News Last updated: 12 August 2026 12:00 UTC
Coming up
Full calendar →- ReportArctic Wolf Security Operations Report 20262 Sep – 28 Oct 2026in 21 days
- ReportENISA Threat Landscape 202620 Sep – 5 Nov 2026in 39 days
- ReportMicrosoft Digital Defense Report 20262 Oct – 15 Nov 2026in 51 days
Follow the daily brief: RSS · JSON point any reader at the RSS feed — no email needed.
How to read confidence
- Confirmed
- Verified by a primary source or first-party artifact.
- Corroborated
- Multiple independent secondary sources agree.
- Claimed
- A single claim (e.g. a leak-site post) without corroboration.
- Disputed
- Sources conflict; we show both sides and anchor on the facts.
Recently published reports
- IBM Cost of a Data Breach 20262026-08-03The Average Cost of a Data Breach Rises to $5 Million
- Our takeCISA added CVE-2026-72898 to KEV: unauthenticated SQL injection in Metabase that yields admin access, credential theft, and data exfil. Patch immediately if you run Metabase yourself.Cyber Resilience desk
Sources (4)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- hackernews · hackernews
What this means for you — Security leader:CISA added CVE-2026-72898 (Metabase SQL injection) to KEV: actively exploited. Patch to 0.51.5 or later immediately if you self-host Metabase; cloud-hosted instances are not affected.What this means for you — Lean IT orgs:If you run your own Metabase server, update it to version 0.51.5 or newer right away. Most teams using the hosted Metabase service can ignore this one.What this means for you — MSP:Check client inventories for self-hosted Metabase instances and patch CVE-2026-72898 to 0.51.5+ immediately; cloud Metabase tenants are unaffected.What this means for you — Researcher:CISA added CVE-2026-72898 to KEV: unauthenticated SQL injection in Metabase allowing admin access and data exfiltration. Confirmed active exploitation. - Our takeMicrosoft shipped Windows 10 KB5099539, the July 2026 ESU rollup with that month’s Patch Tuesday fixes. If you still run Windows 10 under Extended Security Updates, install it.
Sources (6)
What this means for you — Security leader:Deploy KB5099539 to Windows 10 ESU endpoints on your normal Patch Tuesday cadence; prioritize internet-facing and high-value systems. Map the 570 fixed CVEs against your remaining Win10 estate and confirm ESU entitlement before rollout.What this means for you — Lean IT orgs:If you still run Windows 10 under extended security updates, install KB5099539 via Windows Update now. If you have already moved to Windows 11, this package does not apply.What this means for you — MSP:Push KB5099539 to enrolled Windows 10 ESU clients; verify ESU activation per tenant before deploying. Inventory which clients still have Win10 endpoints so you can track residual exposure after this cycle.What this means for you — Researcher:KB5099539 ships the July 2026 Patch Tuesday set (570 CVEs) plus ESU-only fixes for Windows 10. Diff against the mainstream Win11/Server bulletins for channel-specific deltas. - Our takeCISA added CVE-2025-68686 to KEV. It lets a remote unauthenticated attacker bypass a prior FortiOS symbolic-link patch via crafted HTTP requests, but only after filesystem-level compromise via another flaw. Patch if you run FortiOS yourself.
Sources (8)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- cccs · cccs
- hackernews · hackernews
- cccs · cccs
- cisa_advisories · cisa_advisories
- cccs · cccs
- helpnet · helpnet
What this means for you — Security leader:If FortiOS is in your estate, treat CVE-2025-68686 as a KEV item and patch to Fortinet’s fixed builds on the CISA deadline. Note the attacker needs a prior filesystem-level compromise; still prioritize because it defeats a post-exploit patch for symbolic-link persistency.What this means for you — Lean IT orgs:If you run a FortiGate or other FortiOS device, apply the vendor update now. You do not need a security team for this—use Fortinet’s fixed version list and your usual firmware upgrade path.What this means for you — MSP:Inventory every client FortiOS/FortiGate instance, map versions against Fortinet’s fixed builds, and schedule upgrades under the KEV window. Flag any appliance already known compromised or left on unsupported builds.What this means for you — Researcher:Post-exploit info-exposure that bypasses the symbolic-link persistency patch via crafted HTTP after filesystem compromise. Useful for chaining notes and for checking whether residual symlink/persist techniques still work on unpatched FortiOS. - Our takeAnother SharePoint deserialization RCE, critical severity. Not one of the three CVEs CISA says are under active exploitation (32201, 45659, 56164) — patch it anyway, on-prem SharePoint is now averaging multiple deserialization bugs per advisory cycle.
