About this episode
Emergency Windows fixes and actively exploited control planes lead into risks across development tooling, identity, critical infrastructure, mobile devices, and trusted cloud services. The episode connects those incidents through access validation, evidence preservation, and defensive context.
This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.
Play the episode, then review the stories and chapter list for the reporting and topics covered.
Stories covered this week
Microsoft Issues Emergency Windows Updates for RDS Failures
Microsoft has released out-of-band updates to fix Remote Desktop Services failures caused by recent security updates, along with Hyper-V and USB audio issues on certain Windows versions. These emergency patches aim to restore affected functionality without compromising security.
Source: BleepingComputer
Dutch NCSC Warns of Imminent Exploitation of Critical Check Point VPN Flaws
The Dutch Nationaal Cyber Security Centrum has issued a warning about the imminent exploitation of two critical vulnerabilities in Check Point VPN, identified as CVE-2026-85102 and CVE-2026-85103. Immediate mitigation is advised to prevent potential breaches.
Source: BleepingComputer
CISA Adds Cisco Secure Email Gateway SQLi to Known Exploited Vulnerabilities
CISA has added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation emerged. Federal agencies are required to urgently patch this high-risk flaw under Binding Operational Directive 26-04.
Source: CISA
CISA Alerts on Ransomware Exploiting Critical VMware vCenter Flaw
CISA warns that ransomware gangs have begun exploiting a critical remote code execution vulnerability in VMware vCenter that was patched in July. This ongoing exploitation underscores the urgent need for timely patching in enterprise environments.
Source: BleepingComputer
Critical ScreenConnect Flaw Now Actively Exploited in Real Attacks
CISA warns of active exploitation of a critical-severity vulnerability in ConnectWise ScreenConnect. This flaw poses a significant risk for unauthorized remote access and compromise.
Source: BleepingComputer
Critical Vulnerabilities Discovered in mySCADA myPRO Manager
Two critical vulnerabilities in mySCADA myPRO Manager allow unauthenticated attackers to access privileged management functions and send arbitrary SMS messages via connected GSM modems. Affected versions are up to 2.1, with fixes available in version 2.2.
Source: CISA
Critical Issabel Framework Flaw Enables Unauthenticated OS Command Execution
A critical vulnerability in the Issabel Framework (CVE-2026-89026) allows unauthenticated remote attackers to execute arbitrary OS commands. The flaw is actively exploited and carries a CVSS score of up to 9.8.
Source: The Hacker News
Critical RCE Flaw in Unbound DNSSEC Validator Fixed in 1.26.1
A critical heap overflow vulnerability in Unbound's DNSSEC validator before version 1.26.1 allows remote code execution via malicious DNS zones. The issue, tracked as CVE-2026-81642, was fixed in the latest release.
Source: The Hacker News
Critical Authentication Flaw in Mitsubishi Electric GX Works3 and Motion Control
A high-severity authentication vulnerability in Mitsubishi Electric GX Works3 and its packaged Motion Control Settings allows local attackers to bypass password checks and manipulate control programs. Updates are available to mitigate this risk and prevent unauthorized access.
Source: CISA
Critical Check Point Flaw Allows Root Privilege Code Execution
Check Point Software has patched a critical vulnerability that lets attackers execute code with root privileges on management systems. Exploiting this flaw could lead to full system compromise in enterprise environments.
Source: BleepingComputer
CISA Adds Two Actively Exploited Linux Kernel Vulnerabilities to KEV Catalog
CISA has added two Linux Kernel vulnerabilities, CVE-2025-39964 and CVE-2026-53266, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation. Federal agencies are urged to prioritize patching these high-risk flaws per Binding Operational Directive 26-04.
Source: CISA
CISA Guidance on Using Cyber Decoys to Enhance Detection and Response
CISA has released guidance to help cybersecurity teams implement cyber decoy strategies that improve detection of adversaries using legitimate credentials and living off the land techniques. These decoys support Zero Trust environments by creating high-fidelity alerts and reducing alert fatigue.
Source: CISA
Russian Hackers Use AI to Rebuild Malware Faster After Detection
Anthropic has disrupted a Russian state-sponsored threat actor's campaign that used the AI model Claude to develop AI-assisted workflows to evade malware detection. The group, called GTG-20006, is linked to the Midnight cluster and represents an evolution in cyber espionage tactics.
Source: The Hacker News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts
Microsoft revealed two campaigns where attackers exploited third-party email systems for financial scam phishing and used passkey-themed social engineering to breach cloud accounts. Over a million scam emails were sent mimicking CEOs in early August 2026.
Source: The Hacker News
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Globally
The threat actor Red Heron has exploited a recent remote code execution vulnerability in Gitea, compromising 13 organizations across six countries in a rapid, multi-national campaign. Acronis TRU reports Red Heron scanned over 1,300 Gitea instances and targeted 477 systems in Taiwan alone.
Source: The Hacker News
Hackers Target Exposed Vite Servers to Steal AWS and Azure Secrets
A mass-scanning campaign is targeting internet-exposed Vite development servers to steal cloud credentials from AWS and Azure environments. The attackers aim to exploit misconfigured servers to access sensitive cloud configurations.
Source: BleepingComputer
Iranian Hackers Deploy Telegram-Controlled Malware Against Dissidents
US, UK, and Dutch agencies report Iran's intelligence uses Windows malware controlled via Telegram to spy on dissidents and journalists globally. The malware steals emails, chats, screenshots, and records audio from targets.
