Security Round-Up

Monday

2026-08-24
Your source for daily security alerts from some of the best experts in the world.
Find the problems, secure your systems now!
Get these alerts in your inbox every morning. Subscribe

CONTENTS

MSRC Unclassified ( 15 )
Hacker News ( 9 )
Bleeping Computer ( 14 )
Cisco Advisories
DataBreaches.net ( 5 )
CVEMon Intruder ( 10 )
Hacking Lab ( 2 )
Schneier on Security ( 4 )
Securelist
Synacktiv
Talos – Vulnerability Reports
Troy Hunt ( 2 )


MSRC Unclassified

08/23 TOC Mariner – rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Hands...
08/23 TOC Mariner – rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution...
08/23 TOC Mariner – rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Threa...
08/23 TOC Mariner – rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backu...
08/23 TOC Mariner – rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Ent...
08/23 TOC Mariner – rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEO...
08/23 TOC Mariner – rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()...
08/23 TOC Mariner – rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()...
08/23 TOC Mariner – etcd: `tlsListener.acceptLoop` spawns unbounded handshake go…
08/23 TOC Mariner – Kbd: local privilege escalation in openvt via incorrect proc…
08/23 TOC Mariner – Vim: Out-of-bounds Access in Popup Opacity Handling CVE-2026…
08/23 TOC Mariner – Vim: Use-after-free in JSON Decoding CVE-2026-73071
08/23 TOC Mariner – Perl versions from 5.9.4 before 5.41.9 produce incorrect reg…
08/23 TOC Mariner – rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Han...
08/23 TOC Mariner – rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from ...

Hacker News

08/24 TOC UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR By…
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open
08/22 TOC TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit…
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million “upon entry of an order vacating a prior consent decree entered against
08/21 TOC 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assis…
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. “When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process,” TrendAI, Trend Micro’s
08/21 TOC Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security S…
Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a
08/21 TOC Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Pr…
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. “The malware spread through the built-in updaters of
08/21 TOC Wazuh and AI For Enhanced SOC Workflows
Artificial Intelligence (AI) has become one of this decade’s defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate
08/21 TOC Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring C…
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below –
08/21 TOC GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of D…
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring
08/21 TOC Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Cod…
Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the “Exploited” field under the Exploitability Assessment table as “Yes,” on August 21, 2026, Microsoft corrected the “Exploited” status to “No” after The Hacker News contacted the company for comment. It also noted, “this vulnerability was not

Bleeping Computer

08/24 TOC CISA orders urgent patching of actively exploited Zimbra flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. […]
08/24 TOC Microsoft shares temporary fix for Windows 11 gaming issues
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. […]
08/23 TOC ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. […]
08/22 TOC Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. […]
08/22 TOC Named Pipes Under Attack: Securing Windows Interprocess Communication
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. […]
08/21 TOC New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. […]
08/21 TOC Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. […]
08/21 TOC Microsoft blames Windows gaming issues on RGB lighting devices
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. […]
08/21 TOC Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. […]
08/21 TOC Microsoft rolls out Classic Outlook theme for New Outlook users
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. […]
08/21 TOC CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. […]
08/21 TOC Microsoft patches max severity code execution, privilege escalation fl…
Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that allowed attackers to gain remote code execution and escalate privileges. […]
08/21 TOC Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. […]
08/21 TOC SickKids data breach exposes employee and job applicant info
Toronto’s Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) […]

Cisco Advisories

08/21 TOC Cisco Crosswork Security Hardening Release: August 2026

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. 

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. 

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh


Security Impact Rating: Critical
CVE: CVE-2026-20030,CVE-2026-20357,CVE-2026-20358,CVE-2026-20359

DataBreaches.net

08/23 TOC ShinyHunters claims hack of ReliaQuest; no confirmation by ReliaQuest …
Cybersecurity firm ReliaQuest has reported its research findings about ShinyHunters multiple times recently. On August 17,  @ReliaQuestTR tweeted that they were tracking yet another ShinyHunters campaign. But after another forum user replied on August 23 with some screenshots and a pithy “Who’s hunting who?” ReliaQuestTR deleted their tweet and hasn’t posted anything on that account…

Source

08/22 TOC Connecticut says data from 41,000 Medicaid members exposed in portal b…
WSFB reports: State officials say a data breach involving the Connecticut Medicaid program’s provider portal exposed payment and claims information tied to roughly 41,000 HUSKY Health members. The Connecticut Department of Social Services said Gainwell Technologies, which serves as the state’s fiscal agent for the Medicaid program, first detected the breach on June 25, 2026,…

Source

08/21 TOC Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens o…
In April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG says a recent attack was actually its second on one law firm, and they will…

Source

08/21 TOC Scammers Pose as NYPD Officers in Well-Done Video-Call Impersonation S…
The phone rang, and when “Eddie” (not his real name) picked up, the caller identified herself as being from American Express. Even though Eddie didn’t have any American Express account, he wasn’t initially suspicious. According to the caller, Eddie’s name had shown up in an attempt to purchase a firearm, and AmEx suspected identity theft….

