patch news
306 stories · page 4 of 7
Brinqa acquires PlexTrac to bring validated remediation to exposure management
Brinqa has announced its acquisition of PlexTrac, a move that integrates validated remediation capabilities into its exposure management platform. This acquisition aims to provide enterprises with a comprehensive solution for identifying, prioritizing, and verifying the resolution of security exposures, effectively closing the Cyber Threat Exposure Management (CTEM) loop.

943 Patches Rolled Out With Oracle’s August 2026 Security Update
Oracle has released its August 2026 Critical Patch Update (CPU), which includes 943 security fixes addressing a wide array of vulnerabilities across its product portfolio. This extensive update resolves over 1,000 individual vulnerabilities, with a significant portion of these issues being remotely exploitable.

Windows 11 24H2 Home and Pro reach end of support in 2 months
Microsoft has issued a reminder that Home and Pro editions of Windows 11 version 24H2 will reach their end-of-life for updates on October 13, 2026. After this date, devices running these specific editions will no longer receive monthly security or non-security preview updates, leaving them vulnerable to new security threats.

Prison for data analyst who tried to extort $2.5 million from his employer
A former data analyst for Brightly Software, Cameron Curry, has been sentenced to 24 months in federal prison for attempting to extort $2.5 million from his employer after learning his contract would not be renewed. Curry, 27, of Charlotte, North Carolina, was convicted on six counts of transmitting interstate communications with intent to extort. In addition to his prison sentence, he will…

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle has released its August 2026 Critical Security Patch Update (CSPU), addressing 925 unique Common Vulnerabilities and Exposures (CVEs) through 943 security updates across 23 of its product families. This update includes 154 critical severity patches, accounting for 16.3% of the total fixes.

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
A critical use-after-free vulnerability, identified as CVE-2026-68820, in the Windows Ancillary Function Driver for WinSock (afd.sys) is currently under active exploitation and has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability allows a low-privilege local attacker to escalate privileges to SYSTEM without requiring user interaction.

More than 200 victims of Medusa ransomware identified over the last year, CISA says
Federal cybersecurity agencies have identified over 200 new victims of the Medusa ransomware group in the past year, bringing the total confirmed victim count to more than 500 as of April 2026. This updated figure comes from an advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, which was initially released in March 2025 and previously reported 300…

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The Medusa ransomware-as-a-service group has expanded its victim count to over 500 organizations, an increase of more than 200 since March 2025, according to an updated advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS). The group, first identified in 2021, has also refined its tactics for initial…

CISA gives feds 3 days to fix actively exploited Ray RCE bug
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch a critical vulnerability in the open-source Ray framework within three days. The flaw, identified as CVE-2025-62593, is actively being exploited and carries a CVSS v4 score of 9.4, indicating a severe risk of remote code execution (RCE).
Apple plugs image-processing hole ripe for spyware abuse
Apple has issued a series of security updates for its iPhones, iPads, and Macs, addressing a critical image-processing vulnerability that security experts believe could be exploited for spyware delivery. The most significant fix, identified as CVE-2026-65346, is an integer-overflow bug found within Apple's ImageIO framework, which is responsible for parsing image files.

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has issued patches for a critical code injection vulnerability, CVE-2026-19478, which could allow unauthenticated attackers to modify or delete public projects and user data. The flaw, rated with a CVSS score of 9.4, affects both GitLab Community Edition (CE) and Enterprise Edition (EE).

GitLab Patches Critical Code Injection Vulnerability
GitLab has released a patch for a critical code injection vulnerability that could allow unauthenticated attackers to modify or delete user data and public projects. The flaw was described as critical, indicating a high potential impact and ease of exploitation.

Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
Apple has released security updates for macOS and iOS that address dozens of vulnerabilities in WebKit, the browser engine powering Safari and other applications. These updates are critical as the reported flaws could lead to a range of severe security issues, including application crashes, memory corruption, sensitive data leakage, sandbox escapes, and data exfiltration. Users are strongly…

Weekly Update 517: Cyber Ransoms
A recent report indicates a complex and evolving landscape within the realm of cyber ransoms, highlighting a significant disconnect between the technical execution of attacks and the subsequent financial operations. The situation is characterized by a high volume of successful extortion attempts, often lacking traditional malware components, and a notable challenge for perpetrators in…

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has issued security updates to address a critical vulnerability in its Community Edition (CE) and Enterprise Edition (EE) software. The flaw, identified as CVE-2026-19478 and rated with a CVSS score of 9.4, reportedly allows an unauthenticated attacker to remotely modify or delete public projects and associated user data under specific conditions.

Apple Patches iOS and macOS, (Mon, Aug 17th)
Apple has released significant security updates for its iOS/iPadOS and macOS operating systems, addressing a substantial number of vulnerabilities. The updates, released on Monday, August 17th, include iOS/iPadOS versions 26 and 18, and macOS version 26. This release follows a smaller macOS-specific update approximately two weeks prior that targeted a single screen-sharing vulnerability.

