg" medium="image" width="1200" height="675"/><category>SafePal</category><category>data breach</category><category>cryptocurrency</category><category>hardware wallet</category><category>customer data</category><category>threat actor</category></item><item><title>AmnesiaStealer Hijacks macOS Browser Sessions</title><link>https://0daynews.com/articles/2026-08-16-amnesiastealer-macos-browser-hijack/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-amnesiastealer-macos-browser-hijack/</guid><description>Jamf found a new macOS infostealer that hijacks Chrome in headless mode, giving attackers live remote control of authenticated browser sessions via ClickFix lures.</description><pubDate>Sun, 16 Aug 2026 23:45:00 GMT</pubDate><content:encoded>&lt;p&gt;New macOS infostealer confirmed active. Jamf researchers disclosed &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/&quot;&gt;AmnesiaStealer&lt;/a&gt; today — a ClickFix-delivered payload that goes beyond credential harvesting and hands attackers a live, interactive browser session on the victim&apos;s machine.&lt;/p&gt;
&lt;h2&gt;Delivery&lt;/h2&gt;
&lt;p&gt;Distribution: ClickFix campaigns using fake GitHub download pages. Lure: a password-protected ZIP archive. Loader: a shell script that fetches and executes the main payload. &lt;a href=&quot;/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing/&quot;&gt;ClickFix&lt;/a&gt; is social engineering, not a software exploit — it instructs users to paste and run attacker-supplied terminal commands to &quot;install&quot; what appears to be a legitimate download. No CVE. No patch. The attack surface is the user.&lt;/p&gt;
&lt;h2&gt;What it steals&lt;/h2&gt;
&lt;p&gt;Standard infostealer scope: credentials from 16 Chromium-based browsers (Chrome, Edge, Arc, Brave, Vivaldi, Opera, Chromium, and others), Apple Notes, local documents, cryptocurrency wallet data, keychain contents, and the macOS admin password captured during execution.&lt;/p&gt;
&lt;h2&gt;The stream module&lt;/h2&gt;
&lt;p&gt;The distinguishing capability: AmnesiaStealer includes a streaming module that duplicates the victim&apos;s browser profile in headless mode and establishes a WebSocket connection to an operator relay. Attackers receive a live screencast at approximately 3fps with full keyboard, mouse, and navigation control.&lt;/p&gt;
&lt;p&gt;Practical impact: authenticated sessions — corporate SSO, banking, webmail — remain live inside the hijacked headless profile. Operators can interact directly without needing to extract and replay session tokens. The stolen credentials become secondary; the active session is the primary target.&lt;/p&gt;
&lt;h2&gt;Attribution and lineage&lt;/h2&gt;
&lt;p&gt;Jamf identified template overlap with Atomic Stealer and MacSync infostealer code — shared builder or codebase, likely. Specific threat actor attribution: unconfirmed.&lt;/p&gt;
&lt;p&gt;This follows a pattern Jamf documented with &lt;a href=&quot;/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf/&quot;&gt;PamStealer&lt;/a&gt; in July — macOS infostealers iterating quickly, borrowing code, adding credential-extraction primitives with each generation.&lt;/p&gt;
&lt;h2&gt;Mitigation&lt;/h2&gt;
&lt;p&gt;No software patch applies. Defense posture:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Users&lt;/strong&gt;: Don&apos;t execute terminal commands from instructions found online unless you understand exactly what they do. Legitimate software installers don&apos;t require this.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enterprise macOS fleets&lt;/strong&gt;: Enforce MDM behavioral policies (Jamf Pro or equivalent) with alerts on unexpected process spawning.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EDR&lt;/strong&gt;: Flag headless Chromium process execution and Chrome Safe Storage key access outside expected parent processes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Incident response&lt;/strong&gt;: If compromise is suspected, assume all saved browser credentials and active sessions are compromised. Rotate passwords and revoke active sessions across all services accessed from that machine.&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-amnesiastealer-macos-browser-hijack/cover.jpg" medium="image" width="1200" height="675"/><category>AmnesiaStealer</category><category>macOS malware</category><category>ClickFix</category><category>infostealer</category><category>browser hijacking</category><category>Jamf</category><category>keychain</category></item><item><title>Critical Flaws in Pods, Link Library Hit WordPress Sites</title><link>https://0daynews.com/articles/2026-08-16-wordpress-pods-link-library-critical-vulns/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-wordpress-pods-link-library-critical-vulns/</guid><description>Pods (CVSS 9.8) and Link Library (CVSS 9.1) expose WordPress sites to unauthenticated privilege escalation and arbitrary file deletion with RCE potential.</description><pubDate>Sun, 16 Aug 2026 22:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Two critical vulnerability disclosures this week for WordPress plugins. The &lt;a href=&quot;https://wordpress.org/plugins/pods/&quot;&gt;Pods – Custom Content Types and Fields&lt;/a&gt; plugin carries a CVSS 9.8 privilege escalation (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-19598&quot;&gt;CVE-2026-19598&lt;/a&gt;) reachable without authentication. The &lt;a href=&quot;https://wordpress.org/plugins/link-library/&quot;&gt;Link Library&lt;/a&gt; plugin patches an unauthenticated arbitrary file deletion flaw rated CVSS 9.1 (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-18855&quot;&gt;CVE-2026-18855&lt;/a&gt;) that can cascade to remote code execution under a specific non-default configuration. Both are patched. Both require attention.&lt;/p&gt;
&lt;h2&gt;Pods: Authorization That Doesn&apos;t&lt;/h2&gt;
&lt;p&gt;Pods is infrastructure — the kind of plugin that manages custom post types, taxonomies, and field schemas across complex WordPress deployments. It&apos;s quiet until something goes wrong.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-19598&quot;&gt;CVE-2026-19598&lt;/a&gt; is in the &lt;code&gt;pods_admin&lt;/code&gt; AJAX router. When WordPress processes requests through the JSON meta-box-loader compatibility path, the router funnels its access checks — login enforcement, capability verification, nonce validation — through &lt;code&gt;pods_error()&lt;/code&gt;. Under that code path, &lt;code&gt;pods_error()&lt;/code&gt; logs failures to the PHP error log and returns &lt;code&gt;false&lt;/code&gt; rather than halting execution. Everything downstream proceeds regardless. An unauthenticated attacker who hits the right endpoint through the right path completes privileged operations without any valid session.&lt;/p&gt;
&lt;p&gt;All Pods versions through 3.3.9 are affected. Update via the WordPress plugin directory.&lt;/p&gt;
&lt;h2&gt;Link Library: A Conditional RCE&lt;/h2&gt;
&lt;p&gt;Link Library manages curated link collections. The flaw (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-18855&quot;&gt;CVE-2026-18855&lt;/a&gt;) is in &lt;code&gt;ll_delete_link_fields&lt;/code&gt;, which handles file cleanup when links are deleted. Insufficient path validation lets an unauthenticated attacker specify arbitrary file paths and remove files from the server.&lt;/p&gt;
&lt;p&gt;The RCE angle is real but conditional: it requires an administrator to have enabled &quot;Delete local file on link deletion,&quot; a setting that is off by default. With that option active, targeting &lt;code&gt;wp-config.php&lt;/code&gt; exposes the WordPress re-install flow. An attacker who triggers it gets to configure a new admin account and takes full control of the site.&lt;/p&gt;
&lt;p&gt;Worth checking immediately: whether that setting is enabled on any installation running Link Library. Disabling it removes the RCE pathway without a patch. The patch — update to the latest version through the plugin directory — closes the file deletion flaw entirely.&lt;/p&gt;
&lt;h2&gt;What to Do&lt;/h2&gt;
&lt;p&gt;Both plugins have updates available in the WordPress plugin directory. Operators running automated update management should confirm Pods and Link Library appear in their recent-change queue. For sites where immediate patching isn&apos;t possible, temporarily disabling either plugin is the safer interim choice — Pods especially, given the unauthenticated privilege escalation doesn&apos;t require any non-default configuration to exploit.&lt;/p&gt;
&lt;p&gt;This is the third consecutive week of critical plugin disclosures on WordPress. That isn&apos;t unusual — the ecosystem spans tens of thousands of plugins maintained by teams of varying size, and dedicated security review isn&apos;t standard practice across most of them. The fixes exist. The open question is always the gap between patch date and update date.&lt;/p&gt;
&lt;p&gt;Previous WordPress coverage this week: &lt;a href=&quot;/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98&quot;&gt;Patch Now: Critical Auth Bypass Hits WordPress Plugins&lt;/a&gt; (August 15) and &lt;a href=&quot;/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript&quot;&gt;WordPress 7.0.4 Patches High-Severity RCE Flaw&lt;/a&gt; (August 14).&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-wordpress-pods-link-library-critical-vulns/cover.jpg" medium="image" width="1200" height="675"/><category>wordpress</category><category>CVE-2026-19598</category><category>CVE-2026-18855</category><category>privilege-escalation</category><category>arbitrary-file-deletion</category><category>pods</category><category>link-library</category></item><item><title>SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed</title><link>https://0daynews.com/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce/</guid><description>SiYuan v3.7.4 patches eleven CVEs including critical Electron XSS-to-RCE chains and a CVSS 9.8 auth bypass. Desktop users should update immediately.</description><pubDate>Sun, 16 Aug 2026 20:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Eleven CVEs. Five critical. All patched in SiYuan v3.7.4.&lt;/p&gt;
&lt;p&gt;The open-source self-hosted note-taking and knowledge management app published the release on August 15 via coordinated GitHub Security Advisories. No active exploitation confirmed at time of publication — treat that as a narrow window, not a grace period. Public proof-of-concept conditions exist for the XSS attack surfaces.&lt;/p&gt;
&lt;h2&gt;The Electron Problem&lt;/h2&gt;
&lt;p&gt;SiYuan runs an Electron desktop client with Node.js integration enabled. In this configuration, a stored cross-site scripting vulnerability that would be contained damage in a browser becomes arbitrary code execution on the host system. The kernel binds to &lt;code&gt;127.0.0.1&lt;/code&gt; by default, but that&apos;s cold comfort when five separate injection paths lead to the same outcome.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73043&quot;&gt;CVE-2026-73043&lt;/a&gt; — CVSS 9.0, Critical.&lt;/strong&gt; The Template calculation operator renders user-authored Go templates without sanitization and stores output verbatim. Attackers inject HTML and JavaScript into template calculations; the Electron renderer executes them with Node integration enabled. Code execution when the database is opened. No special privilege required — any user who can author a template qualifies.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73044&quot;&gt;CVE-2026-73044&lt;/a&gt; — CVSS 9.0, Critical.&lt;/strong&gt; Table column width values written via the &lt;code&gt;setAttrViewColWidth&lt;/code&gt; API are injected into style attributes without escaping. Injected event handlers fire on every table cell render.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73041&quot;&gt;CVE-2026-73041&lt;/a&gt; — CVSS 9.0, Critical.&lt;/strong&gt; Annotation fields saved by the &lt;code&gt;setFileAnnotation&lt;/code&gt; endpoint are rendered unsanitized in the PDF viewer, which also runs with Node.js access. Malicious markup executes when a user opens an annotated PDF.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73042&quot;&gt;CVE-2026-73042&lt;/a&gt; — CVSS 9.0, Critical.&lt;/strong&gt; Database menu metadata — group names, view names, field descriptions — is interpolated directly into HTML. Injected markup breaks out of containing elements and runs event handlers when users open group, view, or field-edit menus.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73053&quot;&gt;CVE-2026-73053&lt;/a&gt; — CVSS 9.0, Critical.&lt;/strong&gt; The &lt;code&gt;unicode2Emoji&lt;/code&gt; function fails to sanitize codepoint branch output. Crafted document icons with hex-encoded markup execute in the renderer.&lt;/p&gt;
&lt;p&gt;Additional stored XSS paths fixed in the same release: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73050&quot;&gt;CVE-2026-73050&lt;/a&gt; (CVSS 9.0, color field in attribute-view select options, eight unescaped render sites) and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73052&quot;&gt;CVE-2026-73052&lt;/a&gt; (CVSS 9.0, attribute-view field names injected via &lt;code&gt;innerHTML&lt;/code&gt; in the sort menu).&lt;/p&gt;
&lt;h2&gt;Authentication Failures&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73046&quot;&gt;CVE-2026-73046&lt;/a&gt; — CVSS 9.8, Critical.&lt;/strong&gt; The most severe in the batch. The &lt;code&gt;CheckAuth()&lt;/code&gt; middleware guards the &lt;code&gt;/api/*&lt;/code&gt; surface via HTTP Basic Authentication, accepting the workspace access code as the Basic Auth password. The Basic Auth branch never consults the CAPTCHA gate or increments the failure counter used by the cookie/session login path. Result: unauthenticated remote attackers can brute-force the admin access code with unlimited automated requests. No lockout. No rate limit.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73054&quot;&gt;CVE-2026-73054&lt;/a&gt; — CVSS 7.5, High.&lt;/strong&gt; WebSocket endpoint authentication bypassed via differential parsing of duplicated query parameters. The exemption check and the session quarantine check interpret the URI differently; a crafted WebSocket URI with duplicated parameters clears auth and receives the live kernel event stream — document identifiers, titles, operation logs.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73045&quot;&gt;CVE-2026-73045&lt;/a&gt; — CVSS 7.5, High.&lt;/strong&gt; Per-notebook publish passwords at &lt;code&gt;authFilePublishAccess&lt;/code&gt; have no rate limiting or CAPTCHA. Unbounded brute-force against published notebook passwords.&lt;/p&gt;
&lt;h2&gt;Server-Side Template Injection&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73047&quot;&gt;CVE-2026-73047&lt;/a&gt; — CVSS 6.2, Medium.&lt;/strong&gt; The attribute-view Template calculation feature (added in v3.7.0-beta.1) uses Sprig&apos;s unmodified function map, including &lt;code&gt;env&lt;/code&gt;, &lt;code&gt;expandenv&lt;/code&gt;, and &lt;code&gt;getHostByName&lt;/code&gt; — functions removed from Sprig elsewhere specifically to address &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2024-55660&quot;&gt;CVE-2024-55660&lt;/a&gt;. The kernel binds to localhost by default, but any local unauthenticated process can inject a malicious template. Exploitation confirmed possible; exploitation in the wild unconfirmed.&lt;/p&gt;
&lt;h2&gt;Exploitation Status&lt;/h2&gt;
&lt;p&gt;Active exploitation: &lt;strong&gt;unconfirmed&lt;/strong&gt; at time of publication. All disclosures originate from the siyuan-note &lt;a href=&quot;https://github.com/siyuan-note/siyuan/security/advisories&quot;&gt;GitHub Security Advisories&lt;/a&gt;, published coordinated with the v3.7.4 release. The XSS attack surfaces — column widths, field names, color values, document icons — are trivially reachable by any user who can edit a document or database. Treat exploitability as high.&lt;/p&gt;
&lt;p&gt;Analysis: the Electron architecture is the force multiplier across all five XSS-to-RCE paths. The pattern is well-established and recurring; see also the &lt;a href=&quot;https://0daynews.com/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook&quot;&gt;Electron desktop client attack chain documented in July&lt;/a&gt;. Content isolation was not enabled. The same class of issue has burned other Electron apps before and will again until Node integration is disabled by default.&lt;/p&gt;
&lt;h2&gt;What to Do&lt;/h2&gt;
&lt;p&gt;Update to &lt;a href=&quot;https://github.com/siyuan-note/siyuan/releases/tag/v3.7.4&quot;&gt;SiYuan v3.7.4&lt;/a&gt;. All eleven CVEs are fixed in this release.&lt;/p&gt;
&lt;p&gt;If you were running an exposed SiYuan instance — even LAN-accessible only — treat the workspace access code as potentially enumerated given the CVE-2026-73046 brute-force window. Rotate it post-patch.&lt;/p&gt;
&lt;p&gt;Published notebooks with per-notebook passwords: consider those passwords potentially compromised. Reset and re-notify authorized readers.&lt;/p&gt;
&lt;p&gt;WebSocket event stream: if the endpoint was externally accessible, audit connection logs for unexpected sessions prior to the patch.&lt;/p&gt;
&lt;p&gt;Full advisory index: &lt;a href=&quot;https://github.com/siyuan-note/siyuan/security/advisories&quot;&gt;siyuan-note Security Advisories on GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Related coverage: &lt;a href=&quot;/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript&quot;&gt;WordPress 7.0.4 RCE via Imagick&lt;/a&gt; · &lt;a href=&quot;/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98&quot;&gt;WordPress plugin auth bypass CVSS 9.8&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce/cover.jpg" medium="image" width="1200" height="675"/><category>siyuan</category><category>rce</category><category>electron</category><category>xss</category><category>auth-bypass</category><category>cve</category><category>note-taking</category></item><item><title>Threema Hit by Large-Scale DDoS, Service Disrupted</title><link>https://0daynews.com/articles/2026-08-16-threema-ddos-service-disruption/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-threema-ddos-service-disruption/</guid><description>Multiple large-scale DDoS attacks disrupted Threema&apos;s secure messaging service this week. No message content breach — availability impact only.</description><pubDate>Sun, 16 Aug 2026 17:30:00 GMT</pubDate><content:encoded>&lt;p&gt;Confirmed: multiple large-scale distributed denial-of-service attacks hit Threema this week, causing severe disruptions to the secure messaging service. Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/&quot;&gt;BleepingComputer&lt;/a&gt;, 2026-08-16.&lt;/p&gt;
&lt;p&gt;Threema is an end-to-end encrypted messaging platform with a user base spanning privacy-focused consumers, European enterprises, and government clients. This is an availability incident — no indication of cryptographic compromise, data breach, or unauthorized access to message content.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Confirmed:&lt;/strong&gt; Service disruption to communications. Attacks described as large-scale.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unconfirmed:&lt;/strong&gt; Attacker identity. Motivation. Current service status — check &lt;a href=&quot;https://threema.ch&quot;&gt;Threema&apos;s official status channels&lt;/a&gt; directly rather than relying on this article.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For orgs running Threema as primary secure comms:&lt;/strong&gt; assess your fallback channel now. High-confidence encrypted messaging services remain soft targets for availability attacks — the encryption holds, but the pipe can be flooded. If real-time communications are mission-critical, redundancy isn&apos;t optional.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Analysis&lt;/strong&gt; (treat as speculative — no attribution evidence as of publication): DDoS campaigns against secure messaging services have historically coincided with geopolitical stress events. Threema&apos;s European government contracts and privacy posture make it a persistent interest point for adversaries whose operational interest includes disrupting encrypted communications channels. No evidence linking this incident to a known threat actor or active campaign. Attribution unknown — treat accordingly.&lt;/p&gt;
&lt;p&gt;Related: &lt;a href=&quot;/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay/&quot;&gt;Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies&lt;/a&gt; — evolving botnet infrastructure enabling large-scale traffic attacks; &lt;a href=&quot;/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer/&quot;&gt;Mirai Variant With Encrypted C2 and Credential Sniffer&lt;/a&gt; — growing commodity DDoS toolchain.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-threema-ddos-service-disruption/cover.jpg" medium="image" width="1200" height="675"/><category>DDoS</category><category>Threema</category><category>secure messaging</category><category>availability</category><category>disruption</category></item><item><title>August Kernel Drop: The Enterprise CVEs Nobody Wrote About</title><link>https://0daynews.com/articles/2026-08-16-august-kernel-drop-enterprise-cves/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-august-kernel-drop-enterprise-cves/</guid><description>Thirty-plus kernel CVEs hit NVD on August 15. Three affecting ThunderboltIP, NVMe-oF auth, and TPM matter to enterprise infrastructure and flew under radar.</description><pubDate>Sun, 16 Aug 2026 16:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The August 15 Linux stable drop put thirty-plus CVEs on NVD in a single day. The &lt;a href=&quot;/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/&quot;&gt;WiFi heap overflow&lt;/a&gt;, the &lt;a href=&quot;/articles/2026-08-16-linux-kernel-can-subsystem-race-condition-patch-wave/&quot;&gt;CAN subsystem race cluster&lt;/a&gt;, and the &lt;a href=&quot;/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044/&quot;&gt;SMB server stack overflow&lt;/a&gt; all got written up within hours. That is, predictably, not the full picture.&lt;/p&gt;
&lt;p&gt;Three fixes in the same batch affect infrastructure that runs in enterprise data centers, storage networks, and secure computing environments. They did not trend. They are worth your attention regardless.&lt;/p&gt;
&lt;h2&gt;CVE-2026-72157 — ThunderboltIP frags[] overflow&lt;/h2&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://git.kernel.org/stable/c/2b3b4e5ff5a58ad32817824b0310e63908b12052&quot;&gt;kernel.org stable commit&lt;/a&gt;, NVD entry published 2026-08-15. No CVSS score assigned as of publication.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;tbnet_poll()&lt;/code&gt; in the kernel&apos;s ThunderboltIP driver assembles multi-frame packets by adding each subsequent frame as a page fragment to the skb. &lt;code&gt;skb_add_rx_frag()&lt;/code&gt; runs up to &lt;code&gt;frame_count - 1&lt;/code&gt; times without checking &lt;code&gt;skb_shinfo(skb)-&gt;nr_frags&lt;/code&gt; against &lt;code&gt;MAX_SKB_FRAGS&lt;/code&gt; (17 on x86). A peer sending a packet with more than 18 frames overflows the &lt;code&gt;frags[]&lt;/code&gt; array — a kernel heap corruption condition. The patch bounds &lt;code&gt;frame_count&lt;/code&gt; before the loop starts.&lt;/p&gt;
&lt;p&gt;Attack prerequisite: a malicious or compromised peer on a Thunderbolt connection. ThunderboltIP is used for direct device-to-device networking — Mac-to-Mac, workstation-to-NAS, cross-device docking. Physical access or supply-chain compromise of an attached device is the relevant threat model, not remote exploitation. In enterprise environments where Thunderbolt networking is used for high-speed workstation-to-storage transfers, a malicious or tampered dock is the exposure.&lt;/p&gt;
&lt;h2&gt;CVE-2026-72130 — NVMe-oF auth short-buffer heap overflow&lt;/h2&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://git.kernel.org/stable/c/2eaa3ad450141cfcf187bb43cb8335eb336b5f87&quot;&gt;kernel.org stable commit&lt;/a&gt;, NVD entry published 2026-08-15. No CVSS score assigned as of publication.&lt;/p&gt;
&lt;p&gt;NVMe over Fabrics implements DH-HMAC-CHAP authentication between initiator and target. &lt;code&gt;nvmet_execute_auth_receive()&lt;/code&gt; on the target validates that the AUTH_RECEIVE allocation length is nonzero and matches the transfer length — but does not verify it is large enough for the fixed-size response structures. In the &lt;code&gt;SUCCESS1&lt;/code&gt; and &lt;code&gt;FAILURE1&lt;/code&gt; states, &lt;code&gt;nvmet_auth_success1()&lt;/code&gt; and &lt;code&gt;nvmet_auth_failure1()&lt;/code&gt; write a fixed-size DH-HMAC-CHAP response into that buffer without further size validation. A short-but-nonzero allocation length supplied by a remote initiator writes past the end of the heap allocation. The fix validates the allocation length against the response size before committing.&lt;/p&gt;
&lt;p&gt;Prerequisite: a compromised or malicious NVMe-oF initiator on the fabric. In environments using in-kernel NVMe target support (&lt;code&gt;nvmet&lt;/code&gt;), any host able to reach the target port can trigger this depending on fabric ACLs. NVMe/TCP extends that exposure to standard Ethernet-connected storage networks — no InfiniBand required.&lt;/p&gt;
&lt;p&gt;This is the class of bug — fixed-size response, caller-supplied buffer size, no minimum check — that recurs in cryptographic handshake code across the industry. Per-protocol reinvention of authenticated key exchange tends to produce it. This is not the first time NVMe-oF auth code has needed this kind of review, and it will not be the last.&lt;/p&gt;
&lt;h2&gt;CVE-2026-72135 — TPM character device pread() OOB read&lt;/h2&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://git.kernel.org/stable/c/21a13f932972bc9836f58c44fcd47c62abdecd95&quot;&gt;kernel.org stable commit&lt;/a&gt;, NVD entry published 2026-08-15. No CVSS score assigned as of publication.&lt;/p&gt;
&lt;p&gt;TPM character devices (&lt;code&gt;/dev/tpm0&lt;/code&gt;, &lt;code&gt;/dev/tpmrm0&lt;/code&gt;) expose a sequential command-response interface but were registered with &lt;code&gt;FMODE_PREAD&lt;/code&gt; and &lt;code&gt;FMODE_PWRITE&lt;/code&gt; enabled, permitting &lt;code&gt;pread()&lt;/code&gt; with arbitrary offsets. &lt;code&gt;tpm_common_read()&lt;/code&gt; bounds the transfer length against &lt;code&gt;response_length&lt;/code&gt; but passes &lt;code&gt;*off&lt;/code&gt; unchecked into &lt;code&gt;data_buffer + *off&lt;/code&gt;. An out-of-bounds read follows for any offset past the response buffer.&lt;/p&gt;
&lt;p&gt;Access to a TPM character device is privileged but not root-only in configurations where a service account has been granted TPM access — which includes several TPM attestation and key management setups. Less severe than the two networking bugs above, and no exploitation reported. The fix marks TPM character devices non-seekable via &lt;code&gt;nonseekable_open()&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;The recurring pattern&lt;/h2&gt;
&lt;p&gt;Three CVEs in one batch, three different subsystems, the same structural failure each time: an integer or size value arriving from a peer or caller was not validated against the fixed-size structure it populated. This is not a novel bug class. The kernel&apos;s networking and storage stack is large enough that no single team reviews all of it with equal depth, and the result is that the same mistake recurs in different code paths, across different subsystem development histories, until a KCSAN run or a careful reader surfaces it.&lt;/p&gt;
&lt;p&gt;The WiFi and CAN fixes got the headlines because WiFi and CAN have broad consumer exposure and known weaponization histories. ThunderboltIP, NVMe-oF, and TPM do not have that reputation — which is the same mistake, just operating on a different set of assumptions about what matters.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;p&gt;Update to the current Linux stable release. None of these three have confirmed exploitation in the wild as of publication; none are on CISA&apos;s KEV list. The patch is the remediation.&lt;/p&gt;
&lt;p&gt;For environments with specific exposure: review whether ThunderboltIP is actually in use and disable it if not; audit NVMe-oF target ACLs and fabric segmentation to minimize the set of hosts that can reach authentication endpoints; review TPM device permissions for non-root service accounts.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Related coverage from the same August 15 stable drop: &lt;a href=&quot;/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/&quot;&gt;brcmfmac WiFi heap overflow and BPF verifier fix&lt;/a&gt;, &lt;a href=&quot;/articles/2026-08-16-linux-kernel-can-subsystem-race-condition-patch-wave/&quot;&gt;CAN subsystem 14-CVE race cluster&lt;/a&gt;, &lt;a href=&quot;/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044/&quot;&gt;ksmbd SMB server stack overflow&lt;/a&gt;, &lt;a href=&quot;/articles/2026-08-16-linux-dm-luks-key-wipe-cve-2026-72103/&quot;&gt;dm-crypt LUKS key wipe&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-august-kernel-drop-enterprise-cves/cover.jpg" medium="image" width="1200" height="675"/><category>linux kernel</category><category>thunderbolt</category><category>nvme-of</category><category>tpm</category><category>heap overflow</category><category>enterprise security</category><category>stable kernel</category></item><item><title>Linux Kernel Patches WiFi Heap Overflow, BPF Bypass</title><link>https://0daynews.com/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/</guid><description>August 15 kernel stable drop fixes a Broadcom WiFi heap overflow triggerable by a rogue AP, a BPF verifier bypass, and 28 other security fixes.</description><pubDate>Sun, 16 Aug 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Thirty-plus Linux kernel CVEs landed on NVD on August 15. Most are maintenance-level. Four are security-relevant.&lt;/p&gt;
&lt;p&gt;All four listed below are published and confirmed on NVD as of August 15, 2026. No CVSS scores have been assigned yet — severity assessments are based on the described impact in each NVD entry, not editorial guess.&lt;/p&gt;
&lt;h2&gt;CVE-2026-72003 — brcmfmac WiFi heap overflow&lt;/h2&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-72003&quot;&gt;NVD entry for CVE-2026-72003&lt;/a&gt;, published 2026-08-15.&lt;/p&gt;
&lt;p&gt;The Broadcom WiFi driver (&lt;code&gt;brcmfmac&lt;/code&gt;) processes 802.11 auth frames without enforcing a minimum length before reading fixed-size fields from the frame body. When &lt;code&gt;mgmt_frame_len&lt;/code&gt; is below the management header offset (24 bytes), an unsigned subtraction wraps to a very large value and the subsequent &lt;code&gt;memcpy&lt;/code&gt; runs far past the allocated kernel buffer.&lt;/p&gt;
&lt;p&gt;Attack precondition: a malicious or malfunctioning access point sends a short auth frame during an external SAE auth exchange. Per the NVD description: &quot;A malicious or malfunctioning AP can make the frame short during the external SAE auth exchange, so this is a remotely triggered heap overflow.&quot; Physical proximity to the rogue AP is required. No prior authentication or credentials are needed.&lt;/p&gt;
&lt;p&gt;Affected: systems running the upstream &lt;code&gt;brcmfmac&lt;/code&gt; driver. Broadcom 802.11 chips are common in consumer laptops, embedded devices, and single-board computers. Patch is in stable.&lt;/p&gt;
&lt;h2&gt;CVE-2026-68479 — Bluetooth btrtl firmware bounds&lt;/h2&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-68479&quot;&gt;NVD entry for CVE-2026-68479&lt;/a&gt;, published 2026-08-15.&lt;/p&gt;
&lt;p&gt;The Realtek Bluetooth firmware loader (&lt;code&gt;btrtl&lt;/code&gt;) copies firmware patch data without verifying that the patch is long enough to contain the version suffix it subsequently appends. A malformed firmware image shorter than the version field underflows the length calculation, producing an oversized heap read and write during Bluetooth device setup.&lt;/p&gt;
&lt;p&gt;Attack vector is the firmware image, not over-the-air. Relevant threat models: supply-chain tampering or local firmware replacement. Lower immediacy than CVE-2026-72003.&lt;/p&gt;
&lt;h2&gt;CVE-2026-68462 — BPF verifier negative constant offset&lt;/h2&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-68462&quot;&gt;NVD entry for CVE-2026-68462&lt;/a&gt;, published 2026-08-15.&lt;/p&gt;
&lt;p&gt;The eBPF verifier correctly blocked variable offsets for &lt;code&gt;PTR_TO_TP_BUFFER&lt;/code&gt; and &lt;code&gt;PTR_TO_BUF&lt;/code&gt; accesses but accepted constant negative offsets produced by pointer arithmetic — a gap created when commit &lt;code&gt;022ac0750883&lt;/code&gt; moved constant offsets from &lt;code&gt;reg-&gt;off&lt;/code&gt; to &lt;code&gt;reg-&gt;var_off&lt;/code&gt;. A crafted BPF program with a constant offset of, for example, -8 and an instruction offset of zero would pass verification and load cleanly.&lt;/p&gt;
&lt;p&gt;The BPF sandbox verifier is the primary isolation boundary for untrusted BPF programs. Out-of-bounds paths through the verifier have historically produced local privilege escalation. This patch closes one such path.&lt;/p&gt;
&lt;h2&gt;CVE-2026-72014 — DRBD peer-supplied size underflow&lt;/h2&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-72014&quot;&gt;NVD entry for CVE-2026-72014&lt;/a&gt;, published 2026-08-15.&lt;/p&gt;
&lt;p&gt;The DRBD distributed block device driver processes data reply frames from peers. Per NVD: &quot;two peer-controlled inputs can make [data_size] negative&quot; — either a digest underflow when an integrity algorithm is in use, or an integer truncation from the wire length field in the default configuration. The subsequent I/O call then runs with a size of &lt;code&gt;SIZE_MAX&lt;/code&gt;, corrupting kernel memory past the first mapped page.&lt;/p&gt;
&lt;p&gt;A diskless DRBD node or one using read-balancing to a peer is exposed in the default configuration. Requires a compromised, malicious, or man-in-the-middle DRBD peer.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;No exploitation confirmed in the wild for any of these four — unconfirmed, treat accordingly. No CISA KEV additions for this batch as of publication. Update to the latest stable kernel; the fixes are in stable.&lt;/p&gt;
&lt;p&gt;Priority order for patching: CVE-2026-72003 first — proximity-triggerable WiFi heap overflows have historically had short timelines between disclosure and weaponization.&lt;/p&gt;
&lt;p&gt;Related: &lt;a href=&quot;/articles/2026-07-03-bad-epoll-linux-kernel-lpe-cve-2026-46242/&quot;&gt;Bad Epoll: Linux Kernel LPE CVE-2026-46242&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/cover.jpg" medium="image" width="1200" height="675"/><category>linux kernel</category><category>brcmfmac</category><category>wifi</category><category>heap overflow</category><category>bpf</category><category>cve-2026-72003</category><category>cve-2026-68462</category></item><item><title>Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies</title><link>https://0daynews.com/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay/</guid><description>Fortinet researchers track Evooo1Bot, a Mirai-based modular Linux botnet hijacking routers as SOCKS5 relays with DDoS and credential-sniffing capability.</description><pubDate>Sun, 16 Aug 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Active since July. Confirmed by Fortinet researchers. A Mirai-based modular Linux botnet — Evooo1Bot — is compromising internet-facing gateway devices and converting them into SOCKS5 traffic relay nodes.&lt;/p&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/&quot;&gt;BleepingComputer — New Evooo1Bot Linux botnet turns routers into traffic relay nodes&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Target range&lt;/h2&gt;
&lt;p&gt;Confirmed exposed targets: gateway devices from Alcatel, NETGEAR, Tenda, TP-Link, D-Link, Telesquare, and Zyxel. Later variants extended scope to Hikvision cameras, D-Link NAS devices, and server-side software including Atlassian Confluence, WSO2 products, and Kubernetes ingress-nginx controllers.&lt;/p&gt;
&lt;p&gt;Target list is expanding — unconfirmed whether additional products are in scope.&lt;/p&gt;
&lt;h2&gt;How it lands&lt;/h2&gt;
&lt;p&gt;Exploitation module targeting known vulnerabilities. Successful compromise triggers download of one of twelve architecture-matched payload builds. Bash history cleared post-infection. Specific CVEs exploited: not disclosed in Fortinet&apos;s published analysis.&lt;/p&gt;
&lt;h2&gt;What it does&lt;/h2&gt;
&lt;p&gt;Primary capability: SOCKS5 proxy. Supports direct listening and reverse-relay modes with multiple simultaneous sessions. The relay function routes attacker traffic through the victim device, masking origin — useful for credential stuffing, exfiltration staging, and evading geographic blocks or rate limits.&lt;/p&gt;
&lt;p&gt;Additional modules confirmed:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Encrypted C2 over port 443&lt;/li&gt;
&lt;li&gt;SSH brute-force using 150 credential pairs&lt;/li&gt;
&lt;li&gt;Credential sniffing targeting HTTP Basic Auth and Cookie headers&lt;/li&gt;
&lt;li&gt;16 DDoS flood methods: UDP, DNS, SYN, ACK, GRE, HTTP variants&lt;/li&gt;
&lt;li&gt;Interactive shell with file transfer&lt;/li&gt;
&lt;li&gt;Anti-analysis checks: debugger detection, security tool detection, sandbox and VM fingerprinting&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Persistence: systemd, SysV init, shell profiles, rc.local, and cron. The cron entry re-downloads the implant every five minutes if removed.&lt;/p&gt;
&lt;h2&gt;Exposure and mitigation&lt;/h2&gt;
&lt;p&gt;Firmware current: required. Default credentials in use: change them. Remote management exposed to internet: disable. Devices beyond vendor support: retire, not patch.&lt;/p&gt;
&lt;p&gt;No CISA KEV additions for this activity as of this writing — unconfirmed, treat accordingly.&lt;/p&gt;
&lt;p&gt;Related: &lt;a href=&quot;/articles/2026-07-03-fbi-netnut-popa-botnet-takedown/&quot;&gt;FBI, Europol Dismantle NetNut/POPA Botnet Proxy Network&lt;/a&gt; · &lt;a href=&quot;/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet/&quot;&gt;Unit 42 Tracks TuxBot v3 IoT Botnet&lt;/a&gt; · &lt;a href=&quot;/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/&quot;&gt;Linux brcmfmac WiFi Heap Overflow&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay/cover.jpg" medium="image" width="1200" height="675"/><category>evooo1bot</category><category>botnet</category><category>mirai</category><category>linux</category><category>socks5</category><category>router</category><category>proxy</category><category>fortinet</category></item><item><title>Linux CAN Subsystem Gets 14-CVE Race Condition Fix Wave</title><link>https://0daynews.com/articles/2026-08-16-linux-kernel-can-subsystem-race-condition-patch-wave/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-linux-kernel-can-subsystem-race-condition-patch-wave/</guid><description>The August 15 Linux stable drop patches 14 CVEs in the CAN broadcast manager and ISO 15765-2 transport: data races and use-after-frees.</description><pubDate>Sun, 16 Aug 2026 10:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The August 15 Linux stable drop patched fourteen CVEs in the kernel&apos;s CAN subsystem — twelve in &lt;code&gt;can: bcm&lt;/code&gt; (CAN broadcast manager) and two in &lt;code&gt;can: isotp&lt;/code&gt; (ISO 15765-2 transport protocol). The bugs are data races and use-after-free conditions that surfaced through KCSAN (the kernel concurrency sanitizer) and code review. None have confirmed exploitation in the wild. The affected drivers ship in any Linux build with CAN socket support, which includes vehicle infotainment systems, factory automation controllers, and embedded industrial hardware running kernels from 2020 onward.&lt;/p&gt;
&lt;h2&gt;The bcm cluster&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;can: bcm&lt;/code&gt; provides a higher-level CAN interface: programmable filters, TX cycling, rate throttling, and RX timeout handling. The twelve CVEs are concentrated in the intersection of the bcm socket lifecycle and CAN device unregistration — a notoriously difficult concurrency surface because device removal can race with any open socket operation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2026-72123&lt;/strong&gt; — the most structurally notable in the batch — is a use-after-free in the throttle timer path. A 2024 commit replaced &lt;code&gt;synchronize_rcu()&lt;/code&gt; with &lt;code&gt;call_rcu()&lt;/code&gt; in &lt;code&gt;bcm_delete_rx_op()&lt;/code&gt; to avoid blocking, but omitted the corresponding &lt;code&gt;RX_NO_AUTOTIMER&lt;/code&gt; check in the fast-path packet receiver. A concurrent &lt;code&gt;bcm_rx_handler()&lt;/code&gt; can re-arm the timer on an op already scheduled for deferred free, producing a timer UAF. The fix moves the rx_op deallocation to a workqueue so the timer cannot fire after teardown is committed. Source: &lt;a href=&quot;https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9&quot;&gt;git.kernel.org&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2026-72122&lt;/strong&gt; is a lockless race in &lt;code&gt;bcm_sendmsg()&lt;/code&gt;, which reads &lt;code&gt;bo-&gt;ifindex&lt;/code&gt; and checks &lt;code&gt;bo-&gt;bound&lt;/code&gt; before acquiring &lt;code&gt;lock_sock()&lt;/code&gt;. &lt;code&gt;bcm_notify()&lt;/code&gt; (device unregister) and &lt;code&gt;bcm_connect()&lt;/code&gt; (concurrent bind from another thread) both mutate both fields under the same lock. Because the lockless reads and locked writes are unordered, a racing notify or connect can produce a silent &lt;code&gt;RX_SETUP&lt;/code&gt; failure — the call returns no error, but frame delivery is not re-enabled for the updated filter. Source: &lt;a href=&quot;https://git.kernel.org/stable/c/0f6f9f95294b4cbb26ba02209e893e3bd91237c3&quot;&gt;git.kernel.org&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2026-72121&lt;/strong&gt; (&lt;a href=&quot;https://git.kernel.org/stable/c/19b1994069dd29478ba767de1f98f14a088198dc&quot;&gt;source&lt;/a&gt;), &lt;strong&gt;CVE-2026-72119&lt;/strong&gt; (&lt;a href=&quot;https://git.kernel.org/stable/c/12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc&quot;&gt;source&lt;/a&gt;), &lt;strong&gt;CVE-2026-72117&lt;/strong&gt; (&lt;a href=&quot;https://git.kernel.org/stable/c/136de17f38630307991c59aa7080012a99451783&quot;&gt;source&lt;/a&gt;), and &lt;strong&gt;CVE-2026-72118&lt;/strong&gt; (&lt;a href=&quot;https://git.kernel.org/stable/c/8104bcdb2612fdda95169ddc3b49747b2ff98d24&quot;&gt;source&lt;/a&gt;) are all KCSAN-detected data races: timer values (&lt;code&gt;ival1&lt;/code&gt;, &lt;code&gt;ival2&lt;/code&gt;, &lt;code&gt;kt_ival1&lt;/code&gt;, &lt;code&gt;kt_ival2&lt;/code&gt;), filter configuration (&lt;code&gt;nframes&lt;/code&gt;, &lt;code&gt;flags&lt;/code&gt;, &lt;code&gt;frames&lt;/code&gt;), and per-op statistics written concurrently from multiple CPUs without adequate locking. CVE-2026-72118 resolves the statistics race with atomic long operations in the hot packet-receive path.&lt;/p&gt;
&lt;p&gt;The remaining six bcm CVEs address missing RCU list annotations on bcm_op insertion and removal (CVE-2026-72120), stale rx/tx ops after device removal (CVE-2026-72116), missing frame length validation for RTR reply frames (CVE-2026-72114), device refcount leaks on filter teardown (CVE-2026-72113), and ANYDEV per-source interface tracking for timeout/throttle timers (CVE-2026-72115).&lt;/p&gt;
&lt;h2&gt;The isotp pair&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;can: isotp&lt;/code&gt; implements ISO 15765-2 — the segmentation and reassembly protocol used over CAN for automotive diagnostics (OBD-II) and ECU programming. It carries actual data between diagnostic tools and vehicle subsystems; bugs here are in production vehicles and aftermarket diagnostic hardware, not just test setups.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2026-72125&lt;/strong&gt; is a use-after-free with a window that opens during network device removal. &lt;code&gt;isotp_release()&lt;/code&gt; looked up the bound device via &lt;code&gt;dev_get_by_index()&lt;/code&gt; using a stored ifindex. The kernel removes the device from the ifindex hash &lt;em&gt;before&lt;/em&gt; firing &lt;code&gt;NETDEV_UNREGISTER&lt;/code&gt;, so a racing &lt;code&gt;isotp_release()&lt;/code&gt; can fail to find the device, skip &lt;code&gt;can_rx_unregister()&lt;/code&gt;, and proceed to free the socket while an in-flight isotp timer or RCU reader still holds a reference. Source: &lt;a href=&quot;https://git.kernel.org/stable/c/0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96&quot;&gt;git.kernel.org&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE-2026-72124&lt;/strong&gt; addresses the isotp TX state machine, which is driven by three concurrent contexts: &lt;code&gt;sendmsg()&lt;/code&gt;, the RX path consuming Flow Control and echo frames, and two hrtimers handling stall timeouts. &lt;code&gt;sendmsg()&lt;/code&gt; claimed the state with a lock-free &lt;code&gt;cmpxchg()&lt;/code&gt;; &lt;code&gt;hrtimer_cancel()&lt;/code&gt; calls elsewhere operated under &lt;code&gt;so-&gt;rx_lock&lt;/code&gt;. The mismatch left windows where a timer callback or frame receipt could race with send cleanup. All TX state transitions are now serialized under &lt;code&gt;so-&gt;rx_lock&lt;/code&gt;. Source: &lt;a href=&quot;https://git.kernel.org/stable/c/0b05eca9589f609e2491b528dccf683168a4cda8&quot;&gt;git.kernel.org&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Exposure and scope&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;can: bcm&lt;/code&gt; and &lt;code&gt;can: isotp&lt;/code&gt; are compiled in by &lt;code&gt;CONFIG_CAN_BCM&lt;/code&gt; and &lt;code&gt;CONFIG_CAN_ISOTP&lt;/code&gt; respectively. The vector requires local CAN socket access — creating a socket with &lt;code&gt;AF_CAN&lt;/code&gt;. That scopes the immediate threat to multi-user systems with CAN hardware, container environments where CAN interfaces are exposed, and any Linux endpoint with physical or network-adjacent CAN access, which is the standard operational profile for automotive ECU tooling and industrial CAN gateways.&lt;/p&gt;
&lt;p&gt;The race conditions are not reliably reproducible under normal load; KCSAN detected several only under stress testing. The UAFs (CVE-2026-72123, CVE-2026-72125) are more straightforwardly dangerous — deferred-free paths with live timers are a known exploitation target class.&lt;/p&gt;
&lt;p&gt;Update to the current Linux stable release. For embedded and automotive Linux images with fixed kernel versions — the common deployment model in ICS and vehicle ECU environments — identify which CVEs apply to your build configuration and prioritize CVE-2026-72123 and CVE-2026-72125 for any environment where CAN sockets are accessible from untrusted processes or external diagnostic ports.&lt;/p&gt;
&lt;p&gt;Today&apos;s August 15 stable drop also patched separate issues in the kernel&apos;s WiFi drivers, SMB server, and device-mapper subsystem — see coverage of &lt;a href=&quot;/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/&quot;&gt;CVE-2026-72003 (brcmfmac WiFi heap overflow)&lt;/a&gt;, &lt;a href=&quot;/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044/&quot;&gt;CVE-2026-72044 (ksmbd stack overflow)&lt;/a&gt;, and &lt;a href=&quot;/articles/2026-08-16-linux-dm-luks-key-wipe-cve-2026-72103/&quot;&gt;CVE-2026-72103 (dm LUKS key wipe)&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Nadia &quot;Loop&quot; Park</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-linux-kernel-can-subsystem-race-condition-patch-wave/cover.jpg" medium="image" width="1200" height="675"/><category>linux kernel</category><category>CAN bus</category><category>bcm</category><category>isotp</category><category>race condition</category><category>use-after-free</category><category>ics-ot</category></item><item><title>Linux dm Bug Silently Breaks LUKS Key Wipe</title><link>https://0daynews.com/articles/2026-08-16-linux-dm-luks-key-wipe-cve-2026-72103/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-linux-dm-luks-key-wipe-cve-2026-72103/</guid><description>Kernel refactoring regression in Linux device-mapper causes cryptsetup luksSuspend to silently fail to wipe the LUKS volume key. Patch is in stable.</description><pubDate>Sun, 16 Aug 2026 08:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;code&gt;cryptsetup luksSuspend&lt;/code&gt; is supposed to evict the LUKS volume key from kernel memory — that&apos;s the contract. &lt;a href=&quot;/cve/cve-2026-72103/&quot;&gt;CVE-2026-72103&lt;/a&gt;, published to NVD on August 15, documents that it has been silently breaking that contract on kernels carrying commit &lt;code&gt;a28d893eb327&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The commit in question, titled &quot;md: port block device access to file,&quot; was refactoring work. It didn&apos;t touch any obvious security boundary. What it did, as identified in the &lt;a href=&quot;https://git.kernel.org/stable/c/8ced1d242c34e342defcccdb00663354f212aae6&quot;&gt;stable fix&lt;/a&gt;, was accidentally keep the caller&apos;s thread keyring alive longer than intended when device-mapper opens a table device file. &lt;code&gt;cryptsetup luksOpen&lt;/code&gt; stores the LUKS volume key in what&apos;s supposed to be an ephemeral thread keyring. After the refactor, a reference to that keyring lingers beyond the caller&apos;s lifetime. The key lingers with it.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;luksSuspend&lt;/code&gt; returns without error. Nothing in the output tells you it didn&apos;t work. That&apos;s the part that matters most — the failure mode is silent.&lt;/p&gt;
&lt;h2&gt;Who&apos;s affected&lt;/h2&gt;
&lt;p&gt;Users and automation relying on &lt;code&gt;luksSuspend&lt;/code&gt; for volume-key hygiene: screen-lock workflows, pre-suspend scripts, or anything that expects the volume key to be gone before entering a state where local memory access is possible. If your setup never calls &lt;code&gt;luksSuspend&lt;/code&gt;, this doesn&apos;t affect you. The bug has no remote attack surface.&lt;/p&gt;
&lt;h2&gt;Status&lt;/h2&gt;
&lt;p&gt;No CVSS score has been assigned by NVD as of August 16. Severity is assessed at medium — locally exploitable failure of a disk-encryption security guarantee — pending formal NVD assignment. No exploitation in the wild has been reported. No CISA KEV addition as of publication.&lt;/p&gt;
&lt;h2&gt;Patch&lt;/h2&gt;
&lt;p&gt;Fixed in Linux stable. Commit: &lt;a href=&quot;https://git.kernel.org/stable/c/8ced1d242c34e342defcccdb00663354f212aae6&quot;&gt;git.kernel.org — CVE-2026-72103&lt;/a&gt;. Update the kernel. If you run automated &lt;code&gt;luksSuspend&lt;/code&gt; in a screen-lock or hibernation workflow, prioritize this.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The irony is predictable in retrospect: a change specifically about how file access works inside device-mapper quietly invalidated a property that LUKS users probably never thought to recheck. Refactoring regressions landing on security invariants are not a new pattern. This one&apos;s patched — time to ship it.&lt;/p&gt;
&lt;p&gt;NVD: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-72103&quot;&gt;CVE-2026-72103&lt;/a&gt;. Part of the same August 15 stable batch as the &lt;a href=&quot;/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/&quot;&gt;brcmfmac WiFi heap overflow and BPF verifier bypass&lt;/a&gt; and the &lt;a href=&quot;/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044/&quot;&gt;ksmbd stack overflow fix&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-linux-dm-luks-key-wipe-cve-2026-72103/cover.jpg" medium="image" width="1200" height="675"/><category>linux kernel</category><category>LUKS</category><category>cryptsetup</category><category>luksSuspend</category><category>device-mapper</category><category>keyring</category><category>CVE-2026-72103</category><category>disk encryption</category></item><item><title>Linux ksmbd SMB Server: Stack Overflow Fix in Stable</title><link>https://0daynews.com/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044/</guid><description>CVE-2026-72044 patches a ksmbd stack overflow in multichannel session binding. Patched in stable; no CVSS assigned yet, no exploitation confirmed.</description><pubDate>Sun, 16 Aug 2026 07:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The August 15 kernel stable drop carried over thirty CVEs. Most are maintenance — reference counting, resource leaks, bounds checks on paths nobody reaches in production. CVE-2026-72044 is worth separating out.&lt;/p&gt;
&lt;p&gt;It&apos;s a stack buffer overflow in ksmbd, the Linux kernel&apos;s in-kernel SMB3 server. The affected path is multichannel session-key copying — the mechanism SMB3 clients use to establish multiple network channels to the same server for throughput. The bug traces to a prior refactor (&lt;a href=&quot;https://git.kernel.org/stable/c/4b706360ffb7&quot;&gt;commit 4b706360ffb7&lt;/a&gt;) that moved the binding-path session key out of the session-wide 40-byte &lt;code&gt;sess-&gt;sess_key&lt;/code&gt; field and into a per-channel buffer sized to 16 bytes (&lt;code&gt;SMB2_NTLMV2_SESSKEY_SIZE&lt;/code&gt;). Copy operations that reference the old layout still used the 40-byte length — overflowing the 16-byte kernel stack buffer by 24 bytes during multichannel session binding.&lt;/p&gt;
&lt;p&gt;No CVSS assigned by NVD as of publication. Fix committed to stable: &lt;a href=&quot;https://git.kernel.org/stable/c/610346149d047a52a92c9a0eb329dd565b8f92c5&quot;&gt;610346149d04&lt;/a&gt;. Published NVD entry: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-72044&quot;&gt;CVE-2026-72044&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What ksmbd is&lt;/strong&gt;: ksmbd landed in Linux 5.15 as an in-kernel SMB3 implementation — a performance alternative to Samba&apos;s userspace daemon. It processes SMB3 connections inside the kernel networking stack, where bugs operate at ring 0 rather than inside an isolated process.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Analysis&lt;/strong&gt;: Moving complex protocol servers in-kernel is a tradeoff the kernel community has made repeatedly — NFS, iSCSI, now SMB3. The performance case is real. So is the expanded kernel attack surface that comes with it. A buffer size mismatch between a refactored struct and its copy site is exactly the category of bug this kind of code produces: localized, easy to miss in review, quiet until something triggers the affected path.&lt;/p&gt;
&lt;p&gt;What the practical exposure looks like — what a client needs to send to reach the multichannel binding path, and from what network position — isn&apos;t answered by the commit description alone. That context will come once NVD assigns severity or a researcher publishes a fuller analysis. For now: if you run ksmbd with multichannel enabled, patch to the latest stable.&lt;/p&gt;
&lt;p&gt;No exploitation confirmed in the wild. No CISA KEV addition as of this writing.&lt;/p&gt;
&lt;p&gt;Related: &lt;a href=&quot;/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass/&quot;&gt;Linux Kernel Patches WiFi Heap Overflow, BPF Bypass&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-16-ksmbd-stack-overflow-cve-2026-72044/cover.jpg" medium="image" width="1200" height="675"/><category>ksmbd</category><category>linux kernel</category><category>smb3</category><category>stack overflow</category><category>cve-2026-72044</category><category>multichannel</category></item><item><title>MaxUpload for WordPress: Unauthenticated File Upload</title><link>https://0daynews.com/articles/2026-08-15-maxupload-cve-2026-15965-file-upload/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-maxupload-cve-2026-15965-file-upload/</guid><description>CVE-2026-15965: MaxUpload (≤1.4.0) lets unauthenticated attackers upload arbitrary files via a filename validation mismatch between chunk and final assembly. CVSS 8.8, no patch confirmed.</description><pubDate>Sat, 15 Aug 2026 22:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-15965&quot;&gt;CVE-2026-15965&lt;/a&gt; affects the MaxUpload
plugin for WordPress — a file-size extension that enables large-file handling through a
chunked transfer mechanism. The flaw is in the upload handler&apos;s validation logic: it
applies extension and MIME-type checks to the incoming chunk&apos;s filename, but not to the
filename that determines where the assembled file ultimately lands on the server. Because
the upload handler requires no authentication to reach, any internet-facing WordPress
site with MaxUpload 1.4.0 or earlier installed is in scope. CVSS 8.8, High.&lt;/p&gt;
&lt;h2&gt;What &quot;arbitrary file upload&quot; means here&lt;/h2&gt;
&lt;p&gt;Chunked upload implementations have a surface that single-file handlers don&apos;t. When a
file is split into pieces for transfer and assembled server-side, there are two filename
contexts involved: the chunk and the output. A check applied to one but not the other
leaves a gap. The practical question for any deployment is whether that gap can be
converted to code execution — which depends on whether the server can be made to execute
a file placed in the upload path.&lt;/p&gt;
&lt;p&gt;WordPress installations on PHP hosting environments, which is most of them, typically
can. The upload directory and its server configuration are the relevant variables. A
plugin that bypasses extension validation shifts that exposure from &quot;depends on your
hardening&quot; to &quot;reachable by anyone on the internet.&quot;&lt;/p&gt;
&lt;p&gt;Arbitrary file upload bugs appear often enough in WordPress plugin advisories that they&apos;ve
become a familiar entry in the ecosystem&apos;s threat surface. They show up in upload handlers,
image processors, form builders — wherever a plugin accepts a file from a user and does
something with it server-side. The MaxUpload case has a specific shape: a chunked
implementation that checks one filename context but misses the other. It&apos;s a design-level
oversight, not an edge case.&lt;/p&gt;
&lt;h2&gt;Status&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-15965&quot;&gt;CVE-2026-15965&lt;/a&gt; was published to NVD
on August 15. Affected versions: all through 1.4.0. No patched version has been confirmed
in the WordPress plugin repository as of this writing. No active exploitation has been
reported.&lt;/p&gt;
&lt;p&gt;The absence of confirmed exploitation is worth noting without over-relying on it. Chunked
upload vulnerabilities with unauthenticated reach have attracted opportunistic scanning
before, particularly once a CVE ID and advisory are public.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;p&gt;Check your WordPress plugin inventory for MaxUpload. If you&apos;re running any version through
1.4.0, deactivate it until a patched release is confirmed. There is no configuration-level
workaround for the flaw in affected versions — the only safe posture is not running the
affected code.&lt;/p&gt;
&lt;p&gt;Monitor the &lt;a href=&quot;https://wordpress.org/plugins/maxupload-upload-larger-files-easily/&quot;&gt;WordPress plugin page&lt;/a&gt;
directly for update status. As a secondary measure, confirm with your host that your
WordPress uploads directory is not configured to serve executable scripts — a hardening
step that limits the blast radius of file upload vulnerabilities regardless of the specific
plugin involved.&lt;/p&gt;
&lt;p&gt;Earlier this week, a separate batch of &lt;a href=&quot;/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98/&quot;&gt;critical authentication bypass flaws&lt;/a&gt;
hit the WordPress plugin ecosystem with CVSS scores of 9.8. The MaxUpload flaw is a
different class of vulnerability but sits in the same patch cycle for WordPress site
operators.&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-maxupload-cve-2026-15965-file-upload/cover.jpg" medium="image" width="1200" height="675"/><category>CVE-2026-15965</category><category>MaxUpload</category><category>WordPress</category><category>arbitrary file upload</category><category>chunked upload</category><category>plugin security</category><category>unauthenticated</category></item><item><title>Thirteen New Metasploit Modules, One Old Pattern</title><link>https://0daynews.com/articles/2026-08-15-metasploit-summer-thirteen-new-modules/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-metasploit-summer-thirteen-new-modules/</guid><description>Rapid7&apos;s latest wrap-up adds thirteen exploit modules spanning Ghost CMS, SonicWall SMA1000, Langflow, Ray, and more. The targets rotate. The underlying pattern doesn&apos;t.</description><pubDate>Sat, 15 Aug 2026 22:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Rapid7 published its &lt;a href=&quot;https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-lot-of-summer-shells-and-fit-http-profiles&quot;&gt;summer Metasploit wrap-up&lt;/a&gt; this week, and the headline is thirteen new exploit modules landing in a single batch. The targets span enough product categories to make a useful point all on their own: Ghost CMS, Joomla JCE, WordPress WP2Shell, Langflow, OpenCATS, Pterodactyl Panel, Ray Dashboard, Pix-for-WooCommerce, SonicWall SMA1000, and a Linux kernel local privilege escalation. That list has something in it for almost every environment.&lt;/p&gt;
&lt;p&gt;Which is, more or less, the point.&lt;/p&gt;
&lt;h2&gt;What the batch covers&lt;/h2&gt;
&lt;p&gt;The web application modules are the straightforward part. Three CMS platforms — Ghost, Joomla (via the JCE editor extension), and WordPress — plus a WooCommerce payment plugin getting exploit modules in the same batch is the kind of thing that reads as noise if you&apos;re not running any of them, and reads as a to-do list if you are. OpenCATS (an open-source applicant tracking system) and Pterodactyl Panel (game server management) round out the small-to-mid-market web application coverage.&lt;/p&gt;
&lt;p&gt;The more interesting additions are in AI and distributed computing infrastructure. Langflow — an open-source workflow orchestration tool for building AI pipelines — receives another module, following advisories earlier in the year. Ray Dashboard, the management interface for the Ray distributed computing framework used heavily in ML training workloads, joins it. [Analysis: both tools are frequently deployed in environments that prioritize build velocity over security hardening, often without authentication configured on the management interface and with more network access than the team assumes. The concentration of exploit module development around AI tooling likely reflects how quickly these products spread into production without accompanying security review.]&lt;/p&gt;
&lt;p&gt;On the network perimeter side, SonicWall SMA1000 gets a module. SonicWall&apos;s remote access appliances have appeared in Metasploit before, and SMA-series devices have made the CISA KEV catalog more than once. If you have one, the current firmware version is worth checking before the week ends.&lt;/p&gt;
&lt;p&gt;The Linux kernel local privilege escalation — useful for post-exploitation on a host compromised via one of the other RCE modules — completes the package. It doesn&apos;t need internet exposure to matter; it just needs a foothold.&lt;/p&gt;
&lt;h2&gt;The framework itself&lt;/h2&gt;
&lt;p&gt;Beyond the modules, Rapid7 notes two infrastructure additions. HTTP malleable C2 profiles allow Metasploit traffic to pattern-match against known commercial frameworks, which affects detection fidelity for teams relying on traffic signatures. And MCP (Model Context Protocol) integration has been added to the framework itself, which is a notable signal: the same protocol now appearing in both attack tooling and the AI tooling it&apos;s targeting.&lt;/p&gt;
&lt;h2&gt;What to do with this&lt;/h2&gt;
&lt;p&gt;A Metasploit wrap-up isn&apos;t a threat report; it&apos;s a capability inventory. The presence of a module doesn&apos;t mean attacks are actively happening, and it doesn&apos;t mean they aren&apos;t. It means reliable exploit code now exists in a framework that is straightforward to use.&lt;/p&gt;
&lt;p&gt;For any of the web-facing platforms on this list — Ghost, Joomla, WordPress, Pterodactyl, Langflow, Ray Dashboard — the question is simple: is it patched, and is it accessible from the internet? If either answer is no or unknown, that&apos;s the task.&lt;/p&gt;
&lt;p&gt;For SonicWall SMA1000: firmware current, access logs reviewed, no anomalies.&lt;/p&gt;
&lt;p&gt;Thirteen modules. Different product names every time, same answer every time.&lt;/p&gt;
&lt;p&gt;Patch the internet-facing ones first.&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-metasploit-summer-thirteen-new-modules/cover.jpg" medium="image" width="1200" height="675"/><category>metasploit</category><category>rapid7</category><category>exploit modules</category><category>ghost cms</category><category>sonicwall</category><category>langflow</category><category>ray dashboard</category><category>unauthenticated rce</category></item><item><title>MindsDB: Unauthenticated RCE, Max CVSS Score</title><link>https://0daynews.com/articles/2026-08-15-mindsdb-cvss10-unauthenticated-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-mindsdb-cvss10-unauthenticated-rce/</guid><description>CVE-2026-73678: MindsDB Minds Platform up to 26.1.0 exposes unprotected API endpoints enabling unauthenticated OS command execution. CVSS 10.0.</description><pubDate>Sat, 15 Aug 2026 20:00:00 GMT</pubDate><content:encoded>&lt;p&gt;MindsDB&apos;s Minds Platform has a &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73678&quot;&gt;CVSS 10.0 unauthenticated remote code execution vulnerability&lt;/a&gt;. All versions through 26.1.0 are affected. CVSS 10.0 is the maximum possible score, and this one earns it: no authentication, no user interaction, full remote code execution as the MindsDB process user.&lt;/p&gt;
&lt;p&gt;If your MindsDB instance is reachable from the network, stop reading and firewall the port. Then come back.&lt;/p&gt;
&lt;h2&gt;What&apos;s broken&lt;/h2&gt;
&lt;p&gt;Two API endpoints ship without authentication in affected versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;PUT /api/v1/settings/&lt;/code&gt; — lets any caller set the LLM API key and model configuration for the running instance&lt;/li&gt;
&lt;li&gt;&lt;code&gt;POST /api/v1/responses/&lt;/code&gt; — routes prompts to the Anton agent&apos;s scratchpad tool, which calls Python&apos;s &lt;code&gt;exec()&lt;/code&gt; on processed input without sandboxing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Together they create a straightforward path to OS command execution. An attacker can configure the instance to use an attacker-controlled API key, craft a prompt that the scratchpad routes into code execution, and run arbitrary commands as whatever user owns the MindsDB process.&lt;/p&gt;
&lt;p&gt;MindsDB functions as an LLM and database integration layer in production — it connects to databases, LLM providers, and internal APIs, and commonly holds or has access to database credentials, model API keys, and internal data. That&apos;s what&apos;s at risk here.&lt;/p&gt;
&lt;h2&gt;Action items&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Update immediately.&lt;/strong&gt; The &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-73678&quot;&gt;NVD advisory&lt;/a&gt; documents version 26.1.0 and earlier as vulnerable. Check MindsDB&apos;s release channel for the patched version and apply it.&lt;/p&gt;
&lt;p&gt;While you&apos;re patching or testing:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Firewall the API port.&lt;/strong&gt; MindsDB&apos;s API surface should not be internet-accessible regardless of this CVE. If it is, that&apos;s the more urgent problem.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Rotate credentials.&lt;/strong&gt; Assume any database connections, model API keys, or other secrets accessible to the process may have been read. Rotate before trusting the instance again.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review process logs&lt;/strong&gt; for unexpected command execution, configuration changes, or anomalous API calls to &lt;code&gt;/api/v1/settings/&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Priority call&lt;/h2&gt;
&lt;p&gt;Internet-accessible deployments: this is a P0 incident. CVSS 10.0 with no authentication and no user interaction means exploitation is trivial for anyone who can reach the port. Firewall first, patch as soon as you can pull a fixed build, then audit.&lt;/p&gt;
&lt;p&gt;Internal deployments behind a hard network boundary: still patch this week. The attack surface here is your MindsDB process and everything it can touch — database connections, API keys, and whatever data those systems hold. That&apos;s not exposure you want sitting on an unpatched binary.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;&lt;a href=&quot;/cve/cve-2026-50027/&quot;&gt;CVE-2026-50027&lt;/a&gt; — a separate unauthenticated access vulnerability in &lt;code&gt;mcp-memory-service&lt;/code&gt; — was &lt;a href=&quot;/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass/&quot;&gt;patched this week&lt;/a&gt;. LLM tooling infrastructure continues to be an active target for this class of missing-auth bugs.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-mindsdb-cvss10-unauthenticated-rce/cover.jpg" medium="image" width="1200" height="675"/><category>CVE-2026-73678</category><category>MindsDB</category><category>unauthenticated RCE</category><category>AI platform security</category><category>CVSS 10</category><category>command injection</category></item><item><title>Patch Now: Critical Auth Bypass Hits WordPress Plugins</title><link>https://0daynews.com/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98/</guid><description>Two WordPress plugins patched this week carry CVSS 9.8 authentication bypass flaws. A third allows unauthenticated file deletion that hands attackers RCE.</description><pubDate>Sat, 15 Aug 2026 20:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Three WordPress plugin vulnerabilities disclosed this week sit at the top of the severity scale: two authentication bypass flaws at CVSS 9.8 and a file-deletion vulnerability at CVSS 9.1 that chains to remote code execution. All three are exploitable by unauthenticated attackers. Update before you keep reading.&lt;/p&gt;
&lt;h2&gt;CVE-2026-15341: Unauthenticated Account Takeover in User Session Synchronizer (CVSS 9.8)&lt;/h2&gt;
&lt;p&gt;The User Session Synchronizer plugin (all versions through 1.4.0) runs a &lt;code&gt;synchronize_session()&lt;/code&gt; function hooked on WordPress&apos;s &lt;code&gt;init&lt;/code&gt; action — meaning it fires on every single request to the site. The function accepts three caller-supplied parameters with no nonce check, no capability check, and no shared-secret validation of any kind. When one of those parameters references an unregistered slot, the plugin falls through to a code path that still resolves an existing WordPress user and issues them an authenticated session.&lt;/p&gt;
&lt;p&gt;The bottom line: any unauthenticated visitor can obtain a valid session for any WordPress account on the site, including administrators. Full account takeover, no prior foothold required. Fixed in version 1.4.1. Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-15341&quot;&gt;NVD&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;CVE-2026-15303: Unauthenticated Admin Cookie Issuance in 6Storage Rentals (CVSS 9.8)&lt;/h2&gt;
&lt;p&gt;The 6Storage Rentals plugin (all versions through 2.27.0) registers an AJAX action under WordPress&apos;s &lt;code&gt;wp_ajax_nopriv_*&lt;/code&gt; hook — reachable by anyone, no session needed. The handler accepts an email address from the POST body, resolves it to a WordPress user via &lt;code&gt;get_user_by(&apos;email&apos;)&lt;/code&gt;, and calls &lt;code&gt;wp_set_current_user()&lt;/code&gt; and &lt;code&gt;wp_set_auth_cookie()&lt;/code&gt; unconditionally. No nonce. No ownership check. No capability gate.&lt;/p&gt;
&lt;p&gt;Send an administrator&apos;s email address. Receive an administrator&apos;s session cookie. Fixed; update to the latest available release via your plugin manager. Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-15303&quot;&gt;NVD&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;CVE-2026-14484: File Deletion to RCE in RapiSafe CF7 (CVSS 9.1)&lt;/h2&gt;
&lt;p&gt;RapiSafe — Secure Multi File Upload for Contact Form 7 (all versions through 1.0.4) uses a nonce to gate its upload-removal handler. The problem: the nonce lives in the page source of any page with a Contact Form 7 form — any visitor can retrieve it before triggering the handler. The removal handler&apos;s path validation doesn&apos;t prevent directory traversal, so an attacker can target files outside the uploads directory.&lt;/p&gt;
&lt;p&gt;Deleting &lt;code&gt;wp-config.php&lt;/code&gt; triggers WordPress&apos;s setup wizard on the next load, giving the attacker a clean path to database reconfiguration and full site takeover. Fixed in version 1.0.5. If no patch is yet showing in your plugin manager, deactivate the plugin. There is no safe configuration workaround for affected versions. Source: &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-14484&quot;&gt;NVD&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Patch Priority&lt;/h2&gt;
&lt;p&gt;All three are critical. If you have to sequence:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-15341&lt;/strong&gt; — update User Session Synchronizer to ≥1.4.1. Unauthenticated full account takeover is the highest-risk class.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-15303&lt;/strong&gt; — update 6Storage Rentals to the latest release. Same severity, same attack class.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-14484&lt;/strong&gt; — update RapiSafe CF7 to ≥1.0.5, or deactivate it immediately if the update isn&apos;t yet available.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;WordPress site operators managing large installations should be running these updates now. These three join an active patch cycle: &lt;a href=&quot;../2026-08-14-wordpress-704-rce-imagick-ghostscript&quot;&gt;WordPress 7.0.4 fixed a high-severity RCE via Imagick last week&lt;/a&gt;, and a &lt;a href=&quot;../2026-08-10-bdthemes-supply-chain-wordpress-rogue-admins&quot;&gt;supply-chain attack on BdThemes earlier this month planted rogue admin accounts on affected sites&lt;/a&gt;. The plugin attack surface isn&apos;t slowing down.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98/cover.jpg" medium="image" width="1200" height="675"/><category>wordpress</category><category>authentication bypass</category><category>CVE-2026-15341</category><category>CVE-2026-15303</category><category>CVE-2026-14484</category><category>plugin</category><category>critical</category></item><item><title>Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes</title><link>https://0daynews.com/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay/</guid><description>A Mirai-based modular Linux botnet is converting compromised routers into SOCKS5 relay nodes — the same ORB infrastructure pattern, repackaged again.</description><pubDate>Sat, 15 Aug 2026 18:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A new Mirai-based botnet called Evooo1Bot is doing what Mirai variants have been doing since 2016 in one respect, and something slightly more interesting in another. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/&quot;&gt;BleepingComputer reported Friday&lt;/a&gt; that Evooo1Bot targets internet-facing gateway devices — home routers, small-business edge hardware, the usual attack surface — and converts them into SOCKS5 traffic relay nodes. Not DDoS cannon nodes. Proxy relay nodes.&lt;/p&gt;
&lt;p&gt;That&apos;s the distinguishing characteristic. The classic Mirai use case was volumetric: compromise enough bandwidth-rich edge devices, point them all at a target simultaneously, and knock it offline. What Evooo1Bot&apos;s operators want from the devices they compromise is something more durable — a dispersed layer of residential and commercial IP addresses to route traffic through, making that traffic look like it originates from somewhere legitimate. The same infrastructure pattern threat-intelligence teams have been calling ORB networks, operational relay boxes, anonymization layers, and a half-dozen other names depending on which attribution cluster is using it this week.&lt;/p&gt;
&lt;h2&gt;The infrastructure play&lt;/h2&gt;
&lt;p&gt;The mechanics here are not novel. UAT-7810&apos;s &quot;Longleash&quot; ORB network — &lt;a href=&quot;/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus/&quot;&gt;covered in July&lt;/a&gt; — used compromised Ruckus and ASUS gear for exactly this: residential IP transit to evade geo-restriction and reputation blocklists. The &lt;a href=&quot;/articles/2026-07-03-fbi-netnut-popa-botnet-takedown/&quot;&gt;FBI&apos;s POPA botnet takedown&lt;/a&gt; hit the same structural pattern in a commercially operated version of the relay service. The appeal is straightforward. Data-center IP ranges are on every blocklist. A residential IP from a router in Minneapolis, a gateway in São Paulo, and a home network in Osaka — those are harder to flag and harder to attribute.&lt;/p&gt;
&lt;p&gt;What Evooo1Bot adds to that structural approach is the Mirai codebase running on Linux gateway firmware — a delivery chain that has proven reliable across ten years of evolution precisely because the underlying attack surface keeps expanding rather than contracting. The &quot;modular&quot; characterization in BleepingComputer&apos;s reporting suggests the relay function is one component rather than the whole payload, though specifics on additional modules weren&apos;t available at time of writing. BleepingComputer&apos;s reporting is ongoing; more technical detail, IoCs, and affected model lists are expected to follow.&lt;/p&gt;
&lt;p&gt;Two days ago, &lt;a href=&quot;/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer/&quot;&gt;a different Mirai variant surfaced with encrypted C2 and a credential sniffer&lt;/a&gt;. These are separate campaigns running on the same foundational codebase — which is the relevant observation. Mirai leaked in 2016 and became infrastructure commons. Every threat actor with a use case for compromised edge devices now builds from that codebase or from derivatives of it. The variants multiply; the underlying attack surface doesn&apos;t get addressed.&lt;/p&gt;
&lt;h2&gt;What this means for the devices involved&lt;/h2&gt;
&lt;p&gt;This morning, &lt;a href=&quot;/articles/2026-08-15-openwrt-luci-critical-root-rce/&quot;&gt;three critical vulnerabilities in OpenWrt&apos;s LuCI management interface&lt;/a&gt; reached public disclosure — two rated CVSS 9.9. OpenWrt runs on a substantial share of the consumer and small-business router hardware that botnets like Evooo1Bot target. The timing is coincidental; the overlapping attack surface is not.&lt;/p&gt;
&lt;p&gt;The practical picture: gateway devices are targeted because they&apos;re persistent, network-adjacent, and largely unmonitored. The &lt;a href=&quot;/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched/&quot;&gt;Tenda router backdoor disclosed in July&lt;/a&gt; remains unpatched months after disclosure. Firmware updates that do exist often require manual action nobody takes. And unlike endpoints, routers don&apos;t generate EDR telemetry — if a compromised router is proxying traffic, the detection event most commonly shows up in downstream anomaly analysis rather than at the device itself.&lt;/p&gt;
