A serious vulnerability in SharePoint, identified as CVE-2026-55040, is currently being exploited by attackers following the release of a public proof-of-concept on August 12. This flaw, which has a CVSS score of 9.1, allows unauthenticated users to impersonate SharePoint administrators, posing a significant risk to organizations using this platform. The vulnerability was patched in July, but the rapid exploitation indicates that many systems may still be vulnerable. Companies using SharePoint need to prioritize applying the latest security updates to protect their environments from unauthorized access. The situation underscores the importance of timely patch management in preventing exploitation.
The Information Commissioner's Office (ICO) has reprimanded the Association of Chief Police Officers Criminal Records Office (ACRO) following a data breach that occurred in 2023. The breach was attributed to failures in patch management and security monitoring, which allowed unauthorized access to sensitive information. As a result, individuals whose criminal records were managed by ACRO may have had their personal data exposed. This incident raises concerns about the handling of sensitive information by governmental organizations and the potential risks to privacy and security for those affected. The ICO's action serves as a reminder that even agencies tasked with law enforcement must prioritize robust cybersecurity measures to protect citizen data.
Kaspersky researchers have identified a new cyber-espionage campaign linked to the group Armored Likho. This campaign masquerades as a fundraising initiative and uses a newly developed tool called the Still Toolkit, which is specifically designed to steal data from Telegram and eavesdrop on users. The implications of this attack are significant, particularly for individuals and organizations that rely on Telegram for communication. Users should be cautious about unsolicited fundraising requests and consider enhancing their security measures to protect sensitive information. This incident illustrates the ongoing risks posed by sophisticated cyber-espionage tactics, which continue to evolve and target popular communication platforms.
Cisco has reported a high-severity vulnerability, designated as CVE-2026-20349, that attackers are using to cause temporary disruptions in the operation of Cisco firewalls. This flaw has been recognized by the Cybersecurity and Infrastructure Security Agency (CISA) and is included in their catalog of known exploited vulnerabilities. US civilian federal agencies are required to address this issue by August 14, 2026. While Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation in August, specific details regarding the attacks have not been disclosed. The urgency for remediation highlights the potential risks to organizations relying on Cisco’s firewall products.
Belgium's electronic ID system has suffered a significant breach due to serious vulnerabilities found in a crucial browser extension. This compromise means that unauthorized individuals could potentially access citizen accounts, revealing sensitive personal information. The issue raises concerns not just about Belgium's system but also highlights broader risks associated with browser extensions in general. As more services rely on digital identities, the security of these systems becomes increasingly important. Citizens using the eID system should be aware of the risks and consider additional security measures to protect their accounts.
DDoS attacks have surged in scale during the first half of 2026, according to Cloudflare's latest report. Attackers are employing multi-vector techniques, leading to massive traffic floods that can exceed 1 terabit per second. These hyper-volumetric campaigns are impacting various online services across multiple industries, causing disruptions that can cripple businesses and services. The report notes that these attacks are not only larger but also shorter in duration, suggesting a shift towards more automated and efficient methods of conducting these attacks. As organizations increasingly rely on online services, the growing frequency and intensity of DDoS attacks present a significant challenge to cybersecurity.
Wireshark has released version 4.6.8 to address 28 security vulnerabilities, with nine of these affecting file parsers that process saved capture files. These vulnerabilities could be exploited simply by opening a maliciously crafted capture file, which means an attacker does not need direct access to the network. The affected file parsers include formats like pcapng, Endace ERF, and several others, specifically on Windows systems. This update is critical for users of Wireshark, as it helps prevent potential exploitation that could compromise sensitive data or system integrity. Users are urged to update to the latest version to mitigate these risks.
A data theft campaign is targeting Salesforce Experience Cloud and ServiceNow customer portals, exploiting data that is exposed to anonymous users. Attackers are using custom tools to gain access to sensitive information, potentially impacting organizations that rely on these platforms. This ongoing threat raises concerns about the security of data shared on customer portals, particularly when access controls are not properly enforced. Companies using Salesforce and ServiceNow need to review their portal configurations and ensure that sensitive data is not accessible to unauthorized users. The situation highlights the importance of strong security measures and user authentication to protect against such attacks.
Thailand's Digital Economy and Society Minister is pushing for mandatory multi-factor authentication (MFA) across all government systems. This move comes after a significant data leak, raising concerns about the security of sensitive information. By implementing MFA, the government aims to enhance protection against unauthorized access and potential cyber threats. The proposal is currently awaiting cabinet approval, highlighting the urgency of improving cybersecurity measures within government operations. This initiative is crucial, as it could set a precedent for better security practices in both public and private sectors in Thailand.
Colombia's Ministry of Justice recently became the target of a ransomware attack that disrupted essential services, particularly those related to drug monitoring and legal procedures. This incident follows a warning from Colombia's national Computer Emergency Response Team (CERT), which had alerted agencies about an uptick in ransomware activity in the country. The attack raises significant concerns about the vulnerability of government systems to cyber threats, particularly as they handle sensitive information regarding drug-related crimes. The impact of this breach could delay legal processes and hinder the monitoring of illicit activities, potentially allowing criminal operations to flourish. As ransomware attacks continue to escalate globally, this incident serves as a stark reminder of the need for enhanced cybersecurity measures in critical government sectors.
A recent supply chain attack targeting LiteLLM, a Python library and proxy server, has affected more than 2,500 organizations. The compromise occurred indirectly, meaning the attackers may have infiltrated the supply chain rather than attacking LiteLLM directly. This incident raises concerns about the security of third-party libraries and the potential ripple effects on organizations that rely on them for their operations. As LiteLLM is commonly used in various applications, the widespread nature of this attack puts many companies at risk, emphasizing the need for enhanced scrutiny of software dependencies. Organizations should assess their use of LiteLLM and consider implementing additional security measures to mitigate potential risks.
The Trump administration has lifted a ban on TikTok for federal devices that was implemented in 2022. This ban was put in place due to concerns over the app's parent company, ByteDance, and its potential connections to the Chinese government, which raised alarms about data privacy and security. The reversal of this ban means that federal employees can now use TikTok on government-issued devices. This decision could lead to renewed concerns about data collection practices and the implications for national security, especially given the app's extensive user base and the sensitive information that could be at risk. As government agencies reassess their policies, users and lawmakers may continue to debate the balance between technology use and privacy protections.
The 'City-Forum' campaign has been stealing data since at least March 2025, targeting various organizations with tailored tools. This campaign has affected multiple sectors, indicating a broad approach by attackers who are likely seeking sensitive information from diverse sources. The custom tooling suggests a sophisticated level of planning and execution, raising concerns about the security measures in place at affected organizations. As this campaign continues, it emphasizes the need for businesses to enhance their cybersecurity defenses and remain vigilant against such targeted attacks. The implications of these data thefts can be significant, potentially leading to financial losses and reputational damage for the victims.
Researchers have identified a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms that could allow hackers to take control of customer accounts. This flaw impacts businesses using these platforms, raising serious concerns for online retailers and their customers. Attackers could exploit this vulnerability to gain unauthorized access to sensitive user information, potentially leading to identity theft and financial fraud. As attempts to exploit this flaw have already been detected, it's crucial for affected users to take immediate action to secure their accounts. The situation underscores the ongoing risks faced by e-commerce platforms and the need for timely software updates.
CEVA Logistics experienced a cyberattack on July 29 that significantly disrupted its operations across Europe. The attack affected eight of its warehouses, leading to halted shipments and ongoing service restoration efforts. The company, which provides logistics and supply chain services, is still in the process of addressing the fallout from this incident. This disruption not only impacts CEVA's operations but also raises concerns for clients relying on timely deliveries in an already strained supply chain environment. The incident serves as a reminder of the vulnerabilities that logistics companies face in an increasingly digital world.