
Cyber Security News for August 12 2026 - Daily DefSec Brief
Show notes
1. Windows WinSock use-after-free zero-day exploited by Lazarus — CVE-2026-68820 — SecurityWeek — https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/
2. Cisco ASA/FTD VPN flaw exploited to crash firewalls — CVE-2026-20349 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
3. Microsoft Defender 'ShieldBreak' PoC bypasses patch for SYSTEM — CVE-2026-50656 — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges/
4. SharePoint RCE chain fully disclosed — CVE-2026-63520, CVE-2026-55040 — Rapid7 — https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed
5. SAP Commerce Cloud max-severity RCE — CVE-2026-58231 — The Hacker News — https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html
6. Adobe ColdFusion and Campaign Classic critical RCE flaws — CVE-2026-48362, CVE-2026-48273, CVE-2026-71384 — SecurityWeek — https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/
7. Zoom annotation zero-click RCE between participants — CVE-2026-53413, CVE-2026-53414, CVE-2026-53415 — The Hacker News — https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html
8. SonicWall critical RCE in discontinued GMS platform — CVE-2026-66147, CVE-2026-66145 — SecurityWeek — https://www.securityweek.com/sonicwall-patches-critical-vulnerabilities-in-discontinued-gms-platform/
9. Ivanti EPM remotely exploitable flaws — CVE-2026-18129, CVE-2026-18125, CVE-2026-18127 — SecurityWeek — https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
10. Sandworm subgroup pushes trojanized WireGuard VPN via fake interviews — BleepingComputer — https://www.bleepingcomputer.com/news/security/sandworm-hackers-target-it-pros-with-trojanized-wireguard-vpn-client/
11. ClickFix abuses signed IBM SPSS IDE to deploy CNCMachineRMS RAT — Cyber Security News — https://cybersecuritynews.com/clickfix-attack-ibm-spss-ide/
12. CAV3RN espionage framework hides C2 behind Google Apps Script — Cyber Security News — https://cybersecuritynews.com/cav3rn-uses-google-apps-script/
13. Malicious SIM card runs attacker code inside cellular IoT modems — CVE-2021-31698, CVE-2025-48618, CVE-2026-57550 — The Hacker News — https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
14. Microsoft patches high-severity Outlook RCE — CVE-2026-70329 — Cyber Security News — https://cybersecuritynews.com/microsoft-outlook-rce-vulnerability-2/← Previous
Cyber Security News for August 11 2026 - Daily DefSec Brief
Next →
Cyber Security News for August 13 2026 - Daily DefSec Brief