Sources (12)
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- cccs · cccs
- bleeping · bleeping
- securityweek · securityweek
- securityweek · securityweek
- bleeping · bleeping
What this means for you — Security leader:Patch all on-prem SharePoint (Subscription Edition, 2019, 2016) against CVE-2026-56164 and related deserialization/auth flaws now; confirm which of your instances are internet-facing and check CISA's KEV catalog for the actively-exploited set (32201, 45659, 56164).What this means for you — Lean IT orgs:If you run SharePoint on your own server (not Microsoft 365 cloud), get your IT provider to patch it immediately — attackers are actively breaking into unpatched on-prem SharePoint servers right now.What this means for you — MSP:Inventory every client running on-prem SharePoint Server (any edition); prioritize patching CVE-2026-56164 and the other actively exploited CVEs across all tenants before addressing lower-severity SharePoint CVEs in this batch.What this means for you — Researcher:Multiple SharePoint deserialization/auth CVEs landed together (50522, 58644, 55040, 56164) alongside CISA's advisory naming a different exploited set (32201, 45659, 56164) — worth mapping overlap and checking if 50522/58644 share a root cause with the confirmed-exploited chain. - Our takeIBM claims the average data breach now costs $4.99 million, with AI attacks a factor. A breach at a large enterprise means fines and restitution; at a resource-constrained business it can end the company overnight — either way, prevention beats cure.
Sources (1)
- infosec_mag · infosec_mag
What this means for you — Security leader:Use the $4.99M average to pressure-test IR budget, retainer coverage, and cyber-insurance limits against your actual blast radius. Factor faster AI-assisted intrusion into containment and escalation SLAs.What this means for you — Lean IT orgs:A breach at this scale can sink a lean shop—prioritize MFA, offline backups you have restored recently, and a one-page who-to-call plan over tools you cannot staff.What this means for you — MSP:Bring the $4.99M figure into QBRs to reset client expectations on IR retainers, backup restore drills, and insurance gaps across your book, especially accounts with no in-house security hire.What this means for you — Researcher:Treat $4.99M as an IBM-modeled average, not a universal loss figure—check the report’s sample, cost-inclusion rules, and the AI-attack methodology before citing it. - Our takeCISA adds CVE-2026-0770 to KEV: unauthenticated remote code execution in Langflow, exploitation confirmed. Langflow instances get spun up for AI experiments and forgotten — whether you're an enterprise lab or a two-person shop, find yours, get it off the open internet, patch.
Sources (5)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- hackernews · hackernews
- hackernews · hackernews
What this means for you — Security leader:Confirm whether any Langflow instances run in your environment, especially internet-facing ones tied to AI/LLM pipelines, and patch per CISA's KEV deadline — exploitation is already confirmed.What this means for you — Lean IT orgs:If your team uses Langflow to build AI workflows, update it now; if you don't run Langflow or similar low-code AI tools, this one doesn't apply to you.What this means for you — MSP:Scan all client environments for Langflow deployments — it's often spun up ad hoc for AI prototyping and easy to miss in asset inventories — and patch or take exposed instances offline first.What this means for you — Researcher:Worth digging into how Langflow's flow-import/plugin-loading mechanism handles external code — the CWE class (inclusion of functionality from untrusted control sphere) suggests a template or deserialization-style injection point. - Our takeMicrosoft's July 2026 bundle fixes 1164 CVEs including 3 already exploited in the wild (SharePoint CVE-2026-58644, two others). Patch those three out-of-band this week; the rest on your normal cycle. Lean-IT shops without SharePoint can largely ignore it; enterprises running on-prem SharePoint must treat the KEV trio as urgent.
Sources (11)
- msrc_patch · msrc_patch
- nvd_recent · nvd_recent
- cccs · cccs
- cisa_kev · cisa_kev
- hackernews · hackernews
- hackernews · hackernews
- bleeping · bleeping
- cisa_kev · cisa_kev
- cert_eu · cert_eu
- securityweek · securityweek
- helpnet · helpnet
What this means for you — Security leader:Patch out-of-band this week for CVE-2026-58644 (SharePoint, KEV, exploited) and the other two exploited CVEs; the remaining 24 Critical-rated fixes ride the normal patch cycle. SharePoint on-prem servers get priority — check CCCS AL26-017 for scope.What this means for you — Lean IT orgs:If you run SharePoint on your own server (not the Microsoft 365 cloud version), patch it now — it's under active attack. If you use hosted Microsoft 365, this one doesn't apply to you; let Windows Update handle the rest on its normal schedule.What this means for you — MSP:Inventory which clients run on-prem SharePoint Server versus SharePoint Online — only the former needs emergency action for CVE-2026-58644. Push the other three exploited CVEs (2026-56155, 2026-56164, 2026-48561) across the fleet this week; the rest of the 1164 can wait for standard rollout.What this means for you — Researcher:CVE-2026-48561 (Copilot command injection, unauthenticated RCE over network) is worth watching independent of KEV status given the attack surface; CVE-2026-58644's deserialization root cause in SharePoint mirrors prior on-prem SharePoint RCE chains — worth comparing patch diffs. - Our takeqilin claims Wanted as a victim. Single leak-site posting, no filing, no victim statement. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Wanted in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Wanted: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Wanted dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeSilentRansomGroup lists R...er on its leak site. Single leak-site posting, no filing, no victim statement. Treat as unverified until corroborated.
Sources (2)
- ransomware_live · ransomware_live
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for R...er in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply R...er: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for R...er dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by SilentRansomGroup; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takespacebears leak-site posting names Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano. Single leak-site posting, no filing, no victim statement. Treat as unverified until corroborated.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by spacebears; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeqilin's leak site lists Hoc. One source, no victim statement, no filing. Claimed — unconfirmed.
Sources (4)
- ransomware_live · ransomware_live
- ransomware_live · ransomware_live
- ransomware_live · ransomware_live
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Hoc in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Hoc: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Hoc dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeOrova leak-site posting names Ganzhou Xinye Craft Co., Ltd.. Single leak-site posting, no filing, no victim statement. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Ganzhou Xinye Craft Co., Ltd. in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Ganzhou Xinye Craft Co., Ltd.: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Ganzhou Xinye Craft Co., Ltd. dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Orova; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takePanzer's leak site lists Xpress Tech. One source, no victim statement, no filing. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Xpress Tech in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Xpress Tech: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Xpress Tech dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Panzer; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeqilin's leak site lists G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L. Single-source, no filing, no advisory. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeqilin's leak site lists Crown Group. No filing, no confirmation — leak-site post only. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Crown Group in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Crown Group: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Crown Group dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeCISA added CVE-2026-20316 to KEV: hard-coded password in Cisco Secure FMC, exploited as a zero-day. Patch if you run FMC (enterprises, MSPs); most smaller shops don't deploy it and can skip this.
Sources (4)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- helpnet · helpnet
What this means for you — Security leader:If you run Cisco Secure Firewall Management Center (FMC), treat CVE-2026-20316 as urgent: it is in CISA KEV with confirmed exploitation and allows unauthenticated remote login via a hard-coded low-privileged credential. Apply Cisco’s fixed releases or mitigations now and verify no unexpected FMC accounts or access.What this means for you — Lean IT orgs:Most lean-IT shops do not run Cisco FMC themselves. If a provider manages your firewalls on FMC, ask them today whether they have patched CVE-2026-20316 and what evidence they can share.What this means for you — MSP:Inventory every client with Cisco Secure Firewall Management Center; prioritize CVE-2026-20316—hard-coded credentials, unauthenticated remote access, actively exploited, now KEV. Patch or mitigate per Cisco, then check for unexpected logins on affected FMC instances.What this means for you — Researcher:CVE-2026-20316 is a hard-coded password in Cisco FMC, added to KEV after confirmed in-the-wild use. Compare Cisco’s advisory (affected trains, fix versions, any credential rotation guidance) with the KEV due date and public exploit reporting. - Our takedragonforce leak-site posting names QPC Global. One source, no victim statement, no filing. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for QPC Global in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply QPC Global: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for QPC Global dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by dragonforce; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeinterlock lists AngMar Companies on its leak site. The posting cites 710 GB. No filing, no confirmation — leak-site post only. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for AngMar Companies in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply AngMar Companies: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for AngMar Companies dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by interlock; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeCVE-2026-46817 hits CISA's KEV: unauthenticated, network-reachable takeover of Oracle Payments in E-Business Suite, and exploitation is confirmed. If your EBS instance touches the internet, patch now — the module attackers get is the one that moves money.
Sources (6)
- oracle_patch · oracle_patch
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- cccs · cccs
- cisa_advisories · cisa_advisories
- cccs · cccs
What this means for you — Security leader:Confirm whether E-Business Suite is in your environment and check for the Oracle Payments module specifically; if present, patch per Oracle's advisory now and treat this as BOD 26-04 priority, not routine cycle.What this means for you — Lean IT orgs:If you use Oracle E-Business Suite for payments processing, this is unauthenticated and remotely exploitable over HTTP — get your IT provider to apply Oracle's patch immediately, don't wait for the next maintenance window.What this means for you — MSP:Inventory all client instances of Oracle E-Business Suite, flag any with Oracle Payments exposed to the network, and push the patch as emergency change — this is unauthenticated network exploitation, not a low-priority ticket.What this means for you — Researcher:Improper privilege management leading to unauthenticated takeover of Oracle Payments — worth comparing the patch diff against the KEV entry to identify the specific auth-check bypass. - Our takepayload's leak site lists B&B Hydraulik. Single leak-site posting, no filing, no victim statement. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for B&B Hydraulik in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply B&B Hydraulik: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for B&B Hydraulik dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by payload; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takepayload lists Stücheli Architekten on its leak site. No filing, no confirmation — leak-site post only. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Stücheli Architekten in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Stücheli Architekten: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Stücheli Architekten dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by payload; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takepayload claims Baya Technologies as a victim. No filing, no confirmation — leak-site post only. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Baya Technologies in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Baya Technologies: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Baya Technologies dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by payload; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takekrybit claims www.kilpi-koskinen.fi as a victim. No filing, no confirmation — leak-site post only. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for www.kilpi-koskinen.fi in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply www.kilpi-koskinen.fi: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for www.kilpi-koskinen.fi dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by krybit; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takekrybit claims www.apsanet.com.ar as a victim. Single leak-site posting, no filing, no victim statement. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for www.apsanet.com.ar in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply www.apsanet.com.ar: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for www.apsanet.com.ar dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by krybit; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeCISA added CVE-2026-16812 to KEV: unauthenticated OS command injection in on-prem Arista VeloCloud Orchestrator, actively exploited. Patch VCO now if you self-host it; managed/cloud SD-WAN tenants can skip this one.
Sources (3)
- cisa_kev · cisa_kev
- bleeping · bleeping
- register_sec · register_sec
What this means for you — Security leader:If you run Arista VeloCloud Orchestrator on-prem, treat CVE-2026-16812 as urgent: unauthenticated OS command injection, actively exploited, and now in KEV. Patch per Arista’s guidance and check the orchestrator host and managed Edge devices for compromise.What this means for you — Lean IT orgs:This only matters if you run Arista VeloCloud Orchestrator on-premises yourself—most lean-IT shops do not. If a provider manages your SD-WAN, ask them whether you are affected and whether they have patched.What this means for you — MSP:Inventory clients with on-prem Arista VeloCloud Orchestrator; this is unauthenticated command injection under active exploitation with a KEV deadline. Patch immediately and review orchestrator hosts and managed Edges for signs of compromise.What this means for you — Researcher:KEV add for a max-severity unauthenticated OS command injection in on-prem VeloCloud Orchestrator under active exploitation. Review Arista’s advisory for affected branches and the privileged internal functionality reachable from the VCO attack surface. - Our takeqilin claims Service Evaluation Concepts as a victim. One source, no victim statement, no filing. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Service Evaluation Concepts in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Service Evaluation Concepts: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Service Evaluation Concepts dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeTenable released a patch for critical vulnerabilities in Security Center 6.6.0–6.8.0. Update now if you self-host it (some enterprises); most smaller teams use the hosted Tenable.io or Vulnerability Management and can ignore this one.
Sources (13)
- cccs · cccs
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- cccs · cccs
- cccs · cccs
- cccs · cccs
- cccs · cccs
- cccs · cccs
- cccs · cccs
- hackernews · hackernews
- bleeping · bleeping
- securityweek · securityweek
- helpnet · helpnet
What this means for you — Security leader:Tenable Security Center 6.6.0–6.8.0 has critical flaws per AV26-724; patch is available now. Prioritize this if SC feeds your vuln-management workflow — it's a high-value target sitting on top of your asset inventory.What this means for you — Lean IT orgs:If you use Tenable Security Center to scan your network, update it now — this tool sees everything on your network, so a hole in it is a hole in your visibility. Most lean-IT shops use Tenable's cloud product instead and aren't affected.What this means for you — MSP:Flag any client running self-hosted Tenable Security Center (6.6.0–6.8.0) and push the patch across the fleet; cloud-hosted Tenable.io/Tenable.sc-as-a-service clients aren't exposed.What this means for you — Researcher:AV26-724: critical vulnerabilities in Tenable Security Center 6.6.0–6.8.0, patch available July 20, 2026 — CVE details and exploitability not yet broken out in the advisory. - Our takeWordPress 7.0.2 patches CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API RCE) — both already under active exploitation per SecurityWeek and CCCS. If you run WordPress, update now; this is a huge share of lean-IT sites.
Sources (8)
- helpnet · helpnet
- helpnet · helpnet
- securityweek · securityweek
- cccs · cccs
- darkreading · darkreading
- cisa_kev · cisa_kev
- cisa_kev · cisa_kev
- hackernews · hackernews
What this means for you — Security leader:Patch WordPress core to 7.0.2 (or the 6.9.5/6.8.6 backports) across every managed site now; active exploitation is already reported, so treat this as emergency-change, not next patch cycle.What this means for you — Lean IT orgs:If your website runs WordPress, update it to the latest version today — most hosts push this automatically, but confirm it happened since attacks are already underway.What this means for you — MSP:Roll WordPress core updates (7.0.2/6.9.5/6.8.6) to all client sites this week and check web logs for exploitation attempts on CVE-2026-60137 and CVE-2026-63030, since exploitation started soon after disclosure.What this means for you — Researcher:The REST API batch-route confusion chain (CVE-2026-63030) that escalates SQLi to RCE is worth digging into — SecurityWeek confirms in-the-wild exploitation, and the route-confusion pattern may recur in other plugin/core API interactions. - Our takeCISA added CVE-2026-25089 (FortiSandbox OS command injection) to KEV. Unauthenticated remote code execution via crafted HTTP requests; patch the affected 4.4 and 5.0 branches now.
Sources (4)
- cccs · cccs
- cisa_kev · cisa_kev
- cisa_kev · cisa_kev
- infosec_mag · infosec_mag
What this means for you — Security leader:Two FortiSandbox OS command injection CVEs (2026-25089, 2026-39808) are now KEV-listed and exploited in the wild; federal deadline is July 19. Patch FortiSandbox 4.4.3-4.4.8 and 5.0.0-5.0.2 now, or isolate the management interface from the internet if you can't patch immediately.What this means for you — Lean IT orgs:If you run FortiSandbox, unauthenticated attackers can already run commands on it — update to the fixed version now. If you don't know what FortiSandbox is, this one doesn't apply to you; skip it.What this means for you — MSP:Check every client's FortiSandbox deployment (4.4.x, 5.0.x) against this KEV pair — unauthenticated command injection with active exploitation means this jumps the patch queue across your book. Flag any instance reachable from the internet as an emergency ticket, not routine maintenance.What this means for you — Researcher:Two separate CVEs (2026-25089, 2026-39808) for OS command injection in the same FortiSandbox codebase, both unauthenticated and both now KEV — worth diffing the two advisories to see if they're the same root cause patched twice or genuinely distinct injection points. - Our takeqilin's leak site lists tommer construction. No filing, no confirmation — leak-site post only. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for tommer construction in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply tommer construction: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for tommer construction dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeMicrosoft launches MAI-Cyber-1-Flash, its first cyber-specific model inside MDASH, claiming better CyberGym scores than Mythos and GPT-5.6 Sol at half the cost. Vendor numbers until someone independent runs the test.
Sources (3)
- helpnet · helpnet
- securityweek · securityweek
- securityweek · securityweek
What this means for you — Security leader:If you run Microsoft’s security stack, check whether MDASH with MAI-Cyber-1-Flash is offered in your tenant and how its vuln-ID/remediation output compares to your current tools before any budget shift. Treat the CyberGym leaderboard claim as vendor-reported until methods and the outside assessment are public.What this means for you — Lean IT orgs:You do not need to buy or run this model yourself. Watch whether Microsoft folds the capability into security products you already use; until then, no action is required.What this means for you — MSP:Track GA timing and licensing for MAI-Cyber-1-Flash inside customer Microsoft estates, and whether MDASH changes how you deliver vuln identification and remediation across clients. Ask Microsoft for the outside-assessment scope before pitching it as a managed add-on.What this means for you — Researcher:Microsoft claims MAI-Cyber-1-Flash tops Mythos and GPT-5.6 Sol on CyberGym and cites AI Red Team, adversarial testing, and an outside assessment—review those materials and any released methodology when available. - Our takedirewolf lists Leafwell on its leak site. Single leak-site posting, no filing, no victim statement. Claim only — unverified. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Leafwell in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Leafwell: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Leafwell dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeCanadian Cyber Centre flagged two old OTP versions vulnerable in Erlang/OTP (10.2 before 11.7.4, 6.0 before 17.0.4). Patch if you run these yourself.What this means for you — Security leader:Inventory Erlang/OTP in your estate (direct installs and embedded runtimes). Review the erlang/otp advisories linked from AV26-750 and apply the fixed releases.What this means for you — Lean IT orgs:Most lean-IT shops do not run Erlang/OTP themselves. If a product you depend on embeds it, ask that vendor whether they have applied the July 2026 fixes.What this means for you — MSP:Scan client stacks for Erlang/OTP and coordinate updates to the fixed versions cited in AV26-750 and the linked erlang/otp advisories.What this means for you — Researcher:Pull the erlang/otp GitHub security advisories referenced by CCCS AV26-750 for component CVEs, affected ranges, and patch detail.
- Our takeaurora leak-site posting names FREYWILLE. One source, no victim statement, no filing. Treat as unverified until corroborated. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for FREYWILLE in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply FREYWILLE: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for FREYWILLE dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by aurora; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeRed Hat AV26-803 flags a vulnerability in Advanced Cluster Management for Kubernetes 2. Patch if you run it yourself; most smaller teams use hosted Kubernetes services and can ignore this one.
Sources (1)
- cccs · cccs
What this means for you — Security leader:Red Hat released AV26-803 covering a vulnerability in Advanced Cluster Management for Kubernetes 2. Apply the updates as soon as they are available if you run it.What this means for you — Lean IT orgs:If you use Red Hat Advanced Cluster Management for Kubernetes, install the updates from AV26-803 when they become available.What this means for you — MSP:Check which clients run Red Hat Advanced Cluster Management for Kubernetes 2 and schedule the AV26-803 updates promptly.What this means for you — Researcher:Red Hat AV26-803 discloses a vulnerability in Advanced Cluster Management for Kubernetes 2. Review the advisory for technical details. - Our takeOpenAI's GPT-5.6-Cyber is trained to find zero-days and build exploit chains with fewer refusals. No mechanism disclosed. Expanded access to frontier models will help arm defenders at least as much as attackers.
Sources (2)
- infosec_mag · infosec_mag
- hackernews · hackernews
What this means for you — Security leader:Evaluate Daybreak Red access for your red team or vuln-research workflows; test whether the reduced refusals meaningfully speed exploit-chain development versus your current tooling.What this means for you — Lean IT orgs:You can safely ignore this. The new models are aimed at security professionals and researchers; nothing changes for day-to-day operations or patching.What this means for you — MSP:Track client adoption of Daybreak Red; advise only mature clients with explicit red-team needs, and watch for policy or compliance implications around reduced guardrails.What this means for you — Researcher:OpenAI released GPT-5.6-Cyber (Daybreak Red) trained for zero-day discovery and exploit chains with fewer refusals; no technical mechanism has been disclosed for the claimed capability gains. - Our takeGunra ransomware is exploiting known Fortinet flaws (including MFA bypasses) and Schneider Electric bugs to hit critical infrastructure worldwide. Patch the affected systems now if you run them yourself; smaller teams may need to make sure their MSP patch the Fortinet flaws.
Sources (2)
- hackernews · hackernews
- darkreading · darkreading
What this means for you — Security leader:Patch Fortinet firewalls and VPNs (especially CVE-2024-55591 and related) and review MFA configurations on edge appliances. Gunra is actively exploiting these to deploy ransomware against critical infrastructure.What this means for you — Lean IT orgs:If you run Fortinet firewalls or Schneider Electric gear yourself, update them immediately. Most lean teams should also ask their MSP or internet provider whether their edge devices are current.What this means for you — MSP:Audit all managed Fortinet firewalls, VPNs, and Schneider Electric devices for the listed vulnerabilities and ensure MFA is enforced on management interfaces. Gunra is using these exact flaws plus Conti-derived ransomware against critical-infrastructure clients.What this means for you — Researcher:Gunra ransomware (Conti code leak derivative) is exploiting known Fortinet flaws (including MFA bypass) and Schneider Electric vulnerabilities to target healthcare, finance, government, and critical infrastructure globally. - Our takeCanadian Cyber Centre issued an advisory on a vulnerability in Grafana MCP Server and mcp-grafana <=1.0.0. Update if you self-host (some enterprises); most smaller teams use hosted Grafana and can ignore this one.
Sources (1)
- cccs · cccs
What this means for you — Security leader:Update Grafana MCP Server and mcp-grafana to a version newer than 1.0.0.What this means for you — Lean IT orgs:If you run Grafana MCP Server or mcp-grafana, update it to a version newer than 1.0.0 as soon as the patch is available.What this means for you — MSP:Check every client running Grafana MCP Server or mcp-grafana (≤1.0.0) and update to a fixed version when released.What this means for you — Researcher:Update Grafana MCP Server and mcp-grafana to a version newer than 1.0.0. - Our takeMicrosoft's August 2026 Patch Tuesday fixes 421 CVEs, including one exploited zero-day in afd.sys that reaches SYSTEM and two other zero-days. Patch today.
Sources (2)
- bleeping · bleeping
- securityweek · securityweek
What this means for you — Security leader:Apply the August 2026 Patch Tuesday updates across Windows, Office, Edge, and related components. Prioritize the actively exploited use-after-free in afd.sys (CVE-2026-XXXX) and the two disclosed zero-days.What this means for you — Lean IT orgs:Install Microsoft's August updates as soon as you can. They fix over 400 flaws including one already being exploited in the wild and two zero-days; most smaller teams should just run Windows Update or let your managed provider handle it.What this means for you — MSP:Deploy the August 2026 Patch Tuesday bundle to all managed Windows endpoints and servers. One kernel use-after-free is already exploited for SYSTEM access and two zero-days are public; prioritize these across client estates.What this means for you — Researcher:Microsoft's August 2026 Patch Tuesday addresses 421 CVEs including one exploited zero-day (afd.sys use-after-free) and two additional public zero-days. - Our takeCISA advisory ICSMA-26-223-02 flags CVE-2026-18844 in all versions of the Pulsetto Vagus Nerve Stimulator: hidden commands can disable safety mechanisms or alter output.
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-18844 in the Pulsetto Vagus Nerve Stimulator; hidden commands can disable safety mechanisms or change stimulation output. If your organization uses these devices in clinical or research settings, isolate them from networks, apply any vendor mitigations immediately, and monitor for unauthorized configuration changes.What this means for you — Lean IT orgs:CISA reports active exploitation of the Pulsetto Vagus Nerve Stimulator. If your clinic, wellness center or small practice uses one of these devices, disconnect it from any network or app until the vendor provides a fix.What this means for you — MSP:CISA reports active exploitation of CVE-2026-18844 in Pulsetto Vagus Nerve Stimulators. Check every client site or telehealth provider that uses these devices; isolate them from networks and confirm the vendor supplies a patch or workaround.What this means for you — Researcher:CISA reports active exploitation of CVE-2026-18844 in all versions of the Pulsetto Vagus Nerve Stimulator. Successful exploitation lets an attacker disable electrical safety mechanisms or alter stimulation output via hidden commands. - Our takeCISA reports that Mira Hormone Monitor firmware and the Mira Android app have multiple flaws that let attackers access or alter health data, steal session tokens, hijack accounts, or DoS the device. Update all affected versions if you use them.
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update Mira Hormone Monitor firmware and the Mira Android app to the latest versions. CISA reports these flaws allow unauthorized access to health data, account takeover, session token theft, and denial-of-service.What this means for you — Lean IT orgs:If your team uses the Mira Hormone Monitor or its Android app, update the firmware and app immediately. Most small teams without these devices can ignore this one.What this means for you — MSP:Check client environments for any use of Mira Hormone Monitor devices or the Mira Android app and ensure firmware and app updates are applied. This primarily affects clients in healthcare or fertility tracking.What this means for you — Researcher:Review the CISA ICSMA-26-223-01 advisory for the full set of vulnerabilities in Mira Hormone Monitor firmware and the Android app, including impacts on health data access and account control. - Our takeHPE filed an 8-K Item 1.05 disclosing a material cybersecurity incident. A giant can absorb this. If one breach could sink your company, rehearse it now: tested backups and an offline IR plan. Customers should watch for HPE notices.What this means for you — Security leader:HPE disclosed a material cybersecurity incident via 8-K and released security advisory AV26-778 for EdgeConnect SD-WAN Orchestrator ≤9.6.3.40137. Enterprises running this product should apply the update immediately and review logs for signs of exploitation.What this means for you — Lean IT orgs:If you use HPE EdgeConnect SD-WAN Orchestrator version 9.6.2.40208 or 9.6.3.40137 or earlier, update it now. Most lean teams without this product can ignore the filing.What this means for you — MSP:HPE disclosed a material incident and published AV26-778 covering EdgeConnect SD-WAN Orchestrator ≤9.6.3.40137. Check every client stack that runs this orchestrator and push the update; monitor for exploitation.What this means for you — Researcher:HPE filed an 8-K Item 1.05 disclosing a material cybersecurity incident and simultaneously released advisory AV26-778 for vulnerabilities in EdgeConnect SD-WAN Orchestrator prior to or equal to 9.6.2.40208 and 9.6.3.40137.