Source: The Hacker News
Transparent Tribe Deploys New Rust Backdoor Targeting South Asia
The Pakistan-aligned threat group Transparent Tribe (APT36) has launched new cyber attacks using novel Rust-based backdoors and private GitHub repos for command and control. The campaign targets government and defense sectors in India and Afghanistan with previously undocumented tools.
Source: The Hacker News
Hackers Exploit Tencent App Flaw to Deploy GrayRabbit Malware
A China-linked espionage group is exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deliver the GrayRabbit backdoor malware. This active exploitation poses a significant risk to affected users and enterprises.
Source: BleepingComputer
RatHat Android Malware Exploits ADB to Maintain Shell Access
Researchers have identified RatHat, Android malware operated by China-based threat actors that uses AI to control devices and abuses ADB to retain shell access after uninstallation. It spreads via targeted smishing and malvertising leading to deceptive download portals.
Source: The Hacker News
New RatHat Android Malware Uses AI for Automated Device Control
RatHat is a newly discovered Android malware featuring an AI-powered subsystem that allows operators to remotely navigate and control compromised devices. This innovation automates device exploitation steps, increasing attack efficiency.
Source: BleepingComputer
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials
A new Brazilian banking malware called KREMLIN uses malicious browser extensions on Chrome and Edge to steal credentials and session tokens. The operation impersonates over a dozen Brazilian banks and has been active since May 2025.
Source: The Hacker News
Gyazo Server Vulnerability Leads to Theft of 23.6 Million User Records
Gyazo, an image-sharing platform, confirmed a major data breach after hackers exploited a server flaw to steal 23.6 million user records. The breach highlights risks tied to server vulnerabilities in widely used platforms.
Source: BleepingComputer
Brevo Supply-Chain Attack Injected Malicious Scripts on Customer Sites
Attackers stole a Cloudflare API key from Brevo and injected malicious ClickFix scripts into Brevo websites and JavaScript embedded on their customers' sites. This led to the distribution of malware via a supply-chain compromise.
Source: BleepingComputer
CenterPoint Energy Confirms Customer Data Stolen in Cyberattack
CenterPoint Energy has confirmed a data breach after attackers leaked customers' personal information, highlighting ongoing risks to critical utility sectors. The incident underscores the importance of robust cybersecurity defenses in protecting sensitive data.
Source: BleepingComputer
Florida DMV Database Breached via Stolen Police Credentials
The Florida Department of Highway Safety and Motor Vehicles confirmed a data breach of its DAVID driver database after attackers accessed it using stolen police department credentials. This incident highlights risks of credential theft and lateral movement in state-run systems.
Source: BleepingComputer
3BB Attacker Leveraged MeshCentral Backdoor for Root Access
An attacker infiltrated 3BB, a major Thai broadband provider, using a MeshCentral backdoor to control internal systems and target subscriber credentials. The breach was uncovered through investigation of a publicly exposed server containing the attacker's tools.
Source: The Hacker News
Attacker Hijacks AI Coding Assistant, Spreads Malware Across 100 Repos
An attacker hijacked an active AI coding-assistant session to push poisoned software recommendations, spreading the Shai-Hulud worm across about 100 internal code repositories. The worm stole repository secrets and source code at an unnamed SaaS provider.
Source: The Hacker News
Chapters
- Opening
- Microsoft Issues Emergency Windows Updates for RDS Failures
- CISA Adds Cisco Secure Email Gateway SQLi to Known Exploited Vulnerabilities
- Dutch NCSC Warns of Imminent Exploitation of Critical Check Point VPN Flaws
- Critical Check Point Flaw Allows Root Privilege Code Execution
- CISA Alerts on Ransomware Exploiting Critical VMware vCenter Flaw
- Critical ScreenConnect Flaw Now Actively Exploited in Real Attacks
- Critical Issabel Framework Flaw Enables Unauthenticated OS Command Execution
- CISA Adds Two Actively Exploited Linux Kernel Vulnerabilities to KEV Catalog
- Critical RCE Flaw in Unbound DNSSEC Validator Fixed in 1.26.1
- Critical Vulnerabilities Discovered in mySCADA myPRO Manager
- Critical Authentication Flaw in Mitsubishi Electric GX Works3 and Motion Control
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Globally
- Hackers Target Exposed Vite Servers to Steal AWS and Azure Secrets
- Attacker Hijacks AI Coding Assistant, Spreads Malware Across 100 Repos
- Brevo Supply-Chain Attack Injected Malicious Scripts on Customer Sites
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts
- Florida DMV Database Breached via Stolen Police Credentials
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials
- CenterPoint Energy Confirms Customer Data Stolen in Cyberattack
- Gyazo Server Vulnerability Leads to Theft of 23.6 Million User Records
- Russian Hackers Use AI to Rebuild Malware Faster After Detection
- Hackers Exploit Tencent App Flaw to Deploy GrayRabbit Malware
- Iranian Hackers Deploy Telegram-Controlled Malware Against Dissidents
- Transparent Tribe Deploys New Rust Backdoor Targeting South Asia
- New RatHat Android Malware Uses AI for Automated Device Control
- RatHat Android Malware Exploits ADB to Maintain Shell Access
- 3BB Attacker Leveraged MeshCentral Backdoor for Root Access
- CISA Guidance on Using Cyber Decoys to Enhance Detection and Response
- Closing