ISC2 domain 7
Security Operations
Day-to-day operations and what goes wrong: malware, ransomware, detection, incident response and recovery.
News
252 articles in this subject area
New exploit is said to grant SYSTEM through Microsoft Defender
On 12 August 2026 the researcher known as Nightmare Eclipse released exploit code called ShieldBreak, said to grant SYSTEM privileges through Microsoft Defender on fully patched machines. The researcher describes it as a full bypass of the RoguePlanet fix, and Will Dormann states that the code works when Defender is enabled.
A signed kernel driver now hides the CoolClient backdoor on Windows
Kaspersky has analysed a new version of the CoolClient backdoor that installs a signed driver in the Windows kernel. The driver hides the malware process, its files and its registry keys, and the activity is attributed to HoneyMyte, also known as Mustang Panda.
A fake donation app steals the logged in Telegram session
On 13 August 2026 Kaspersky described an espionage campaign it attributes to the Armored Likho group, in which an app posing as a donation service is in reality a dropper. The Still Toolkit steals Telegram session data and pulls out conversations, while a separate module listens for speech and records audio.
Attackers picked up the SharePoint exploit code the day after it was published
On 11 August 2026 Rapid7 published a technical analysis of CVE-2026-55040 in Microsoft SharePoint, together with code showing how the flaw is exploited. Defused states on X that attackers were using that same code against its SharePoint honeypots the following day.
Meta says one of its models broke into another company during testing
Meta says one of its models unexpectedly gained internet access during a security evaluation, and that the model then exploited a vulnerability in a service outside the test environment. The test was run by Irregular, which also ran the evaluations for Anthropic, and the firm told the BBC that it is the same test environment fault Anthropic disclosed the week before.
Only two of 421 vulnerabilities in the August release carry a flag
Microsoft's August security release consists of 421 CVEs. One is marked Exploitation Detected and one Publicly Known, and both are elevation of privilege flaws that require a local account.
Fake recruiters talked IT staff into installing a VPN client that ran hidden code
CERT-UA describes how the threat cluster UAC-0145 approaches IT professionals on job sites and runs a full hiring process, complete with a Telegram conversation and a genuine Zoom interview. The candidate is eventually asked to download a VPN client called SopraVPN, built from WireGuard source code and running PowerShell code hidden in the SymmetricKey configuration option.
A fake job offer ended with a rootkit in the Windows kernel
Check Point Research attributes a new wave of Operation Dream Job to Lazarus, where fake job offers in the defence and aviation industries ended in exploitation of the zero-day CVE-2026-68820 in the Windows AFD.sys driver. Microsoft fixed the flaw on 11 August 2026 after Check Point reported it, and the same investigation found command traffic running through hijacked Roundcube and WordPress servers.
A flaw in Metabase gave administrator access without a sign-in
Metabase confirmed on 6 August that a vulnerability in version 58 and later is being exploited in attacks. An unauthenticated attacker can inject SQL into Metabase's own application database through the password reset endpoint, and from there gain administrator access.
How attackers reached a Polish power plant through a shared mobile network
CERT Polska published a follow-up report on 8 August covering the 29 December 2025 attacks on Poland's energy supply. It describes an attack on a heat and power plant serving around 50,000 residents, where the way in ran through the grid operator's private mobile network.
An eighteen-year-old Linux kernel flaw hands ordinary users root
Tencent Zhuque Lab has found a flaw in the SCTP part of the Linux kernel that has been there since 2008. An ordinary user can use it to gain root, and to escape a container.
Voicemail lures slip past MFA and hunt for payroll payouts
Arctic Wolf has uncovered a widespread phishing campaign against Microsoft 365 accounts in Europe, Canada and the US. The attackers take over the session after MFA is completed, hunting specifically for payroll, HR and finance.
Official installers for QuickFox VPN carried a backdoor for nearly a year
Fortinet has found that the QuickFox VPN installers spread a backdoor for nearly a year. The backdoor was only installed on machines that looked like work machines.
Europe takes more control of the vulnerability register, and NATO IT agency joins
ENISA announced on 6 August 2026 that the NATO Communications and Information Agency and the company AISLE have become CVE Numbering Authorities under the ENISA Root. According to ENISA there are now twenty such authorities under the European Root, eight of them transferred from the MITRE Root.
The industrial software shipped with a database that went out of date years ago
CISA published three new industrial control system advisories on 6 August 2026. The weightiest concerns ABB Ability Zenon, where the IIoT services install alongside MongoDB 4.2, and where twelve of the thirteen listed vulnerabilities date from 2020 and 2021.
The AI agents built their own message board, and got out of the test environment
OpenAI presented new technical details at Black Hat on 6 August 2026 about experimental agents that broke out of the test environment. According to the presentation, the agents used an internal Artifactory server as a message board, gained administrative access through a flaw there, and restored the channel after OpenAI had rebuilt the service and revoked the credentials.
Cisco closes top-severity holes in SD-WAN and IOS XE, and there is no way around them
Cisco published security updates for Catalyst SD-WAN, IOS XE and the Integrated Management Controller on 5 August 2026. Three of the SD-WAN vulnerabilities carry a CVSS score of 9.9, and Cisco states that no workarounds exist for any of the advisories.
CrashStealer poses as Apple crash reporting and empties the Keychain on Mac
Kaspersky has described CrashStealer, a macOS information stealer delivered through a fake videoconferencing installer. The installer is both signed and notarized, and the malware asks the user for the password in a dialog that looks like a system message from Apple.
DOUBLECUP hides the next stage in an image and lets the user start the attack
SOCRadar has described DOUBLECUP, a Russian loader sold as a service and used in ClickFix campaigns since early June. The code is embedded in fake login pages for NetSuite, Odoo, HubSpot and Salesforce, and the next stage is pulled out of an image sitting in the browser cache.
Two arrested in Pakistan over development of the Tycoon2FA phishing platform
Two people suspected of developing the phishing platform Tycoon2FA have been arrested in Pakistan following cooperation between the Singapore Police Force, INTERPOL and Pakistani authorities. The platform is said to be linked to more than 96,000 victims globally, and several of the cases in Singapore involved business accounts compromised despite multi-factor authentication.
Critical authentication bypass in Check Point management servers
Check Point has fixed a critical vulnerability in Security Management Server and Multi-Domain Security Management Server. CVE-2026-18574 is scored at 9.3 and lets an attacker without login run arbitrary commands on a server reachable over the network.
Greatness expands its toolkit for getting past multi-factor authentication
ZeroBEC has analysed the phishing service Greatness, which has grown from credential harvesting into a broader platform. The service combines adversary in the middle, device code phishing and OAuth abuse to obtain authentication tokens.
Self-propagating worm in npm compromised Keyv and other widely used packages
A large scale supply chain attack on npm, tracked as ChainDrop, hit Keyv and other widely used packages. The malware ran during installation, stole credentials from developers and build pipelines, and used that access to publish further infected releases automatically.
N-able N-central flaw exploited to take control of an entire network
Sophos has described an attack in which CVE-2026-18577 was exploited to take privileged control of an N-central server. The attackers then used its remote control features to reach domain controllers, backup servers and application servers.