Wednesday , August 12 2026
Cisco

CVE-2026-20349, CVE-2026-68820
Cisco and Windows patched zero days exploited in attack

Cisco warns customers that it has fixed a serious security hole in firewalls using Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The flaw tracked as CVE-2026-20349, is related to the processing of HTTP requests.

An attacker can make a device restart and make a denial-of-service (DoS) issue by sending a special HTTP request to the Remote Access SSL VPN service. Cisco has asked customers to use the hotfixes right away. CISA added CVE-2026-20349 to its list of known problems on Tuesday, telling federal agencies to fix it by August 14.

CVE-2026-20349, CVE-2026-68820
Cisco and Windows patched zero days exploited in attack

Cisco warns customers that it has fixed a serious security hole in firewalls using Secure Firewall Adaptive Security Appliance (ASA)...
Read More
CVE-2026-20349, CVE-2026-68820  Cisco and Windows patched zero days exploited in attack

Microsoft Patch 394 Flaws, Including 3 Zero-Days

Microsoft announced fixes for 394 CVEs on Tuesday, including a serious flaw that has been used by hackers as a...
Read More
Microsoft Patch 394 Flaws, Including 3 Zero-Days

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else's device in a live meeting...
Read More
AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

Hacker Actively Exploit SonicWall and SharePoint Flaws

The CISA in the U.S. has added two important SonicWall SMA1000 flaws—CVE-2026-15409 and CVE-2026-15410-to its list of Known Exploited Vulnerabilities...
Read More
Hacker Actively Exploit SonicWall and SharePoint Flaws

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service,...
Read More
Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link that looked like a real...
Read More
Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Android users are reminded that a known app store listing can hold a money threat. Researchers found harmful loaders on...
Read More
Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer Incident Response Team (BGD e-GOV...
Read More
Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

A group of almost 800 harmful packages was added to the npm registry in a new effort to spread malware...
Read More
Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Google has launched Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update brings 41 security...
Read More
Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Windows AFD.sys 0-Day Actively Exploited

North Korea’s Lazarus group has been found using a Windows flaw to install a new version of its FudModule rootkit, based on new findings from Check Point Research.

The flaw, dubbed CVE-2026-68820, is found in AFD.sys, which is the driver that controls network sockets in the Windows kernel. Microsoft fixed it on August 11 during its August Patch Tuesday update, just a few days after Check Point shared the issue.

Successful use of CVE-2026-68820 gives attackers SYSTEM-level access and starts FudModule, the Lazarus group’s known kernel-mode rootkit that first appeared in 2021 and was earlier connected to a different AFD.sys use-after-free issue, CVE-2024-38193.

Check Point found at least 17 different hacked relay nodes. They also saw the group using VPN services like ExpressVPN to hide where they came from.

Organizations using Windows 11 versions 26100 or 26200 should focus on the August Patch Tuesday update to fix CVE-2026-68820. Security teams in the defense sector should closely monitor outgoing traffic to Roundcube and CMS-hosted systems that might be acting as hidden relay points instead of real mail servers.

Check Also

Bank of Baroda

Massive customer data from India’s Bank of Baroda surfaced online

India’s leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that …