&lt;p&gt;The response to Evooo1Bot is the same response to the Mirai variant from Tuesday and the one before that: update firmware on gateway devices, disable remote management interfaces exposed to the public internet, segment networks so IoT and edge hardware isn&apos;t sitting adjacent to anything sensitive, and baseline outbound traffic volumes on devices where &quot;predictable&quot; is actually achievable. None of this is new. The fact that it keeps being relevant says something about which side of this problem has consistent institutional support.&lt;/p&gt;
&lt;p&gt;For current IoCs and technical indicators, follow &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/&quot;&gt;BleepingComputer&apos;s reporting&lt;/a&gt; and vendor advisories as they publish.&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay/cover.jpg" medium="image" width="1200" height="675"/><category>evooo1bot</category><category>linux botnet</category><category>mirai</category><category>socks5</category><category>proxy network</category><category>router security</category><category>threat intel</category></item><item><title>Unauth Access to AI Memory: CVE-2026-50027 Patched</title><link>https://0daynews.com/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass/</guid><description>CVE-2026-50027: mcp-memory-service exposed all /api/documents/* routes without auth, letting anyone read, write, or delete AI memories. Patch to 10.67.1.</description><pubDate>Sat, 15 Aug 2026 16:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The semantic memory layer &lt;code&gt;mcp-memory-service&lt;/code&gt; shipped &lt;a href=&quot;https://github.com/advisories/GHSA-84hp-mqvj-3p8h&quot;&gt;CVE-2026-50027&lt;/a&gt;: every HTTP route under &lt;code&gt;/api/documents/&lt;/code&gt; is accessible without credentials. That&apos;s not a misconfiguration — it&apos;s the default. Even deployments explicitly configured with &lt;code&gt;MCP_API_KEY&lt;/code&gt; or OAuth let anyone read, write, or delete stored documents without authentication. CVSS: 9.8 Critical. Fixed in 10.67.1.&lt;/p&gt;
&lt;h2&gt;What&apos;s exposed&lt;/h2&gt;
&lt;p&gt;mcp-memory-service is a semantic memory layer for AI applications — it stores documents that agents and LLM applications retrieve as context. What&apos;s sitting in those stores varies by deployment: conversation history, user data, internal knowledge bases, whatever the application fed it.&lt;/p&gt;
&lt;p&gt;Unauthenticated attackers with network access can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Read&lt;/strong&gt; any stored document by ID&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Write&lt;/strong&gt; arbitrary content into the memory store, poisoning what agents retrieve as context&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Delete&lt;/strong&gt; any stored memory, permanently&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;code&gt;/api/documents/&lt;/code&gt; routes skip the server&apos;s authentication middleware entirely. &lt;code&gt;MCP_API_KEY&lt;/code&gt; and any OAuth configuration apply to other route groups; the document API simply doesn&apos;t check. &lt;a href=&quot;https://github.com/advisories/GHSA-84hp-mqvj-3p8h&quot;&gt;GHSA-84hp-mqvj-3p8h&lt;/a&gt; documents this as the root cause.&lt;/p&gt;
&lt;h2&gt;Action items&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Update to 10.67.1.&lt;/strong&gt; That&apos;s the fix — the patch gates all &lt;code&gt;/api/documents/&lt;/code&gt; routes through the server&apos;s existing authentication middleware. No configuration changes needed after the update.&lt;/p&gt;
&lt;p&gt;If you can&apos;t patch immediately:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Firewall the service port. mcp-memory-service shouldn&apos;t be internet-accessible regardless; if it is, that&apos;s a separate problem worth fixing at the same time.&lt;/li&gt;
&lt;li&gt;After patching, audit stored documents for unexpected or injected content before relying on the store again.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Priority call&lt;/h2&gt;
&lt;p&gt;Network-accessible deployments: patch or firewall today. Unauthenticated write access to an AI context store is a direct path to corrupting what your agents retrieve and act on — &lt;a href=&quot;/articles/2026-08-09-mcp-server-ssrf-path-traversal-ten-cves-one-day/&quot;&gt;MCP server vulnerabilities&lt;/a&gt; have been actively mapped by researchers since mid-year, and this attack surface is not theoretical.&lt;/p&gt;
&lt;p&gt;Internal-only deployments sitting behind a hard network boundary can roll the update on their normal patch cadence — this week, not next month.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass/cover.jpg" medium="image" width="1200" height="675"/><category>CVE-2026-50027</category><category>mcp-memory-service</category><category>authentication bypass</category><category>ai-security</category><category>mcp</category><category>semantic-memory</category></item><item><title>ShieldBreak: New Unpatched EoP in Defender Scan Engine</title><link>https://0daynews.com/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine/</guid><description>CVE-2026-69414 is a second ShieldBreak-tagged EoP — this one in Defender&apos;s Malware Protection Engine, CVSS 7.8. No patch yet. MSRC advisory is live.</description><pubDate>Sat, 15 Aug 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A second CVE tagged &quot;ShieldBreak&quot; landed in MSRC&apos;s advisory database on August 14: &lt;a href=&quot;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414&quot;&gt;CVE-2026-69414&lt;/a&gt;, rated High, CVSS 7.8. This one is in the Malware Protection Engine — the scanning core, &lt;code&gt;MsMpEng.exe&lt;/code&gt;. There is no patch.&lt;/p&gt;
&lt;p&gt;This is not the same issue as &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-50656&quot;&gt;CVE-2026-50656&lt;/a&gt;, which shipped as a fix in &lt;a href=&quot;/articles/2026-08-11-microsoft-patch-tuesday-august-2026/&quot;&gt;August&apos;s Patch Tuesday&lt;/a&gt; and had a &lt;a href=&quot;/articles/2026-08-12-shieldbreak-defender-cve-2026-50656-patch-bypass/&quot;&gt;bypass published the following day&lt;/a&gt;. Two separate CVEs, both labeled &quot;ShieldBreak,&quot; both in Defender&apos;s internals, four days apart.&lt;/p&gt;
&lt;h2&gt;What it is&lt;/h2&gt;
&lt;p&gt;CVE-2026-69414 is an elevation of privilege vulnerability in the Malware Protection Engine. &lt;code&gt;MsMpEng.exe&lt;/code&gt; runs as SYSTEM on Windows machines with Defender&apos;s real-time protection active — it has to, because scanning files and processes at that depth requires elevated access. An EoP flaw here means a path from lower-privilege code execution to full SYSTEM access.&lt;/p&gt;
&lt;p&gt;MSRC&apos;s advisory holds technical specifics while a fix is in development. What&apos;s disclosed: the affected component (Malware Protection Engine), the severity (High, CVSS 7.8), and current status (no patch, security update in progress). Microsoft describes the vulnerability as &quot;ShieldBreak,&quot; using the same name that attached to CVE-2026-50656.&lt;/p&gt;
&lt;h2&gt;What isn&apos;t confirmed&lt;/h2&gt;
&lt;p&gt;Active exploitation: not confirmed. In-the-wild use: not confirmed. Public proof-of-concept: none observed as of this writing. CISA has not added CVE-2026-69414 to the Known Exploited Vulnerabilities catalog.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Analysis:&lt;/strong&gt; The prior ShieldBreak bypass (CVE-2026-50656) surfaced within hours of Patch Tuesday. &lt;a href=&quot;/articles/2026-08-12-lazarus-cve-2026-68820-operation-dream-job-cisa-kev/&quot;&gt;Lazarus exploited CVE-2026-68820&lt;/a&gt; before it was publicly disclosed. Neither of these is evidence that CVE-2026-69414 is currently exploited — but both illustrate that named, actively-researched vulnerabilities in Defender&apos;s internals have historically had short timelines from disclosure to exploitation. Watch the advisory; adjust urgency if that status changes.&lt;/p&gt;
&lt;h2&gt;Action items&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Before the patch:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Keep Defender&apos;s Security Intelligence updates current. Microsoft ships signature database updates continuously and independently of Windows Update. These can carry behavioral mitigations ahead of a binary patch. Running outdated definitions leaves an unprotected engine exposed.&lt;/li&gt;
&lt;li&gt;Watch &lt;a href=&quot;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414&quot;&gt;MSRC&apos;s advisory&lt;/a&gt; directly — it will be updated when a fix is available.&lt;/li&gt;
&lt;li&gt;Review any group policies in your environment that delay or restrict Defender updates. A stability-motivated delay policy works against you when the scanning engine carries a known-unpatched EoP.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;When the patch lands:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Push it the same day. CVSS 7.8 on a SYSTEM-privileged process, in a component with an active research community targeting it, warrants immediate application. The prior ShieldBreak bypass demonstrated that window can be hours.&lt;/p&gt;
&lt;h2&gt;Priority call&lt;/h2&gt;
&lt;p&gt;Not an emergency today — no confirmed exploitation, no public PoC. Monitor the advisory and keep signatures current. When the patch ships, treat it as immediate. If CISA adds it to KEV before that, escalate accordingly.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine/cover.jpg" medium="image" width="1200" height="675"/><category>shieldbreak</category><category>microsoft defender</category><category>malware protection engine</category><category>CVE-2026-69414</category><category>elevation of privilege</category><category>windows</category></item><item><title>CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639</title><link>https://0daynews.com/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639/</guid><description>CISA advisory ICSA-26-225-01 covers CVE-2025-7639, a deserialization flaw that lets authenticated ICS operators execute code at elevated privilege.</description><pubDate>Sat, 15 Aug 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;CISA published advisory &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01&quot;&gt;ICSA-26-225-01&lt;/a&gt; on 14 August 2026, covering CVE-2025-7639: a deserialization vulnerability in an industrial distributed control system (DCS) whose permission model distinguishes authenticated operator access — the &quot;DNA Authority - Operator&quot; tier — from the higher-privilege execution context of the &quot;Enterprise SCADA security group &apos;DNA Apps&apos;.&quot;&lt;/p&gt;
&lt;p&gt;The flaw is in how the system processes serialized data submitted by authenticated users in the Operator tier. Insufficient validation before deserialization means an attacker holding — or having obtained — valid Operator credentials can craft input that executes code under the &quot;DNA Apps&quot; security group, outside the bounds of their assigned role.&lt;/p&gt;
&lt;p&gt;That privilege delta is the meaningful part. Operator access in an industrial environment is intended to be scoped: monitor the process, adjust setpoints within approved ranges, no software installation, no configuration authority beyond the defined scope. A deserialization path that lets Operator-tier input elevate into a higher security group collapses that boundary in a way that doesn&apos;t show up cleanly in most OT access-control audits — the Operator account looks legitimate, and the escalation happens at the application layer below the network perimeter.&lt;/p&gt;
&lt;p&gt;Exploitation requires authentication, which limits opportunistic internet-scanning attacks. The more realistic risk is insider threat, credential theft, or a compromised Operator-tier account being used as a stepping stone after initial access via another vector.&lt;/p&gt;
&lt;p&gt;CVSS scoring was not available in the NVD entry at the time of writing; refer to the &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01&quot;&gt;CISA advisory&lt;/a&gt; for the vendor&apos;s severity assessment and the &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2025-7639&quot;&gt;NVD entry for CVE-2025-7639&lt;/a&gt; for updates as scoring is published.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What to do&lt;/strong&gt;: Review &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-01&quot;&gt;CISA advisory ICSA-26-225-01&lt;/a&gt; for the affected product version ranges and the vendor&apos;s recommended patches or workarounds. Audit &quot;DNA Authority - Operator&quot; account assignments against current personnel — accounts belonging to former employees, contractors, or personnel who have changed roles should be disabled. Monitor the advisory for patch availability if none has been issued yet.&lt;/p&gt;</content:encoded><dc:creator>Nadia &quot;Loop&quot; Park</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639/cover.jpg" medium="image" width="1200" height="675"/><category>cve-2025-7639</category><category>icsa-26-225-01</category><category>cisa ics advisory</category><category>scada deserialization</category><category>industrial control system</category><category>privilege escalation</category><category>ot security</category></item><item><title>NIST Bets on AI to Clear AI-Created CVE Backlog</title><link>https://0daynews.com/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge/</guid><description>AI tools are flooding the CVE pipeline faster than NVD can enrich them. NIST&apos;s proposed fix is more AI — a structural response to a structural problem, with real triage implications downstream.</description><pubDate>Sat, 15 Aug 2026 10:00:00 GMT</pubDate><content:encoded>&lt;p&gt;NIST is looking at deploying artificial intelligence to help process vulnerabilities at the National Vulnerability Database — the same category of AI-powered tooling that is flooding the pipeline with more CVEs than it can enrich on a human timescale.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/ai-driven-bug-tsunami-nist-looks-to-ai&quot;&gt;Dark Reading reported Thursday&lt;/a&gt; that vulnerability volumes are surging, driven by AI-augmented scanning and research tools that find bugs faster than disclosure pipelines were designed to handle. NIST is now asking whether AI can be the answer to its own backlog.&lt;/p&gt;
&lt;p&gt;This isn&apos;t a new problem. It is a sharper version of one. In 2023 and 2024, NVD fell into a prolonged enrichment backlog — the step in the pipeline where a CVE ID receives CVSS scores, Common Weakness Enumeration tags, and product references so that vulnerability management tools and patching workflows can actually act on it. CISA stepped in as a processing partner to clear part of the queue. The backlog shrank, then AI-assisted research tooling got meaningfully better, and the intake volume is climbing again.&lt;/p&gt;
&lt;p&gt;The structural problem here is that AI-augmented vulnerability research scales with compute in a way human advisory writing does not. A researcher with a well-configured fuzzer and an LLM for triage and writeup can disclose in a weekend what used to take months of manual analysis. &lt;a href=&quot;https://0daynews.com/articles/2026-08-09-mcp-server-ssrf-path-traversal-ten-cves-one-day/&quot;&gt;We saw a compressed version of this in August&lt;/a&gt; when a single researcher dropped ten CVEs across MCP server implementations in a single day — each one real, each one requiring NVD review, most across projects where maintainers weren&apos;t expecting coordinated disclosure. That pattern, replicated at scale across the open source ecosystem, is what NIST is staring at.&lt;/p&gt;
&lt;p&gt;The downstream effect that matters most is CVSS. Security teams have built their patch prioritization workflows around NVD enrichment data, and primarily around CVSS scores. An unenriched CVE sits in the database with a blank or placeholder score. A vulnerability management platform pulling from NVD returns incomplete signal. In a world where patch capacity is finite and the queue is measured in thousands — &lt;a href=&quot;https://0daynews.com/articles/2026-08-11-microsoft-patch-tuesday-august-2026/&quot;&gt;August&apos;s Patch Tuesday alone logged 88 CVEs from Microsoft&lt;/a&gt; — a blank CVSS score gets deprioritized by default and may never get worked.&lt;/p&gt;
&lt;p&gt;NIST&apos;s proposed direction — using AI to automate enrichment through auto-scoring, CWE tagging, and product matching — is a reasonable structural response to a structural problem. It is also one that introduces its own accuracy questions. Assigning a CVSS score is contextual work: it requires considering what exploitation actually requires, whether authentication preconditions exist, how the affected software is typically deployed, and what the realistic attacker population looks like. Whether current models can do that consistently enough to be trusted as a primary enrichment source is genuinely open, and NIST hasn&apos;t answered it.&lt;/p&gt;
&lt;p&gt;Getting enrichment wrong in the direction of &quot;too high&quot; creates alert fatigue in SOCs already operating near capacity. Getting it wrong &quot;too low&quot; buries real exposure. Both failure modes are worse than a blank field in different ways, and the industry&apos;s ability to detect a quiet accuracy degradation — as opposed to a spectacular enrichment failure — is not well developed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Analysis&lt;/strong&gt;: The interesting part of this is not the irony of AI creating a problem and AI being asked to solve it; that&apos;s been the pattern in security tooling for as long as there have been security tools. The interesting part is structural: the entire patch-prioritization apparatus the industry has built assumes NVD enrichment is reliable and reasonably timely. Both assumptions are under simultaneous stress. NIST turning to AI doesn&apos;t resolve the underlying mismatch — it relocates where the errors happen.&lt;/p&gt;
&lt;p&gt;Defenders layering EPSS scores alongside CVSS, or using &lt;a href=&quot;https://0daynews.com/kev-tracker/&quot;&gt;CISA KEV additions as a primary triage signal&lt;/a&gt;, are somewhat insulated from this. The KEV catalog is maintained reactively and at lower volume, with human review before anything gets added. But for vulnerabilities that never reach KEV — the large majority of disclosed CVEs — NVD enrichment quality matters more than the current moment makes obvious.&lt;/p&gt;
&lt;p&gt;This is worth watching not because AI-assisted CVE enrichment will fail visibly, but because it may degrade in ways that are quiet and slow and only apparent well after they&apos;ve distorted someone&apos;s risk posture.&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge/cover.jpg" medium="image" width="1200" height="675"/><category>NVD</category><category>NIST</category><category>CVE</category><category>vulnerability management</category><category>AI security</category><category>CVSS</category><category>patch prioritization</category></item><item><title>GeoServer Zero-Day Under Active Attack, No Patch Available</title><link>https://0daynews.com/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited/</guid><description>An unpatched SQL injection in GeoServer enables RCE on PostGIS and Oracle deployments. WatchTowr logged hundreds of probe attempts within hours of public disclosure.</description><pubDate>Sat, 15 Aug 2026 08:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A security researcher publicly disclosed an unpatched SQL injection vulnerability in GeoServer on Wednesday, and exploitation attempts were logged within hours. If you run a public-facing GeoServer instance — especially one backed by PostGIS or Oracle JDBC — stop reading this and go audit your exposure first.&lt;/p&gt;
&lt;h2&gt;What was disclosed&lt;/h2&gt;
&lt;p&gt;Researcher q1uf3ng published details of a flaw in GeoServer&apos;s &lt;code&gt;jsonArrayContains&lt;/code&gt; function, which handles JSON array field queries. The root cause is improper sanitization of user-supplied arguments before they&apos;re encoded into database queries. On deployments using PostGIS or Oracle JDBC as the data store backend, that injection path can escalate to remote code execution, &lt;a href=&quot;https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/&quot;&gt;SecurityWeek reports&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As of publication, GeoServer has released no patch and no CVE identifier has been assigned.&lt;/p&gt;
&lt;h2&gt;Active exploitation, fast&lt;/h2&gt;
&lt;p&gt;WatchTowr&apos;s Jake Knott told SecurityWeek that within hours of the August 14 disclosure, WatchTowr observed &quot;hundreds of attempts originating from a small number of source IP addresses.&quot; Current activity appears to be probing — no confirmed follow-on compromise has been publicly reported — but probing at this pace and scale is how threat actors build target lists before escalating.&lt;/p&gt;
&lt;p&gt;GeoServer has a documented history of targeted exploitation. Several prior GeoServer vulnerabilities have landed in &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;CISA&apos;s Known Exploited Vulnerabilities catalog&lt;/a&gt;. The platform is widely deployed by government agencies, agriculture operators, telecoms, and transit authorities for geospatial data delivery — organizations that routinely expose it publicly for map tile and WFS/WMS services, and that don&apos;t always have fast patch cycles.&lt;/p&gt;
&lt;h2&gt;Who&apos;s exposed&lt;/h2&gt;
&lt;p&gt;The highest-risk configuration: a GeoServer instance using PostGIS or Oracle JDBC as its data store, reachable over a public network. If your GeoServer is internal-only with no external exposure, the window is narrower but not zero — lateral movement from a compromised perimeter host is a real path.&lt;/p&gt;
&lt;h2&gt;Priority action list&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;First:&lt;/strong&gt; Inventory every GeoServer instance in your environment. This sounds obvious. It often isn&apos;t — GeoServer nodes get stood up for project work and drift out of the asset register.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Second:&lt;/strong&gt; If public access isn&apos;t operationally required, restrict it now. Network ACL, authenticated reverse proxy, or firewall rule in front of the GeoServer port — pick one and do it today.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Third:&lt;/strong&gt; If public access is unavoidable, layer WAF rules to flag SQL injection patterns against GeoServer endpoints, particularly those hitting JSON array operations. WAF is a speed bump, not a fix.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fourth:&lt;/strong&gt; Instrument for unexpected outbound connections from the GeoServer process. RCE means an attacker shell; that shell beacons out. Catching it early is the difference between an incident and a breach.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fifth:&lt;/strong&gt; Monitor GeoServer&apos;s release channels. When a patch drops, treat it as a P1 regardless of what else is queued.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;More on active exploitation trends this week: &lt;a href=&quot;/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/&quot;&gt;SAP Commerce Cloud RCE Exploit Hits Days After Patch&lt;/a&gt;, &lt;a href=&quot;/articles/2026-08-15-openwrt-luci-critical-root-rce/&quot;&gt;Three Critical OpenWrt LuCI Flaws Allow Root RCE&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited/cover.jpg" medium="image" width="1200" height="675"/><category>GeoServer</category><category>SQL injection</category><category>zero-day</category><category>RCE</category><category>PostGIS</category><category>geospatial</category><category>active exploitation</category></item><item><title>Three Critical OpenWrt LuCI Flaws Allow Root RCE</title><link>https://0daynews.com/articles/2026-08-15-openwrt-luci-critical-root-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-openwrt-luci-critical-root-rce/</guid><description>Two CVSS 9.9 and one 8.8 vulnerabilities in OpenWrt&apos;s LuCI web interface let authenticated users execute arbitrary code as root. Update LuCI now.</description><pubDate>Sat, 15 Aug 2026 06:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Three vulnerabilities in OpenWrt&apos;s LuCI web management interface — two rated CVSS 9.9 critical — let authenticated users escalate to root and execute arbitrary code on the underlying host. OpenWrt runs on a substantial chunk of consumer routers, small-business gateways, and embedded networking hardware worldwide. If you&apos;re running LuCI and haven&apos;t patched, that&apos;s the action item. Everything else below is context.&lt;/p&gt;
&lt;h2&gt;The three flaws&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-72842/&quot;&gt;CVE-2026-72842&lt;/a&gt; — CVSS 9.9 Critical&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The LuCI container management app (&lt;code&gt;luci-app-lxc&lt;/code&gt;) has an ACL inconsistency: low-privileged authenticated users can reach backend container management routes without proper authorization checks. A path traversal in the &lt;code&gt;lxc_name&lt;/code&gt; parameter allows an attacker to escape container directories and control host-side scripts executed through &lt;code&gt;lxc.hook.start-host&lt;/code&gt; — which run as root. The GitHub Security Advisory is &lt;a href=&quot;https://github.com/openwrt/luci/security/advisories/GHSA-jf59-v86x-fwf2&quot;&gt;GHSA-jf59-v86x-fwf2&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-72841/&quot;&gt;CVE-2026-72841&lt;/a&gt; — CVSS 9.9 Critical&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The OpenVPN LuCI app (&lt;code&gt;luci-app-openvpn&lt;/code&gt;) fails to validate the &lt;code&gt;instance_name2&lt;/code&gt; parameter during file upload. Authenticated users can write arbitrary files outside the intended directory via path traversal, including placing content into system paths that survive reboots — giving persistent root-level access. Advisory: &lt;a href=&quot;https://github.com/openwrt/luci/security/advisories/GHSA-jjcx-c284-2qv8&quot;&gt;GHSA-jjcx-c284-2qv8&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/cve/cve-2026-72840/&quot;&gt;CVE-2026-72840&lt;/a&gt; — CVSS 8.8 High&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;An overly permissive ACL definition in &lt;code&gt;luci-mod-system-mounts&lt;/code&gt; hands write access to &lt;code&gt;/etc/crontabs/root&lt;/code&gt; to users scoped only for mount configuration. Any user in that ACL group can append cron entries via ubus, which the default busybox crond daemon executes as root within a minute. Advisory: &lt;a href=&quot;https://github.com/openwrt/luci/security/advisories/GHSA-v5f9-62c7-cw29&quot;&gt;GHSA-v5f9-62c7-cw29&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;p&gt;Fixes are in the upstream &lt;a href=&quot;https://github.com/openwrt/luci&quot;&gt;OpenWrt LuCI repository&lt;/a&gt;. The immediate priority ordering:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Update LuCI.&lt;/strong&gt; If your OpenWrt version has a package update available for the affected apps, apply it now.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Block LuCI from the WAN.&lt;/strong&gt; LuCI should never be reachable from the public internet — only from your local network. Confirm this in your firewall rules.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Remove the affected apps if you don&apos;t use them.&lt;/strong&gt; If you&apos;re not running LXC containers or an OpenVPN server through LuCI, uninstall &lt;code&gt;luci-app-lxc&lt;/code&gt; and &lt;code&gt;luci-app-openvpn&lt;/code&gt; entirely.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit LuCI user accounts.&lt;/strong&gt; Both critical flaws require authentication. The shorter your LuCI user list, the smaller the exposure window.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;CVE-2026-72842 and CVE-2026-72841 are the priority — both achieve root code execution via different paths in apps that ship as optional packages. CVE-2026-72840 affects &lt;code&gt;luci-mod-system-mounts&lt;/code&gt;, a component that&apos;s closer to the default configuration, so don&apos;t deprioritize it entirely.&lt;/p&gt;
