Security News — 12 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 13 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 12 August 2026 · 26 items.
Government & Critical Vulnerability Advisories
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (F…
Read at source →Johnson Controls C-CURE 9000 and Victor application server (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A…
Read at source →Pulsetto Vagus Nerve Stimulator
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Ne…
Read at source →Mira Hormone Monitor, Mira Android App
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token i…
Read at source →Primary Threat Research & Vendor Intelligence
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
Read at source →Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 .
Read at source →Independent Investigative Journalism & Breaking News
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]
Read at source →Microsoft's Patch Tuesday Deluge Continues With August Updates
Security experts say prioritization should be the main focus for the August updates, not the massive CVE volume.
Read at source →Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly det…
Read at source →Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
Read at source →Sandworm hackers target IT pros with trojanized WireGuard VPN client
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. [...]
Read at source →Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already…
Read at source →Cisco warns of ASA and FTD VPN flaw exploited to crash devices
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. [...]
Read at source →Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-serv…
Read at source →Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw an…
Read at source →Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to tr…
Read at source →Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. [...]
Read at source →Blue Team, Incident Response & Detection Engineering
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critic…
Read at source →A Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI
<p>This blog post should not exist, but it does due to an unfortunate reality: Many large prime defense contractors are attempting to impose CMMC Level 2 audit requirements on subcontractors that do not handle Controlled…</p>
Read at source →ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)
Read at source →Security Executive, Architecture & Policy
Creativity vs. Consumption
Charcoal sketch of a seated figure whose left arm dissolves into a cascade of purple glowing phones while their right hand builds a warm wooden tower/images/creativity-vs-consumption-header.webp/images/creativity-vs-consumption-header.webp…
Read at source →Where an AI Watermark Can Hide in Plain Text
Diagram of the four layers a text watermark can live in, from encoding down to meaning, with the two bypasses canonical regeneration and prose rewriting crossing out the layers they strip/images/where-watermarks-hide-in-text-layers.webp/im…
Read at source →AI Genie in the Wild
When I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it…
Read at source →"Nobody Asked for A.I." Is a Stupid Argument
Charcoal sketch of a colossal kneeling figure made of hundreds of interlocking hands, reaching down with open palms toward a vast crowd of suffering people/images/nobody-asked-for-ai-header.webp/images/nobody-asked-for-ai-header.webp With…
Read at source →AI for Military Support
Interesting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into th…
Read at source →