Here is the most recent Cybersecurity news for the past week:
πͺMicrosoft August 2026 Patch Tuesday Addresses Actively Exploited Zero-Day
Microsoft released its August 2026 Patch Tuesday security updates resolving more than 400 vulnerabilities. The release includes CVE-2026-68820, a high-severity flaw in the Windows Ancillary Function Driver for WinSock that is already being exploited to gain SYSTEM privileges.
πSafePal Hardware Wallet Discloses Data Breach Impacting 40,000 Customers
SafePal disclosed an authorization vulnerability in an order-tracking plug-in that exposed personal and shipping information belonging to nearly 40,000 customers. Wallet private keys, seed phrases, and financial credentials were not affected.
https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html
πHackers Actively Exploit Unpatched GeoServer Zero-Day Vulnerability
Attackers began exploiting an unpatched SQL injection vulnerability in GeoServer within hours of public disclosure. Under certain configurations, unauthenticated attackers can use the flaw to execute arbitrary code remotely.
https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/
π¦GitLab Issues Emergency Out-of-Band Fix for Critical Data Deletion Flaw
GitLab released an emergency update for a critical GraphQL vulnerability affecting self-managed Community and Enterprise Edition servers. Under specific conditions, unauthenticated attackers could modify or delete public projects and user data.
https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html
π¨CISA Warns Microsoft SharePoint Flaw Now Exploited in Ransomware Attacks
CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after ransomware operators began actively exploiting the Microsoft SharePoint Server vulnerability to execute arbitrary code on exposed systems.
|
|



