Researchers have identified 19 browser extensions—18 for Google Chrome and one for Microsoft Edge—that contain malicious code designed to steal cryptocurrency wallet secrets and drain funds. These extensions were published in the last six months and share similar coding techniques, suggesting they may be part of a coordinated attack. Users of these browsers who have downloaded these extensions are at risk of losing their cryptocurrency assets. This discovery highlights the need for users to scrutinize extensions before installation and for browser vendors to enhance their review processes to prevent such malicious software from being available in their stores.
Vercel has issued security patches for two serious vulnerabilities in the Next.js framework that could allow attackers to execute code remotely without authentication. The first vulnerability arises from the handling of AVIF image files, which can be manipulated to exploit the system. The second flaw is a path traversal issue that affects installations on Windows filesystems, enabling unauthorized access to files. These vulnerabilities are particularly concerning because they can be exploited without any user interaction, putting many applications at risk if they use Next.js. Developers using this framework should prioritize updating to the latest version to mitigate these risks.
On August 26, CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating that these flaws are being actively exploited by attackers. The affected products include software from Microsoft, Linux, Red Hat, and Citrix, which are widely used in various computing environments. This is a significant concern for organizations relying on these systems, as attackers could leverage these vulnerabilities to gain unauthorized access or disrupt services. Companies should prioritize patching these flaws to mitigate potential risks. The ongoing exploitation of these vulnerabilities underscores the need for vigilance in maintaining software security.
The Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are currently being exploited in the wild. These vulnerabilities affect a variety of systems, including Red Hat Libuser, Microsoft SQL Server, and Citrix NetScaler, among others. The identified vulnerabilities range from privilege escalation to remote code execution, posing serious risks to federal agencies and potentially impacting other organizations as well. CISA urges all entities to prioritize fixing these vulnerabilities to protect their systems, especially those that expose critical assets to attackers. The agency encourages reporting any additional exploited vulnerabilities that are not yet in the KEV Catalog for potential inclusion.
A new Windows backdoor known as SLEEPWALKER has been discovered by an independent malware researcher. This backdoor remains inactive until it receives a specifically crafted network packet, at which point it executes commands written in a unique 23-instruction language. The malicious software is an unsigned 64-bit dynamic-link library (DLL) totaling nearly 60,000 bytes, designed for side-loading. This means that it could potentially be used to infiltrate systems quietly and execute commands without detection. The implications are serious, as it poses a risk to Windows users who may unknowingly execute this backdoor, allowing attackers to take control of affected machines.
At least 274 Zimbra servers have been compromised by attackers exploiting a vulnerability identified as CVE-2026-73570. This particular flaw is a code injection issue in the Zimbra Collaboration Suite (ZCS), which is widely used by organizations that prefer to manage their own data instead of relying on more expensive services like Microsoft 365 or Google Workspace. The vulnerability was patched by Synacor in version 10.1.20 of ZCS, released on July 20, 2026. However, many instances remain unpatched, leaving them vulnerable to exploitation. This incident highlights the risks associated with not keeping software updated, especially for platforms that handle sensitive communication and collaboration.
Doubloon Dredger is a malicious campaign that exploits Notion and uses harmful PDFs to steal Microsoft authentication tokens. This means that attackers can gain unauthorized access to user accounts by intercepting the tokens, which are crucial for logging into Microsoft services. The campaign targets individuals and organizations that use Notion for collaboration and document management, potentially compromising sensitive information. Users are at risk of having their accounts hijacked, leading to data breaches and other security concerns. It's crucial for users to be cautious about the files they open and to ensure their security settings are up to date to mitigate this threat.
Windows named pipes, a method for fast communication between processes, have been identified as a potential security risk due to weak access controls. This vulnerability allows untrusted processes to potentially access privileged services, posing a threat to system integrity. Security experts from ThreatLocker recommend several strategies to mitigate these risks, including endpoint verification, command authorization, strict input validation, and limiting privileges to what is necessary. These measures can help secure named-pipe communications and protect against unauthorized access. Organizations using Windows systems should take these recommendations seriously to safeguard their environments from potential exploitation.
