A researcher has demonstrated that Apple's Find My location-tracking service can be manipulated to function on Linux systems through protocol manipulation, despite being designed exclusively for Apple devices. The exploit reveals a potential security gap in how the service validates and handles location data requests from non-Apple platforms.
Adversa AI has disclosed a cryptographic context injection attack that could enable adversaries to extract sensitive user data from xAI's Grok chatbot, including names, locations, subscription information, and conversation prompts, by tricking users into summarizing seemingly ordinary web pages. The attack leverages the chatbot's interaction with web content to redirect data to attacker-controlled servers without the user's knowledge or consent.
A zero-day elevation-of-privilege vulnerability tracked as CVE-2026-69414 in the Microsoft Malware Protection Engine allows low-privilege local attackers to escalate to SYSTEM level, with a public proof-of-concept released on August 12, 2026. Microsoft assigned the CVE on August 14 with no patch currently available, and CISA's binding operational directive 26-04 mandates remediation within 14 days. Organizations running Microsoft Defender should prioritize detection and mitigation efforts while awaiting an official patch.
A critical vulnerability in the isolated-vm sandbox library allows attackers to escape the isolated JavaScript environment and achieve remote code execution on the host system. The flaw, tracked as GHSA-864f-rcv7-6rh4, affects all versions through 7.0.0 of the popular open-source project. Security researchers have disclosed the escape technique, highlighting a significant risk for applications relying on isolated-vm for code isolation.
Citrix has patched a critical authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway that could allow attackers to circumvent security controls on affected deployments. The flaw impacts customer-managed instances across multiple configurations, including FIPS and NDcPP builds, as well as SecurAccess. Organizations running these products should prioritize applying the available updates to prevent potential unauthorized access.
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra
Check Point Research demonstrates how Microsoft Defender's remediation driver can be weaponized as a kernel-level primitive to execute arbitrary file and registry operations with Ring 0 privileges, bypassing the need for traditional exploits or memory corruption vulnerabilities. This technique leverages a signed, trusted security component to grant attackers powerful kernel capabilities without requiring vulnerability exploitation, presenting a novel attack surface within Windows Defender itself.
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges. View CVE Details Affected Products Johnson Controls Simplex Incident Manager Vendor: Johnson Controls Inc. Product Version: Johnson Controls Simplex Incident Manager: <=V2.01 Product Status: known_affected Remediations Mitigation Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging. Mitigation For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-28. https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Mitigation Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems. Relevant CWE: CWE-316 Cleartext Storage of Sensitive Information in Memory Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.8 MEDIUM CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L 4.0 5.8 MEDIUM CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N Acknowledgments Johnson Controls reported this vulnerability to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. This vulnerability has a high attack complexity. Revision History Initial Release Date: 2026-08-20 Date Revision Summary 2026-08-20 1 Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-28 Legal Notice and Terms of Use
CISA has added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-72529 (missing authentication for critical function) and CVE-2026-72530 (code injection), both showing evidence of active exploitation. Under BOD 26-04, federal agencies must prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices.
Security researchers at Cycode have discovered a critical vulnerability chain in NASA/JPL's AIT-GUI operator console that enables unauthenticated attackers to send arbitrary commands to spacecraft and instruments. The flaw, rated 9.4 CVSS severity and tracked as GHSA-p9r8-2q67-fp86, affects the browser-based interface used with the open-source AMMOS Instrument Toolkit.
US government officials have alerted industrial control system operators to an emerging threat involving AI-generated exploitation scripts targeting exposed Siemens S7 Series PLCs. The advisory highlights how attackers are leveraging artificial intelligence to automate and accelerate attacks against critical infrastructure programmable logic controllers.
A critical vulnerability in Elementor Pro's Forms module allows unauthenticated attackers to upload PHP files and execute arbitrary code on affected WordPress installations. Tracked as CVE-2026-32475 with a CVSS score of 9.0, this unrestricted file upload flaw poses severe risk to sites running the vulnerable plugin. Researchers have publicly disclosed technical details of the vulnerability, increasing the likelihood of active exploitation.
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9 (Critical). Affects TrueConf Server.
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects TrueConf Server.
CISA and the FBI have warned of an ongoing AI-backed campaign targeting vulnerable Siemens S7 industrial control devices across multiple critical sectors including energy and water utilities. Threat actors are employing disguised scripts that appear to be legitimate software to compromise these systems, leveraging artificial intelligence in their attack methodology.
Researchers have disclosed a remote Spectre attack against Cloudflare Workers that successfully extracted a JSON Web Token from a co-located Worker in production, achieving data exfiltration rates of up to 12 bits per second. The attack represents a significant improvement over previous demonstrations, running 360 times faster than a similar attack shown in 2021, and was conducted using an attacker-controlled Worker alongside a victim Worker in a controlled end-to-end experiment.
CVE-2026-19490 is a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway with a CVSS score of 9.3 that can be exploited remotely by unauthenticated attackers without user interaction. The vulnerability impacts NetScaler ADC and Gateway versions 14.1 prior to 14.1-73.32 and 13.1 prior to 13.1-63.21, along with affected FIPS variants, and organizations should prioritize emergency patching given the high-value nature of these perimeter-deployed systems and their history of rapid exploitation.
The Linux Foundation's Akrites initiative is set to launch operationally in September, enabling the submission of AI-generated vulnerability reports for open-source projects. This new system represents an effort to streamline vulnerability disclosure processes for the open-source community through automated analysis capabilities.
VulnerabilitySANS Internet Storm Center·4 days ago
Attackers can exploit the cloud metadata service accessible at 169.254.169.254 to retrieve sensitive credentials and IAM role tokens from virtual machines, beyond just benign instance information like region and IP addresses. Cloud providers expose this REST API by design to allow running code access to machine-specific data, but the credential exposure risk makes it an attractive target for adversaries seeking to escalate privileges or move laterally within cloud environments.
Oracle's August 2026 Critical Patch Update addressed 943 security vulnerabilities across multiple product families, with some vulnerabilities affecting more than one product. Oracle Fusion Middleware and Oracle Hyperion received the most patches in this release with 262 each, while the update also included fixes for third-party components integrated into Oracle products.