Overview
Description
Statistics
- 19 Posts
- 11 Interactions
Fediverse
「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA
「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。
この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」
https://www.ipa.go.jp/security/security-alert/2026/0812-ms.html
「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews
「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。
このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。
この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」
https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: https://thecybermind.co/jily
📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign
Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...
Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.
#PatchTuesday #Microsoft #ZeroDay #CVE #WindowsSecurity #InfoSec
Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.
#Lazarus #ZeroDay #CVE202668820 #OperationDreamJob #Cybersecurity #DPRK #FudModule #DefenseSector
CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. https://radar.offseq.com/threat/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks-bbf9980a8328f4c4 #OffSeq #ZeroDay #Windows #Cybersecurity
Bluesky
Overview
- Microsoft
- Microsoft Malware Protection Engine
Description
Statistics
- 7 Posts
- 7 Interactions
Fediverse
🚨Nightmare Eclipse has released a new zero-day PoC called ShieldBreak
Per the security researcher: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."
On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update
https://github.com/MSNightmare/ShieldBreak
#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse
A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.
#ShieldBreak #CVE202650656 #WindowsDefender #PrivilegeEscalation #PoC #RoguePlanet #Cybersecurity
https://securityonline.info/shieldbreak-defender-poc/?utm_source=mastodon&utm_medium=jetpack_social
„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“
https://borncity.com/blog/2026/08/12/shieldbreak-poc-fuer-microsoft-defender-0-day-schwachstelle/
August 2026 Patchday: Updates gerade freigegeben, da veröffentlicht Nightmare Eclipse #Shieldbreak als Proof of Concept (PoC). Der PoC umgeht die ungenügend gepatchte #Defender Schwachstelle CVE-2026-50656 (#RoguePlanet).
https://borncity.com/blog/2026/08/12/shieldbreak-poc-fuer-microsoft-defender-0-day-schwachstelle/
Overview
Description
Statistics
- 8 Posts
- 2 Interactions
Fediverse
This is being actively exploited. CVE-2026-20349. Patch now. Like right now. #infosec #vpn #cisco #cve
https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER
「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。
CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。
シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」
🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: https://thecybermind.co/jily
Bluesky
Overview
- Microsoft
- Microsoft SharePoint Enterprise Server 2016
Description
Statistics
- 4 Posts
- 4 Interactions
Fediverse
Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.
#CVE202655040 #SharePoint #AuthenticationBypass #JWT #Rapid7 #PoC #Cybersecurity
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews
「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。
CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。
この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」
https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
Overview
Description
Statistics
- 4 Posts
- 4 Interactions
Fediverse
CVE-2026-17106: Docker docker cp Container-to-Host Arbitrary File Write
CopyEscape (CVE-2026-17106) lets a malicious Docker container abuse docker cp to overwrite host files through a filesystem race and symlink extraction flawhttps://thecybersecguru.com/news/copyescape-cve-2026-17106-docker-cp/
Bluesky
Overview
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
CVE-2026-9198: Langflow sotto attacco attivo, ecco perché aggiornare subito
#tech
https://spcnet.it/cve-2026-9198-langflow-sotto-attacco-attivo-ecco-perche-aggiornare-subito/
@informatica
Overview
- Microsoft
- Windows Server 2012
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
Details and PoC for CVE-2026-27912 (ResetNightmare) are public. This Kerberos flaw lets attackers reset AD passwords and gain SYSTEM.
