Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7

SonicWall SMA1000 remote-access appliances hit by exploited zero-day flaws

SonicWall is warning that two flaws in its SMA1000 remote-access appliances are being actively exploited as zero-days, and has released hotfixes. CVE-2026-15409 is an unauthenticated server-side request forgery bug in the appliance's WorkPlace interface that lets an attacker make the device send requests to internal systems, turning an edge gateway into a pivot point. CVE-2026-15410 is a code-injection flaw in the management console that lets an administrator run operating-system commands, and SonicWall rates the overall advisory a top CVSS score of 10.0. Both were added to CISA's exploited-vulnerabilities catalog, with a federal deadline of July 17. Because exploitation is confirmed, any unpatched appliance should be treated as potentially compromised.

Check
Identify all SonicWall SMA1000 appliances, including standby and disaster-recovery nodes, apply the hotfix immediately, and review authentication logs, new accounts, outbound connections, and configuration changes for signs of intrusion.
Affected
Organizations running SonicWall SMA1000 remote-access appliances (CVE-2026-15409, CVE-2026-15410); attackers are actively exploiting the flaws, and the request-forgery and code-injection bugs could be chained to reach and run commands on internal systems.
Fix
Apply SonicWall's hotfix now, restrict management interfaces to trusted networks until patched, and because exploitation is confirmed, run a compromise assessment and assume unpatched appliances may already be backdoored.

Old Microsoft-signed Linux boot files let attackers bypass Secure Boot on most PCs

Researchers at ESET found 11 old Microsoft-signed Linux boot components, called shims, that can be used to bypass UEFI Secure Boot on almost any PC, regardless of its operating system. The trick needs no new vulnerability: because these shims were signed years ago with a trusted Microsoft certificate and never revoked, an attacker with admin or boot-level access can copy an old vulnerable shim onto a machine and run untrusted code before the operating system loads. That enables stealthy bootkits that survive reinstalls and start before security tools. Microsoft revoked all 11 in June by blocklisting their hashes, which Windows applies automatically and Linux systems can pull through firmware updates.

Check
Confirm the June UEFI revocation update reached your systems: Windows applies it automatically, while Linux hosts should pull it through the firmware update service, and use ESET's check for the revoked hashes.
Affected
Almost any UEFI-based computer trusting Microsoft's third-party 2011 certificate (CVE-2026-8863, CVE-2026-10797), regardless of operating system; an attacker with boot-level access can load an old signed shim to defeat Secure Boot.
Fix
Apply the UEFI revocation update on Windows and Linux, disable third-party UEFI signing where it is not needed, consider Secured-core hardware, and protect against the admin access these attacks require.

RabbitMQ flaws leak the broker's OAuth secret and expose cross-tenant data

Researchers at Miggo disclosed two access-control flaws in RabbitMQ, the widely used message broker, that have been present since early 2024. In the more serious one, an obsolete management endpoint had its authorization check hard-coded to always allow, so an unauthenticated attacker can leak the broker's confidential OAuth client secret in a single request, a direct path to full broker takeover where that secret is used. The second lets any logged-in user, even one with no assigned permissions, read other tenants' queue and exchange metadata, useful reconnaissance in shared environments. Both are fixed in updated releases, and the risk is sharpest where the management port is reachable from untrusted networks.

Check
Identify RabbitMQ instances on affected 3.13 and later releases, check whether the management interface and port 15672 are reachable from untrusted networks, and confirm how the OAuth client secret is configured.
Affected
RabbitMQ deployments from release 3.13.0 onward (CVE-2026-57219, CVE-2026-57221), especially cloud or multi-tenant setups with the management port exposed; attackers can leak the OAuth secret or read other tenants' metadata.
Fix
Update to a fixed RabbitMQ release, rotate the OAuth client secret if the management interface was internet-reachable, restrict access to port 15672, separate tenants by virtual host, and firewall the vulnerable endpoint.