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive
Microsoft has acknowledged a delay in the release of Cumulative Update 1 (CU1) for Exchange Server Subscription Edition (SE), attributing the setback to an increased volume of security vulnerabilities identified by artificial intelligence tools. The company’s Exchange team addressed customer inquiries in a post titled “Where is Exchange SE CU1 anyway?” published last Thursday, confirming that…

New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware, dubbed AmnesiaStealer, is targeting macOS users through "ClickFix" campaigns, according to research from Jamf. The malware's notable capability is its "stream_module," which allows attackers to remotely control a victim's web browser through a hidden, headless instance, effectively hijacking authenticated sessions.

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
A newly discovered espionage campaign, dubbed PATCHCORD, has been observed targeting Afghan telecommunications providers and critical infrastructure organizations in South Asia. Security researchers at Acronis identified a custom C/C++ backdoor, PATCHCORD, being delivered through highly specific lures, including fake VPN installers designed to impersonate legitimate tools from Afghan Telecom…

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
A critical vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is being actively exploited in the wild just days after a patch was released. The flaw, which carries a maximum CVSS score of 10.0, allows for unauthenticated arbitrary code execution and compromise of internal components.

GeoServer Zero-Day Is Already Being Probed. That’s the Problem
A newly disclosed zero-day vulnerability in GeoServer, an open-source geospatial platform, is already being actively probed by attackers, with no patch currently available. The flaw, publicly revealed on August 12, 2026, by a security researcher identified as q1uf3ng, allows for unauthorized SQL injection through the `jsonArrayContains` functionality. In specific configurations where GeoServer…

Max severity SAP Commerce Cloud flaw now targeted in attacks
A critical remote code execution vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is reportedly being exploited in active attacks just three days after a patch was released. The flaw, which carries a maximum severity rating, affects the core Data Hub Adapter extension of the e-commerce platform, formerly known as SAP Hybris.

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
A new macOS infostealer, dubbed AmnesiaStealer, is being distributed through social engineering attacks that trick users into executing malicious commands, according to research published by Jamf on August 13. The Rust-based malware employs a multi-stage infection process to harvest credentials, browser data, and live user sessions.

AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers
Jamf Threat Labs researchers have uncovered AmnesiaStealer, a new Rust-based macOS infostealer that provides attackers with live, hidden control over a victim's web browser. The multi-stage malware, first observed on August 14, 2026, spreads through convincing fake GitHub download pages that employ the "ClickFix" technique.

Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has issued security patches to address a Windows zero-day vulnerability, identified as "LegacyHive," which was publicly disclosed following the July 2026 Patch Tuesday. The vulnerability, now tracked as CVE-2026-62832, was patched as part of Microsoft's August Patch Tuesday updates.

Critical VMware vCenter RCE flaw exploited for reverse SSH access
A critical remote code execution (RCE) vulnerability in VMware vCenter Syslog Server, identified as CVE-2026-59310, is actively being exploited to establish persistent remote access through a reverse SSH tool. Broadcom, the vendor, confirmed the flaw on July 29 and released emergency patches, describing it as a directory traversal vulnerability that allows unauthenticated attackers with…

Adobe Commerce Bug Targeted Immediately After Disclosure
Exploitation attempts targeting a recently disclosed vulnerability in Adobe Commerce, identified as CVE-2026-71362, were observed almost immediately following the release of patches by Adobe. This rapid move from disclosure to active targeting highlights a recurring challenge in software security, where threat actors quickly weaponize newly public vulnerability information.

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Attackers are actively exploiting a critical vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, following the public release of proof-of-concept (PoC) exploit code. The flaw, which allows for authentication bypass and impersonation, was addressed by Microsoft in its July 2026 Patch Tuesday updates.

WordPress 7.0.4 Patches Remote Code Execution Vulnerability
WordPress has released version 7.0.4, which includes a patch for a remote code execution (RCE) vulnerability. The flaw reportedly allowed attackers with Author-level user permissions or higher to execute arbitrary code on affected systems. The vulnerability was exploitable through the use of malicious Postscript files.

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet has released patches addressing authentication vulnerabilities in its FortiWeb Web Application Firewall (WAF) and FortiManager centralized management solution. The reported flaws could potentially enable unauthorized access, allowing attackers to log in using arbitrary usernames and passwords or to impersonate FortiGate appliances.

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
A new Windows zero-day exploit, dubbed "ShieldBreak," has reportedly been released, allowing any user to elevate their privileges to System-level. The exploit was made public on a recent Patch Tuesday, a day typically associated with the release of security updates from Microsoft. This timing suggests the exploit was either intentionally released to coincide with a presumed patching cycle or…

ICO Reprimands Criminal Records Office After 2023 Breach
The UK's Information Commissioner's Office (ICO) has issued a reprimand to the Criminal Records Office (ACRO) following a 2023 data breach that compromised the personal information of over 10,000 individuals. The ICO's investigation identified significant security failures, including inadequate patch management and insufficient security monitoring, as contributing factors to the incident.

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
Cisco has confirmed that a high-severity vulnerability, identified as CVE-2026-20349, is actively being exploited to cause denial-of-service (DoS) conditions on its firewall products. The company's Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026.

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers
Wireshark version 4.6.8 has been released, addressing a total of 28 security vulnerabilities within the popular network protocol analyzer. Nine of these critical flaws are located in file parsers, meaning they can be triggered simply by opening a specially crafted capture file without any network interaction.

SharePoint Vulnerability Exploited Shortly After PoC Release
A vulnerability affecting Microsoft SharePoint has reportedly been exploited in the wild shortly after the release of a proof-of-concept (PoC) exploit. The flaw was previously patched by Microsoft in July, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) had issued a warning regarding its potential for active exploitation.

“Zoomsday” flaws could let one Zoom participant attack another
Three vulnerabilities, collectively dubbed "Zoomsday" by researchers, have been identified in the Zoom meeting platform. These flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could enable one participant in a Zoom meeting to compromise another through specially crafted collaboration data.

Patch Tuesday: Update now to fix 421 flaws, including three zero-days
Microsoft’s August 2026 Patch Tuesday addresses 421 vulnerabilities across its product line, including 62 rated as critical. The update package, while smaller than July’s record release, remains one of the largest Patch Tuesday batches to date. Among the fixes are three zero-day vulnerabilities, one of which has been actively exploited in the wild by the Lazarus group.

Exposed: Woeful security at UK criminal records office that led to sensitive data leak
The UK's criminal records office, ACRO, has received a regulatory reprimand from the Information Commissioner's Office (ICO) following security failures that potentially exposed sensitive data belonging to nearly 11,000 individuals. The incident, initially disclosed by ACRO in April 2023, involved persistent attacker access to their website and content management system for over seven months,…

Three intrusions at UK criminal records office went undetected for two years
The UK's ACRO Criminal Records Office, a national policing unit responsible for sensitive data on the Police National Computer, was subjected to three separate security intrusions over a period of nearly two years, exposing the personal data of thousands of individuals. The incidents, which occurred between July 2021 and June 2023, went largely undetected due to a series of fundamental…

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
Artificial intelligence has become a foundational element in security operations centers (SOCs) over the past two years, moving beyond pilot programs to become a core strategy. A recent survey of 500 security professionals, conducted by Omdia and commissioned by Rapid7, indicates widespread positive outcomes from this shift.

Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
Microsoft released fixes for 419 security vulnerabilities in its latest Patch Tuesday update, marking one of the largest monthly counts on record. This follows a trend of escalating vulnerability disclosures, with 137 patches in May, 206 in June, and 622 in July, surpassing the company's annual record of approximately 1,250 vulnerabilities. The company has indicated that AI-powered…

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical Microsoft Windows vulnerability, CVE-2026-68820, by August 25. This directive follows confirmation from both CISA and Microsoft that the flaw is actively being exploited in real-world attacks, notably by North Korean state-sponsored hackers.

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
A security researcher known as Nightmare Eclipse has released a new zero-day exploit, dubbed "ShieldBreak," affecting Microsoft Defender. The exploit, disclosed on August 12, 2026, after Microsoft's August Patch Tuesday updates, is described as a bypass for a previously identified privilege escalation flaw in Defender, CVE-2026-50656, known as "RoguePlanet."

Weekly Update 516: Live From Vietnam
This week's report from Vietnam highlighted a technical curiosity concerning Brinks Home's frequently asked questions (FAQ) section. The report noted that the company appeared to have authored its own FAQ, yet seemingly failed to adhere to or properly implement the information contained within it. This observation was made amidst minor technical difficulties during the report's transmission,…

Ivanti EPM Update Patches Remotely Exploitable Flaws
Ivanti has released an update for its Endpoint Manager (EPM) software to address several remotely exploitable vulnerabilities. These flaws, if successfully exploited, could lead to the leakage of credentials used for external SQL connections or cause an agent service to crash. The update is critical for maintaining the integrity and availability of systems managed by EPM.

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Cisco has released patches for a zero-day vulnerability in its Secure Firewall ASA and FTD devices, which has reportedly been exploited in the wild to launch denial-of-service (DoS) attacks. The flaw, identified as CVE-2026-20349, allows for remote exploitation without requiring authentication, posing a significant risk to affected systems.

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security updates for August 2026, addressing a total of 421 vulnerabilities across various products. Of these, 62 are classified as "critical" by Microsoft. The company confirmed that one of the vulnerabilities, CVE-2026-68820, an elevation of privilege flaw in the Windows Ancillary Function Driver for WinSock, has already been exploited in the wild. This…

Microsoft Patch Tuesday, August 2026 Security Update Review
Microsoft's August 2026 Patch Tuesday release addresses 421 vulnerabilities, including 62 critical and 357 important-severity issues across a broad range of products and services. This month's updates include fixes for three zero-day vulnerabilities, one of which has been actively exploited in the wild, while the other two were publicly disclosed prior to the patch release.