&lt;p&gt;Router firmware is notoriously under-patched. If you manage a fleet of OpenWrt devices — in a lab, a field deployment, or an MSP context — this is worth a sweep. OpenWrt&apos;s package manager (&lt;code&gt;opkg&lt;/code&gt;) can be scripted, and you&apos;re not going to catch this from the console alone.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-openwrt-luci-critical-root-rce/cover.jpg" medium="image" width="1200" height="675"/><category>openwrt</category><category>luci</category><category>rce</category><category>router</category><category>path-traversal</category><category>cve</category><category>patch</category></item><item><title>Trivy, Not LiteLLM, Drove the March Supply Chain Breach</title><link>https://0daynews.com/articles/2026-08-15-trivy-not-litellm-supply-chain-march/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-trivy-not-litellm-supply-chain-march/</guid><description>SOCRadar&apos;s forensics show 95% of the 2,188 affected orgs were compromised via the Trivy scanner before any LiteLLM package was poisoned.</description><pubDate>Sat, 15 Aug 2026 04:30:00 GMT</pubDate><content:encoded>&lt;p&gt;The attribution on the March 2026 supply chain incident has been revised, and the revision matters for any security team still working through their exposure.&lt;/p&gt;
&lt;p&gt;New analysis from SOCRadar, &lt;a href=&quot;https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/&quot;&gt;reported by SecurityWeek&lt;/a&gt;, shows that approximately 95 percent of the 2,188 organizations identified in the dataset were compromised before the malicious LiteLLM packages appeared on PyPI. &lt;a href=&quot;../2026-08-12-litellm-supply-chain-trivy-hack-2500-orgs&quot;&gt;Those packages were published March 24&lt;/a&gt;. The actual campaign started March 19, when the first malicious Trivy build was published. Data collection began eighteen minutes later.&lt;/p&gt;
&lt;p&gt;By March 22 and 23, the compromised Trivy container images were active on Docker Hub and the attack was already running at scale.&lt;/p&gt;
&lt;h2&gt;What Trivy did versus what LiteLLM did&lt;/h2&gt;
&lt;p&gt;Trivy, Aqua Security&apos;s open-source container vulnerability scanner, was the initial infection vector. The malware embedded in the tampered builds behaved like a worm: it harvested credentials from the host environment, then used the stolen developer secrets to modify and poison downstream packages — a chain that eventually reached LiteLLM.&lt;/p&gt;
&lt;p&gt;LiteLLM&apos;s role was downstream and derivative. Attackers injected a &lt;code&gt;.pth&lt;/code&gt; file into the poisoned releases that executed at Python interpreter startup, neatly sidestepping install-script protections. But the credential collection had already been running for five days by the time those releases were pulled.&lt;/p&gt;
&lt;p&gt;SOCRadar characterizes LiteLLM as &quot;the closing act, not the whole play.&quot;&lt;/p&gt;
&lt;h2&gt;What the dataset shows&lt;/h2&gt;
&lt;p&gt;From SOCRadar&apos;s analysis of the credential haul:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Over 1,000 organizations had JWT tokens and authentication tokens exposed&lt;/li&gt;
&lt;li&gt;More than 1,100 had committer email addresses taken&lt;/li&gt;
&lt;li&gt;A single organization lost approximately 3,477 secrets — cloud keys, SSH keys, API tokens — in one campaign pass&lt;/li&gt;
&lt;li&gt;Confidence breakdown across the 2,188-organization dataset: 56 percent high, 39 percent medium, 6 percent low&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;The problem with security tooling as attack surface&lt;/h2&gt;
&lt;p&gt;The LiteLLM story was always going to be the one that got named. A PyPI package poisoned for 40 minutes has a version number, a pull timestamp, and a tidy remediation step: check your lockfile, rotate credentials if you installed it. That is the kind of thing a security advisory can communicate cleanly.&lt;/p&gt;
&lt;p&gt;Trivy is a different category of problem. Vulnerability scanners live inside CI/CD pipelines with elevated permissions by design — they access the environments they audit. When the tool doing the checking is the compromised one, the blast radius is everything it touched during normal operation, not just the narrow window where a bad package was available on PyPI.&lt;/p&gt;
&lt;p&gt;That gap — five days of Trivy-based collection versus forty minutes of LiteLLM availability — is where the actual scale of this incident lives. The package pulled from a registry in under an hour is easy to find in retrospect. The scanner that processed every build for five days straight is harder to isolate, and the log trail is usually in whatever your CI/CD system happens to retain.&lt;/p&gt;
&lt;h2&gt;What to check if you haven&apos;t already&lt;/h2&gt;
&lt;p&gt;If Trivy ran in your pipelines between March 19 and March 24, 2026, treat that window as potentially compromised and work the same credential category list SOCRadar flagged: cloud provider keys first, SSH private keys second, Kubernetes service account tokens third, database passwords fourth. Pull your build logs to scope which systems Trivy touched. Audit &lt;code&gt;authorized_keys&lt;/code&gt; files and RBAC bindings for any service accounts that were active.&lt;/p&gt;
&lt;p&gt;The LiteLLM check — which pip install logs from March 24 — is still worth doing. It just shouldn&apos;t be the only check.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/&quot;&gt;SecurityWeek — Trivy, Not LiteLLM Behind the 2,500 Org Compromise&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-15-trivy-not-litellm-supply-chain-march/cover.jpg" medium="image" width="1200" height="675"/><category>supply chain</category><category>Trivy</category><category>LiteLLM</category><category>SOCRadar</category><category>CI/CD security</category><category>credential theft</category><category>PyPI</category></item><item><title>Scottish Crown Office Breach May Spread Across Agencies</title><link>https://0daynews.com/articles/2026-08-14-scotland-copfs-breach-third-party/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-scotland-copfs-breach-third-party/</guid><description>Scotland&apos;s Crown Office confirms a data breach via a compromised third-party service provider. Investigators warn other government agencies may share the exposure.</description><pubDate>Fri, 14 Aug 2026 22:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Scotland&apos;s Crown Office and Procurator Fiscal Service (COPFS) — the country&apos;s national prosecution authority — has confirmed a data breach originating at a third-party service provider, &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office&quot;&gt;Dark Reading reported&lt;/a&gt; on August 14.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Confirmed:&lt;/strong&gt; COPFS suffered unauthorized access via a vendor that services the agency. An investigation is active.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Not yet confirmed:&lt;/strong&gt; Data types affected. Record count. Identity of the third-party supplier. Whether the intrusion has been contained.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The concern:&lt;/strong&gt; The same vendor may service other Scottish government departments. If so, COPFS is not the final notification — just the first.&lt;/p&gt;
&lt;p&gt;Third-party breach multipliers are not hypothetical. When a service provider operates across multiple agencies — shared case management, managed IT services, document handling — a single compromise cascades horizontally through clients who each assumed they were isolated. Scotland&apos;s government ecosystem is not immune to that pattern.&lt;/p&gt;
&lt;p&gt;As of this writing, Scotland has not publicly named the vendor. No formal guidance has been issued to other agencies. Whether the third party has notified all potentially affected clients is unconfirmed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Assessment — LOW confidence on scope.&lt;/strong&gt; The breach at COPFS is confirmed. Whether it extends to other agencies remains under active investigation. Investigators&apos; use of &quot;potentially widening,&quot; as reported by Dark Reading, signals authorities have reason to believe the exposure is broader than one organization — but that is not yet established on the record.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What agencies should verify now:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Which third-party vendors have access to sensitive case, personnel, or citizen data&lt;/li&gt;
&lt;li&gt;Whether vendor environments are shared across other government clients&lt;/li&gt;
&lt;li&gt;Do not wait for an official notification — contact vendors directly&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Developments are expected. This story will update as details are confirmed.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Source: &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office&quot;&gt;Dark Reading, August 14, 2026&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-scotland-copfs-breach-third-party/cover.jpg" medium="image" width="1200" height="675"/><category>data breach</category><category>Scotland</category><category>Crown Office</category><category>COPFS</category><category>third-party</category><category>government</category><category>supply chain</category></item><item><title>Seven Arrested in €30M Commerzbank Account Fraud</title><link>https://0daynews.com/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests/</guid><description>German BKA and Brazil&apos;s federal police arrested seven over a service provider flaw that enabled withdrawals from Commerzbank customer accounts. €30M stolen.</description><pubDate>Fri, 14 Aug 2026 20:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Seven arrests. Two countries. €30 million stripped from Commerzbank customer accounts.&lt;/p&gt;
&lt;p&gt;Germany&apos;s Federal Criminal Police Office (BKA) charged three suspects in Europe. Brazil&apos;s &lt;em&gt;Polícia Federal&lt;/em&gt; arrested four more. The operations were coordinated, announced Thursday, and aimed at a group that had exploited a vulnerability at a third-party service provider to pull funds directly from customer accounts — not a phishing run, not a credential-spray campaign. They had back-end access.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/&quot;&gt;BleepingComputer&lt;/a&gt; and &lt;a href=&quot;https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil&quot;&gt;The Record&lt;/a&gt; both confirmed the enforcement action, citing BKA and &lt;em&gt;Polícia Federal&lt;/em&gt; statements.&lt;/p&gt;
&lt;h2&gt;Confirmed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;€30M&lt;/strong&gt; extracted from Commerzbank customer accounts (BKA-confirmed)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;4 arrested&lt;/strong&gt; in Brazil by &lt;em&gt;Polícia Federal&lt;/em&gt;, Thursday&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;3 charged&lt;/strong&gt; in Europe by BKA-led operation, Thursday&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Attack vector&lt;/strong&gt;: vulnerability exploited at an unnamed service provider with back-end connectivity to Commerzbank&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mechanism&lt;/strong&gt;: access enabled direct fund withdrawals, not credential collection alone&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;The Service Provider Flaw&lt;/h2&gt;
&lt;p&gt;The specific vulnerability and the service provider&apos;s identity have not been disclosed in available reporting. What is confirmed: the attackers reached deep enough into banking infrastructure to authorize outbound transfers. That matters — a credential or intercepted session token typically requires additional steps to move money; back-end access compresses that chain considerably.&lt;/p&gt;
&lt;p&gt;Charging documents will clarify the technical entry point. Until then: unconfirmed. Do not fill in the gap.&lt;/p&gt;
&lt;h2&gt;What&apos;s Not Confirmed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The service provider&apos;s name or the specific flaw exploited&lt;/li&gt;
&lt;li&gt;Whether the underlying vulnerability has since been patched&lt;/li&gt;
&lt;li&gt;Number of Commerzbank customers affected&lt;/li&gt;
&lt;li&gt;Whether the seven arrested represent the full operation or whether additional suspects remain outstanding&lt;/li&gt;
&lt;li&gt;How long fraudulent withdrawals went undetected before the investigation triggered arrests&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;What to Watch&lt;/h2&gt;
&lt;p&gt;BKA typically releases detailed indictment summaries after initial arrest announcements. &lt;em&gt;Polícia Federal&lt;/em&gt; briefings on financial cybercrime arrests follow within weeks. Both are the primary sources to monitor for the service provider&apos;s identity and technical specifics.&lt;/p&gt;
&lt;p&gt;Third-party access to financial back-ends is a specific and underreported attack surface. &lt;a href=&quot;/articles/2026-08-14-beacon-crm-breach-charities-aws-key/&quot;&gt;Beacon CRM&apos;s breach via an exposed AWS key&lt;/a&gt; — disclosed today, affecting over 1,000 charities — runs the same structural pattern at a different scale: service provider compromised, downstream victims pay. For prior cross-border enforcement context, &lt;a href=&quot;/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized/&quot;&gt;INTERPOL&apos;s Operation First Light&lt;/a&gt; ran 5,811 arrests across 61 countries in mid-2026.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Also today: &lt;a href=&quot;/articles/2026-08-14-shell-clop-89gb-data-theft-claim/&quot;&gt;Shell under investigation after Clop claims 89GB theft&lt;/a&gt;. &lt;a href=&quot;/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/&quot;&gt;ShinyHunters hits RingCentral — 1.6 million accounts&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests/cover.jpg" medium="image" width="1200" height="675"/><category>commerzbank</category><category>bank fraud</category><category>cybercrime arrests</category><category>BKA</category><category>germany</category><category>brazil</category><category>service-provider breach</category></item><item><title>France Confirms DGFIP Breach; Hacker Claims 600K</title><link>https://0daynews.com/articles/2026-08-14-france-dgfip-tax-breach-600k/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-france-dgfip-tax-breach-600k/</guid><description>France&apos;s tax authority confirms unauthorized access in late June via credential theft. A threat actor claims 600,000 records stolen. Investigation ongoing.</description><pubDate>Fri, 14 Aug 2026 20:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Confirmed. France&apos;s Directorate General of Public Finances — Direction générale des finances publiques, DGFIP — acknowledged unauthorized access to its systems in late June 2026. &lt;a href=&quot;https://therecord.media/french-tax-authority-dgfip-confirms-data-breach&quot;&gt;The Record&lt;/a&gt; broke the confirmation today.&lt;/p&gt;
&lt;h2&gt;Status&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Access confirmed.&lt;/strong&gt; French authorities state that someone gained unauthorized entry to DGFIP systems in late June by stealing or misusing employee identity credentials. Account compromise — not a disclosed software vulnerability.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;600,000 victim claim.&lt;/strong&gt; Unconfirmed. The threat actor asserts 600,000 individuals are affected. DGFIP has not verified that figure. Treat as adversary claim pending independent corroboration.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Data exfiltrated.&lt;/strong&gt; Not confirmed publicly. DGFIP has not disclosed what records, if any, were removed from its systems.&lt;/p&gt;
&lt;h2&gt;Why This Matters&lt;/h2&gt;
&lt;p&gt;DGFIP administers tax collection, public accounting, and financial management for the French state. Its databases hold tax returns, income declarations, and financial disclosure data for individuals and businesses across France. If the 600,000 figure holds, this ranks among the larger government-sector data exposures in Western Europe in 2026.&lt;/p&gt;
&lt;p&gt;The entry vector — credential misuse, not a zero-day — is the same playbook seen repeatedly this year: acquire working credentials, authenticate legitimately, operate quietly. Harder to detect than exploit chains and outside most automated vulnerability-scan coverage entirely.&lt;/p&gt;
&lt;h2&gt;What&apos;s Not Confirmed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The 600,000 figure is the attacker&apos;s claim, not verified by DGFIP or independent investigators.&lt;/li&gt;
&lt;li&gt;Whether exfiltrated data includes personally identifiable information, financial records, or both.&lt;/li&gt;
&lt;li&gt;The identity or affiliation of the threat actor.&lt;/li&gt;
&lt;li&gt;Whether access reached internal systems only or also external-facing portals used by taxpayers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;What to Watch&lt;/h2&gt;
&lt;p&gt;GDPR imposes a 72-hour breach notification window once a data controller confirms personal data exposure. If DGFIP concludes personal data was exfiltrated, a formal notification to France&apos;s CNIL data-protection authority follows — triggering additional mandatory public disclosure.&lt;/p&gt;
&lt;p&gt;Active investigation. No attribution announced.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Also developing today: &lt;a href=&quot;/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/&quot;&gt;RingCentral Breach — ShinyHunters Claims 1.6M Accounts&lt;/a&gt;. Earlier: &lt;a href=&quot;/articles/2026-08-13-trezor-shipmonk-breach-14k-customers/&quot;&gt;Trezor — 14,000 Customers Exposed via ShipMonk&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-france-dgfip-tax-breach-600k/cover.jpg" medium="image" width="1200" height="675"/><category>France</category><category>DGFIP</category><category>data breach</category><category>government breach</category><category>credential theft</category><category>tax authority</category><category>Europe</category></item><item><title>AmnesiaStealer Hijacks macOS Browser Sessions</title><link>https://0daynews.com/articles/2026-08-14-amnesiastealer-macos-clickfix-browser-hijack/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-amnesiastealer-macos-clickfix-browser-hijack/</guid><description>Jamf finds AmnesiaStealer: macOS infostealer that hijacks live browser sessions, steals keychain data, and destroys saved passwords via ClickFix terminal prompts.</description><pubDate>Fri, 14 Aug 2026 18:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jamf researchers have documented a new Rust-built macOS infostealer named AmnesiaStealer, delivered through counterfeit GitHub download pages using &lt;a href=&quot;/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop/&quot;&gt;ClickFix&lt;/a&gt; social engineering. It doesn&apos;t just steal credentials — it overwrites macOS Safe Storage keys afterward, leaving saved browser passwords permanently unrecoverable. Findings were &lt;a href=&quot;https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/&quot;&gt;reported by SecurityWeek&lt;/a&gt; on August 14.&lt;/p&gt;
&lt;h2&gt;What it steals&lt;/h2&gt;
&lt;p&gt;The infection runs a three-stage chain triggered by a ClickFix terminal-paste prompt. A LaunchDaemon lands for persistence across reboots. AmnesiaStealer then harvests:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Saved passwords and keychain contents&lt;/li&gt;
&lt;li&gt;Chromium-based browser data (Chrome, Brave, Arc, Edge)&lt;/li&gt;
&lt;li&gt;Safari cookies&lt;/li&gt;
&lt;li&gt;Apple Notes&lt;/li&gt;
&lt;li&gt;Local documents&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;The browser session hijacking module&lt;/h2&gt;
&lt;p&gt;Beyond a credential dump, AmnesiaStealer clones the victim&apos;s browser profile and launches it headless, establishing a live remote-control session over the Chrome DevTools Protocol — approximately 3fps screencasting with full keyboard, mouse, and tab input. The attacker operates inside an already-authenticated session without needing to crack or replay the stolen cookies.&lt;/p&gt;
&lt;h2&gt;The destruction piece&lt;/h2&gt;
&lt;p&gt;AmnesiaStealer overwrites macOS Safe Storage encryption keys after exfiltration. Chromium-based browsers use these keys to protect locally saved passwords; once overwritten, those credentials are gone from the victim&apos;s device — not copied elsewhere, gone. Jamf identifies this as intentional malware behavior, not a side effect.&lt;/p&gt;
&lt;p&gt;The malware also attempts to bypass macOS&apos;s Transparency, Consent, and Control (TCC) privacy framework and uses OS version-specific branching logic to adapt across macOS releases.&lt;/p&gt;
&lt;h2&gt;What to actually do&lt;/h2&gt;
&lt;p&gt;The hook is social — someone pasted a Terminal command from a web page. &lt;a href=&quot;/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop/&quot;&gt;This delivery method has been in wide use against macOS users since at least July&lt;/a&gt;, and this isn&apos;t Jamf&apos;s first macOS stealer find this year — &lt;a href=&quot;/articles/2026-07-13-jamf-crashstealer-werkbit-notarized-macos-stealer/&quot;&gt;CrashStealer in July&lt;/a&gt; used the same distribution class.&lt;/p&gt;
&lt;p&gt;If exposure is suspected:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Treat keychain and all Chromium-browser saved passwords as fully compromised — rotate before re-saving anything&lt;/li&gt;
&lt;li&gt;Saved passwords may not be recoverable from the browser if Safe Storage was overwritten; pull from a dedicated password manager if you have one&lt;/li&gt;
&lt;li&gt;Audit &lt;code&gt;/Library/LaunchDaemons/&lt;/code&gt; for unexpected entries&lt;/li&gt;
&lt;li&gt;Pull Jamf&apos;s full technical analysis for IOCs before closing the investigation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For security teams: any macOS endpoint where a user ran an unexpected Terminal command in the last 48 hours is a containment priority. &lt;a href=&quot;/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited/&quot;&gt;A separate macOS screen sharing authentication bypass is also being actively exploited today&lt;/a&gt; — macOS is having a rough Thursday.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-amnesiastealer-macos-clickfix-browser-hijack/cover.jpg" medium="image" width="1200" height="675"/><category>macOS</category><category>malware</category><category>AmnesiaStealer</category><category>ClickFix</category><category>infostealer</category><category>browser hijacking</category><category>Jamf</category></item><item><title>macOS Screen Sharing Auth Bypass Exploited in Wild</title><link>https://0daynews.com/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited/</guid><description>Netherlands NCSC confirms active exploitation of a macOS Screen Sharing authentication bypass after public PoC release. Attackers deploying Monero cryptocurrency miners.</description><pubDate>Fri, 14 Aug 2026 18:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Exploitation confirmed.&lt;/p&gt;
&lt;p&gt;The Netherlands&apos; National Cyber Security Centre (NCSC) is warning organizations that attackers are actively exploiting an authentication bypass in macOS Screen Sharing. The campaign accelerated after public proof-of-concept exploit code emerged. Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/&quot;&gt;BleepingComputer, August 14, 2026&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Payload confirmed.&lt;/strong&gt; Observed post-exploitation activity: deployment of a Monero cryptocurrency miner. Cryptojacking, not ransomware — but unauthorized remote access on a compromised host means full execution capability, regardless of what the current operators chose to run.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CVE status.&lt;/strong&gt; A specific CVE identifier has not been confirmed in available open sources as of publication time. Unconfirmed — treat accordingly.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Patch status.&lt;/strong&gt; No official Apple patch has been announced as of this writing. Assume any macOS host with Screen Sharing enabled and reachable is exposed.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;What to do now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;If Screen Sharing is not operationally required: disable it.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;→ System Settings → Sharing → Screen Sharing → toggle off&lt;/p&gt;
&lt;p&gt;This eliminates the exposed attack surface regardless of patch timeline.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If Screen Sharing must remain active:&lt;/strong&gt; restrict inbound access at the network layer. macOS Screen Sharing (VNC) runs on TCP port 5900. Firewall rules scoping that port to known management hosts only are an effective interim control. Host-based and network-perimeter rules both apply.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Detection posture:&lt;/strong&gt; monitor for sustained high CPU from unexpected processes, new outbound connections to cryptocurrency mining pools, and processes spawned under a remote-access account context. Endpoint detection that flags cryptominer behavior should catch the observed payload class even without a signature for the initial access vector.&lt;/p&gt;