#CVE202627912 #ResetNightmare #Kerberos #ActiveDirectory #PrivilegeEscalation #InfoSec
https://cravaterouge.com/articles/resetnightmare/
Overview
- Zoom Communications
- Zoom Clients
Description
Statistics
- 2 Posts
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
StormEncryptor: come l’ex affiliato Medusa Storm-1175 ha trasformato N-central in un launchpad ransomware
Microsoft attribuisce a Storm-1175, gruppo legato alla Cina e già affiliato Medusa, lo sfruttamento della falla CVE-2026-18577 in N-able N-central per distribuire il nuovo ransomware StormEncryptor a cascata su decine di MSP e relativi clienti.La innovadora botnet Aeternum usa blockchain para evadir detección, mientras cámaras IP ucranianas y drones militares sufren infiltraciones que exponen datos sensibles; una vulnerabilidad crítica en KVM permite escalada de privilegios y ataques a plugins de WordPress generan accesos administrativos falsos; además, ransomware de origen chino amenaza sistemas empresariales. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:
🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 11/08/26 📆 |====
🔐 ANÁLISIS DE LA AMENAZA PERMANENTE: BOTNET AETERNUM USANDO BLOCKCHAIN
La botnet Aeternum representa un riesgo avanzado al utilizar contratos inteligentes en la blockchain Polygon para establecer una infraestructura descentralizada de comando y control (C2). Esta arquitectura evita la detección tradicional y facilita la ejecución de cargas maliciosas. Conocer esta técnica innovadora es esencial para reforzar las defensas contra amenazas persistentes modernas. Descubre el análisis completo y cómo proteger tus sistemas aquí 👉 https://djar.co/tLv9vV
🎥 EXPLOITACIÓN DE CÁMARAS IP UCRANIANAS POR OPERADOR DE HABLA RUSA
Se ha revelado un directorio abierto que expone las herramientas usadas para comprometer cámaras IP en Ucrania, además de intentos de acceso a sitios gubernamentales y militares. Este caso destaca los riesgos reales en dispositivos IoT y la importancia crítica de proteger infraestructuras sensibles ante actores sofisticados. Infórmate sobre las tácticas y medidas preventivas recomendadas aquí 👉 https://djar.co/Qd0A
⚠️ CVE-2026-64561: ESCAPE DE INVITADOS KVM CON PRIVILEGIOS ROOT EN LINUX
Una vulnerabilidad crítica permite a usuarios invitados de máquinas virtuales KVM escapar al host Linux con privilegios root, comprometiendo la seguridad del sistema completo. Este fallo subraya la urgencia de aplicar parches y fortalecer configuraciones en entornos virtualizados para evitar accesos no autorizados de alto nivel. Lee el análisis técnico y recomendaciones aquí 👉 https://djar.co/v9txO
🛠️ ATAQUE A LA CADENA DE SUMINISTRO EN PLUGINS DE WORDPRESS BdThemes
Se ha detectado la explotación de paquetes JSON maliciosos en plugins de WordPress, permitiendo a atacantes crear usuarios administradores falsos y desplegar shells web PHP sin necesidad de actualizar los plugins. Esta vulnerabilidad de tipo XSS evidencia el peligro que representa no validar adecuadamente componentes de terceros y la necesidad de mantener actualizaciones constantes. Entiende cómo mitigar este riesgo hoy mismo aquí 👉 https://djar.co/3ib0TB
🚁 VULNERABILIDADES EN DRONES MILITARES DE LA MARINA REAL: FILTRACIÓN DE DATOS HACIA CHINA
Un informe revela que drones de la Marina Real presentan fallas de seguridad que permiten la transmisión no autorizada de información sensible hacia China. Este incidente resalta la importancia de implementar controles robustos en sistemas militares y tecnológicos para proteger datos estratégicos. Accede al reporte completo y medidas recomendadas aquí 👉 https://djar.co/DLBej8
🦠 RANSOMWARE STORMENCRYPTOR DESPLEGADO POR HACKERS VINCULADOS A CHINA
Microsoft alerta que el grupo Storm-1175 utiliza el ransomware StormEncryptor, aprovechando la vulnerabilidad CVE-2026-18577 en N-able N-central para comprometer sistemas empresariales. Se recomienda la aplicación inmediata de parches y monitoreo activo para evitar daños severos por este ataque sofisticado. Profundiza en la investigación y pautas de defensa aquí 👉 https://djar.co/tV8x
Overview
- Cisco
- Cisco Secure Endpoint
Description
Statistics
- 4 Posts
- 2 Interactions
Fediverse
「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER
「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。
これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。
シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」
The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. https://www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaws-with-public-exploits/