August 8, 2026

Hello all,

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

My vacation ends this weekend. It has been nice to unplug to some degree, but as you’ve noticed, I always keep the shields up and stay abreast of cyber-happenings. There were a few important ones this past week, so let’s get to them.

Headline NEWS:

  • Cisco patched several products, SD-WAN, IOS XE, Integrated Management Controller (IMC), Terminal Service (TS) Agent, Catalyst SD-WAN Manager, RoomOS,and Secure Firewall Management Center (FMC). While none are known to be currently exploited, it is only a matter of time before they are successfully attacked since Proof of Concept (PoC) code already exists for at least one of the defects. Of special concern is the NOT-Secure Firewall Management Center that has a CVSS 10.0 and a CVSS 8.8 vulnerability that can enable unauthenticated remote code access as root.
  • cPanel has a critical defect that can allow privilege escalation, enabling authenticated users to execute SQL commands as root. This enables the attacker to bypass restrictions regarding administrative functions, and depending on the database configuration, could allow access to the underlying operating system. cPanel, WHM, and WP Squared have patches available and should be applied sooner than later.
  • Metabase SQLi is under active exploitation from a zero-day vulnerability that has resulted in some high-profile customers such as LexisNexis experiencing data-theft. “The vulnerability is an unauthenticated SQL injection flaw in Metabase that can ultimately give a remote attacker administrator access to a customer’s instance.” Cloud hosted instances have been patched now. However, self-hosted versions 1.58 and above are vulnerable and should immediately apply the Metabase patch to patch this critical defect. The vendor has guidance on patching, mitigation, and in detecting compromise.
  • N-able N-central God mode flaw Late last week Huntress broke the news that N-central had a critical defect that was allowing threat actors to take over the RMM and subsequently infect client devices. This week, N-able identified that the first patch was insufficient and released a second one. If you use N-central and self-host, it is critical that you apply the newly released patch immediately. If your instance is cloud-hosted by N-able, they’ve taken care of the patching.
  • TP-Link Omada Zero Touch Provisioning (ZTP) defects allow evil doers to chain vulnerabilities and achieve remote code execution (RCE) access. There were over a dozen flaws found across much of the Omada product line. Updates are available and should be implemented without haste.

In Ransomware, Malware, and Vulnerabilities News:

  • Over 4,400 Rockwell PLC’s Exposed Online. The recent attacks on municipal water systems across the US should serve as a jarring wakeup call to public sector utilities. They cannot continue to operate as if the world was unchanged. Postmortem investigations continue, but at this point it is known that up to a dozen states were impacted by the recent attack. Right now, the focus is on Rockwell, which has advised utilities to take Programmable Logic Controllers (PLC’s) off the internet. However, there are at least seven other vendors that make similar products. The 4K number is rather sobering. That was current as of a week ago.

In Other News Events of Note and Interest:

  • OpenAI agents rebuilt a secret message board after the company shut it down. This headline is another in a line of ones that is rapidly convincing me that Pandora has escaped the box. The AI’s are doing things that their makers didn’t intend and didn’t want them to do. They are solely task oriented and will conspire together, as was seen on the message board of their own making, to get around obstacles and guardrails put into place. One AI agent even offered to contribute computing power to the collective so that they could achieve root access. Scary stuff.

Musings

I’m in the final hours of a much-needed time of vacation. We took a road trip through the heartland of the USA. It was fascinating to see the impact of two technological wonders upon the landscape. The first one is the highway system; it enables cars and trucks to traverse incredible distances efficiently and usually swiftly. The second is the railway system. It likewise enables commerce across vast distances. The impact of both technologies was very evident; where there were intersections of rail and highway, there were thriving towns, and cities. Where there was just one, a town or small village might appear along the path. Everywhere in the heartland there were miniscule communities of only hundreds of residents that cannot exist without one or the other, rail or highway. And there were plenty of ghost towns that had been bypassed by the highway or had their rail service stopped. Our modern world is dependent upon myriads of technological advances. I’m very grateful for what these two bring and for those who carved the routes out of the untamed wilderness.

Visc. Jan Broucinek

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

 

Share this with: