RansomwareHuntress Blog·1 week ago

Akira Hits Safe Mode: Ransomware Rebooting Around EDR

An Akira ransomware affiliate attempted to evade endpoint detection and response tools by rebooting into Safe Mode to disable EDR and Windows Defender, but the technique backfired when the ransomware itself failed to execute in that environment. Huntress has documented the complete attack chain showing how this evasion tactic ultimately hindered the attacker's own encryption capabilities. The incident highlights the double-edged nature of Safe Mode abuse, where defensive measures can inadvertently impede malicious payloads.

Policy & LegalRapid7 Blog·1 week ago

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?

AI has moved from experimental pilot programs to embedded production systems in security operations centers, with 97% of SOC teams reporting positive outcomes—yet security executives are notably more concerned than frontline staff about data governance, accountability, and risk management. The confidence gap reflects a maturity shift: operational teams validated that AI works, while leaders now grapple with harder questions about governance, oversight, and what happens when AI systems fail. The organizations pulling ahead aren't choosing between AI and human expertise; they're building models where AI handles volume and pattern matching while analysts retain decision authority, and buyers increasingly expect transparency into how AI decisions are made rather than simply faster automation.

VulnerabilityCISA Advisories·1 week ago

Siemens RUGGEDCOM APE1808

All versions of Siemens RUGGEDCOM APE1808 are affected by two Fortinet vulnerabilities: a cross-site scripting flaw (CVE-2026-23573, CVSS 6.1) that allows authenticated remote users to execute code via crafted requests, and a path traversal vulnerability (CVE-2026-59839, CVSS 5.5) exploitable by privileged authenticated attackers with physical access to delete the file system. Siemens recommends contacting customer support and following Fortinet's mitigation guidance, while CISA advises minimizing network exposure and isolating control system networks from the internet.

VulnerabilityWired Security·1 week ago

This Coin-Sized Device Can Hack a Boeing 737

Security researchers demonstrated a vulnerability in Boeing 737 aircraft where a small, coin-sized device can be physically inserted into an external hatch in under 60 seconds to compromise critical flight systems. The attack allows an attacker to redirect the aircraft's autopilot or modify its flight plan, highlighting a significant physical security gap in commercial aviation.

OtherWired Security·1 week ago

‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware

Criminal organizations are escalating cargo theft tactics to unprecedented levels of violence in California, specifically targeting high-value AI hardware and data center equipment. Security experts point to at least two recent incidents as evidence that theft rings view these server shipments as lucrative enough to employ increasingly dangerous methods to intercept them.

VulnerabilityInfosecurity Magazine·1 week ago

Microsoft Fixes 400 Flaws on August Patch Tuesday

Microsoft addressed 400 vulnerabilities across its product portfolio in its August Patch Tuesday release. The substantial update volume underscores the ongoing volume of security issues requiring remediation across Microsoft's software ecosystem.

OtherSnyk·1 week ago

The Agent Baseline: 35 Controls, But Where Should You Start?

The Agent Baseline defines 35 controls across six security outcomes—but the right starting point depends on how your organization uses agents. Learn how to sequence controls for coding, internal, and production agents.

VulnerabilityQualys·1 week ago

Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review

Microsoft's August 2026 Patch Tuesday release addresses 421 vulnerabilities across its product portfolio, including 62 critical and 357 important-severity issues, with three zero-day vulnerabilities patched—two publicly disclosed and one actively exploited in the wild. The update underscores the ongoing threat landscape where timely patching remains essential for enterprises to reduce exposure and mitigate attack surface.

VulnerabilityDark Reading·1 week ago

Microsoft's Patch Tuesday Deluge Continues With August Updates

Microsoft's August Patch Tuesday release includes CVE-2026-62878, a critical remote code execution vulnerability in Windows DNS Server with a CVSS score of 9.8 that requires no user interaction. This RCE flaw represents a significant risk to organizations running affected DNS Server infrastructure and should be prioritized for immediate patching.

VulnerabilityKrebs on Security·1 week ago

Microsoft Plugs Nearly 400 Security Holes

Microsoft released patches for nearly 400 security vulnerabilities across Windows operating systems and supported software, addressing multiple flaws that posed immediate risk to users. The update included at least one vulnerability already under active exploitation and two additional weaknesses that had been publicly disclosed before the patch release.

RansomwareDark Reading·1 week ago

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The Gunra ransomware gang is actively exploiting known Fortinet vulnerabilities and leveraging leaked Conti code to compromise critical infrastructure targets while circumventing multi-factor authentication. The group's success against defended environments suggests that unpatched firewall and VPN appliances remain a significant attack surface, even when MFA protections are in place.

VulnerabilityRapid7 Blog·1 week ago

Patch Tuesday - August 2026

August 2026 Patch Tuesday brings 421 vulnerabilities including a critical SharePoint RCE chain discovered by Rapid7 researchers and an actively exploited Windows Ancillary Function Driver elevation-of-privilege flaw, while the pseudonymous researcher "Nightmare Eclipse" continues a pattern of late-cycle disclosures with ShieldBreak, a patch bypass for previously patched Defender vulnerabilities. Microsoft Edge received delayed security patches compared to Chrome, with a five-day gap between Chrome and Edge updates marking an unusual slowdown in the browser's typical patching cadence.

VulnerabilityTenable·1 week ago

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Microsoft's August 2026 Patch Tuesday addressed 398 CVEs across a broad range of products, with 42 rated critical and three zero-days including one actively exploited in the wild. Notable vulnerabilities include a critical remote code execution flaw in Windows Deployment Services TFTP Server with a CVSS score of 9.8, a critical Windows DHCP Server RCE affecting unauthenticated remote attackers, and the actively exploited Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability. Elevation of privilege vulnerabilities accounted for 40.7% of this month's patches, followed by remote code execution vulnerabilities at 27.1%.

Load more