
Hello all,
The week started out with the normal level of chaos, plotting, exploitation, threats, and mayhem in Pandemonium (kingdom of demons), and then Oracle unleashed their second monthly vulnerability notices and things got a bit more exciting. Mind you, you can’t get Oracle patches without a subscription, but they announced patches for an astonishing 925 CVEs! Citrix followed close on with a massive vulnerability in NetScaler that can enable unauthenticated RCE, and Cisco released patches for multiple issues, some of which ranked a perfect 10.0 on CVSS. But wait, there’s more! GitLab is urging patching of a zero-click defect, and VMware’s latest flaw is now under active exploitation.
This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. Now, on to the headline news.
Headline NEWS:
- Cisco Patched Nine Crosswork and Secure Workload flaws tops the alphabetical headlines this week. Crosswork, which is supposed to simplify network operations by automating and centralizing control over multidomain and multivendor environments, and Secure Workload which enables micro-segmentation, theoretically reducing the attack surface, have both been found by Cisco to desperately need updates to prevent full takeover. Thankfully, the vendor found the flaws, and this isn’t known to be actively exploited yet. So, patch quickly.
- Citrix urges admin to patch new NetScaler flaws as soon as possible. NetScaler Gateway and NetScaler ADC both need updates to prevent threat actors from being able to bypass authentication and perform Denial of Service (DoS). These defects are not known to be exploited currently.
- GitLab has a Zero-Click defect that requires no authentication or user interaction to exploit. No technical details were provided about this flaw. If you self-host GitLab, patch quickly.
- VMware vCenter defect is under attack, enabling ESXi ransomware. The initial access is via a flaw in syslog and enables a threat actor to gain full control of a vulnerable instance. From there they can pivot to anything managed by the vCenter server. If you have Broadcom subscription, patch immediately. If you don’t, you’re out of luck. Whether you have a subscription or not, management access should be limited to known trusted systems or networks and you should review new accounts, cron jobs, and folders for activity indicating compromise.
In Ransomware, Malware, and Vulnerabilities News:
- WordPress has been in the news a lot this week. Plugins are amazing in what they enable websites to do. But they are also a perpetual source of potential threat actor ingress. The latest batch of issues comes from plugins, Forminator, Elementor, and Pods. All three can enable malicious uploads and/or remote code execution. If you use these, make sure that they are on the latest version. And WordPress itself recently updated to version 7.1 where multiple stability fixes were introduced.
In Other News Events of Note and Interest:
- Amazon’s Prime Air is taking off in nearly 500 US Cities. In rural America, this is also known as skeet-shooting with prizes attached. Please do not attempt to do so. It is a federal crime to interfere with any drone, whether or not you feel it is violating your privacy or trespassing. Drones are considered aircraft and messing with one carries the same penalties as if you shot at an airplane full of passengers! It’ll be interesting to see how effective this delivery method is, especially in light of a recent video showing an Amazon drone delivering a package into someone’s swimming pool.
Musings
Keeping up with technology changes can be challenging, that’s for certain. I personally skim through hundreds of articles weekly and spend time reading dozens so that I stay aware and able to publish this newsletter, and so that very little that happens in the tech world catches me by surprise. I recently, at the urging of a colleague, started getting a daily briefing from ChatGPT. I’ve got to confess, it is very useful, and a bit scary in how efficient it is. Thankfully, the AI doesn’t have my particular brand of dry wit down – yet.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
- Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials
- Citrix urges admins to patch new NetScaler flaws as soon as possible
- Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
- VMware Syslog Path Traversal Becomes Root RCE, Persistent SSH Access and ESXi Ransomware
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- DEF CON hackers add new muscle to water utility protection
- Vulnerabilities and Exploits
- Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs
- CISA orders feds to patch actively exploited TrueConf Server flaws
- Microsoft working on Defender patch for ShieldBreak zero-day
- Microsoft Entra ID Remote Code Execution Vulnerability Exploited in the Wild
- Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
- 600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
- 100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
