Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has released security patches addressing multiple critical vulnerabilities across ColdFusion, Commerce, and Campaign Classic products. The most severe flaw, CVE-2026-48362 in ColdFusion, carries a maximum CVSS score of 10.0 and involves operating system command injection that could enable arbitrary code execution and privilege escalation.
AIAttackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter with a CVSS score of 9.8. The flaw allows attackers with network access to execute arbitrary code and gain persistent remote access to vCenter servers, though patches have been released.
AISAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has issued critical security patches for a maximum-severity vulnerability (CVE-2026-58231) in SAP Commerce Cloud's Data Hub Adapter that could allow unauthenticated attackers to execute arbitrary code. The flaw, rated 10.0 on the CVSS scale, stems from insufficient authorization checks and input validation. Organizations using SAP Commerce Cloud should prioritize immediate patching to mitigate
AIMicrosoft Plugs Nearly 400 Security Holes
Microsoft released patches for 398 security vulnerabilities in August 2024, including one actively exploited zero-day flaw and two publicly disclosed vulnerabilities. The patch volume surge is attributed to AI-assisted vulnerability discovery, though research shows AI-generated patches fail to properly fix flaws more than half the time. Security experts recommend organizations maintain measured pa
AIMicrosoft's Patch Tuesday Deluge Continues With August Updates
Microsoft released its August Patch Tuesday updates, continuing a trend of high-volume security patches. Security experts emphasize that organizations should focus on prioritizing critical vulnerabilities rather than being overwhelmed by the sheer number of CVEs addressed in the update cycle.
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, FBI, and international partners have issued a joint advisory warning about the Gunra ransomware-as-a-service operation targeting healthcare organizations and critical infrastructure globally. The group, which transitioned to a RaaS model in 2026, offers affiliates an 80% ransom cut and exploits known vulnerabilities in VPNs and firewalls to gain network access, conducting double extortion at
AIOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI has released GPT-5.6-Cyber, a specialized AI model designed for cybersecurity professionals focusing on vulnerability research, penetration testing, and incident response. Built on the GPT-5.6 Sol foundation, the model features enhanced capabilities for identifying zero-day vulnerabilities and developing exploit chains, while notably reducing safety restrictions for certain high-risk securi
AIResearchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Security researchers have demonstrated a critical vulnerability in Windows 11's Plug and Play functionality that allows attackers to achieve SYSTEM-level access by exploiting the automatic installation process for emulated USB devices. The attack leverages signed vendor software fetched through PnP mechanisms and can be executed remotely via Remote Desktop when USB redirection is enabled, affectin
AIThe Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
Organizations need to shift from traditional CVSS-based vulnerability patching approaches to a strategic 'choke-point patching' methodology that focuses on breaking attack chains leading to critical assets. This approach prioritizes vulnerabilities based on their position in potential attack paths rather than severity scores alone, enabling more effective resource allocation and risk reduction.
AIN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released additional hotfixes for its N-central RMM platform in response to active exploitation of a recently disclosed security vulnerability. The company is proactively enhancing protections as threat actors evolve their attack techniques and have reportedly reached managed systems with persistent access. This represents an escalating security incident requiring immediate attention fro
AINew WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has patched a critical pre-authentication reflected XSS vulnerability (CVE-2026-64638) affecting all versions of the CMS. The high-severity flaw, with a CVSS score of 8.9, requires no attacker privileges and can potentially be chained to achieve PHP code execution on the server, making immediate patching essential for all WordPress installations.
AI18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A critical 18-year-old use-after-free vulnerability in Linux's SCTP networking code enables local privilege escalation to root access and container escape. Tencent researchers demonstrated successful exploitation to break out of containers and compromise the underlying host system. Patches are available in stable kernel versions released August 3, 2025, making immediate updates essential for syste
AIThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
This week's security landscape demonstrates how attackers are exploiting minimal user interaction through automated execution vectors. Threats now leverage exposed infrastructure, supply chain vulnerabilities, and trusted defaults to achieve compromise before users can respond. The attack surface has expanded to include repository auto-execution, hidden malicious packages, weaponized documents, an
AICryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Security firm Coinspect has traced $5.7 million in cryptocurrency wallet drains to a weak random number generator in CryptoJS that has existed for 12 years. The vulnerable CryptoJS.lib.WordArray.random() function provided insufficient entropy for generating recovery phrases in five affected crypto wallet applications, enabling attackers to compromise wallets in two major sweeps since late May.
AIAWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Critical security vulnerabilities have been discovered in agent infrastructure from AWS, Google, and Vercel that allow attackers to bypass AI model authorization and directly trigger agent tools. These flaws enable malicious instructions to reach tools without running through the model, circumventing system prompts, content filters, and guardrails designed to prevent unauthorized actions.
AIFlaws in Google APK for Python Unlock Agent-to-Agent Attack
Google has patched security vulnerabilities in its APK for Python that enabled agent-to-agent attacks by exploiting trust boundaries between AI agents operating at different privilege levels. The flaws posed supply chain security risks by allowing unauthorized automation to be triggered across agent privilege boundaries.
AIVeeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and Django have collectively patched 11 critical vulnerabilities across their platforms, including a CVSS 10.0-rated cross-tenant authentication flaw in Terraform MCP Server and a 9.5-rated unauthenticated credential exposure bug in Veeam Service Provider Console. These severe vulnerabilities pose significant risks to enterprise environments, particularly for managed service prov
AICISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
CISA added three critical vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, 2026, including a severe code injection flaw in Langflow (CVE-2026-9198) with a CVSS score of 9.8, along with vulnerabilities in Apache Tomcat and N-central. All three flaws are being actively exploited in the wild, enabling unauthenticated remote code execution and posing significant risks to ent
AINew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has released a critical security patch addressing CVE-2026-58048, a vulnerability that allowed authenticated hosting customers to execute SQL commands with database root privileges, effectively bypassing account-level security boundaries. The targeted security release also fixes two additional vulnerabilities that could enable privilege escalation beyond account boundaries.
