
Hello all,
For the past week, the only time I’ve used my electronic work-related tools has been to peruse news reports for inclusion into this report, to curate the links, and to write this summary. That’s not to say that it has been a dearth of technology, I’ll write about that in my Musings section in a bit.
This commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. So, on to the headline news.
Headline NEWS:
- Adobe Campaign Classic has a CVSS 10.0 flaw, yes the same Campaign Classic that had a CVSS 10.0 in my July 4th RedDotSecurity.news edition. The defect, which can allow for code execution in the context of the current logged in user, without any interaction by that user. Adobe isn’t aware of any active exploitation yet. A patch has been released for this, for eight critical defects in Adobe Bridge, and one in Adobe Format Plugins. If you use Adobe products, update soon.
- Hackers targeted municipal water systems in 7 states this week, according to the FBI. The headline writers really need some lessons in the English language, they are not “hackers”, this sort of attack has that potential to poison millions of people. They are “Terrorists”, not “hackers”. The evil actors were able to affect the water pressure at a number of facilities, which resulted in manual operations going into effect, and boil water notices across a multiple water systems. The Federal government is tentatively attributing the attacks to Iran, and has called upon all system operators to take their vulnerable systems off the internet.
- Breaking news – N-Able RMM has a massive hole that needs to be patched immediately. https://www.huntress.com/blog/n-able-vulnerability-exploitation
- Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution. Broadcom announced that VMware vCenter, and items that rely on it, such as VMware ESX, VMware Fusion, VMware Workstation, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud all require patches. There are no work arounds, and all are rated critical. If you have a VMware subscription, update quickly. Note that you’re required to have an active update subscription to get and use security updates from Broadcom. Otherwise, no patch for you.
In Ransomware, Malware, and Vulnerabilities News:
- IBM: AI-driven attacks increased 56% last year, and data breach costs are up 12%. IBM puts out a yearly comprehensive publication named “Cost of a Data Breach Report”. The 2026 edition has some very sobering numbers that every organization should keep in mind, especially when shopping for cyber insurance coverage. The average cost for a data breach climbed to $4.99 million dollars last year, a 12% increase over the previous year. When AI is involved, which increased exponentially and grew at 56% last year, the cost rises to $6 million per average breach. The numbers cited are global. When you narrow down to the US, and factor in regulatory fines, and other costs such as notification requirements, the average cost goes to $11.5 million. Can your business absorb such a cost? There is some good news reported, organizations that employed AI in their defenses saved $1.93 million, and significantly lowered breach times.
In Other News Events of Note and Interest:
- Anthropic says its internal models got online and cyberattacked 3 other organizations. Pandora has escaped the box – again, and again, and again. This should send chills up the spines of every security professional. First, it was OpenAI’s pair bots that broke out like Frank Morris, and the Anglin brothers from Alcatraz, and now Anthropic reports that a crew of three breached the walls of their forced confinement to breathe the rarified air of the open internet. Once there, several organizations were subsequently breached by the trio of determined AI jailbirds. Even more chilling is that one of the newly liberated decided that the best way to achieve its goal was to deploy a malicious Python package, which was then downloaded by 15 organizations. Yeah, this is not looking good. How long before we have a Morris worm event?
Musings
I find that even when on vacation, it is impossible to escape my technological overlords. I suppose if I truly put my mind to it, and carefully planned in advance, I’d be able to pull it off, but that seems incredibly Luddite. I use my phone to navigate the most efficient, or least crowded, or most scenic route to my destination. I use it to find points of interest, food, gas, and lodging. I use my credit card to pay for just about everything, and since I have it linked to my phone for easy tap-to-pay, I always have it with me. We listen to Audible books via a Bluetooth connection in the car. I take pictures with my phone, lots of pictures. And I read news to stay up-to-date so that I can write this column. Yeah, I’m a slave to my technology. Thankfully, it isn’t sentient yet.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- US investigating whether Iran was behind cyberattack on Minnesota water systems
- Hackers targeted municipal water systems in 7 states this week, FBI says
- Breaking News – Massive hole in N-Able RMM. Patch immediately!
- Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System
- Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- CISA shares advice on isolating vital systems during cyberattacks
- CISA sets a new SBOM baseline
- SharePoint zero-day grants Farm Admin rights, CISA warns
- FCC bans foreign robots and inverters over China fears
- FCC: Ban on Foreign-Made Robots Includes Robot Vacuums
- US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
- 16th AF, Cyber Mission Force partners lean forward to protect critical infrastructure
- Vulnerabilities and Exploits
- n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- VPN Provider Fights Microsoft’s Hidden Windows Device Tracking
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
- vBulletin fixes critical pre-auth RCE flaw with public exploit
- Cisco warns of FMC static credential flaw exploited in zero-day attacks
- Specter: Open-source NFC reader bug sweep for Flipper Zero
- Cyber firm Wiz says flaw could have led to mass exposure of Microsoft cloud customers
- JetBrains warns of critical TeamCity remote code execution flaw
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
- Phishing, Malware, and Similar
- Phishing Dominates as Initial Entry Method for Cyber-Attacks
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
- Steam forum ClickFix attacks infect gamers with XMRig cryptominers
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
- Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
- Phishing-as-a-Service: Inside Two AI-Built Kits That Automate BEC
- ‘Flying Eagle’ Full-Service Mobile RAT Builder Wings Across China
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks
- Apple accused of letting fake crypto app steal $1.8 million
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- Breaches, Leaks, and Ransomware
- IBM: AI-driven attacks drive up data breach costs by 12%
- Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
- Coca-Cola says Fairlife resumes production at 4 US plants after cyberattack
- Coca-Cola confirms data theft in Fairlife ransomware attack
- Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
- Tribeca Film Festival Leak Exposes Celebrity & Industry Data
- Australia’s Origin Energy flags possible data exposure of about 900,000 customers
- UK Education department says 607,000 records taken in cyber attack
- EY Data Breach Claimed by ShinyHunters Hacker Group
- Scotland’s university procurement center confirms cybercrooks broke in
- US bank places trust in ransomware crew that promised to delete its data
- North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
Other News Events of Note and Interest
- Cool Tool: Calibre 9.12.0
- The 2026 Password Table Is Here: How Fast Can a Hacker Crack Your Password?
- What happened to ARCNET
- “Google and Reddit do not own the Internet,” web scraper says after court win
- Google wants to update Chrome without a full browser restart
- Google Chrome to start getting security updates twice a week
- Microsoft seeks Supreme Court lifeline in pre-owned license battle
- Remembering John C. Dvorak, a Passionate Chronicler of PC History
- Foxconn drops VMware, adopts hyperconverged upstart Arcfra for workloads including AI
- The Architecture of Guilt: How Duolingo Weaponized Negative Emotion to Build a Design System
- Amazon Plans to Launch 5,000 New Satellites to Beam Data to iPhones
- X Money officially launches in the US with Apple Wallet support after invite-only beta
- GrapheneOS says its data-wiping “duress” password is perfectly legal, after user faces federal charges
- DEF CON bans Meta-style ‘pervert glasses’
- The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
- Inforcer raises $50M to help prepare smaller businesses for a new world of AI and security risks
- AI, LLM’s, and Skynet
- Anthropic AI Models Hacked Three Companies During Tests
- Not just OpenAI: Now Anthropic says its internal models got online and cyberattacked 3 other organizations
- Microsoft’s solution to AI security: more AI and more acronyms
- Rethinking security for the age of AI – The Official Microsoft Blog
- Introducing Claude Opus 5
- Our position on open-weights models Anthropic
- George Clooney, Tom Hanks, and Meryl Streep back new ‘Human Consent Standard’ for AI licensing
- Artist sues AI meme generator for selling deeply personal comic as ad template
- Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
- Judge says government’s case got “worse” in Anthropic fight
- Amazon’s Zoox wins first U.S. approval for paid robotaxis without human controls
- Google says AI helped Chrome fix 1,072 security bugs in two releases
- SpaceXAI launches Grok Voice Think Fast 2.0 on Agent Builder
- Microsoft
- Microsoft faces competition probe over Copilot subscription price hike
- Microsoft admits Windows 11 native apps hog RAM, promises a WinUI performance boost before Start menu rewrite
- Windows 11 KB5101684 out with a speed boost, direct download links for offline installer
- Windows 11’s August Patch Tuesday update brings several important changes, and I break down the biggest ones
- Why Intune Devices Became Noncompliant After the July Update
- Microsoft earnings Q4 26: Cloud brings revenue rain
- Windows 11 File Explorer just changed how file sizes work, how to see MB and GB right now
- Microsoft says Classic Outlook’s Copilot button is getting bigger and will nudge you with AI suggestions as you work
- Microsoft Says Windows Secure Boot Certificate Rollout Is Ongoing
