CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
CISA added a critical flaw in the open-source Ray distributed computing framework to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug, rated 9.4 in severity, stems from Ray’s lack of authentication on core endpoints and can be chained with a DNS rebinding attack so that simply visiting a malicious website or ad in Firefox or Safari triggers remote code execution on a developer’s machine, with the attack also capable of reaching network-adjacent Ray instances inside corporate networks. Federal agencies have been told to apply the fix, shipped in Ray version 2.52.0, by August 20.
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p extortion gang has now publicly named more than 40 organizations, including Shell, Philips, Fiserv, Zebra Technologies, and Mindray, that it claims to have hit through a critical unauthenticated code execution flaw in PTC’s Windchill and FlexPLM product lifecycle management software. Attackers used a custom web shell that maps and decrypts Windchill’s credential vault and doubles as a backdoor for follow-on activity such as lateral movement or ransomware deployment, stealing engineering files, blueprints, and other corporate data ranging from 1 GB to several terabytes per victim.
Trezor says 13,689 customers hit by data breach at shipping partner
Hardware wallet maker Trezor disclosed that unauthorized access to systems at its mailing partner ShipMonk exposed the personal data of nearly 13,700 customers who placed orders between May and August across seven countries. Roughly 12,000 of those affected had their full name, address, phone number, and email leaked, while the rest had a smaller set of details exposed, and Trezor is warning recipients to watch for phishing attempts by mail, phone, or email since its devices and private keys were not compromised.
Rogue ransomware affiliate poses as recovery firm to steal payments
Researchers have identified a suspected ransomware affiliate operating under the name “Ransom Busters” that contacts victims before their attacks become public, offering to delete stolen data and hand over decryption keys for fees between $20,000 and $60,000. Overlapping tooling and infrastructure across multiple incidents tied to different ransomware-as-a-service brands suggest this is a single affiliate attempting to divert ransom payments away from the operations it works with, rather than a legitimate recovery service, and investigators are discouraging victims from paying.
ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
A newly disclosed elevation-of-privilege flaw in the Microsoft Malware Protection Engine, dubbed ShieldBreak and tracked as CVE-2026-69414, sidesteps the fix Microsoft shipped in July for a related bug called RoguePlanet, allowing a local attacker to gain SYSTEM-level control through a different exploitation path. Proof-of-concept code is already public and no official patch is available yet, though testing indicates the exploit chain requires Defender itself to be active to succeed.