Overview
Description
Statistics
- 24 Posts
- 18 Interactions
Fediverse
「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA
「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。
この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」
https://www.ipa.go.jp/security/security-alert/2026/0812-ms.html
「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews
「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。
このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。
この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」
https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: https://thecybermind.co/jily
📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign
Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...
Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.
#PatchTuesday #Microsoft #ZeroDay #CVE #WindowsSecurity #InfoSec
Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.
#Lazarus #ZeroDay #CVE202668820 #OperationDreamJob #Cybersecurity #DPRK #FudModule #DefenseSector
CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. https://radar.offseq.com/threat/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks-bbf9980a8328f4c4 #OffSeq #ZeroDay #Windows #Cybersecurity
⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…
🤖 AI generated summary
Bluesky
Overview
Description
Statistics
- 10 Posts
Fediverse
「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER
「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。
CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。
シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」
🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: https://thecybermind.co/jily
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. https://www.securityweek.com/cisco-patches-firewall-zero-day-exploited-for-dos-attacks/
📰 Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Cisco patches an actively exploited zero-day (CVE-2026-20349) in ASA and FTD firewalls. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS). Patch immediately to prevent network disruption. #Cisco #ZeroDay #CyberSecu...
Bluesky
Overview
- Microsoft
- Microsoft SharePoint Enterprise Server 2016
Description
Statistics
- 11 Posts
- 5 Interactions
Fediverse
Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.
#CVE202655040 #SharePoint #AuthenticationBypass #JWT #Rapid7 #PoC #Cybersecurity
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews
「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。
CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。
この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」
https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/
New SharePoint auth bypass already being exploited hours after PoC went public
Rapid7 published a proof-of-concept exploit today for CVE-2026-55040, an authentication bypass in SharePoint's JWT token validation that lets an attacker impersonate any user or admin without credentials....
En las últimas 24 horas, se detectaron vulnerabilidades críticas en Microsoft SharePoint que permiten ejecución remota de código sin autenticación, potenciada por IA, y fallas en autenticación con manipulación de tokens. Cisco alerta sobre exploits activos que afectan sus VPN ASA y FTD, mientras México enfrenta pérdidas millonarias por rezago en ciberseguridad. Además, DEF CON ofrece acceso libre a su valioso contenido formativo. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:
🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 12/08/26 📆 |====
🔓 VULNERABILIDAD CRÍTICA EN MICROSOFT SHAREPOINT: EJECUCIÓN REMOTA DE CÓDIGO
Rapid7 y Microsoft han revelado una grave vulnerabilidad en SharePoint, identificada como CVE-2026-63520, que permite la ejecución remota de código sin autenticación cuando se combina con otra falla. Esta amenaza pone en riesgo servidores corporativos, facilitando ataques sofisticados que pueden comprometer datos sensibles y el control del sistema. Mantener SharePoint actualizado es vital para proteger su entorno. Descubre los detalles completos sobre esta vulnerabilidad y cómo proteger tu infraestructura aquí 👉 https://djar.co/3cd5Vh
🛡️ ANÁLISIS DETALLADO DE FALLAS EN LA AUTENTICACIÓN DE MICROSOFT SHAREPOINT (CVE-2026-55040)
Un análisis técnico profundo revela cómo CVE-2026-55040 permite eludir el sistema de autenticación mediante la manipulación del token JWT en SharePoint. Esta brecha puede ser explotada por atacantes para suplantar identidades y obtener acceso indebido, facilitando ataques posteriores. Comprender la naturaleza de esta vulnerabilidad es esencial para implementar medidas de defensa eficaces. Consulta el informe técnico completo y fortalece tu seguridad aquí 👉 https://djar.co/SrXg
🤖 CADENA DE EXPLOTACIÓN CON ASISTENCIA DE IA EN SHAREPOINT: RIESGO DE EJECUCIÓN REMOTA SIN AUTENTICAR
Investigadores han demostrado cómo la vulnerabilidad CVE-2026-55040, combinada con CVE-2026-63520, permite a los atacantes no autenticados ejecutar código remotamente en SharePoint. El uso de inteligencia artificial en esta cadena de explotación agiliza y potencia la sofisticación del ataque, elevando los riesgos para organizaciones que no actualizan a tiempo sus sistemas. Infórmate sobre esta amenaza avanzada y cómo mitigarla inmediatamente 👉 https://djar.co/h7SaRv
🔥 ALERTA DE CISCO: VULNERABILIDAD EN VPN ASA Y FTD CON EXPLOIT ACTIVAMENTE USADO
Cisco ha emitido una advertencia crítica sobre una vulnerabilidad de alta gravedad en sus productos Secure Firewall ASA y Threat Defense (FTD). Ha sido detectado un exploit activo que provoca ataques de denegación de servicio remoto, llevando a la caída de dispositivos, comprometiendo la continuidad operativa de las redes corporativas. Es imprescindible aplicar los parches y seguir las recomendaciones oficiales para evitar interrupciones. Conoce la advertencia oficial y pasos para proteger tus dispositivos aquí 👉 https://djar.co/qy7j
💸 IMPACTO DEL REZAGO EN CIBERSEGURIDAD EN MÉXICO: PÉRDIDAS MILLONARIAS
El rezago en ciberseguridad que enfrenta México está generando un impacto económico de miles de millones de pesos, afectando tanto al sector privado como al público. La falta de inversiones adecuadas y estrategias de protección digital robustas pone en riesgo la estabilidad tecnológica y financiera del país. Conocer esta realidad invita a reflexionar sobre la urgencia de implementar políticas y prácticas eficaces en seguridad informática. Lee el análisis completo sobre esta problemática y su impacto económico aquí 👉 https://djar.co/QWHu9
📼 ACCESO LIBRE A TODO EL CONTENIDO DE DEF CON: PRESENTACIONES, DOCUMENTALES Y MÁS
Para quienes buscan formación continua en seguridad informática, media.defcon.org ofrece un archivo completo con videos, presentaciones, documentales y más del reconocido congreso DEF CON. Este extenso repositorio es una fuente invaluable de conocimiento actual, técnicas, y tendencias en hacking ético y defensa digital. No pierdas la oportunidad de aprender de los mejores expertos del mundo. Explora todo el material disponible para potenciar tu expertise aquí 👉 https://djar.co/XzsPs
Bluesky
Overview
- Microsoft
- Microsoft Malware Protection Engine
Description
Statistics
- 7 Posts
- 3 Interactions
Fediverse
On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update
https://github.com/MSNightmare/ShieldBreak
#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse
A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.
#ShieldBreak #CVE202650656 #WindowsDefender #PrivilegeEscalation #PoC #RoguePlanet #Cybersecurity
https://securityonline.info/shieldbreak-defender-poc/?utm_source=mastodon&utm_medium=jetpack_social
„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“
https://borncity.com/blog/2026/08/12/shieldbreak-poc-fuer-microsoft-defender-0-day-schwachstelle/
August 2026 Patchday: Updates gerade freigegeben, da veröffentlicht Nightmare Eclipse #Shieldbreak als Proof of Concept (PoC). Der PoC umgeht die ungenügend gepatchte #Defender Schwachstelle CVE-2026-50656 (#RoguePlanet).
https://borncity.com/blog/2026/08/12/shieldbreak-poc-fuer-microsoft-defender-0-day-schwachstelle/
Overview
Description
Statistics
- 2 Posts
Fediverse
🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: https://thecybermind.co/jily
Overview
- Ivanti
- Endpoint Manager
Description
Statistics
- 3 Posts
Fediverse
Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
Overview
- Trusted Computing Group
- TPM2.0
Description
Statistics
- 2 Posts
Bluesky
Overview
- Phoenix Contact
- AXC F 1152
Description
Statistics
- 2 Posts
- 5 Interactions
Fediverse
#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware
This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771
https://certvde.com/en/advisories/vde-2025-056/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json
Overview
- VMware
- Cloud Foundation
Description
Statistics
- 3 Posts
Fediverse
The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi
Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday
Overview
- Microsoft
- Windows App Client for Windows Desktop
Description
Statistics
- 1 Post
- 8 Interactions
Fediverse
vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.
One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.
This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.
The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
https://vulnerability.circl.lu/vuln/cve-2026-59124
#cve #gcve #opensource #vulnerabilitylookup #opendata #vulnerabilitymanagement #cyberecurity #ssvc