The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them by specific deadlines. The vulnerabilities affect Cisco Secure Firewall, Microsoft Windows, and Metabase, with the Metabase flaw being a critical SQL injection that was actively exploited.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to address them promptly. The newly cataloged flaws include a critical SQL injection vulnerability in Metabase, a use-after-free flaw in Microsoft Windows' Ancillary Function Driver for WinSock, and a heap inspection vulnerability affecting Cisco Secure Firewall products.
The Metabase SQL injection vulnerability, tracked as CVE-2026-72898, carries a CVSS score of 10.0, indicating maximum severity. This flaw allows an unauthenticated attacker to inject arbitrary SQL commands directly into the Metabase application database. Metabase, a business intelligence tool, confirmed that its cloud service was attacked using an unknown zero-day vulnerability in versions 1.58 and above. The company stated it detected the attack, blocked the exploited endpoints, and patched the vulnerability, with cloud instances running the fixed version before the public advisory. For self-hosted deployments, Metabase urged immediate patching. An attacker exploiting this vulnerability could gain administrator rights, alter application configurations, steal credentials for connected databases, and access sensitive data.
Microsoft's Windows Ancillary Function Driver for WinSock (afd.sys) is affected by a use-after-free vulnerability, CVE-2026-68820, with a CVSS score of 7.0. This kernel-mode driver flaw could allow attackers to execute code with SYSTEM-level privileges. Microsoft has confirmed active exploitation of this vulnerability.
The third vulnerability, CVE-2026-20349, impacts Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software, with a CVSS score of 8.6. This heap inspection vulnerability could enable unauthenticated, remote attackers to trigger a denial-of-service condition by crashing affected devices. The flaw results from insufficient error checking during HTTP request processing. Attackers can exploit it by sending a specially crafted request to the Remote Access SSL VPN service, forcing the firewall to reload and disrupt network access.
Under CISA's Binding Operational Directive (BOD) 22-01, federal civilian executive branch (FCEB) agencies are required to remediate these vulnerabilities by specific deadlines. Agencies must address CVE-2026-20349 and CVE-2026-72898 by August 14, 2026. The deadline for patching CVE-2026-68820 is August 25, 2026. CISA also recommends that private sector organizations review the KEV catalog and apply necessary mitigations to their infrastructure to protect against potential attacks.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a