Swati KhandelwalAug 11, 2026Vulnerability / Enterprise Security Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an… Read More "Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE"
Metabase SQLi exploit grants attackers total access
Metabase said that after it discovered the attack, it immediately blocked the exploited endpoints, patched the vulnerability, terminated relevant sessions, and revoked credentials used in the incident. Metabase Cloud customers have already been upgraded and patched against the vulnerability, but… Read More "Metabase SQLi exploit grants attackers total access"
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Shutting down endpoint detection and response (EDR) tools before encryption begins has become standard operating procedure across the ransomware ecosystem, analysis of attacks by researchers at Halcyon has warned. The practice, sometimes called EDR-kill, was once considered a specialist capability.… Read More "Ransomware Groups Increasingly Deploy EDR Kill Techniques"
What is Vulnerability Remediation? | UpGuard
The “patch everything” model has become technically and operationally unsustainable for mid- to large-scale organizations. Today’s security teams navigate an environment where thousands of new CVEs are published monthly, necessitating a shift from reactive, point-in-time scanning to a disciplined remediation… Read More "What is Vulnerability Remediation? | UpGuard"
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Federal lawmakers and cybersecurity leaders have launched parallel initiatives to protect US water infrastructure from growing cyber threats, combining new federal legislation with a grassroots defense project for local utilities. Senators Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.) introduced the… Read More "US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’"
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client
Swati KhandelwalAug 11, 2026Vulnerability / Software Security Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter’s. The flaw sat in the annotation tool,… Read More "Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client"
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
Advice for CSOs For CSOs, the primary strategic priority should be reducing the window of exposure around CVE-2026-68820, because exploitation is already occurring, Bicer said. CVE-2026-62832 should follow closely, because it is publicly disclosed and assessed as more likely to… Read More "Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability"
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
The Operators of a well-known malvertising campaign have developed a novel technique to avoid detection: hiding their activity in the victim’s browser to secretly build and then deliver the final payload. The new tactics by SourTrade, a prolific and evolving… Read More "SourTrade Malvertising Campaign Secretly Builds Malware in the Browser"
25 Security Vulnerabilities That Have Defined the 2020s (Thus Far)
Welcome to vulnerability management’s big bang. If it feels like your security team is running a marathon on a treadmill set to a permanent incline of 12.0 with 50lb sandbags tied around each ankle, you’re in good company. We have… Read More "25 Security Vulnerabilities That Have Defined the 2020s (Thus Far)"
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory. Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most… Read More "SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities"