Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hundreds of fake Chrome VPN extensions route traffic through a proxy

    August 12, 2026

    Infosec News Nuggets — August 12, 2026 – AboutDFIR

    August 12, 2026

    Help shape the future of resilient private 5G

    August 12, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Infosec News Nuggets — August 12, 2026 – AboutDFIR
    News

    Infosec News Nuggets — August 12, 2026 – AboutDFIR

    adminBy adminAugust 12, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Microsoft Plugs Nearly 400 Security Holes

    August’s Patch Tuesday saw Microsoft fix 398 vulnerabilities across Windows and supported software, with 42 rated critical. The lone actively exploited zero-day, a privilege escalation flaw in the AFD.sys WinSock driver, gives attackers a path to SYSTEM control after gaining an initial low-privilege foothold. Microsoft has attributed the swelling patch volumes to vulnerability discoveries increasingly aided by artificial intelligence, and researchers note that while AI is proving adept at finding flaws, generating reliable fixes for them remains a largely human-driven task.

     

    BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

    A supply chain compromise at WordPress plugin vendor BdThemes let attackers silently create rogue administrator accounts and install web shells across seven popular Elementor add-ons without altering a single line of code in the official repository. Threat actors instead poisoned a JSON feed pulled by an internal promotional banner system, exploiting a cross-site scripting flaw so the malicious script fires in every logged-in admin’s browser, creates a hidden administrator, and deploys a persistence backdoor. The affected plugins have been pulled from the WordPress directory pending review.

     

    A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond

    A cyberattack that began July 29 against logistics giant Ceva has disrupted at least eight European warehouses and exposed customer names, addresses, phone numbers and order details belonging to clients including Bol, De Bijenkorf, Ajax, ING and Valve’s Steam hardware division. Ceva says the operational impact is confined to those eight sites and that all other global operations continue normally, though its own website was intermittently unreachable following the incident. Dutch authorities have received breach reports from ten separate organizations tied to the intrusion.

     

    Healthcare and Victim Support Charities Affected by Beacon Cyber Incident

    Roughly 1,500 UK charities, including hospices and victim-support organizations, were notified that donor and supporter data held in the Beacon CRM platform was likely accessed and exfiltrated after a compromised access key gave an unauthorized party entry to the company’s systems. The stored data was encrypted, but Beacon warned it cannot rule out that the attacker managed to decrypt it, and has told customers to assume any information they stored, including attachments, was downloaded. No financial or payment data was involved, and affected organizations have been directed to report the incident to the UK’s Information Commissioner’s Office.

     

    CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

    Researchers disclosed a critical authentication bypass in the JWT token validation pipeline of on-premises SharePoint Server, allowing an unauthenticated attacker who knows a target user’s identifier to impersonate that user, including administrators, and carry out actions on their behalf. The flaw was chained with a still-unpatched remote code execution bug to achieve full unauthenticated RCE during a Pwn2Own entry, though patching this authentication bypass alone breaks that exploit chain. A substantial portion of the research that uncovered the flaw was conducted through AI agentic tooling, which the researchers say markedly improved between their first and second research sprints.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHelp shape the future of resilient private 5G
    Next Article Hundreds of fake Chrome VPN extensions route traffic through a proxy
    admin
    • Website

    Related Posts

    News

    Hundreds of fake Chrome VPN extensions route traffic through a proxy

    August 12, 2026
    News

    Help shape the future of resilient private 5G

    August 12, 2026
    News

    Researchers Show How Meta’s ‘Pervert Glasses’ Are Used to Harass Women

    August 12, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    Hundreds of fake Chrome VPN extensions route traffic through a proxy

    August 12, 2026

    Infosec News Nuggets — August 12, 2026 – AboutDFIR

    August 12, 2026

    Help shape the future of resilient private 5G

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.