Source

08/21 TOC AI, Data Breaches, and an Old Lesson from the Law of Bailment
So I didn’t know what the doctrine of bailment is.  If you don’t either, you may want to read this post by Jake L. Ramsey of Offit Kurman. It starts by noting the presentation at BlackHat by two OpenAI engineers about the Hugging Face incident and notes two of their statements: First, one OpenAI engineer…

Source


CVEMon Intruder

08/24 TOC CVE-2026-69836
Currently trending CVE – Hype Score: 35 – Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
08/24 TOC CVE-2026-18963
Currently trending CVE – Hype Score: 31 – A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without …
08/24 TOC CVE-2026-19478
Currently trending CVE – Hype Score: 10 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user …
08/24 TOC CVE-2026-19650
Currently trending CVE – Hype Score: 9 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to …
08/24 TOC CVE-2026-39113
Currently trending CVE – Hype Score: 8
08/24 TOC CVE-2026-73570
Currently trending CVE – Hype Score: 5 – A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an …
08/24 TOC CVE-2026-5388
Currently trending CVE – Hype Score: 3 – justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an …
08/24 TOC CVE-2026-77003
Currently trending CVE – Hype Score: 3 – The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.
08/24 TOC CVE-2026-74705
Currently trending CVE – Hype Score: 3 – In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP …
08/24 TOC CVE-2026-75922
Currently trending CVE – Hype Score: 3 – Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has become a raw byte by the …

Hacking Lab

09/30 TOC Prism: A Multi-Team Orchestration of LLM Agents for Automatic Program …
08/31 TOC QueryHouse: Cross-DBMS Differential Testing with LLM and Query Transpi…

Schneier on Security

08/24 TOC Criminal Deception in Silicon Valley

Interesting paper:

Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: Entrepreneurs construct, perform, and protect illusory appearances (façades) that externally project high-growth performance to audiences while masking ventures’ actual underperformance. We identify three forms of façading—­surface, reinforced, and deep façading­—that are contingent on the severity of the gap that entrepreneurs face between audiences’ performance expectations and ventures’ performance reality. Our theoretical framework captures how entrepreneurs facing minor, wide, and extreme expectation-reality gaps engage in evermore sophisticated efforts to detach the venture’s externally projected appearance from its actual operational reality. Practically, we propose several approaches to deter and detect criminal deception, including the extension of U.S. Securities and Exchange Commission surveillance and whistleblower program, investor due diligence reform, and dedicated entrepreneurship education interventions that clearly demarcate when entrepreneurs transgress into criminal deception. We make contributions to literatures on cultural entrepreneurship, organizational wrongdoing, and the social effects of entrepreneurship. …

08/21 TOC Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation.

The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion.

They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it…

08/21 TOC AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying:

The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside.

Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the models generated about 700,000 potential designs, of which the researchers picked 285 that looked most promising.

The researchers then synthesised new DNA molecules using those designs and inserted them into E. coli bacteria, before waiting to see if viable bacteriophages would emerge…

08/21 TOC More Incidents of AIs Going Rogue in Cybersecurity Challenges

The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities.

The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol with cyber classifiers (mechanisms to prevent misuse) disabled. In the most serious case, an agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering—creating fake online identities and using them to pressure the project’s maintainer to approve the code. A human maintainer caught and refused to approve the malicious code…


Securelist

08/21 TOC The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun head units.

Synacktiv

08/23 TOC AWS EKS forensics: data sources and investigation tooling

AWS EKS forensics: data sources and investigation tooling

24/08/2026
CSIRT
Investigating a compromise in Amazon EKS means piecing together evidence spread across three layers: the managed Kubernetes control plane, the worker nodes, and the surrounding AWS services. This article maps the data sources an EKS cluster exposes for digital forensics and threat hunting, and the tooling used to correlate them, from the Kubernetes audit log down to the AWS identity of the nodes.

Talos – Vulnerability Reports

08/23 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteReq…

Troy Hunt

08/23 TOC Weekly Update 518: IoT Doorlock Nirvana with UniFi

I genuinely think I’ve nailed the IoT door lock situation! Well, Ubiquiti has, but I think I’ve worked out how to put it all into a residential house and have it make sense. There are a few basic tenets:

  1. Main power (never have to rely on
08/23 TOC Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.




Content on this page is collected from remote sources by IPWorX but is not created by IPWorX. The contents belong to the creators and should be considered theirs for all legal purposes, we have no editorial control or responsibility over them. IPWorX does not represent or endorse the accuracy or reliability of any opinion, statement, or other information provided by any third party.

This page contains links to third-party websites. These links are provided solely for your convenience. IPWorX does not control, maintain, or endorse the content, accuracy, or reliability of any third-party resources, and you access them at your own risk.

Scripts and tools to help manage your network found, managed and
happily shared with documentation on usage at the IP WORk eXchange.
https://www.IPWorX.com