- CVE-2026-33696: From a Schema Name to RCE in n8n
- Expired credit cards revived by researchers to make unauthorized payments
- Digital Forensics: Attacking SAM and Extracting Hashes With 7z
- Hackers compromise 14,500 Dahua web cameras in 35-day campaign
- Critical Cursor 0-day Vulnerability Enables Arbitrary Code Execution Attacks
- Public Exploit Code Released for Microsoft SCCM Remote Code Execution Vulnerability
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
- Update Chrome now: Two critical vulnerabilities fixed
- Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot
- Phishing, Malware, and Similar
- Clop created custom web shell for Windchill data theft attacks
- Google Workspace Updates: Managing unsolicited event invitations with user blocking in Google Calendar
- New malware turns Microsoft 365 and Azure into its control center
- New SynkLoader malware pushed in Microsoft Teams phishing campaign
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
- Password spraying attacks surge 155x as hackers exploit MFA gaps
- Microsoft smothers malware by tracking behavior instead of blocking domains
- $10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts
- Government orders Google to shut down hundreds of Firebase accounts after finding pattern of the service being misused by criminals
- Hackers infect Android car head units with proxy botnet malware
- New Manic Android malware can exfiltrate data through nearby devices
- Breaches, Leaks, and Ransomware
- Hacker claims 3.6 million Azure account records stolen from major companies
- Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others)
- US Bank investigates LockBit’s claims as ransomware crims set pay-or-leak deadline
- Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
- Pokémon Center data breach exposes customer info, cancels some orders
- Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases
- Lincoln Maine town office closes after cybersecurity incident encrypts network files
- Beacon CRM Confirms Full Database Theft After AWS Access Key Breach
- Sogang University hit by personal information breach of 180,000
- Wallet provider SafePal says data breach exposed personal info of nearly 40,000 customers
- Trivy, Not LiteLLM Behind the 2,500 Org Compromise
- Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
- French tax authority admits data heist after crook touts 2M records
- Australian hotel chain leaks guests’ PII after breach at third-party database operator
- CareCloud Data Breach Impact Grows to 3.7 Million Individuals
- Sakura Internet hack exposes data of up to 1.36 million accounts
- SickKids data breach exposes employee and job applicant info
- Apollo says hackers accessed personal data in latest Wall Street breach
- Hundreds of leaked AWS keys give full control over corporate accounts
Other News Events of Note and Interest
- Cool Tool: Microsoft pushes PowerToys preview v0.101.2282.0 with Command Palette fixes
- Cool Tool: Microsoft Publisher is dead in October, but this 25-year-old open-source app already replaced it
- It’s final! Judge says HPE’s Juniper acquisition is complete
- Inside Defcon, the Conference That Made Cybersecurity Noob-Friendly
- Linux 7.2 makes TSC support mandatory for x86 CPUs, but it’s not like Windows 11’s TPM 2.0 check
- Google Workspace Updates: New enterprise security controls for Workspace Studio enable expanded collaboration use cases
- Make zero CVEs your new default
- GitHub blames 8-hour outage on autoscaling fail and VS Code retry storm
- Framework responds to complaints that BIOS update bricks Ryzen 7040 laptops
- Apple Accidentally Leaked More Than 10 New Products in macOS Update
- Adoption of WiFi 7
- Calling on Cyber Pros to Help Defend City Hall
- Roblox must make changes after failing to block adults creeping on kids
- Amazon’s Prime Air is taking off in nearly 500 US cities
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
- China joins Europe in scrapping Windows for Linux
- AI, LLM’s, and Skynet
- Anthropic sees AI risks rising, no plan to release stronger “Model 2”
- Anthropic says annualized revenue climbed to $65 billion in July
- Cursor is now a part of SpaceX
- OpenAI Rewrites Safety Rules as Frontier Run Stays Paused
- Microsoft brings Copilot apps together ahead of ‘super app’ overhaul
- AI was meant to simplify IT service management – new research shows it’s creating bigger workloads for teams
- What is AI insurance?
- Are We Thinking Correctly About AI Intelligence?
- No-Filter ‘Kriminal’ AI Platform Raises Cybercrime Concerns
- Microsoft
- Microsoft blames AI for delayed Exchange update, can’t say when it will arrive
- Microsoft starts removing WMIC tool used by cybercriminals
- Microsoft fixes known issue causing Windows Defender crashes
- Microsoft says August Windows updates may cause gaming issues
- Understanding the new 100 GB mailbox entitlement for Microsoft 365 Business suites
- Microsoft reveals Windows 11 26H2 auto-enables a PC recovery feature, verify if it’s already turned on