Microsoft has identified and patched a severe vulnerability in Entra ID, its cloud identity service, which was previously known as Azure Active Directory. The flaw, tracked as CVE-2026-69836, has a maximum severity score of 10.0 and allows unauthenticated attackers to execute code remotely. This vulnerability, discovered by a Microsoft security engineer, poses a significant risk as it affects systems that manage logins and access to Microsoft 365, Azure, and various third-party applications. Due to its exploitation in the wild, companies using Entra ID need to act quickly to protect their systems. Users should ensure their services are updated with the latest security patches to mitigate potential risks.
Microsoft has released 22 security patches aimed at fixing various vulnerabilities, primarily related to code execution, privilege escalation, and information disclosure. These patches are crucial as they address flaws that could allow attackers to gain unauthorized access or execute malicious code on affected systems. Users and organizations running Microsoft products should prioritize applying these updates to safeguard their systems from potential exploitation. The vulnerabilities affect a range of Microsoft software, emphasizing the need for timely remediation to maintain security. It’s a reminder for users to stay vigilant and keep their software up to date.
Microsoft has issued a warning about a severe vulnerability in its Entra ID service, previously known as Azure Active Directory. This security flaw, identified as CVE-2026-69836 and rated 10.0 on the CVSS scale, allows for remote code execution, meaning attackers could potentially execute malicious code on affected systems without needing physical access. Although Microsoft has confirmed that this vulnerability is being exploited in the wild, they have stated that no immediate action is required from customers. This is significant as Entra ID is a critical service for identity and access management in the cloud, and any exploitation could lead to unauthorized access to sensitive data. Users and organizations relying on this service should remain vigilant and monitor for any updates from Microsoft regarding further mitigation steps.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild, adding them to its Known Exploited Vulnerabilities (KEV) catalog. Among these is CVE-2026-65400, a serious authentication flaw in Apple macOS that could allow unauthorized access. Other vulnerabilities affect Microsoft SharePoint, VMware vCenter, and Microsoft IKE, all of which pose significant risks to organizations using these platforms. With a CVSS score of 9.8 for CVE-2026-65400, it’s crucial for users and companies to act quickly to mitigate these risks. The exploitation of these vulnerabilities could lead to severe data breaches or unauthorized access, making it essential for affected parties to stay informed and apply necessary updates and patches.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a serious remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions. This flaw is currently being exploited by attackers, which raises significant concerns for organizations using affected systems. The vulnerability could allow hackers to execute arbitrary code on compromised devices, potentially leading to data breaches or system control. Windows users and administrators are urged to take immediate action to protect their systems. This situation highlights the ongoing risks associated with software vulnerabilities and the importance of timely updates and security measures.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, specifically targeting flaws in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE. One notable vulnerability, CVE-2026-33824, relates to the Windows Internet Key Exchange (IKE) Service Extensions and poses a risk of remote code execution. These vulnerabilities could allow attackers to exploit systems running the affected software, potentially leading to unauthorized access or data breaches. It's crucial for users and organizations utilizing these platforms to take immediate action to mitigate the risks associated with these vulnerabilities. Keeping software updated and applying any available patches is essential to protect against potential exploitation.
The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that they are actively being targeted by cybercriminals. The vulnerabilities include a double free flaw in Microsoft Internet Key Exchange (CVE-2026-33824), a weak authentication issue in Microsoft SharePoint (CVE-2026-55040), a path traversal vulnerability in Broadcom's VMware vCenter (CVE-2026-59310), and an improper authentication vulnerability in Apple macOS (CVE-2026-65400). These vulnerabilities pose significant risks, especially for federal agencies, which are required to prioritize their remediation under Binding Operational Directive 26-04. Although this directive specifically targets federal agencies, CISA encourages all organizations to adopt similar practices to enhance their security posture against these threats.