<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 8/10/2026

SHARE

Top News

200 accounts compromised in Swiss government's Microsoft SharePoint breach

Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland's Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT's security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform and closed the vulnerabilities being exploited. READ MORE...


Corporate Data Stolen in Levi Strauss Cyberattack

Denim company Levi Strauss & Co on Friday disclosed a cyberattack that affected certain corporate data stored on employee computers. The incident, it said in a Form 8-K filing with the US Securities and Exchange Commission (SEC), was the result of social engineering and affected three employees' company-issued computers. The company says its immediate response and containment actions have resulted in the attackers' eviction from the compromised computers. READ MORE...

Breaches

Framework loses customer data in Metabase zero-day attack

Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit. For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected. READ MORE...


LexisNexis shuts down services after suspicious activity on servers

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online. LexisNexis is a global data analytics company providing multiple legal and business services. READ MORE...

Hacking

New Jersey, Alabama Join States Targeted in Water Cyberattacks

New Jersey and Alabama have joined the list of US states that confirmed their water and wastewater facilities have been targeted in a hacking campaign that started in late July. At least 12 states have reportedly been hit, but not all have been identified. Minnesota was the first to confirm that over 30 water systems had their operational technology (OT) systems targeted. Michigan, South Dakota, and Georgia later also confirmed being targeted. READ MORE...

Software Updates

AI-Generated Patches Fail Half the Time

As developers turn to AI models to generate an increasing amount of code, they are also relying on the systems to find vulnerabilities and generate patches. Unfortunately, the models just aren't very good at their jobs. Recent research suggests that even the latest AI systems only produce effective patches about half the time, according to a report published on Aug. 6 by identity management firm 1Password. READ MORE...

Exploits/Vulnerabilities

Critical flaws allow hackers to exploit zero-touch provisioning process in TP-Link Omada

LAS VEGAS -Researchers have found fifteen previously unknown vulnerabilities that affect zero-touch provisioning in TP-Link Omada, which is widely used to provision network devices from a central location, according to a report by Forescout Research - Vedere Labs. Small to medium-sized companies use the technology to rapidly set up routers and firewalls, which in some cases involves thousands of devices. READ MORE...


N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first. The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform. READ MORE...


Critical Progress LoadMaster flaw now actively exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a very popular Application Delivery Controller (ADC) and server load balancer used by tech companies and government entities worldwide (e.g., Amazon, U.S. Air Force) to distribute incoming web traffic across multiple servers, optimize app performance, and ensure high service availability. READ MORE...

On This Date

  • ...in 1846, the Smithsonian Institution is chartered by the US Congress.
  • ...in 1909, inventor and manufacturer Leo Fender, the designer of the classic Telecaster and Stratocaster electric guitars, is born in Anaheim, CA.
  • ...in 1950, Billy Wilder's film noir "Sunset Boulevard," starring William Holden and Gloria Swanson, premieres at Radio City Music Hall.
  • ...in 1960, NASA launches Discoverer 13 satellite; it would become the first object ever recovered from orbit.