IT Security Newsletter - 8/12/2026
Krebs on Security: Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. August's overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June's then-record batch of nearly 200 fixes. READ MORE...
A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals around the world. READ MORE...
DEF CON crowd suspected in fake-hotspot attack on Delta flight
On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS. A description of the incident further stated that these passengers created a fake hotspot with a phishing landing page. READ MORE...
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
Intel and AMD on Tuesday announced patches for a total of more than 80 vulnerabilities across their products. Intel has published 42 new advisories covering 72 vulnerabilities. The company patched several high-severity flaws in PROSet/Wireless WiFi software that could allow an attacker to escalate privileges or conduct a denial-of-service (DoS) attack. These security holes can be exploited for privilege escalation, DoS, and information disclosure. READ MORE...
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
Industrial giants Siemens, Schneider Electric, and Phoenix Contact have published August 2026 Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS products. Siemens has published 10 new advisories. One covers a maximum-severity missing-authentication vulnerability in Simatic IoT2050 Advanced devices. A remote, unauthenticated attacker can exploit it to execute arbitrary code on the underlying server with elevated privileges. READ MORE...
Akira ransomware scum blocked victim's security tools - and broke their own encryptor
An Akira ransomware affiliate rebooted a victim's computer into Safe Mode to kill its security tools - and in the process sabotaged their own malware when the limited-function startup mode also broke their encryptor. But the ending wasn't entirely happy for the victim. The attacker had already stolen credentials and data from file shares before Safe Mode prevented the ransomware from doing its job. READ MORE...
Kimwolf botnet rebuilt to survive takedowns, researchers say
The developers of a notorious botnet that's powered mostly by hijacked Android TV boxes and other internet-connected devices have released a new version built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement, researchers at Palo Alto Networks said in a report published Tuesday. The company's Unit 42 threat intelligence group, which tracks the botnet as Kimwolf, said the newest version has been active since February. READ MORE...
Former BlackFile affiliates linked to extortion campaign targeting private equity
A group of threat actors formerly associated with BlackFile are linked to a wave of extortion attacks targeting private equity, financial-ratings agencies and law firms in recent weeks, according to a report from Google Threat Intelligence Group. The threat cluster, tracked as UNC6671, has been targeting employees at various firms using voice-phishing techniques. The recent targeting follows the supposed retirement of BlackFile in May. READ MORE...
CVE Program eyes automation and globalization to weather AI 'vulnpocalypse'
The global system that catalogs technology vulnerabilities is resilient enough to survive the current onslaught of AI-generated bug reports that has alarmed cybersecurity experts, key leaders of that system said last week during panels at two security conferences here. The Common Vulnerabilities and Exposures (CVE) Program - whose unique vulnerability identifiers are the bedrock of the entire cybersecurity industry - will find a way to scale. READ MORE...
- ...in 1851, inventor Isaac Singer is given a patent on his sewing machine.
- ...in 1908, Henry Ford's first Model T, affectionately known as the "Tin Lizzie," rolls off the assembly line in Detroit, MI.
- ...in 1925, twin brothers Ross and Norris McWhirter, co-founders of the Guinness Book of World Records, are born in Middlesex, England.
- ...in 1949, Dire Straits guitarist and songwriter Mark Knopfler ("Money For Nothing", "Sultans of Swing") is born in Glasgow, Scotland.