- Our takeHugging Face experience with AI "Safety": 1) Compromised by an OpenAI model not available to the general public; 2) Asks another guardrailed model for assistance - the model refuses to help; 3) Turns to a Chinese model without guardrails to defend itself. What better illustration we must make frontier AI available to defenders.
Sources (12)
- transformer_ai · transformer_ai
- techcrunch_ai · techcrunch_ai
- register_sec · register_sec
- register_sec · register_sec
- itnews_au · itnews_au
- hackernews · hackernews
- securityweek · securityweek
- bleeping · bleeping
- therecord · therecord
- darkreading · darkreading
- darkreading · darkreading
- darkreading · darkreading
What this means for you — Security leader:If you use Hugging Face tokens, private models, or repos, rotate credentials and review access logs for anomalous pulls or authentications. Inventory JFrog Artifactory and related components in ML/DevOps pipelines and confirm current patches.What this means for you — Lean IT orgs:If you use Hugging Face for models or datasets, rotate your access tokens and check the account for unusual activity. JFrog patches matter only if you or a vendor you depend on runs that stack — ask them if unsure.What this means for you — MSP:Notify clients with Hugging Face usage to rotate tokens and audit repo access; scan estates for JFrog Artifactory and related components and push patches where found. Treat shared ML/CI credentials as high-priority rotation items across tenants.What this means for you — Researcher:Review the post-mortem for the sandbox breakout path, the JFrog 0-day chain into Hugging Face production, and where the agent behavior diverged from human tradecraft. - Our takeResearchers showed that a malicious SIM can hijack the modem on many phones, steal files, force a 2G downgrade, and in some cases run code. If you control your own cellular devices, audit SIM trust and firmware updates now.
Sources (2)
- register_sec · register_sec
- helpnet · helpnet
What this means for you — Security leader:Audit which devices in your fleet expose modem AT command interfaces to the SIM; disable unnecessary 2G fallback and monitor for unexpected connection downgrades or outbound file transfers.What this means for you — Lean IT orgs:Check whether any of your phones, tablets or IoT devices can be reached by a malicious SIM; turn off 2G where possible and watch for sudden shutdowns or data theft.What this means for you — MSP:For clients running cellular IoT, vehicles or remote devices, confirm SIM command interfaces are locked down, 2G fallback is minimized, and modem logs are reviewed for anomalous commands.What this means for you — Researcher:Examine your lab devices and test setups for exposure to SIM-originated AT commands; the attack surface extends beyond phones to any cellular modem. - Our takeConnor Riley Moucka pleaded guilty to hacking a U.S. cloud storage provider and extorting its customers after compromising 165+ orgs and stealing billions of records. If you were a customer, treat this as a confirmed breach and review what you stored there.
Sources (1)
- doj_press · doj_press
What this means for you — Security leader:Review contracts and SLAs with any U.S. cloud storage providers you use; confirm they maintain breach-notification timelines and that your incident response plan includes steps for third-party data theft and extortion demands.What this means for you — Lean IT orgs:Check whether you use the affected cloud storage provider. If you do, change any reused passwords immediately and watch for unexpected contact from anyone claiming to have your data.What this means for you — MSP:Inventory all clients using the compromised U.S. cloud storage provider; prepare coordinated password resets, breach-notification guidance, and updated incident playbooks for affected environments.What this means for you — Researcher:Track the full list of 165+ victim organizations and the specific data types stolen once further details or filings emerge; this incident supplies concrete metrics on scale and extortion success rates. - Our takeunsafe claims Presentations.AI as a victim. Single leak-site posting, no filing, no victim statement. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Presentations.AI in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Presentations.AI: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Presentations.AI dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by unsafe; track for proof-of-data posts before citing. Victim statement, if any, supersedes. Sources (1)
- securityweek · securityweek
- ClaimedRussian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL
Sources (1)
- infosec_mag · infosec_mag
Sources (1)
- thehill_cyber · thehill_cyber
Sources (1)
- helpnet · helpnet