Cyber Threat Brief
Avsnitt

2026-08-22: CISA adds critical Windows IKE and Zimbra command injection flaws to the KEV catalog with patch

Dela

Show Notes - 2026-08-22

Stories Covered: - Today: - CISA Adds Windows IKE Protocol Vulnerability to KEV Catalog (CVE-2026-33824) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-34-8/) - Zimbra Collaboration Suite OS Command Injection (CVE-2026-73570) (https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog) - Ray-Project Ray Code Injection Exploited by RondoDox Botnet (CVE-2025-62593) (https://www.securityweek.com/in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug/) - Medusa Ransomware Compromises Over 500 U.S. Critical Infrastructure Organizations (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-34-8/) - Troutman Pepper Law Firm Data Leak by Silent Ransom Group (https://databreaches.net/2026/08/21/troutman-pepper-locke-silent-as-threat-actors-leak-client-data-tens-of-thousands-of-ssns/) - Apollo Global Management Discloses Data Breach from BlackFile Campaign (https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/) - 14 Trojanized npm Packages Deploy RedC2 4.0 Linux Backdoor (https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html) - ChainDrop npm Worm Infects 400+ Packages via Preinstall Scripts (https://unit42.paloaltonetworks.com/sdlc-supply-chain/) - Rust Crate Poisoning Campaign Targets Developer Credentials (https://www.theregister.com/security/2026/08/21/hackers-poison-popular-rust-crates-to-steal-developers-credentials/) - Joomla Extensions Vulnerabilities Exploited (CVSS 10.0) (https://www.theregister.com/foss/2026/08/21/baddies-caught-exploiting-extensions-bugs-with-perfect-10-scores-on-vulnerable-joomla-websites/) - Microsoft Defender BTR.sys Driver Weaponized for Security Software Deletion (https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html) - On-Premises SharePoint Under Zero-Day Attack (https://www.theregister.com/security/2026/08/21/microsoft-patches-failed-to-fix-on-prem-sharepoint-which-is-now-under-zero-day-attack/) - U.S. Indicts 17 Iranian Nationals for Massive Academic IP Theft (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-34-8/) - GitHub Vulnerability Found by Autonomous Wiz AI Agent (https://www.securityweek.com/in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug/) - T-Mobile Physically Cut Router Cable to Stop Chinese Salt Typhoon Hackers (https://www.securityweek.com/in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug/) - TikTok Settles COPPA Violations for $400 Million (https://www.justice.gov/opa/pr/justice-department-secures-400m-settlement-tiktok-and-bytedance-resolve-childrens-privacy) - OpenAI Implements New Security Controls After Hugging Face Incident (https://www.darkreading.com/application-security/openai-adds-controls-already) - OWASP Releases Top 10 AI Skills Security Risks (https://www.darkreading.com/application-security/owasp-flags-top-ai-skill-risks-security-blueprint) - AI-Powered Phishing Toolkit iAuthFlow V2 Uses Passkeys for Persistence (https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/) - Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini (https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/) - Cisco Patches Nine Vulnerabilities, Five Scoring CVSS 10.0 (https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html) - Critical isolated-vm Type Confusion Enables Host RCE (https://www.securityweek.com/critical-isolated-vm-vulnerability-leads-to-rce-on-host/) - TrueConf Videoconferencing Software Vulnerabilities (https://www.theregister.com/patches/2026/08/21/homeland-security-cybercops-say-patch-true ...

Podden och tillhörande omslagsbild på den här sidan tillhör Carolina Clear Tech, LLC. Innehållet i podden är skapat av Carolina Clear Tech, LLC och inte av, eller tillsammans med, Poddtoppen.