August 22, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

The week started out with the normal level of chaos, plotting, exploitation, threats, and mayhem in Pandemonium (kingdom of demons), and then Oracle unleashed their second monthly vulnerability notices and things got a bit more exciting. Mind you, you can’t get Oracle patches without a subscription, but they announced patches for an astonishing 925 CVEs! Citrix followed close on with a massive vulnerability in NetScaler that can enable unauthenticated RCE, and Cisco released patches for multiple issues, some of which ranked a perfect 10.0 on CVSS. But wait, there’s more! GitLab is urging patching of a zero-click defect, and VMware’s latest flaw is now under active exploitation.

This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. Now, on to the headline news.

Headline NEWS:

  • Cisco Patched Nine Crosswork and Secure Workload flaws tops the alphabetical headlines this week. Crosswork, which is supposed to simplify network operations by automating and centralizing control over multidomain and multivendor environments, and Secure Workload which enables micro-segmentation, theoretically reducing the attack surface, have both been found by Cisco to desperately need updates to prevent full takeover. Thankfully, the vendor found the flaws, and this isn’t known to be actively exploited yet. So, patch quickly.
  • Citrix urges admin to patch new NetScaler flaws as soon as possible. NetScaler Gateway and NetScaler ADC both need updates to prevent threat actors from being able to bypass authentication and perform Denial of Service (DoS). These defects are not known to be exploited currently.
  • GitLab has a Zero-Click defect that requires no authentication or user interaction to exploit. No technical details were provided about this flaw. If you self-host GitLab, patch quickly.
  • VMware vCenter defect is under attack, enabling ESXi ransomware. The initial access is via a flaw in syslog and enables a threat actor to gain full control of a vulnerable instance. From there they can pivot to anything managed by the vCenter server. If you have Broadcom subscription, patch immediately. If you don’t, you’re out of luck. Whether you have a subscription or not, management access should be limited to known trusted systems or networks and you should review new accounts, cron jobs, and folders for activity indicating compromise.

In Ransomware, Malware, and Vulnerabilities News:

  • WordPress has been in the news a lot this week. Plugins are amazing in what they enable websites to do. But they are also a perpetual source of potential threat actor ingress. The latest batch of issues comes from plugins, Forminator, Elementor, and Pods. All three can enable malicious uploads and/or remote code execution. If you use these, make sure that they are on the latest version. And WordPress itself recently updated to version 7.1 where multiple stability fixes were introduced.

In Other News Events of Note and Interest:

  • Amazon’s Prime Air is taking off in nearly 500 US Cities. In rural America, this is also known as skeet-shooting with prizes attached. Please do not attempt to do so. It is a federal crime to interfere with any drone, whether or not you feel it is violating your privacy or trespassing. Drones are considered aircraft and messing with one carries the same penalties as if you shot at an airplane full of passengers! It’ll be interesting to see how effective this delivery method is, especially in light of a recent video showing an Amazon drone delivering a package into someone’s swimming pool.

Musings

Keeping up with technology changes can be challenging, that’s for certain. I personally skim through hundreds of articles weekly and spend time reading dozens so that I stay aware and able to publish this newsletter, and so that very little that happens in the tech world catches me by surprise. I recently, at the urging of a colleague, started getting a daily briefing from ChatGPT. I’ve got to confess, it is very useful, and a bit scary in how efficient it is. Thankfully, the AI doesn’t have my particular brand of dry wit down – yet.

Visc. Jan Broucinek

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

 

Share this with: