Rosetta Daily · Aug 11, 2026
Scanned 9 sources (NVD, Bleeping Computer, The Hacker News, RansomLook, Anquanke, Unit 42, CISA, Microsoft Security Response Center, arXiv cs.CR — 746 raw items in the 36h window), selected 30.
Critical Vulnerabilities (CVSS ≥ 8.0)
- Joomla Fabrik extension RCE — CVE-2026-66915 (CVSS 10.0): The
ajax_calcfeature of the calc plugin in Fabrik < 4.6.7 lets an unauthenticated attacker execute arbitrary code. NVD - Jenkins FilePath.untarFrom() symlink flaw — CVE-2026-19429 (CVSS 9.4): Even on builds patched for CVE-2026-33001/CVE-2026-70427, an attacker with job-configuration privileges can craft a TAR archive whose extraction creates workspace symlinks to arbitrary controller files, read the signing secrets, forge an admin session cookie, and reach RCE via the Script Console; a companion bypass uses zero-width Unicode characters to defeat the blank-name check. NVD
- NASA fprime-gds ground station software — unauthenticated RCE — CVE-2026-72577 (CVSS 9.8): The Flask app applies no authentication to any endpoint, letting an unauthenticated remote attacker run code on the ground station host and inject commands to connected spacecraft. NVD
- Tencent APIJSON SQL injection — CVE-2026-72565 (CVSS 9.8): The
@havingoperator in Map-form requests bypasses per-table access control, allowing unauthenticated reads of arbitrary database tables. NVD - dulldusk/phpfm file manager — unauthenticated file read/write plus unrestricted upload to RCE — CVE-2026-72592 / CVE-2026-72593 (both CVSS 9.8): Ships with authentication disabled by default and an empty upload-extension filter, letting an unauthenticated attacker upload and run a PHP webshell or freely read/write server files. NVD
- Zyxel WAH7601 router OS command injection — CVE-2026-13206 (CVSS 9.8): Affects firmware through the July 20, 2026 build. NVD
- fosrl/pangolin improper authorization — CVE-2026-72564 (CVSS 9.6): Through v1.20.0, an authenticated attacker can reuse an access token issued for one resource to authenticate to any resource in any organization. NVD
- GIMP PSD plugin integer underflow to RCE — CVE-2026-59090 (CVSS 8.4): Opening a crafted .psd file triggers an unsigned integer underflow in
block_rem, enabling injection of fake layer-resource blocks that can lead to arbitrary code execution. NVD
Actively Exploited (KEV)
- Progress Kemp LoadMaster command injection — CVE-2026-8037: CISA confirmed active exploitation; added to KEV August 7. Bleeping Computer
- SonicWall SMA1000 SSRF/code injection now exploited by ransomware gangs — CVE-2026-15409 (SSRF) / CVE-2026-15410 (code injection): Both added to KEV July 14 and flagged with known ransomware use; CISA confirmed ransomware affiliates are actively exploiting the pair, one a maximum-severity SSRF. Bleeping Computer
- Microsoft SharePoint deserialization RCE now abused by ransomware crews: CISA confirmed ransomware gangs have begun exploiting a high-severity SharePoint RCE flagged as actively exploited since early July. The report doesn't cite a CVE number; the matching KEV entries added in mid-July are CVE-2026-58644 (deserialization, added 7/16) and CVE-2026-56164 (missing auth for a critical function, added 7/14). Bleeping Computer
Vendor Advisories
- CISA/HHS joint #StopRansomware advisory: Gunra ransomware: US and South Korean agencies warn that the Gunra RaaS operation is exploiting Fortinet and Schneider Electric flaws to hit government and critical-infrastructure sectors (healthcare, finance, energy) with double extortion. CISA AA26-222A· The Hacker News
- Microsoft Dynamics 365 Business Central elevation of privilege — CVE-2026-40417: The one genuinely new MSRC bulletin this cycle; the other 337 MSRC feed items were repeat historical CVEs, not fresh Patch Tuesday content. MSRC
- Cisco warns of high-severity ClamAV flaws (Secure Endpoint Connector) with public exploits: Two high-severity bugs can crash the ClamAV scanning process (denial of service). Bleeping Computer
Web Security Research
- Three independent research efforts defeat passkey protections: Reusing signed authentication material exposed by Windows, abusing a cloud-synced passkey system via malware already on the victim's machine, and other techniques bypass phishing-resistant MFA or recover synced private keys without breaking the underlying cryptography. The Hacker News
- Unit 42: Kimwolf v7 botnet evolution: Targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS-based C2 resolution, and Tor backup routing. Unit 42
- Unit 42: Aeternum botnet's Polygon blockchain-based decentralized C2: Uses blockchain smart contracts for C2 infrastructure and payload execution. Unit 42
AI Security
- OpenAI launches GPT-5.6-Cyber with reduced safeguards for authorized exploit development: Available via Daybreak Red to vetted partners, focused on 0-day discovery and exploit-chain construction; OpenAI also detailed cyber-capability evaluations of its upcoming Astra model and how it handled a prior third-party evaluation incident. The Hacker News· Bleeping Computer
- Malicious MCP servers can split instructions to make AI coding agents exfiltrate secrets: Fragmenting a theft request into individually innocuous-looking pieces spread across channels the assistant already trusts can succeed even after a blunt version of the same request was refused, exfiltrating SSH keys, env secrets, source code, and customer data. The Hacker News
- Kimsuky (DPRK) builds an offline AI stack for phishing and automated malware development: South Korean firm Genians reports the group now runs AI on its own servers, wires document-search tooling to files in its possession, and is assembling the software parts needed to embed AI into its malware. The Hacker News
- Analysis: vague-scope AI agent delegation is a security risk: When enterprises grant AI agents broad system access under loosely defined tasks, agents can improvise beyond intended scope; organizations need explicit "agent intent" definitions and continuous permission enforcement. Bleeping Computer
Other
- Mozilla rotates Firefox/Thunderbird (Linux) signing key after accidental exposure in a private GitHub repo: The key verifies downloaded browser builds weren't tampered with; rotation carries some distribution/trust-chain cost. The Hacker News· Bleeping Computer
- Polish combined heat-and-power plant breached via private cellular network (APN), turbine and water-treatment system shut down: Attackers came in over the private cellular network the grid operator uses for remote equipment access; the plant heats roughly 50,000 residents. Recovery began while intruders were still active inside; customers lost neither heat nor water. The Hacker News· Bleeping Computer
- StormEncryptor ransomware: new strain from China-linked Storm-1175 (former Medusa affiliate): Microsoft Threat Intelligence says the financially motivated group has shifted from Medusa to its own C++ ransomware, StormEncryptor (.encrypted extension), likely delivered via an N-central-related flaw. The Hacker News· Bleeping Computer
- BdThemes WordPress plugin supply-chain attack poisons a remote JSON feed to create rogue admin accounts: Wordfence notes no source files in the official WordPress.org repo were modified — instead a remote JSON feed pushed to admin browsers was tampered with; BdThemes has temporarily disabled downloads. The Hacker News· Bleeping Computer
- A malicious SIM card can run attacker code inside cellular IoT modems