
Cyber Security News for August 7 2026 - Daily DefSec Brief
Show notes
1. SOGo webmail XSS exploited in the wild via malicious calendar invites — CVE-2026-8496 — CERT/CC — https://kb.cert.org/vuls/id/487613
2. INTERRUPT INJECTION / TONTOU bypasses Spectre v2 fixes, leaks Linux password hashes — CVE-2023-20569 (ref.) — The Hacker News — https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html · BleepingComputer — https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
3. Microsoft M365 AitM phishing hijacks accounts to harvest payroll and finance email — The Hacker News — https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
4. UNC6671 vishing campaign automates M365/Okta data theft after stealing live tokens — Cyber Security News — https://cybersecuritynews.com/unc6671-automates-microsoft-365/ · BleepingComputer — https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/
5. Windows Hello for Business keys can be abused for persistent Entra ID access — The Hacker News — https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
6. Cisco patches 15 SD-WAN and IOS XE flaws, three at CVSS 9.9 — CVE-2026-20303, CVE-2026-20304 — The Hacker News — https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
7. Microsoft patches three CVSS 10 flaws in Azure, Teams; Apple ships updates — CVE-2026-63508, CVE-2026-56162, CVE-2026-65667 — SecurityWeek — https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/
8. Chrome 151 fixes 41 flaws including six critical use-after-frees — SecurityWeek — https://www.securityweek.com/critical-vulnerabilities-patched-with-chrome-151-update/
9. Zapscape KVM flaw lets a privileged L1 guest escape to the Linux host — CVE-2026-64561 — The Hacker News — https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
10. NatJack manipulates NAT state to hijack TCP sessions and spoof DNS — CVE-2026-56181, CVE-2026-63913 — The Hacker News — https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html
11. CryptoJS weak RNG behind $5.7M in crypto wallet drains — The Hacker News — https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html
12. Datasette SQL injection lets public-table users read private tables — Simon Willison — https://simonwillison.net/2026/Aug/6/datasette/#atom-everything
13. Thousands of Rockwell water-system controllers still exposed online — CVE-2017-16740 — CyberScoop — https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/ · The Hacker News — https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html
14. AI-assisted research tool finds new HTTP desync techniques and an Apache Traffic Server zero-day — CVE-2026-63078 — The Hacker News — https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html
15. Kimi K3 AI model broke out of its test sandbox to reach the internet — Cyber Security News — https://cybersecuritynews.com/kimi-k3-ai-model-escapes-sandbox/
16. Claude Code and Gemini CLI flaws let a GitHub issue reach CI secrets — CVE-2026-12537, CVE-2026-54316 — The Hacker News — https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
← Previous
Cyber Security News for August 6 2026 - Daily DefSec Brief
Next →
Cyber Security News for August 10 2026 - Daily DefSec Brief