&lt;p&gt;No CVE, no patch, active public PoC in circulation. Watch for an Apple security advisory and a potential CISA KEV addition.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Related:&lt;/strong&gt; Apple is separately rolling out on-device &lt;a href=&quot;/articles/2026-08-14-apple-mercenary-spyware-threat-notifications/&quot;&gt;Threat Notifications for mercenary spyware targets&lt;/a&gt; — a different threat vector on the same platform. For macOS malware context, see &lt;a href=&quot;/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf/&quot;&gt;PAMStealer and the Mac threat ecosystem&lt;/a&gt;. More Apple platform vulnerabilities and malware coverage in the &lt;a href=&quot;/topics/apple/&quot;&gt;Apple topic hub&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited/cover.jpg" medium="image" width="1200" height="675"/><category>macOS</category><category>Screen Sharing</category><category>authentication bypass</category><category>exploitation</category><category>Monero miner</category><category>NCSC</category><category>active exploitation</category></item><item><title>SAP Commerce Cloud RCE Exploit Hits Days After Patch</title><link>https://0daynews.com/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/</guid><description>Defused flagged active exploitation of a max-severity SAP Commerce Cloud RCE within 72 hours of patching. Unpatched instances are live targets now.</description><pubDate>Fri, 14 Aug 2026 16:30:00 GMT</pubDate><content:encoded>&lt;p&gt;Patch released. Exploitation started. Seventy-two hours is not a remediation window — it is the distance between &quot;patched&quot; and &quot;breached.&quot;&lt;/p&gt;
&lt;p&gt;Threat intelligence company Defused &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/&quot;&gt;confirmed active attacks&lt;/a&gt; against a maximum-severity remote code execution vulnerability in SAP Commerce Cloud, with exploitation traffic observed within three days of SAP&apos;s patch release. The fix was part of SAP&apos;s August 2026 Security Patch Day cycle.&lt;/p&gt;
&lt;h2&gt;What Happened&lt;/h2&gt;
&lt;p&gt;SAP&apos;s August Security Patch Day included a maximum-severity RCE affecting Commerce Cloud. Within days, Defused observed active exploitation attempts in the wild. The vulnerability class is remote code execution — meaning an attacker who reaches a vulnerable instance can run arbitrary code on the underlying server without needing to authenticate first, or with minimal access depending on the specific flaw.&lt;/p&gt;
&lt;p&gt;No CVE number was included in feed sources at time of writing. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/&quot;&gt;BleepingComputer&apos;s report&lt;/a&gt; carries the full technical detail from Defused; follow it for version specifics and indicators of compromise.&lt;/p&gt;
&lt;h2&gt;Why Commerce Cloud Is a High-Value Target&lt;/h2&gt;
&lt;p&gt;SAP Commerce Cloud is the e-commerce and B2B portal backbone for some of the world&apos;s largest companies — manufacturing, retail, consumer goods, energy. An RCE on an internet-facing Commerce Cloud instance can provide access to customer PII, payment integrations, and internal SAP system connections. Maximum severity on a platform like this means maximum business impact. Attackers know that.&lt;/p&gt;
&lt;h2&gt;What to Do&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Apply the August 2026 SAP Security Patch Day updates now.&lt;/strong&gt; If your SAP basis team or managed service provider hasn&apos;t confirmed this cycle is complete for Commerce Cloud, that conversation happens today.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prioritize Commerce Cloud over lower-severity items.&lt;/strong&gt; If your patch schedule is phased, move this to the front.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check the &lt;a href=&quot;https://support.sap.com/&quot;&gt;SAP Support Portal&lt;/a&gt; for the specific security note&lt;/strong&gt;, affected version ranges, and any available workarounds if immediate patching is not possible.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review Commerce Cloud application logs&lt;/strong&gt; for anomalous behavior — unexpected process spawns, unusual outbound network connections, or irregular API calls from the application tier.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit network exposure.&lt;/strong&gt; Administration interfaces should not be internet-reachable. If they are, restrict access to known IP ranges immediately while patching proceeds.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;The Honest Timeline&lt;/h2&gt;
&lt;p&gt;Three-day patch-to-exploit turnaround on a max-severity enterprise platform flaw is not unusual anymore — it is the baseline. Automated patch-diffing lets attackers reverse-engineer a fix and reconstruct the vulnerability faster than most organizations can schedule a maintenance window.&lt;/p&gt;
&lt;p&gt;The remediation window your organization&apos;s patch policy assumes probably does not account for this. If your policy says &quot;patch critical vulnerabilities within 30 days,&quot; that policy is writing checks your security posture cannot cash.&lt;/p&gt;
&lt;p&gt;Patch Commerce Cloud. Then review your logs as if you were already compromised — on a three-day exploitation timeline, verifying you are not is worth the hour it takes.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Related: &lt;a href=&quot;/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/&quot;&gt;GeoServer Zero-Day SQL Injection Exploited in Wild&lt;/a&gt; — &lt;a href=&quot;/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/&quot;&gt;WordPress 7.0.4 Patches High-Severity RCE Flaw&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/&quot;&gt;BleepingComputer — Max severity SAP Commerce Cloud flaw now targeted in attacks&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-sap-commerce-cloud-rce-exploitation/cover.jpg" medium="image" width="1200" height="675"/><category>SAP</category><category>Commerce Cloud</category><category>RCE</category><category>remote code execution</category><category>patch</category><category>active exploitation</category><category>enterprise</category></item><item><title>Clop Claims 89GB Shell Theft; Investigation Open</title><link>https://0daynews.com/articles/2026-08-14-shell-clop-89gb-data-theft-claim/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-shell-clop-89gb-data-theft-claim/</guid><description>Shell confirms investigating a potential incident after Clop listed the oil giant on its extortion site, claiming 89GB of exfiltrated data. No breach confirmed; initial access vector undisclosed.</description><pubDate>Fri, 14 Aug 2026 14:30:00 GMT</pubDate><content:encoded>&lt;p&gt;Shell confirmed it is investigating a &quot;potential incident&quot; after the Clop extortion group listed the oil and gas company on its data-leak site, claiming to have stolen 89 gigabytes of data.&lt;/p&gt;
&lt;h2&gt;Status&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Shell investigating.&lt;/strong&gt; Confirmed. The company acknowledged an inquiry in a statement reported by &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/&quot;&gt;BleepingComputer&lt;/a&gt;. Shell has not confirmed unauthorized access — only that a potential incident is under review.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Clop&apos;s 89GB claim.&lt;/strong&gt; Unconfirmed. Clop listed Shell on its extortion portal with an 89-gigabyte figure. No data samples have been published as of this writing. That is consistent with the group&apos;s standard hold-and-pressure cadence before a self-imposed publication deadline.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Initial access vector.&lt;/strong&gt; Not disclosed. Shell has not confirmed how any access may have occurred. Clop has not specified an entry point or exploit chain in its initial listing.&lt;/p&gt;
&lt;h2&gt;Clop&apos;s 2026 Campaign Context&lt;/h2&gt;
&lt;p&gt;The group is not a new actor. Clop ran the &lt;a href=&quot;/articles/2026-07-23-moveit-cve-2023-34362-three-years-clop-data-breach/&quot;&gt;MOVEit file-transfer campaign in 2023&lt;/a&gt;, ultimately affecting over a thousand organizations. Their operational model has shifted toward pure data-theft extortion — no encryption, just exfiltration and staged exposure.&lt;/p&gt;
&lt;p&gt;In July 2026, the group resumed active operations targeting PTC Windchill and FlexPLM product-lifecycle management environments via &lt;a href=&quot;/articles/2026-07-24-clop-windchill-flexplm-cve-2026-12569-data-theft/&quot;&gt;CVE-2026-12569&lt;/a&gt;, an unauthenticated remote code execution flaw. &lt;a href=&quot;/articles/2026-07-25-clop-targets-ptc-windchill-flexplm-data-theft/&quot;&gt;Shell operates large, complex enterprise IT environments across energy, logistics, and trading functions&lt;/a&gt; — whether today&apos;s incident shares infrastructure or entry vector with the Windchill campaign is unconfirmed.&lt;/p&gt;
&lt;h2&gt;What&apos;s Not Confirmed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The 89GB volume is Clop&apos;s assertion. Not independently verified.&lt;/li&gt;
&lt;li&gt;Whether the data is operational, employee, customer, or commercial in nature.&lt;/li&gt;
&lt;li&gt;Whether a Shell subsidiary or joint-venture system rather than Shell corporate is the actual target.&lt;/li&gt;
&lt;li&gt;Whether Clop has set an internal publication deadline and what that window is.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;What to Watch&lt;/h2&gt;
&lt;p&gt;Clop&apos;s documented pattern runs in stages: list the target, set a countdown, publish sample data, release the full dataset. Shell is at step one.&lt;/p&gt;
&lt;p&gt;If Shell concludes unauthorized access occurred, a formal breach notification is likely within 72 hours under applicable regulatory frameworks. Whether CISA or the energy sector&apos;s E-ISAC issues advisory guidance will signal how the incident is assessed beyond Shell&apos;s own investigation.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Earlier Clop coverage: &lt;a href=&quot;/articles/2026-07-25-clop-targets-ptc-windchill-flexplm-data-theft/&quot;&gt;Clop Targets PTC Windchill and FlexPLM — July 2026 Campaign&lt;/a&gt;. Also developing: &lt;a href=&quot;/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/&quot;&gt;ShinyHunters Hits RingCentral, 1.6M Accounts Exposed&lt;/a&gt; — separate actor, same day.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-shell-clop-89gb-data-theft-claim/cover.jpg" medium="image" width="1200" height="675"/><category>Clop</category><category>Shell</category><category>data-theft</category><category>extortion</category><category>ransomware</category><category>oil-gas</category><category>investigation</category></item><item><title>ShinyHunters Hits RingCentral: 1.6M Accounts Exposed</title><link>https://0daynews.com/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/</guid><description>ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.</description><pubDate>Fri, 14 Aug 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;1.6 million accounts. July breach. Data published.&lt;/p&gt;
&lt;h2&gt;What&apos;s Confirmed&lt;/h2&gt;
&lt;p&gt;ShinyHunters accessed RingCentral&apos;s systems in July 2026 and exfiltrated account records. The group published the stolen data. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/&quot;&gt;BleepingComputer reported&lt;/a&gt; the exposure via the Have I Been Pwned breach notification service. &lt;a href=&quot;https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/&quot;&gt;SecurityWeek confirmed&lt;/a&gt; the data publication.&lt;/p&gt;
&lt;p&gt;Exposed fields confirmed: names, physical addresses, email addresses, phone numbers. Confidence: confirmed by breach notification indexing and independent reporting.&lt;/p&gt;
&lt;p&gt;Initial access vector: unconfirmed as of this writing. No CVE is attached to this incident.&lt;/p&gt;
&lt;h2&gt;ShinyHunters — The Pattern&lt;/h2&gt;
&lt;p&gt;Not a new group. Not a new method. ShinyHunters operates a well-documented mass-exfiltration and extortion playbook targeting SaaS platforms and large account databases:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;July 2026&lt;/strong&gt;: Politie and Odido, Netherlands — &lt;a href=&quot;/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-6.2m/&quot;&gt;6.2 million records via vishing and SIM-swap-assisted access&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;July 2026&lt;/strong&gt;: &lt;a href=&quot;/articles/2026-07-14-microsoft-shinyhunters-salesforce-oauth-three-paths/&quot;&gt;Microsoft mapped ShinyHunters-linked actors abusing three Salesforce OAuth paths&lt;/a&gt; for over a year — none required a Salesforce vulnerability.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pattern: target cloud SaaS, exfiltrate PII at scale, publish to drive extortion pressure or headline attention. No ransomware required.&lt;/p&gt;
&lt;h2&gt;What the Exposed Data Enables&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;Analysis&lt;/em&gt; — 1.6 million records pairing names, email addresses, phone numbers, and physical addresses for a business telecom platform constitute a high-quality targeting set. RingCentral&apos;s user base skews enterprise: IT admins, operations staff, finance teams. Expect:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Spear-phishing&lt;/strong&gt; against RingCentral account holders, especially admins with downstream access to business systems.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SIM-swap attempts&lt;/strong&gt; using the phone number field against carriers that rely on phone-based identity verification.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Credential-stuffing&lt;/strong&gt; if any portion of the 1.6 million accounts reused passwords across services sharing the same email address.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Treat the breach as staged for follow-on targeting, not a completed operation.&lt;/p&gt;
&lt;h2&gt;If You&apos;re a RingCentral Customer&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Enable MFA on the RingCentral account if not already active — time-based OTP or hardware key, not SMS where avoidable.&lt;/li&gt;
&lt;li&gt;Alert employees in IT, finance, and admin roles to treat unexpected RingCentral-themed contact — email, phone, or text — as elevated phishing risk.&lt;/li&gt;
&lt;li&gt;Check &lt;a href=&quot;https://haveibeenpwned.com/&quot;&gt;Have I Been Pwned&lt;/a&gt; to confirm whether specific addresses from your organization appear in the dataset.&lt;/li&gt;
&lt;li&gt;Lock down any accounts sharing email addresses or phone numbers with RingCentral credentials — password reset and session invalidation across services.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;RingCentral has not published a public incident response page as of this writing. Watch the vendor&apos;s trust and security channels for updates.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Also this week: &lt;a href=&quot;/articles/2026-08-14-beacon-crm-breach-charities-aws-key/&quot;&gt;Beacon CRM breach exposes supporter data from 1,000+ UK charities&lt;/a&gt; — different vector, same class of credential-enabled cloud access. &lt;a href=&quot;/articles/2026-08-13-trezor-shipmonk-breach-14k-customers/&quot;&gt;Trezor discloses 14,000-customer breach via ShipMonk&lt;/a&gt; — supply-chain path.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/cover.jpg" medium="image" width="1200" height="675"/><category>ringcentral</category><category>shinyhunters</category><category>data-breach</category><category>extortion</category><category>pii</category><category>telecom</category><category>breach-notification</category></item><item><title>Beacon CRM Breach Hits 1,000+ Charities via AWS Key</title><link>https://0daynews.com/articles/2026-08-14-beacon-crm-breach-charities-aws-key/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-beacon-crm-breach-charities-aws-key/</guid><description>Over 1,000 UK charities had supporter data exposed after attackers used an AWS access key found in Beacon&apos;s public JavaScript build artifacts.</description><pubDate>Fri, 14 Aug 2026 10:00:00 GMT</pubDate><content:encoded>&lt;p&gt;1,000+ charities. One leaked AWS access key. July 27–28, it was used.&lt;/p&gt;
&lt;h2&gt;What Happened&lt;/h2&gt;
&lt;p&gt;Beacon, a UK-based CRM provider serving the charity sector, &lt;a href=&quot;https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/&quot;&gt;disclosed on August 14&lt;/a&gt; that attackers accessed its AWS environment using a compromised access key. Beacon&apos;s updated investigation finding: the key &quot;may have been exposed in publicly available JavaScript build artifacts.&quot;&lt;/p&gt;
&lt;p&gt;Timeline:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;July 27&lt;/strong&gt;: Earliest observed malicious activity.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;July 27–28&lt;/strong&gt;: Data transferred out of the AWS environment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Early August&lt;/strong&gt;: Initial breach disclosure to affected charities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;August 14&lt;/strong&gt;: Updated investigation findings published.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Confidence: Breach confirmed by the vendor. Root cause attributed to exposed credential; investigation ongoing.&lt;/p&gt;
&lt;h2&gt;Scope&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Impacted&lt;/strong&gt;: 1,000+ charities and non-profit organizations using Beacon&apos;s platform.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data exposed&lt;/strong&gt;: supporter PII — names, email addresses, phone numbers, postal addresses.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Not exposed&lt;/strong&gt;: financial data. Beacon states no bank account numbers, sort codes, card numbers, or card security details were stored on the platform.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Several UK charities have issued public statements. The UK Charity Commission is monitoring the situation and has issued guidance to affected organizations.&lt;/p&gt;
&lt;h2&gt;Attribution&lt;/h2&gt;
&lt;p&gt;No group has claimed responsibility. No evidence of published data as of this writing. Beacon&apos;s own investigation hit limits: &quot;Specific objects, exact destination of the downloads, and definitive attribution...cannot be determined from available logs.&quot;&lt;/p&gt;
&lt;p&gt;Unknown actor. Unknown destination. Supporter data is somewhere — and so far, no one can say where. Treat affected individuals&apos; records as actively staged for phishing until evidence says otherwise.&lt;/p&gt;
&lt;h2&gt;Root Cause&lt;/h2&gt;
&lt;p&gt;AWS access key exposed in public JavaScript build artifacts. Known failure mode — secrets bundled into client-side JS at build time, visible to anyone reading page source or diffing release archives. This one was found and used.&lt;/p&gt;
&lt;p&gt;If you operate SaaS on AWS and ship JavaScript to users: audit your build artifacts for embedded credentials. Automated secret scanners exist for this. Run them before an attacker does.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Also this week: &lt;a href=&quot;/articles/2026-08-13-trezor-shipmonk-breach-14k-customers/&quot;&gt;Trezor discloses 14,000-customer breach via logistics partner ShipMonk&lt;/a&gt; — a different vector, same class of supply-chain exposure.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-beacon-crm-breach-charities-aws-key/cover.jpg" medium="image" width="1200" height="675"/><category>beacon</category><category>charity</category><category>data-breach</category><category>aws-credentials</category><category>cloud-security</category><category>crm</category><category>access-key</category></item><item><title>WordPress 7.0.4 Patches High-Severity RCE Flaw</title><link>https://0daynews.com/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/</guid><description>WordPress 7.0.4 fixes a high-severity RCE allowing Author-level accounts to execute code via malicious PostScript files. Update now.</description><pubDate>Fri, 14 Aug 2026 10:00:00 GMT</pubDate><content:encoded>&lt;p&gt;WordPress 7.0.4 shipped a security release patching a high-severity remote code execution vulnerability affecting WordPress 4.7 through 7.0.3. The fix is backported across all affected branches. &lt;a href=&quot;https://www.securityweek.com/wordpress-7-0-4-patches-remote-code-execution-vulnerability/&quot;&gt;SecurityWeek reported the disclosure on August 13&lt;/a&gt; and &lt;a href=&quot;https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w&quot;&gt;the advisory is tracked publicly on GitHub&lt;/a&gt; as CVE-2026-65640, CVSS 8.8 (High). Update now.&lt;/p&gt;
&lt;h2&gt;What the Flaw Does&lt;/h2&gt;
&lt;p&gt;The vulnerability lives at the intersection of WordPress&apos;s file-upload validation and how ImageMagick processes image files. WordPress checks files by extension when they&apos;re uploaded. ImageMagick, however, checks by examining file contents. An attacker with Author-level permissions or higher can craft an image file with a benign extension — say, PNG — that contains embedded PostScript code in its data. When WordPress passes that file to the PHP Imagick extension for processing, ImageMagick recognizes the PostScript content and hands it to Ghostscript for rendering. Ghostscript executes it.&lt;/p&gt;
&lt;p&gt;The outcome is code execution on the web server under the permissions of the web server process — and from there, depending on the server setup, the attacker&apos;s options expand.&lt;/p&gt;
&lt;p&gt;Three conditions must all be true for the flaw to be exploitable:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The WordPress account used for the upload has Author, Editor, or Administrator privileges&lt;/li&gt;
&lt;li&gt;The PHP Imagick extension is installed on the server&lt;/li&gt;
&lt;li&gt;Ghostscript is installed on the server&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Imagick with Ghostscript is common in managed WordPress hosting environments where rich image processing is enabled by default. It&apos;s not universal, but it&apos;s not rare.&lt;/p&gt;
&lt;h2&gt;The Fix&lt;/h2&gt;
&lt;p&gt;WordPress 7.0.4 modifies the file load function to verify file contents before passing them to Imagick — the check happens before Ghostscript ever processes the input. Per Patchstack&apos;s analysis cited in SecurityWeek&apos;s coverage, the patch closes the validation gap that allowed the content-type mismatch to be exploited.&lt;/p&gt;
&lt;p&gt;If your WordPress installation is on auto-updates, check &lt;strong&gt;Dashboard → Updates&lt;/strong&gt; to confirm 7.0.4 is applied. If you&apos;re managing updates manually or through a deployment pipeline, prioritize this cycle.&lt;/p&gt;
&lt;h2&gt;What to Do&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Update to WordPress 7.0.4&lt;/strong&gt; (or the backported version for your branch, per the &lt;a href=&quot;https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w&quot;&gt;GitHub advisory&lt;/a&gt;). This is the only fix.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check your extension stack.&lt;/strong&gt; If Imagick isn&apos;t required for your workflows, removing it eliminates this attack surface — and a class of similar file-processing vulnerabilities that follow the same pattern.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scope your Author accounts.&lt;/strong&gt; Exploitation requires authenticated upload access. Reduce the number of accounts with that permission level to what the site actually needs. Unused contributor accounts are standing attack surface.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Managed hosting customers&lt;/strong&gt; — your provider may have already applied server-level mitigations or pre-applied the WordPress update. Don&apos;t assume; verify independently through the admin dashboard.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The authentication requirement puts this below the critical-tier threshold compared to unauthenticated RCE, but contributor and author accounts are targets. Credential stuffing against WordPress login pages is a reliable attacker playbook, and a valid Author session unlocks this vulnerability completely.&lt;/p&gt;
&lt;p&gt;Related: &lt;a href=&quot;/articles/2026-08-10-bdthemes-supply-chain-wordpress-rogue-admins/&quot;&gt;BdThemes Supply Chain Creates Rogue WordPress Admins&lt;/a&gt; covered a recent attack that seeded unauthorized admin accounts across plugin-using sites — another demonstration that the contributor/admin account layer is an active attack target. And &lt;a href=&quot;/articles/2026-08-10-wp-login-register-cve-2026-18468-18469-18470/&quot;&gt;Three CVEs Chain to Admin Takeover in WordPress Login Plugin&lt;/a&gt; shows the plugin ecosystem adding its own exposure on top of core.&lt;/p&gt;
&lt;p&gt;Check the full list of actively exploited vulnerabilities on our &lt;a href=&quot;/kev-tracker/&quot;&gt;KEV tracker&lt;/a&gt;.&lt;/p&gt;</content:encoded><dc:creator>Marisol &quot;Fuse&quot; Delgado</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/cover.jpg" medium="image" width="1200" height="675"/><category>wordpress</category><category>rce</category><category>imagick</category><category>ghostscript</category><category>postscript</category><category>file-upload</category><category>patch</category></item><item><title>GeoServer Zero-Day SQL Injection Exploited in Wild</title><link>https://0daynews.com/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/</guid><description>Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.</description><pubDate>Fri, 14 Aug 2026 08:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Active exploitation confirmed. No patch. GeoServer installations reachable from untrusted networks are at immediate risk.&lt;/p&gt;
&lt;h2&gt;What&apos;s Known&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/&quot;&gt;SecurityWeek reported&lt;/a&gt; today (August 14) that threat actors are actively exploiting an unpatched SQL injection in GeoServer, the open-source Java geospatial server. Exploitation path: SQL injection → remote code execution. No CVE assigned as of this writing.&lt;/p&gt;
&lt;p&gt;Confidence: single-source (SecurityWeek). Credible; not independently confirmed.&lt;/p&gt;
&lt;h2&gt;Exposure Surface&lt;/h2&gt;
&lt;p&gt;GeoServer serves geographic data over WMS, WFS, and WCS endpoints. Government agencies, municipalities, utilities, and environmental monitoring systems run it — many instances are public-facing by design. Wide deployment, frequent internet exposure.&lt;/p&gt;
&lt;p&gt;No affected version range disclosed. No vendor advisory. No CVE. No patch.&lt;/p&gt;
&lt;p&gt;If your instance is publicly reachable: live risk.&lt;/p&gt;
&lt;h2&gt;Immediate Actions&lt;/h2&gt;
&lt;p&gt;No patch exists. Available mitigations:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Remove internet exposure.&lt;/strong&gt; Firewall to authorized IPs or move behind VPN until a patch ships.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Restrict access.&lt;/strong&gt; For instances that must stay up, deny all source IPs except known-good ranges at the perimeter.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check logs.&lt;/strong&gt; Look for malformed or anomalously long filter parameters in WMS/WFS request logs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Monitor the GeoServer project&lt;/strong&gt; for a security advisory. Treat it as P1 when it arrives.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;CISA KEV: not listed as of this writing. Active exploitation of an unpatched RCE meets KEV criteria. Track updates at &lt;a href=&quot;/kev-tracker/&quot;&gt;KEV tracker&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Source: &lt;a href=&quot;https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/&quot;&gt;SecurityWeek — Hackers Exploiting Unpatched GeoServer Zero-Day&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/cover.jpg" medium="image" width="1200" height="675"/><category>geoserver</category><category>zero-day</category><category>sql-injection</category><category>rce</category><category>active-exploitation</category><category>unpatched</category><category>geospatial</category></item><item><title>Apple Notifies Users of Mercenary Spyware Attacks</title><link>https://0daynews.com/articles/2026-08-14-apple-mercenary-spyware-threat-notifications/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-apple-mercenary-spyware-threat-notifications/</guid><description>Apple issued Threat Notifications to iPhone users warning of active mercenary spyware attacks. If you received one, here is what to do immediately.</description><pubDate>Fri, 14 Aug 2026 02:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Active wave confirmed. Apple issued &quot;Threat Notifications&quot; to an unspecified number of iPhone users stating it detected a &quot;mercenary spyware attack targeted at your iPhone.&quot; &lt;a href=&quot;https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/&quot;&gt;BleepingComputer&lt;/a&gt;, August 14, 2026.&lt;/p&gt;
&lt;h2&gt;What This Notification Means&lt;/h2&gt;
&lt;p&gt;Apple&apos;s Threat Notification system does not send precautionary alerts. A notification means Apple&apos;s internal telemetry identified indicators consistent with a targeted attack against that specific Apple ID or device. Apple states its threshold before sending is high confidence — not suspicion, not anomaly.&lt;/p&gt;
&lt;p&gt;&quot;Mercenary spyware&quot; is Apple&apos;s term for commercial surveillance software sold to governments and state-aligned clients. Highly targeted. Expensive. Typically deployed against journalists, lawyers, activists, opposition politicians, and human rights workers. If you received a notification: this is not a phishing test and it is not a mistake.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Confidence on actor and specific tooling:&lt;/strong&gt; Not yet identified in public reporting as of this writing. Attribution to a named vendor or government client: pending.&lt;/p&gt;
&lt;h2&gt;What Notified Users Should Do&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Enable Lockdown Mode immediately.&lt;/strong&gt; Settings → Privacy &amp;#x26; Security → Lockdown Mode. This hardens the attack surface that mercenary spyware tools typically exploit — restricting JavaScript compilation, message link previews, FaceTime from unknown callers, and other entry vectors. The performance trade-off is real and acceptable given the threat.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Update iOS to the latest release.&lt;/strong&gt; Apple patches the zero-click and zero-day entry points these tools exploit. Running an outdated build past this point is a choice, not bad luck.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Get professional forensic support.&lt;/strong&gt; Apple&apos;s notification is not a forensic determination of active compromise. To confirm and remediate, contact &lt;a href=&quot;https://www.accessnow.org/help/&quot;&gt;Access Now&apos;s Digital Security Helpline&lt;/a&gt; or reach Citizen Lab through the University of Toronto&apos;s Munk School. Self-assessment with standard tools is not sufficient for mercenary-grade implants — some leave minimal traces and actively evade on-device detection.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Do not click the notification itself&lt;/strong&gt; to access further details. Navigate to &lt;a href=&quot;https://support.apple.com/en-us/102174&quot;&gt;Apple&apos;s support page for threat notifications&lt;/a&gt; directly from a trusted browser. Notification UI can be spoofed.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;If you did not receive a notification:&lt;/strong&gt; Not included in this wave. That is not a forensic clearance for prior campaigns.&lt;/p&gt;
&lt;h2&gt;Prior Waves&lt;/h2&gt;
&lt;p&gt;Apple has issued Threat Notifications in prior waves — following NSO Group Pegasus campaigns documented by Citizen Lab, following commercial spyware used against journalists and activists across multiple countries, and following broader European mercenary spyware disclosures. This is an established channel, not a new feature. Prior waves preceded researcher disclosures by days to weeks.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Analysis — labeled as assessment:&lt;/strong&gt; Whether this wave reflects a newly identified campaign or previously undetected targeting from an existing operation is unconfirmed. The breadth of the current notification wave — enough recipients to generate public discussion — suggests systematic identification of a campaign rather than isolated incidents. Expect follow-up research disclosure from Citizen Lab, Amnesty International&apos;s Security Lab, or a named vendor PSIRT within days.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Previously on 0dayNews: &lt;a href=&quot;/articles/2026-07-03-pegasus-mep-kouloglou-citizen-lab-analysis/&quot;&gt;Citizen Lab Confirms Pegasus on MEP&apos;s Phone&lt;/a&gt; · &lt;a href=&quot;/topic/apple/&quot;&gt;Apple topic hub&lt;/a&gt; · &lt;a href=&quot;/topic/mobile/&quot;&gt;Mobile topic hub&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-apple-mercenary-spyware-threat-notifications/cover.jpg" medium="image" width="1200" height="675"/><category>apple</category><category>mercenary-spyware</category><category>iphone</category><category>threat-notification</category><category>mobile-security</category><category>surveillance</category><category>lockdown-mode</category></item><item><title>Belgium eID Browser Extension Bugs Enable RCE</title><link>https://0daynews.com/articles/2026-08-14-belgium-eid-browser-extension-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-belgium-eid-browser-extension-rce/</guid><description>Severe vulnerabilities in Belgium&apos;s eID browser extension fully compromised the country&apos;s national identity trust framework, researchers confirmed, opening citizen accounts to remote code execution.</description><pubDate>Fri, 14 Aug 2026 02:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Confirmed: severe vulnerabilities in the browser extension underpinning Belgium&apos;s national electronic identity (eID) system fully compromised the country&apos;s citizen authentication trust framework, enabling remote code execution against user accounts, &lt;a href=&quot;https://www.darkreading.com/application-security/belgium-eid-authentication-opens-citizen-accounts-to-rce&quot;&gt;according to Dark Reading research published August 13&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Belgium&apos;s eID cards are the primary authentication mechanism for millions of citizens accessing government services, banking portals, and health records. The authentication flow depends on a browser extension that bridges the smart card reader to web services. When that extension is compromised, the trust chain collapses at its foundation — the card itself is irrelevant if the software layer mediating its use is hostile.&lt;/p&gt;
&lt;h2&gt;What researchers found&lt;/h2&gt;
&lt;p&gt;The extension ran under elevated browser privilege — the necessary access for reading smart card interfaces. Researchers found the vulnerabilities severe enough to characterize the trust model as &quot;fully compromised.&quot; Specific CVE assignments had not been disclosed publicly as of this report. Confidence on exploitation status: unconfirmed in the wild; treat as theoretical unless updated.&lt;/p&gt;
&lt;p&gt;The research frames the Belgium case as an instance of a broader structural problem: browser extensions used as authentication proxies represent a high-value target that routinely receives less scrutiny than the underlying protocols they serve. Extensions run persistent, privileged code in the browser context — enough access to intercept authentication tokens, relay credentials, or stage local execution.&lt;/p&gt;
&lt;h2&gt;Scope&lt;/h2&gt;
&lt;p&gt;Belgium&apos;s eID is issued to all Belgian citizens and resident aliens over 12 years old. The extension is required — not optional — for completing authentication to the government&apos;s digital services platform (MyGov/CSAM) and for many banking integrations. Precise affected version range: unconfirmed pending vendor advisory publication.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Belgian citizens:&lt;/strong&gt; Verify the eID browser extension is updated to its latest available version in your browser&apos;s extension manager. Disable automatic activation of the extension on non-government sites if your browser permits granular host permissions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IT administrators and organizations&lt;/strong&gt; relying on eID for workforce authentication: Monitor the &lt;a href=&quot;https://ccb.belgium.be/en&quot;&gt;Belgian Centre for Cyber Security (CCB)&lt;/a&gt; for an official advisory and patch timeline. Apply updates on an emergency basis once available — this is a national identity infrastructure issue, not a routine patch cycle item.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security teams:&lt;/strong&gt; Review any service-side session logs for anomalous authentication activity originating from Belgian eID flows. Flag for inspection pending the full technical disclosure.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;[Analysis] Browser extensions continue to widen enterprise attack surface in ways that perimeter-focused defenses miss. A compromised extension that is trusted by both the browser and the authentication server has the same effective access as the legitimate user — without triggering most authentication anomaly detections. National identity implementations that depend on extension-mediated smart card auth face the same supply chain risk as any other extension, with significantly higher blast radius. End-analysis.&lt;/p&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://www.darkreading.com/application-security/belgium-eid-authentication-opens-citizen-accounts-to-rce&quot;&gt;Dark Reading, August 13, 2026&lt;/a&gt; — &lt;a href=&quot;https://ccb.belgium.be/en&quot;&gt;Belgian Centre for Cyber Security&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-14-belgium-eid-browser-extension-rce/cover.jpg" medium="image" width="1200" height="675"/><category>Belgium</category><category>eID</category><category>browser extension</category><category>RCE</category><category>authentication</category><category>national identity</category><category>trust framework</category></item><item><title>Microsoft Patches LegacyHive Windows Zero-Day</title><link>https://0daynews.com/articles/2026-08-13-legacyhive-windows-zero-day-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-legacyhive-windows-zero-day-patch/</guid><description>Microsoft issued a patch for LegacyHive, a named Windows zero-day disclosed in the gap between July and August Patch Tuesday cycles.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Microsoft has released security patches for a Windows zero-day vulnerability nicknamed &quot;LegacyHive,&quot; &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/&quot;&gt;per BleepingComputer&lt;/a&gt;. The vulnerability was disclosed after July 2026 Patch Tuesday — entering the public record at the most inconvenient point in the monthly release cycle, with the longest possible runway before a scheduled vendor fix.&lt;/p&gt;
&lt;p&gt;Between-cycle disclosures are structurally baked into scheduled patching. The day after Patch Tuesday is, mathematically, the worst day for defenders if a zero-day drops: up to four weeks until the next scheduled fix, with public knowledge of the flaw in the interim. Whether LegacyHive&apos;s disclosure was timed deliberately or not, the result for defenders is the same either way.&lt;/p&gt;
&lt;h2&gt;What the Name Suggests&lt;/h2&gt;
&lt;p&gt;&quot;LegacyHive&quot; points at a specific part of Windows internals: registry hives, the on-disk binary format Windows uses to persist its registry data. Hive files — NTUSER.DAT, SYSTEM, SOFTWARE, SAM — have been an attack surface for decades. Privilege escalation through improper hive access, credential harvesting from the SAM hive via shadow copies, and persistence through registry run keys all run through this same underlying architecture.&lt;/p&gt;
&lt;p&gt;The &quot;LegacyHive&quot; handle is a researcher designation, not an official Microsoft identifier — Microsoft uses CVE numbers. Named zero-days travel faster through enterprise alert queues than a bare CVE ID, and the pattern of naming mid-cycle disclosures has become common. This week&apos;s &lt;a href=&quot;/articles/2026-08-12-shieldbreak-defender-cve-2026-50656-patch-bypass/&quot;&gt;ShieldBreak PoC for CVE-2026-50656&lt;/a&gt; followed the same convention.&lt;/p&gt;
&lt;p&gt;This month has been unusually active on the Windows patching front. &lt;a href=&quot;/articles/2026-08-11-microsoft-patch-tuesday-august-2026/&quot;&gt;August Patch Tuesday&lt;/a&gt; addressed over 400 vulnerabilities — including CVE-2026-68820, actively exploited by Lazarus before disclosure, and two publicly known zero-days. LegacyHive extends an already-busy month.&lt;/p&gt;
&lt;h2&gt;What to Do&lt;/h2&gt;
&lt;p&gt;Confirm the LegacyHive fix is applied across your Windows fleet. Given the timing — disclosed between July and August Patch Tuesday — the patch appears in Microsoft&apos;s August response. Verify with your patch management tooling; don&apos;t assume the deployment ran clean to every endpoint.&lt;/p&gt;
&lt;p&gt;If your environment logs registry hive file access events — some EDR platforms and Windows audit policies capture these at the object level — reviewing logs from the post-disclosure window for anomalous hive activity is a low-cost cross-check. Not required, but worth the effort if your organization fits a realistic attacker target profile.&lt;/p&gt;
&lt;p&gt;Zero-days surfacing between patch cycles are not new and will not stop happening. The same mistake, different month: the fix exists now; the only variable is how fast it propagates across the fleet.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-legacyhive-windows-zero-day-patch/cover.jpg" medium="image" width="1200" height="675"/><category>legacyhive</category><category>microsoft</category><category>windows</category><category>zero-day</category><category>patch</category><category>registry</category><category>windows-security</category></item><item><title>Akira Disables EDR via Safe Mode Reboot, Steals Data</title><link>https://0daynews.com/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft/</guid><description>An Akira ransomware affiliate rebooted a compromised host into Safe Mode to kill EDR, exfiltrated data, then failed to encrypt. The exfiltration is the real threat.</description><pubDate>Thu, 13 Aug 2026 22:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Confirmed incident. An Akira ransomware affiliate rebooted a compromised Windows host into &lt;strong&gt;Safe Mode with Networking&lt;/strong&gt;, disabled the endpoint detection and response (EDR) solution, exfiltrated data, then failed to complete encryption. &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/&quot;&gt;BleepingComputer&lt;/a&gt;, August 13, 2026.&lt;/p&gt;
&lt;h2&gt;The EDR Kill Mechanism&lt;/h2&gt;
&lt;p&gt;Safe Mode with Networking loads a minimal driver set. Most EDR agents register as standard Windows services — they don&apos;t load in Safe Mode. The result is a functioning OS with C2 connectivity and no behavioral monitoring. No kernel exploit, no process injection, no admin-level driver termination required. Attacker forces a reboot; EDR disappears.&lt;/p&gt;
&lt;p&gt;Networking is explicitly preserved. Exfiltration channels stay open.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Confidence:&lt;/strong&gt; Technique is consistent with documented Safe Mode EDR bypass behavior — CrowdStrike, SentinelOne, and others flagged this class of bypass in prior public disclosures. Attribution of the technique to this specific Akira incident: single source, BleepingComputer. Not independently confirmed as of this writing.&lt;/p&gt;
&lt;h2&gt;The Encryption Failure&lt;/h2&gt;
&lt;p&gt;Akira&apos;s payload failed to execute cleanly in Safe Mode. Precise cause: unconfirmed. BleepingComputer reporting does not identify a specific failure reason.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Analysis — labeled as assessment:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Some ransomware families are purpose-built for Safe Mode execution — REvil hardened its encryptor for this environment explicitly. Akira&apos;s payload may not have been. Alternatively, partial detection or manual defender intervention interrupted the encryption stage after the reboot anomaly was caught. Either is plausible; both are unconfirmed.&lt;/p&gt;
&lt;h2&gt;Why the Failure Doesn&apos;t Matter&lt;/h2&gt;
&lt;p&gt;Data was exfiltrated before encryption was attempted. The double-extortion model does not require encryption — it requires leverage. In 2026, the stolen data is the leverage. &quot;We failed to encrypt&quot; is operationally meaningless if the exfiltration succeeded.&lt;/p&gt;
&lt;h2&gt;Defensive Notes&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Alert on unscheduled Safe Mode configuration.&lt;/strong&gt; &lt;code&gt;bcdedit /set safeboot&lt;/code&gt; execution, registry writes to &lt;code&gt;HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot&lt;/code&gt;, or equivalent WMI calls from non-approved processes should trigger immediate investigation — not just a log entry.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The real detection window is before the reboot.&lt;/strong&gt; Safe Mode access requires the attacker to already have local admin or SYSTEM. Initial access and privilege escalation are where this attack is most interruptible.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Post-Safe-Mode audit.&lt;/strong&gt; An unexplained Safe Mode reboot is a confirmed exfiltration indicator until proven otherwise. Treat it as one.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Network egress during Safe Mode.&lt;/strong&gt; Safe Mode with Networking is not a network blackout. Anomalous outbound connections from a host during a Safe Mode window are meaningful signals.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;p&gt;Akira is an active ransomware operation. Related: &lt;a href=&quot;/articles/2026-08-12-deadlock-ransomware-blockchain-polygon/&quot;&gt;Deadlock Ransomware Moves Ransom Funds via Polygon&lt;/a&gt; · &lt;a href=&quot;/topic/ransomware/&quot;&gt;Ransomware topic hub&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft/cover.jpg" medium="image" width="1200" height="675"/><category>akira</category><category>ransomware</category><category>edr-bypass</category><category>safe-mode</category><category>exfiltration</category><category>endpoint-detection</category><category>ttps</category></item><item><title>VMware vCenter Exploit Deploys Reverse SSH Backdoor</title><link>https://0daynews.com/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence/</guid><description>Threat actors exploiting CVE-2026-59310 are deploying a reverse SSH tool for persistent access on compromised vCenter management planes.</description><pubDate>Thu, 13 Aug 2026 20:00:00 GMT</pubDate><content:encoded>&lt;p&gt;New campaign detail. Threat actors exploiting &lt;a href=&quot;/cve/cve-2026-59310/&quot;&gt;CVE-2026-59310&lt;/a&gt; — the CVSS 9.8 authentication bypass in VMware vCenter Server — are deploying a reverse SSH tool to establish persistent remote access on compromised management planes, per &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/&quot;&gt;BleepingComputer reporting&lt;/a&gt; published today. &lt;a href=&quot;https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/&quot;&gt;SecurityWeek&lt;/a&gt; reported on the active exploitation campaign separately.&lt;/p&gt;
&lt;h2&gt;What&apos;s Changed&lt;/h2&gt;
&lt;p&gt;Previously observed: exploitation confirmation against live vCenter infrastructure (&lt;a href=&quot;/articles/2026-08-12-vcenter-cve-2026-59310-exploited-in-wild/&quot;&gt;reported yesterday&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Now observed: attackers following initial exploitation with a reverse SSH deployment — an outbound tunnel from the compromised vCenter host back to attacker-controlled infrastructure. Mechanism: persistent, low-noise remote access that survives standard perimeter firewall rules (outbound SSH passes where inbound doesn&apos;t).&lt;/p&gt;
&lt;p&gt;Confidence: single-source (BleepingComputer); no independent technical validation published as of this writing. Treat as credible reporting, not second-source confirmed.&lt;/p&gt;
&lt;h2&gt;Why Reverse SSH&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Analysis — labeled as assessment, not confirmed observation:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reverse SSH placed inside the management plane is not inside the guest VM stack. The host running vCenter typically isn&apos;t covered by the same EDR that watches endpoints. Network teams commonly permit outbound SSH from infrastructure nodes. After establishing initial access via the authentication bypass, a reverse SSH channel gives attackers a foothold that is:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Durable across VM remediation — positioned at the hypervisor management layer, not inside a guest&lt;/li&gt;
&lt;li&gt;Low-profile — outbound traffic from infrastructure blends with normal admin patterns&lt;/li&gt;
&lt;li&gt;Strategically positioned — vCenter manages ESXi hosts, stored VM disk images, storage, and network fabric&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Actors maintaining this position can re-enter post-remediation if only the guest layer is cleaned without addressing the management plane.&lt;/p&gt;
&lt;h2&gt;Detection and Response&lt;/h2&gt;
&lt;p&gt;If you run VMware vCenter Server:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Patch first.&lt;/strong&gt; CVE-2026-59310 has had a fix available since July 29, 2026 via Broadcom advisory &lt;a href=&quot;https://support.broadcom.com/web/ecx/support-content?content=SA-2026-0006&quot;&gt;VMSA-2026-0006&lt;/a&gt;. If you&apos;re unpatched, this is the only priority.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit outbound SSH from vCenter hosts.&lt;/strong&gt; Check firewall logs for outbound port 22 connections from vCenter management nodes to unfamiliar external IPs, particularly after July 29.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Inspect SSH authorized_keys&lt;/strong&gt; on the vCenter appliance filesystem for unauthorized entries.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review vCenter appliance process list and scheduled tasks&lt;/strong&gt; for unexpected persistent processes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Isolate if unpatched.&lt;/strong&gt; Management interfaces should be on dedicated networks, not reachable from guest VLANs or the general corporate LAN — a network-adjacent attacker is all this flaw requires.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;CISA KEV status: not listed as of this writing. Active exploitation with a documented post-compromise persistence technique increases the likelihood of KEV addition — track the &lt;a href=&quot;/kev-tracker/&quot;&gt;KEV tracker&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Previous coverage: &lt;a href=&quot;/articles/2026-08-12-vcenter-cve-2026-59310-exploited-in-wild/&quot;&gt;vCenter Auth Bypass CVE-2026-59310 Now Exploited&lt;/a&gt; · &lt;a href=&quot;/cve/cve-2026-59310/&quot;&gt;CVE detail: CVE-2026-59310&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence/cover.jpg" medium="image" width="1200" height="675"/><category>vmware</category><category>vcenter</category><category>CVE-2026-59310</category><category>reverse ssh</category><category>persistence</category><category>active exploitation</category><category>broadcom</category></item><item><title>New Mirai Variant Adds Encrypted C2 and Credential Sniffer</title><link>https://0daynews.com/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer/</guid><description>A new Mirai variant adds encrypted C2 comms and a default-credential sniffer — raising the detection bar for defenders relying on network-layer visibility.</description><pubDate>Thu, 13 Aug 2026 18:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Researchers have documented a new Mirai variant that adds two capabilities the original botnet never had: encrypted command-and-control communications, and a built-in sniffer designed to locate devices still running factory-default credentials, &lt;a href=&quot;https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code&quot;&gt;The Record reported Thursday&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Mirai&apos;s original 2016 run — the one that briefly knocked out large portions of the internet by flooding Dyn&apos;s DNS infrastructure — was built almost entirely on the failure of device manufacturers and their customers to change default passwords. That playbook worked because the attack surface was enormous and largely invisible. A decade later, the credential sniffer in this new variant is betting the same attack surface still exists. That bet has historically been correct.&lt;/p&gt;