148 npm packages posed as student proxies to turn browsers into a DDoS botnet

Researchers at JFrog found 148 npm packages that abused the registry not to attack developers but as free hosting for a booby-trapped web proxy aimed at students trying to bypass school filters. Anyone who opened one of the proxy sites had their browser quietly conscripted into a distributed denial-of-service botnet, flooding target servers with HTTP and WebSocket traffic, alongside injected ads and tracking. Crucially, the packages contained no install-time scripts and were never meant to be added to a project, so dependency scanners and install sandboxes, which watch what runs on install, would not catch them. The operators can re-arm the dormant attack code with a single commit.

Check
Consider that npm and similar registries can host malicious web content, not just installable code; watch for browsers reaching proxy or tutoring-themed sites backed by package registries, and block known campaign domains.
Affected
Anyone, especially students, who visits one of these registry-hosted proxy sites; their browser is silently used to launch denial-of-service attacks, while organizations may see the resulting traffic from their networks.
Fix
Block the campaign's known package and domain indicators, educate users that free web proxies can weaponize their browsers, and treat public package registries as potential malware-hosting infrastructure, not just a dependency source.

LabubaRAT poses as NVIDIA software to take remote control of Windows machines

Researchers at Blackpoint Cyber detailed LabubaRAT, a previously undocumented Rust-based remote access trojan that disguises itself as NVIDIA software to blend into target systems. It arrives as an executable impersonating NVIDIA's container runtime, then profiles the host, identifying installed browsers and security products such as Microsoft Defender, CrowdStrike, and SentinelOne. From there it can run commands and scripts, capture screenshots, move files, and proxy traffic, and it communicates over multiple channels, including HTTPS, WebView2, and DNS tunneling, so access survives if one path is blocked. Its command server details are supplied at runtime, letting attackers reuse the same binary across campaigns, and there are signs it is sold as a service.

Check
Watch for executables impersonating NVIDIA components, such as an unexpected nvidia-sysruntime.exe, and hunt for host-profiling behavior and command-and-control over DNS tunneling or WebView2 that endpoint tools may not flag by default.
Affected
Windows environments where an attacker can plant the malware; LabubaRAT gives hands-on remote control, identifies and works around security tools, and maintains access over several channels, making it hard to fully evict.
Fix
Verify NVIDIA and other software against official sources, deploy endpoint detection tuned for host-profiling and multi-channel command-and-control including DNS tunneling, restrict outbound traffic, and investigate unexpected proxy or SOCKS activity from endpoints.

Fake LastPass and Bitwarden security alerts lure users to phishing sites

LastPass is warning that attackers are impersonating it and Bitwarden with fake security alerts to lure password-manager users to phishing sites. The emails, sent from look-alike domains rather than the real services, mimic corporate notices about updated security policies and push recipients to a page impersonating DocuSign. LastPass stresses its systems were not breached and the messages did not come from its infrastructure. Password managers are attractive phishing targets because compromising one can unlock every stored credential, and users often trust vendor-branded alerts. Related campaigns have pushed fake more-secure desktop apps that actually install remote-access tools, and similar lures have impersonated other password managers.

Check
Remind users that password-manager vendors do not ask for the master password, and to verify any breach or policy alert by logging in through the official site or app, not emailed links.
Affected
LastPass and Bitwarden users, and by extension every credential in their vaults; convincing vendor-branded alerts from look-alike domains can trick them into entering their master password or installing remote-access malware.
Fix
Verify security notices through official portals, enable phishing-resistant multi-factor authentication on password managers, and if credentials were entered on a phishing site, change the master password from a trusted device.

CISA adds actively exploited Cisco IOS flaw to its must-patch catalog

CISA has added a Cisco IOS vulnerability to its Known Exploited Vulnerabilities catalog after confirming it is being used in real attacks, requiring federal agencies to patch it under a binding deadline. Cisco IOS and IOS XE run the routers and switches behind many enterprise and service-provider networks, so a flaw here can give attackers a foothold deep in the network path. The listing lands amid heightened warnings, including a joint US-and-allies advisory this week urging better router hygiene against Russian state-sponsored targeting of network devices. Network gear is attractive because it often sits unmonitored, stays online for years, and rarely runs endpoint security; timely patching is the main defense.

Check
Identify Cisco IOS and IOS XE devices, check them against Cisco's advisory for the newly listed flaw, and prioritize patching internet-facing and edge devices while reviewing configurations and logs for tampering.
Affected
Organizations running affected Cisco IOS or IOS XE network devices, especially internet-facing routers and switches; active exploitation means unpatched devices are at real risk of compromise deep in the network path.
Fix
Apply Cisco's fixed software promptly, restrict and monitor management interfaces, follow current router-hygiene guidance against state-sponsored targeting, and inspect device configurations and logs for signs of unauthorized changes.

Lidl notifies online shop customers of breach at a service provider

Discount supermarket chain Lidl has notified online shop customers in Germany, Belgium, and the Netherlands of a data breach that stemmed from a hack at one of its service providers rather than Lidl's own systems. According to the company, the exposed information involves customer contact and order-related details, while payment card data was not affected. The incident is another example of third-party or supply-chain risk, where attackers compromise a vendor to reach a larger brand's customer data. Even without financial data, the exposed details can fuel convincing phishing and scams that impersonate Lidl, especially messages referencing real orders to make fraudulent requests look legitimate to shoppers who recently used the online shop.

Check
Lidl online shop customers in the affected countries should watch for the notification, be wary of messages referencing Lidl or their orders, and avoid clicking links or sharing details in unsolicited messages.
Affected
Lidl online shop customers in Germany, Belgium, and the Netherlands whose contact and order details were exposed through a hacked service provider; payment card data was not affected.
Fix
Treat Lidl-themed messages with caution and verify through official channels. Organizations should assess vendors' security, limit the customer data third parties hold, and require breach-notification and security commitments in supplier contracts.

MemGhost plants lasting false memories in AI assistants through a single email

Researchers demonstrated MemGhost, an attack that uses one email to plant a false, persistent memory in an AI personal assistant with inbox access. Because these assistants keep notes about the user and reload them every session, a crafted message can trick the agent into saving a fabricated fact while keeping its reply innocuous, so the tampering goes unnoticed and steers later answers. The team trained an attacker model to write such emails automatically, reporting high success against open-source and commercial agents and showing it transfers across memory backends and survives several defenses. Unlike earlier one-shot injection that leaked data only in the moment, MemGhost's memory persists long after the email is gone.

Check
Review whether AI assistants in use have persistent memory and can read untrusted content, and check what controls govern what gets written to memory and whether changes are visible to the user.
Affected
Users of AI personal assistants with persistent memory and inbox access; a single crafted email can silently write a false memory that biases the assistant's answers across future sessions.
Fix
Prefer assistants that log and let users review memory changes, restrict what untrusted content can write to long-term memory, isolate memory from email-triggered actions, and periodically audit stored agent memories.

CrashStealer Mac malware uses an Apple-notarized app to slip past Gatekeeper

Jamf detailed CrashStealer, a macOS infostealer delivered through a signed, Apple-notarized app called Werkbit that passes Gatekeeper, since it carried a valid developer ID before Apple revoked it. Distributed as a disk image and gated behind a meeting PIN so it is served only to targeted visitors, the malware validates the victim's login password locally, then harvests broadly from browsers, cryptocurrency wallets, password managers, and the keychain, encrypting the loot before sending it out. It persists by copying and re-signing itself. There is no zero-click stage: a victim still runs the app and enters their password, but the notarized delivery and careful targeting make it more convincing than typical Mac stealers.

Check
Remind Mac users that notarization does not guarantee an app is safe, to be cautious of apps delivered by disk image behind meeting codes, and to refuse password prompts from unexpected installers.
Affected
Mac users who download and run the notarized Werkbit app and enter their password; CrashStealer then steals browser data, crypto wallets, password-manager contents, and keychain secrets, and reinstalls itself to persist.
Fix
Install apps only from trusted sources, treat unexpected password and disk-image prompts with suspicion, keep macOS and endpoint tools updated to catch known indicators, and monitor for apps copying and re-signing themselves.