CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 82 matching records.
AUTO-POLL // 2026-08-16 03:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-14 21:27 UTC
Vendor Research
TIER 2

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Rapid7 · Rapid7 Labs · indexed 2026-08-16 02:02 UTC

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-fr…

LinuxMicrosoftVulnerabilities CVE-2025-49132CVE-2026-15409CVE-2026-27760CVE-2026-29053CVE-2026-3891CVE-2026-46300CVE-2026-48907CVE-2026-60137CVE-2026-63030
P20
2026-08-14 10:24 UTC
Security Journalism
TIER 3

1.6 Million Likely Impacted by RingCentral Data Breach

SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek.

Data BreachesMicrosoft
P0
2026-08-13 20:11 UTC
Vendor Research
TIER 1

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because th…

LinuxMicrosoftVulnerabilities CVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345CVE-2026-20346CVE-2026-20347CVE-2026-20348
P5
2026-08-13 06:09 UTC
Security Journalism
TIER 3

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

MicrosoftThreat ActorsVulnerabilities CVE-2026-55040
P15
2026-08-12 19:50 UTC
Vendor Research
TIER 1

Control iD iDSecure Multiple Denial of Service Vulnerabilities

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Control iD iDSecure Multiple Denial of Service Vulnerabilities Control iD iDSecure is an on-premises access control and time attendance management application for Windows. Version 4.8.1.0 is affected by multiple vulnerabilities:Unauthenticated Service Restart Denial of Service (High): The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous …

Microsoft
P0
2026-08-12 17:39 UTC
Security Journalism
TIER 3

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

APT / Nation-StateMalwareMicrosoftThreat ActorsVulnerabilities
P25
2026-08-12 06:41 UTC
Security Journalism
TIER 3

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described

MicrosoftSecurity ResearchVulnerabilities CVE-2026-50656
P30
2026-08-11 21:28 UTC
Independent Research
TIER 2

Microsoft Plugs Nearly 400 Security Holes

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Microsoft
P25
2026-08-11 21:10 UTC
Vendor Research
TIER 2

Patch Tuesday - August 2026

Rapid7 · Adam Barnett · indexed 2026-08-16 02:02 UTC

Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday, including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are no…

Cloud SecurityCredential ExposureLinuxMicrosoftSecurity ResearchVulnerabilities CVE-2026-50656CVE-2026-55040CVE-2026-62832CVE-2026-63520CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-72971
P95
2026-08-11 20:10 UTC
Security Journalism
TIER 3

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

Cloud SecurityLinuxMicrosoftVulnerabilities CVE-2026-68820
P30
2026-08-11 17:54 UTC
Community
TIER 2

Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC

This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs. 

MicrosoftVulnerabilities
P70
2026-08-11 16:47 UTC
Security Journalism
TIER 3

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

AI SecurityMicrosoftSecurity ResearchVulnerabilities CVE-2026-55040
P20
2026-08-11 16:35 UTC
Security Journalism
TIER 3

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat

Data BreachesMicrosoftRansomware
P15
2026-08-11 14:04 UTC
Vendor Research
TIER 2

Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Services (AD CS)Application Information ServicesAzure Active DirectoryAzure CycleCloudAzure Monitor Agent…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2022-21919CVE-2022-26904CVE-2024-38193CVE-2025-21418CVE-2025-32709CVE-2026-61348CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62718CVE-2026-62720CVE-2026-62742CVE-2026-62745CVE-2026-62761CVE-2026-62776CVE-2026-62803CVE-2026-62807CVE-2026-62812CVE-2026-62814CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-70307
P65
2026-08-11 13:00 UTC
Vendor Research
TIER 2

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-08-16 02:02 UTC

OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our full disclosure timeline for the exploit chain can be seen below in Figure 1.Figure 1: The road to disc…

AI SecurityMicrosoftSecurity ResearchVulnerabilities CVE-2026-55040CVE-2026-63520
P55
2026-08-11 13:00 UTC
Vendor Research
TIER 2

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

Rapid7 · Stephen Fewer · indexed 2026-08-16 02:02 UTC

OverviewOn July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script.Figure 1: The Rapid7 Labs PoC for CVE-2026-55040.⠀A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline.AnalysisThe f…

MicrosoftVulnerabilities CVE-2026-55040
P15
2026-08-11 10:48 UTC
Security Journalism
TIER 3

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that

Microsoft
P0
2026-08-10 22:00 UTC
Vendor Research
TIER 2

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Palo Alto Networks Unit 42 · Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang · indexed 2026-08-16 02:02 UTC

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

MalwareMicrosoft
P0
2026-08-10 16:38 UTC
Security Journalism
TIER 3

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

MicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-10 16:00 UTC
Vendor Research
TIER 2

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Microsoft Security Blog · Srikanth Shoroff · indexed 2026-08-16 02:02 UTC

Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft Security Blog.

MicrosoftThreat Intelligence
P0
2026-08-10 15:00 UTC
Vendor Research
TIER 2

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-16 02:02 UTC

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.

Data BreachesMicrosoftRansomwareThreat Intelligence
P15
2026-08-10 12:25 UTC
Security Journalism
TIER 3

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a

MalwareMicrosoftPhishing
P0
2026-08-10 07:38 UTC
Security Journalism
TIER 3

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository

MalwareMicrosoftSecurity Research
P0
2026-08-08 06:57 UTC
Security Journalism
TIER 3

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our

DFIRMicrosoftThreat Actors
P0
2026-08-07 19:37 UTC
Vendor Research
TIER 2

A decade of enterprise identity in the cloud with AWS Managed Microsoft AD

AWS Security Blog · Vladimir Provorov · indexed 2026-08-16 02:02 UTC

Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applications and your business.” A decade later, AWS Managed Microsoft AD […]

Cloud SecurityMicrosoft
P0
123