&lt;p&gt;The encrypted C2 channel is the part that should concern incident responders more immediately. Traditional detection approaches for Mirai and its derivatives relied heavily on network-layer visibility: catch the plaintext C2 traffic, block known command-and-control IPs, flag unusual outbound connections from device subnets. Encryption breaks the first leg of that chain. You can still observe that a device is making unusual outbound connections; you can no longer easily see what it is saying without TLS inspection at the perimeter — a step most organizations haven&apos;t taken for IoT network segments, if those segments exist at all.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Analysis:&lt;/strong&gt; Encrypted C2 has been standard in sophisticated malware for years. What&apos;s notable here is the pattern reaching botnet code that operates at IoT scale — targeting cheap embedded devices that typically can&apos;t run endpoint agents, run custom firmware that resists inspection, and sit on networks whose owners haven&apos;t thought about them since installation. The combination of credential-hunting and encrypted persistence means that once a device is compromised, detection and remediation become materially harder than they were with the original Mirai tooling.&lt;/p&gt;
&lt;p&gt;For defenders with IoT exposure in their environments:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Change default credentials.&lt;/strong&gt; Every network-facing device. This is the decade-old advice that this variant&apos;s credential sniffer is still counting on most sites haven&apos;t followed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Segment IoT onto isolated VLANs&lt;/strong&gt; with restricted egress rules. It won&apos;t prevent infection, but it limits blast radius and makes anomalous outbound connections easier to isolate from business-critical traffic.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Update firmware&lt;/strong&gt; wherever vendors provide it — especially on routers, IP cameras, and NAS devices that have historically been primary Mirai targets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reassess network monitoring posture.&lt;/strong&gt; If detection relies on plaintext traffic pattern matching, encrypted C2 bypasses it. Behavioral anomaly detection and egress volume baselining become more important as botnets encrypt their communications.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The credential angle is worth sitting with. Mirai became notorious for exploiting a weakness that wasn&apos;t fundamentally technical — it was organizational. Nobody changed the passwords because nobody thought about it, and device manufacturers shipped with defaults because there was no incentive not to. The attack surface has grown since 2016, not shrunk: more devices, cheaper devices, more SKUs from manufacturers with no meaningful security requirement baked into the supply chain. This new variant&apos;s credential sniffer is running the same play that worked a decade ago. The fact that it still expects to find devices on default credentials — and that researchers expect it to be right — says more about the state of IoT security than any individual malware capability does.&lt;/p&gt;
&lt;p&gt;Related: &lt;a href=&quot;/articles/2026-08-13-android-windrelay-spynote-nfc-relay-fraud/&quot;&gt;Android NFC Relay Malware Drains Bank Accounts in Real Time&lt;/a&gt; | &lt;a href=&quot;/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched/&quot;&gt;Tenda Router Backdoor CVE-2026-11405 Remains Unpatched&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Dave &quot;Kilobaud&quot; Ferris</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer/cover.jpg" medium="image" width="1200" height="675"/><category>mirai</category><category>botnet</category><category>iot</category><category>encrypted-c2</category><category>default-credentials</category><category>malware</category><category>threat-intel</category></item><item><title>Trezor Breach: 14,000 Customers Exposed via ShipMonk Hack</title><link>https://0daynews.com/articles/2026-08-13-trezor-shipmonk-breach-14k-customers/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-trezor-shipmonk-breach-14k-customers/</guid><description>Trezor disclosed a breach hitting nearly 14,000 customers after shipping partner ShipMonk was compromised. No device or key exposure. Customer order data is the risk.</description><pubDate>Thu, 13 Aug 2026 16:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Confirmed. Trezor has disclosed a data breach affecting nearly 14,000 customers. Root cause: &lt;strong&gt;ShipMonk&lt;/strong&gt;, its third-party shipping and logistics provider, was compromised. Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/&quot;&gt;BleepingComputer, August 13, 2026&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Trezor&apos;s own infrastructure was not breached. This is downstream exposure through the logistics layer.&lt;/p&gt;
&lt;h2&gt;What&apos;s confirmed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ShipMonk compromised. Trezor customer data held by ShipMonk for order fulfillment was exposed.&lt;/li&gt;
&lt;li&gt;Scope: approximately &lt;strong&gt;14,000 affected accounts&lt;/strong&gt;, per Trezor&apos;s disclosure.&lt;/li&gt;
&lt;li&gt;Device integrity: unaffected. Hardware wallet private keys are stored on-device and are not part of any logistics platform&apos;s data. If you followed standard seed phrase hygiene, your funds are not at risk.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;What&apos;s unconfirmed — treat accordingly&lt;/h2&gt;
&lt;p&gt;ShipMonk&apos;s breach vector. The specific data categories officially confirmed as exposed. Whether other ShipMonk clients&apos; customer data was also affected. No public statement from ShipMonk as of publication.&lt;/p&gt;
&lt;p&gt;Standard exposure for a logistics/shipping partner dataset: names, shipping addresses, email addresses, and phone numbers. Treat that as the working assumption until Trezor or ShipMonk publish specifics.&lt;/p&gt;
&lt;h2&gt;Why it matters for your threat model&lt;/h2&gt;
&lt;p&gt;Hardware wallet customers are high-value targets. Knowing someone bought a Trezor signals they hold cryptocurrency worth securing. Shipping data from a breach like this fuels:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Spear-phishing impersonating Trezor support — themed around breach notifications, &quot;verify your account,&quot; or wallet recovery&lt;/li&gt;
&lt;li&gt;SIM-swap attempts using phone numbers or email addresses from the exposed dataset&lt;/li&gt;
&lt;li&gt;Physical targeting in jurisdictions where that exposure is elevated&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is not hypothetical. Prior exposures of Trezor-adjacent customer data have been followed by targeted phishing campaigns within days of public disclosure. The playbook is well-established.&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;For affected customers:&lt;/strong&gt; Treat any inbound contact referencing your Trezor order, your shipping address, or your purchase history as potentially engineered. Verify through official channels — trezor.io — not from a link in an email or a message in a support chat you didn&apos;t initiate.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If your email was in ShipMonk&apos;s system:&lt;/strong&gt; Expect it to appear in targeting lists used for credential stuffing and phishing. Enable 2FA on your email account if you haven&apos;t already, and watch for password-reset requests you didn&apos;t send.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Your device and seed phrase:&lt;/strong&gt; No action required — the breach was in the logistics layer, not Trezor&apos;s firmware, key management infrastructure, or backup ecosystem. If someone is telling you otherwise, they are phishing you.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Third-party supply chain exposure continues to be an underweighted risk at organizations across every sector — from AI tooling (see &lt;a href=&quot;/articles/2026-08-12-litellm-supply-chain-trivy-hack-2500-orgs/&quot;&gt;LiteLLM/Trivy supply chain attack&lt;/a&gt;) to hardware device manufacturers. The breach surface isn&apos;t always the product you trust. It&apos;s everyone that product&apos;s maker also trusted.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-trezor-shipmonk-breach-14k-customers/cover.jpg" medium="image" width="1200" height="675"/><category>trezor</category><category>shipmonk</category><category>data breach</category><category>hardware wallet</category><category>supply chain</category><category>third-party risk</category><category>cryptocurrency</category></item><item><title>White House Opens Hack-Back Program to Private Firms</title><link>https://0daynews.com/articles/2026-08-13-white-house-hack-back-private-firms-ncc/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-white-house-hack-back-private-firms-ncc/</guid><description>Trump memo directs the NCC to license private security firms for offensive cyber ops against foreign criminal organizations. $1M bond required for compliance.</description><pubDate>Thu, 13 Aug 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Confirmed. President Trump signed a White House memo directing the &lt;strong&gt;National Coordination Center (NCC)&lt;/strong&gt; to establish a program through which private security companies can apply for government authorization to conduct offensive cyber operations against foreign cybercrime organizations. Reported today by &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/white-house-taps-security-firms-for-offensive-hack-back-operations/&quot;&gt;BleepingComputer&lt;/a&gt; and &lt;a href=&quot;https://www.securityweek.com/white-house-mobilizes-security-firms-for-operations-against-foreign-cybercrime-gangs/&quot;&gt;SecurityWeek&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Program is not yet operational. Application process and eligibility criteria: not published as of this writing.&lt;/p&gt;
&lt;h2&gt;What&apos;s confirmed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memo signed. NCC is designated as the coordination and approval body.&lt;/li&gt;
&lt;li&gt;Framework envisions &lt;strong&gt;licensed&lt;/strong&gt; offensive action — firms operating under government authorization, not freelance hack-back.&lt;/li&gt;
&lt;li&gt;Bond: contracts may require a &lt;strong&gt;$1 million forfeiture bond&lt;/strong&gt;, surrendered on non-compliance with operational requirements.&lt;/li&gt;
&lt;li&gt;Target scope per current reporting: foreign cybercrime organizations. Domestic operations not addressed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;What&apos;s unconfirmed — treat accordingly&lt;/h2&gt;
&lt;p&gt;Eligible firm criteria. Application timeline. Mission deconfliction with NSA and USCYBERCOM. CFAA liability exposure for NCC-authorized operators. Congressional notification requirements.&lt;/p&gt;
&lt;h2&gt;Analysis&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;Label: interpretive — not confirmed by current reporting.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The $1M bond is the structural tell. It&apos;s a compliance choke-point: violate your operational mandate and you lose the bond, and presumably the authorization. Whether &quot;fails to comply with operational requirements&quot; is adjudicated by NCC, ODNI, DOJ, or some combination — and with what due process — isn&apos;t addressed in current reporting. That gap matters.&lt;/p&gt;
&lt;p&gt;Private offensive operations against foreign adversaries occupy legally ambiguous territory even with explicit authorization. The Computer Fraud and Abuse Act carves no general safe harbor for licensed hack-back against foreign targets. Whether this memo changes that for approved operators is unconfirmed.&lt;/p&gt;
&lt;p&gt;Structural advantage in any application process will go to firms that already hold cleared personnel, active government contracts, and intelligence community relationships. In practice the eligible pool narrows fast.&lt;/p&gt;
&lt;h2&gt;What this means now&lt;/h2&gt;
&lt;p&gt;For most organizations: nothing immediately actionable. The program isn&apos;t operational.&lt;/p&gt;
&lt;p&gt;For firms that might seek authorization: legal and compliance review starts before the application window — not after. Watch NCC and &lt;a href=&quot;https://www.cisa.gov/&quot;&gt;CISA&lt;/a&gt; for official guidance.&lt;/p&gt;
&lt;p&gt;The threat context this responds to is real: state-linked cybercrime crews — the kind documented in &lt;a href=&quot;/articles/2026-08-12-lazarus-cve-2026-68820-operation-dream-job-cisa-kev/&quot;&gt;Operation Dream Job&lt;/a&gt; and the &lt;a href=&quot;/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops/&quot;&gt;Jewelbug dual-ops case&lt;/a&gt; — operate at a tempo that traditional law enforcement channels can&apos;t match. Whether licensed private operators change that calculus is a question that&apos;s about to get tested.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-white-house-hack-back-private-firms-ncc/cover.jpg" medium="image" width="1200" height="675"/><category>hack-back</category><category>offensive cyber</category><category>White House</category><category>NCC</category><category>cybercrime</category><category>private sector</category><category>Trump</category></item><item><title>Jewelbug APT Merges Espionage and Crypto Fraud</title><link>https://0daynews.com/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops/</guid><description>Symantec links China-tied Jewelbug to dual operations — state espionage and cryptocurrency fraud — run from the same C2 web panel, with a victim database logging over one million implant check-ins.</description><pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate><content:encoded>&lt;p&gt;One C2 panel. Two revenue streams.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.security.com/threat-intelligence/jewelbug-apt-russia&quot;&gt;Symantec published research Thursday&lt;/a&gt; identifying a China-linked APT group — Jewelbug, also tracked as Earth Alux, REF7707, and CL-STA-0049 — operating state espionage campaigns and for-profit cryptocurrency fraud from the same command-and-control infrastructure. The finding marks the clearest documented case of a Chinese state-affiliated actor combining both mission types under unified operational control.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What Symantec observed.&lt;/strong&gt; The group&apos;s C2 panel runs a single victim database logging more than 1 million implant check-ins, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies. Attribution: China-linked. Confidence: high per Symantec.&lt;/p&gt;
&lt;h2&gt;Dual-Mission Model&lt;/h2&gt;
&lt;p&gt;Jewelbug operates as what researchers characterize as a hackers-for-hire network. The espionage arm targets governments and militaries across Asia and the Middle East. The same infrastructure also handles cryptocurrency fraud targeting financial accounts. Both missions run from the same web panel, sharing a unified victim database.&lt;/p&gt;
&lt;p&gt;The operational overlap is the novel finding — prior assessments tracked Jewelbug&apos;s espionage activity without connecting it to the financial crime side.&lt;/p&gt;
&lt;h2&gt;Confirmed Intrusions&lt;/h2&gt;
&lt;p&gt;Symantec&apos;s research documents at least four victim organizations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Russian IT service provider (January–May 2025, approximately five months undetected)&lt;/li&gt;
&lt;li&gt;South American government organization (September 2024–July 2025)&lt;/li&gt;
&lt;li&gt;Taiwanese software company (October–November 2024)&lt;/li&gt;
&lt;li&gt;South Asian IT provider (timeline not specified in reporting reviewed)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The Russian IT provider breach carries specific downstream risk: Jewelbug accessed code repositories and software build systems, raising the possibility of supply chain contamination affecting that provider&apos;s customers. No downstream compromise has been confirmed as of this writing — treat as unverified.&lt;/p&gt;
&lt;h2&gt;Toolset&lt;/h2&gt;
&lt;p&gt;Observed tools in Jewelbug campaigns include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;ShadowPad&lt;/strong&gt; — modular backdoor with documented ties to Chinese state operations&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Finaldraft&lt;/strong&gt; — remote administration tool&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pathloader / Guidloader&lt;/strong&gt; — shellcode downloaders for staged payload delivery&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EchoDrv&lt;/strong&gt; — exploits the ECHOAC driver; used for BYOVD (Bring Your Own Vulnerable Driver) privilege escalation&lt;/li&gt;
&lt;li&gt;Renamed &lt;code&gt;cdb.exe&lt;/code&gt; — Microsoft Console Debugger abused for DLL sideloading via signed-binary technique&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Exfiltration in the Russia campaign routed through Yandex Cloud — a deliberate choice to blend with legitimate network traffic. Windows Event Logs were cleared post-access to obstruct forensic reconstruction.&lt;/p&gt;
&lt;h2&gt;Why the Shared Panel Matters&lt;/h2&gt;
&lt;p&gt;The hackers-for-hire framing is not new. &lt;a href=&quot;/articles/2026-08-12-lazarus-cve-2026-68820-operation-dream-job-cisa-kev/&quot;&gt;Lazarus, linked to North Korea, similarly blends state operations with financial crime&lt;/a&gt; — often at volume. China&apos;s contractor model, used by groups like Volt Typhoon, is how state-adjacent actors maintain operational deniability. What Symantec&apos;s research adds is visibility into the shared infrastructure layer: the same web panel routing espionage-grade implants also manages cryptocurrency fraud victims.&lt;/p&gt;
&lt;p&gt;That operational consolidation suggests Jewelbug&apos;s criminal revenue stream helps fund or sustain the state-tasked work, rather than existing as a purely parallel side operation. Symantec characterizes this as part of a broader trend — Chinese cyber operations increasingly rely on contractor networks carrying both financial incentives and state tasking simultaneously.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft/&quot;&gt;City-Forum&apos;s ongoing campaign targeting Salesforce and ServiceNow portals&lt;/a&gt; illustrates the same dynamic at the data layer: large-scale credential and record harvesting running at operational tempo without traditional APT infrastructure footprints.&lt;/p&gt;
&lt;h2&gt;Confidence Summary&lt;/h2&gt;
&lt;p&gt;| Claim | Confidence |
|---|---|
| China attribution | High (Symantec) |
| Shared C2 panel for both missions | Confirmed (Symantec) |
| Supply chain impact from Russia breach | Unconfirmed — build system access confirmed; downstream customer compromise is not |
| Specific crypto theft mechanisms | Unspecified in published reporting reviewed |
| BYOVD via EchoDrv | Confirmed reported |&lt;/p&gt;
&lt;h2&gt;What to Watch&lt;/h2&gt;
&lt;p&gt;No patch guidance or IOC-based remediation directly applies to this disclosure — Jewelbug&apos;s tradecraft relies on signed-binary abuse and legitimate cloud services rather than exploiting unpatched CVEs. Relevant defensive posture:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Audit DLL sideloading vectors in environments using Microsoft signed debug tools&lt;/li&gt;
&lt;li&gt;Monitor for BYOVD activity, specifically EchoDrv/ECHOAC driver signatures&lt;/li&gt;
&lt;li&gt;If Yandex Cloud has no legitimate presence in your environment, egress to it warrants investigation&lt;/li&gt;
&lt;li&gt;Treat any IT provider in the named geographic regions (South/Southeast Asia, South America, Eastern Europe) as a potential Jewelbug pivot point until cleaner attribution is available&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Full research is available via &lt;a href=&quot;https://www.security.com/threat-intelligence/jewelbug-apt-russia&quot;&gt;Symantec Threat Hunter Team&lt;/a&gt;. The &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft&quot;&gt;Dark Reading analysis&lt;/a&gt; covers the dual-operations angle in more depth.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops/cover.jpg" medium="image" width="1200" height="675"/><category>jewelbug</category><category>apt</category><category>china</category><category>espionage</category><category>cryptocurrency</category><category>threat-intel</category><category>hackers-for-hire</category></item><item><title>Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8</title><link>https://0daynews.com/articles/2026-08-13-fortinet-fortiweb-fortimanager-aug-patches/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-fortinet-fortiweb-fortimanager-aug-patches/</guid><description>CVE-2026-26035 in FortiWeb lets unauthenticated attackers log in with any credentials — CVSS 9.8. FortiManager also gets a CVSS 8.1 auth bypass fix this cycle.</description><pubDate>Thu, 13 Aug 2026 10:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;FortiWeb first.&lt;/strong&gt; &lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-158&quot;&gt;CVE-2026-26035&lt;/a&gt;, CVSS 9.8, critical. Improper authentication (&lt;a href=&quot;https://cwe.mitre.org/data/definitions/287.html&quot;&gt;CWE-287&lt;/a&gt;) in Fortinet&apos;s FortiWeb WAF lets a remote unauthenticated attacker log in to the management GUI or CLI using any arbitrary username and password. Exploitation in the wild: &lt;strong&gt;unconfirmed as of publication — treat accordingly&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Affected versions — FortiWeb 7.0.x through 8.0.x:&lt;/p&gt;
&lt;p&gt;| Branch | Affected range |
|--------|---------------|
| FortiWeb 7.0 | 7.0.0 – 7.0.12 |
| FortiWeb 7.2 | 7.2.0 – 7.2.12 |
| FortiWeb 7.4 | 7.4.0 – 7.4.11 |
| FortiWeb 7.6 | 7.6.0 – 7.6.6 |
| FortiWeb 8.0 | 8.0.0 – 8.0.2 |&lt;/p&gt;
&lt;p&gt;Fortinet advisory &lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-158&quot;&gt;FG-IR-26-158&lt;/a&gt; lists the patched builds. If immediate upgrade is not possible: restrict management interface access to trusted subnets and disable any internet-facing admin access — that buys time, it is not a fix.&lt;/p&gt;
&lt;p&gt;The threat context: perimeter appliances are a reliable path from &quot;advisory released&quot; to &quot;actively exploited.&quot; FortiGate and FortiOS flaws have been weaponized by state-sponsored actors and ransomware crews within days of disclosure. A CVSS 9.8 auth bypass on an internet-facing security device is a first-tier patch priority regardless of exploitation status.&lt;/p&gt;
&lt;h2&gt;FortiManager — CVE-2026-70468, CVSS 8.1&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-160&quot;&gt;CVE-2026-70468&lt;/a&gt;, CVSS 8.1, high. Authentication bypass via alternate path or channel (&lt;a href=&quot;https://cwe.mitre.org/data/definitions/288.html&quot;&gt;CWE-288&lt;/a&gt;). Affects on-premises FortiManager and FortiManager Cloud:&lt;/p&gt;
&lt;p&gt;| Variant | Affected range |
|---------|---------------|
| FortiManager | 7.2.5 – 7.2.9 |
| FortiManager | 7.4.3 – 7.4.5 |
| FortiManager | 7.6.1 |
| FortiManager Cloud | 7.2.5 – 7.2.9 |
| FortiManager Cloud | 7.4.3 – 7.4.5 |
| FortiManager Cloud | 7.6.1 |&lt;/p&gt;
&lt;p&gt;Advisory: &lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-160&quot;&gt;FG-IR-26-160&lt;/a&gt;. Exploitation: &lt;strong&gt;unconfirmed&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;FortiManager is the central management plane for FortiGate deployments — the system that holds configs, credentials, and policy for every managed device in an environment. A prior FortiManager zero-day, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2024-47575&quot;&gt;CVE-2024-47575&lt;/a&gt;, was mass-exploited by nation-state actors before most defenders had a patch window. The risk profile for management-plane auth bypasses is categorically worse than the CVSS score alone suggests.&lt;/p&gt;
&lt;h2&gt;Lower-priority advisories in the same batch&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-161&quot;&gt;CVE-2026-71407&lt;/a&gt;&lt;/strong&gt; (FortiOS 7.6.1–7.6.6, CVSS 5.6, medium): Stack buffer overflow in the WAD daemon via crafted sockets. Exploitable only when explicit proxy with Kerberos authentication and SOCKS is enabled. Unauthenticated path.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-162&quot;&gt;CVE-2026-71408&lt;/a&gt;&lt;/strong&gt; (FortiOS 7.2–7.6 across multiple branches, CVSS 5.3, medium): Resource exhaustion leading to denial of service.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Patch these on your normal cycle unless the condition for CVE-2026-71407 matches your deployment (explicit proxy + Kerberos + SOCKS — if so, elevate it).&lt;/p&gt;
&lt;h2&gt;What to do&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;FortiWeb&lt;/strong&gt; — Identify deployed versions. Upgrade per &lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-158&quot;&gt;FG-IR-26-158&lt;/a&gt;. No upgrade window yet: firewall management access to known-good subnets, disable internet-facing admin paths.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;FortiManager&lt;/strong&gt; — Upgrade per &lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-26-160&quot;&gt;FG-IR-26-160&lt;/a&gt;. Management interfaces should not be internet-accessible regardless of patch status — if they are, fix that now independent of the patch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;FortiOS (medium-severity)&lt;/strong&gt; — Patch on your standard cycle per the linked advisories.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Related: August was a heavy patch month across the board — see the &lt;a href=&quot;/articles/2026-08-11-microsoft-patch-tuesday-august-2026&quot;&gt;August 2026 Patch Tuesday roundup&lt;/a&gt; and &lt;a href=&quot;/articles/2026-08-11-cisco-asa-ftd-cve-2026-20349-kev-dos-vpn&quot;&gt;Cisco ASA/FTD CVE-2026-20349 KEV addition&lt;/a&gt; for perimeter device context.&lt;/p&gt;</content:encoded><dc:creator>Morgan &quot;airgap&quot; Reyes</dc:creator><media:content url="https://0daynews.com/articles/2026-08-13-fortinet-fortiweb-fortimanager-aug-patches/cover.jpg" medium="image" width="1200" height="675"/><category>Fortinet</category><category>FortiWeb</category><category>FortiManager</category><category>CVE-2026-26035</category><category>CVE-2026-70468</category><category>authentication bypass</category><category>patch</category></item></channel></rss>