ICYMI: 2026-08-11
Latest Headlines
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Corma Raises $60 Million for Defensive Cybersecurity AI Model
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-Days
DEF CON Attendees Allegedly Jammed Plane Wi-Fi and Broadcast Fake ‘Delta WiFi Fast’ Network
Zoom Zero-Click Vulnerabilities Allow Meeting Participants to Hijack Other Users’ Devices
CopyEscape Docker Vulnerability Lets Malicious Containers Overwrite Host Files and Gain Root
Intel’s $20 Billion Stock Sale Fuels a Bigger Fight Over Chip Supply Chain Security
Zenity Raises $125 Million Series C to Strengthen AI Agent Security and Governance
OpenAI, Anthropic, and Google LLM APIs vulnerability Exposes Hidden Reasoning Traces
Ivanti Endpoint Manager Vulnerabilities Let Remote Attackers Crash Agent Service
Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory
Hackers Can Turn Off Refrigeration While the Temperature Display Still Looks Normal
DeadLock ransomware uses blockchain to resist infrastructure takedown
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Windows 11 KB5121003 & KB5120240 cumulative updates released
Wesco confirms security incident after ExfilSquad claims data theft
Mozilla updates GPG signing key for Firefox releases after exposure
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
DDoS attacks over 1 Tbps surged fivefold in the second quarter
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Cisco warns of high-severity ClamAV flaws with public exploits
US and South Korea warn of Gunra ransomware targeting govt agencies
– MTZ