August 1, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

For the past week, the only time I’ve used my electronic work-related tools has been to peruse news reports for inclusion into this report, to curate the links, and to write this summary. That’s not to say that it has been a dearth of technology, I’ll write about that in my Musings section in a bit.

This commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. So, on to the headline news.

Headline NEWS:

  • Adobe Campaign Classic has a CVSS 10.0 flaw, yes the same Campaign Classic that had a CVSS 10.0 in my July 4th RedDotSecurity.news edition. The defect, which can allow for code execution in the context of the current logged in user, without any interaction by that user. Adobe isn’t aware of any active exploitation yet. A patch has been released for this, for eight critical defects in Adobe Bridge, and one in Adobe Format Plugins. If you use Adobe products, update soon.
  • Hackers targeted municipal water systems in 7 states this week, according to the FBI. The headline writers really need some lessons in the English language, they are not “hackers”, this sort of attack has that potential to poison millions of people. They are “Terrorists”, not “hackers”. The evil actors were able to affect the water pressure at a number of facilities, which resulted in manual operations going into effect, and boil water notices across a multiple water systems. The Federal government is tentatively attributing the attacks to Iran, and has called upon all system operators to take their vulnerable systems off the internet.
  • Breaking news – N-Able RMM has a massive hole that needs to be patched immediately. https://www.huntress.com/blog/n-able-vulnerability-exploitation
  • Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution. Broadcom announced that VMware vCenter, and items that rely on it, such as VMware ESX, VMware Fusion, VMware Workstation, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud all require patches. There are no work arounds, and all are rated critical. If you have a VMware subscription, update quickly. Note that you’re required to have an active update subscription to get and use security updates from Broadcom. Otherwise, no patch for you.

In Ransomware, Malware, and Vulnerabilities News:

  • IBM: AI-driven attacks increased 56% last year, and data breach costs are up 12%. IBM puts out a yearly comprehensive publication named “Cost of a Data Breach Report”. The 2026 edition has some very sobering numbers that every organization should keep in mind, especially when shopping for cyber insurance coverage. The average cost for a data breach climbed to $4.99 million dollars last year, a 12% increase over the previous year. When AI is involved, which increased exponentially and grew at 56% last year, the cost rises to $6 million per average breach. The numbers cited are global. When you narrow down to the US, and factor in regulatory fines, and other costs such as notification requirements, the average cost goes to $11.5 million. Can your business absorb such a cost? There is some good news reported, organizations that employed AI in their defenses saved $1.93 million, and significantly lowered breach times.

In Other News Events of Note and Interest:

  • Anthropic says its internal models got online and cyberattacked 3 other organizations. Pandora has escaped the box – again, and again, and again. This should send chills up the spines of every security professional. First, it was OpenAI’s pair bots that broke out like Frank Morris, and the Anglin brothers from Alcatraz, and now Anthropic reports that a crew of three breached the walls of their forced confinement to breathe the rarified air of the open internet. Once there, several organizations were subsequently breached by the trio of determined AI jailbirds. Even more chilling is that one of the newly liberated decided that the best way to achieve its goal was to deploy a malicious Python package, which was then downloaded by 15 organizations. Yeah, this is not looking good. How long before we have a Morris worm event?

Musings

I find that even when on vacation, it is impossible to escape my technological overlords. I suppose if I truly put my mind to it, and carefully planned in advance, I’d be able to pull it off, but that seems incredibly Luddite. I use my phone to navigate the most efficient, or least crowded, or most scenic route to my destination. I use it to find points of interest, food, gas, and lodging. I use my credit card to pay for just about everything, and since I have it linked to my phone for easy tap-to-pay, I always have it with me. We listen to Audible books via a Bluetooth connection in the car. I take pictures with my phone, lots of pictures. And I read news to stay up-to-date so that I can write this column. Yeah, I’m a slave to my technology. Thankfully, it isn’t sentient yet.

Visc. Jan Broucinek

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

 

Share this with: