August 2026 (30)
Adversary-in-the-Middle Phishing via Legitimate Cloud Platforms
2 TTPs 1 IOCThreat actors are increasingly abusing reputable PaaS providers to host multi-stage AitM phishing campaigns that use browser service workers and the Ultraviolet library to intercept credentials and MFA tokens.
Shai-Hulud Campaign Activity
25 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
Multiple Vulnerabilities in Red Hat Enterprise Linux Perl Modules
1 TTPMultiple vulnerabilities in Red Hat Enterprise Linux within DBI and perl-GD components allow local or remote attackers to execute arbitrary code, manipulate data, or trigger denial-of-service conditions.
Remote Code Execution Vulnerability in Zyxel Firewalls
1 TTPA vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.
Local Code Execution Vulnerability in Red Hat Enterprise Linux AI
1 TTPA local vulnerability in Red Hat Enterprise Linux AI enables attackers to execute arbitrary code, potentially resulting in full system compromise or denial-of-service.
Google Security Updates — August 2026
2 CVEsRoundup of Google security advisories published in August 2026.
Multiple Denial of Service Vulnerabilities in IBM Tivoli Netcool/OMNIbus
1 TTPMultiple Denial of Service vulnerabilities in IBM Tivoli Netcool/OMNIbus, potentially involving vulnerable Immutable.js libraries, allow unauthenticated remote attackers to disrupt service availability.
Multiple Denial of Service Vulnerabilities in PJSIP pjmedia
1 TTPMultiple vulnerabilities in the PJSIP pjmedia library can be exploited by a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting telecommunications services.
Multiple Vulnerabilities in LibreNMS
1 TTPLibreNMS versions prior to 26.5.0 are affected by multiple vulnerabilities including RCE, SSRF, and XSS, posing a significant risk for unauthorized system access and network reconnaissance.
Prevalence of Direct-to-IP Malware Command and Control
2 TTPs 6 IOCsNearly half of malware samples with command-and-control activity bypass DNS resolution by connecting directly to hardcoded IP addresses, rendering traditional DNS-based defenses ineffective.
Heap-based Buffer Overflows in GIMP APNG and DDS Loaders
1 TTP 1 CVEGIMP contains multiple heap-buffer-overflow vulnerabilities in its APNG and DDS file format loaders, which can lead to arbitrary code execution when a victim opens a specially crafted image file.
Path Traversal Vulnerability in Zyxel Network Appliance CLI
1 TTP 1 CVEAn authenticated path traversal vulnerability in Zyxel ATP and USG series firmware allows administrators to execute arbitrary configuration files, potentially leading to command execution.
Command Injection in Zyxel WAX650S export-cgi
1 rule 1 TTP 1 CVEAn authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.
Adobe Security Updates — August 2026
5 CVEsRoundup of Adobe security advisories published in August 2026.
Out-of-Bounds Heap Read Vulnerability in AIOHTTP C Parser
1 CVEAn out-of-bounds heap read vulnerability (CVE-2026-69244) in the AIOHTTP C-based HTTP response parser allows a malicious server to trigger a denial-of-service condition via malformed chunked responses.
Guzzle Hostname Validation Bypass via Transport Discrepancy
1 TTP 1 CVEGuzzle versions before 7.15.2 and 8.0.1 are vulnerable to a host-based security check bypass where transport handlers interpret non-canonical URI hostnames differently than application-level validation, potentially enabling SSRF.
Bleichenbacher Oracle Vulnerability in cryptography Library
1 TTP 1 CVEThe cryptography library fails to perform constant-time operations during PKCS#7 EnvelopedData decryption, creating a Bleichenbacher oracle that allows attackers to recover content-encryption keys via error and timing analysis (CVE-2026-69247).
Resource Exhaustion in Python cryptography Certificate Chain Validation
1 TTP 1 CVEAn exponential complexity vulnerability in the certificate chain validation logic of the Python cryptography library allows for denial-of-service attacks via resource exhaustion using crafted, redundant certificate chains.
DLL Hijacking in FirmaCheck for Windows via Unvalidated OpenSSL Configuration
1 rule 2 TTPs 1 CVEFirmaCheck for Windows versions prior to 1.3.16 are susceptible to local privilege escalation and arbitrary code execution due to an unvalidated OpenSSL configuration file path.
SSRF Vulnerability in Jina AI Reader Crawler
1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability in the Jina AI Reader crawler allows remote attackers to perform unauthorized requests, with public exploit code currently available.
OS Command Injection in ClearOS Log Viewer
1 rule 2 TTPs 1 CVEClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands as the webconfig user, with subsequent escalation to root.
Emlog Pro TLS Certificate Validation Bypass
2 TTPs 1 CVEEmlog Pro versions up to 2.6.23 contain a vulnerability in the AI service component that disables TLS certificate verification, allowing attackers to perform man-in-the-middle interception of LLM API keys and manipulate AI responses.
Remote Command Injection in Sangfor Operation and Maintenance Security Management System
1 rule 2 TTPs 1 CVEAn unauthenticated remote OS command injection vulnerability in the Sangfor Operation and Maintenance Security Management System allows attackers to execute arbitrary system commands via the /fort/portal_login endpoint.
Memory Exhaustion in Socket.IO Parser
1 TTP 1 CVEA memory exhaustion vulnerability in socket.io-parser (CVE-2026-69185) allows remote attackers to trigger denial-of-service by sending specially crafted packets containing a large number of binary attachments.
CVE-2026-18446 Host Confusion in fast-uri
1 CVEThe fast-uri package exhibits a URI parsing discrepancy compared to the native Node.js WHATWG URL parser, allowing attackers to bypass host-based security policies through malicious backslash-encoded authorities.
Information Disclosure and Denial of Service in Undici Cache Interceptor
1 CVEThe undici library is susceptible to cache poisoning leading to information disclosure and application crashes due to improper handling of malformed Cache-Control directives in the cache interceptor.
SSRF via Ambiguous IPv4 Parsing in ip-address Library
1 TTP 1 CVEThe ip-address library versions 10.3.0 and below incorrectly parse IPv4 addresses with leading zeros, leading to trust-boundary bypasses and SSRF when used to filter internal network access.
GitPython Argument Injection in IndexFile and TagReference
1 TTPGitPython fails to sanitize keyword arguments passed to git commands, allowing attackers to perform arbitrary file overwrites and unauthorized file reads.
SQL Injection in Sequelize Oracle Dialect
1 TTPSequelize v6.37.3 and earlier versions contain a critical SQL injection vulnerability in the Oracle dialect implementation, allowing unauthenticated attackers to bypass input sanitization and execute arbitrary SQL.
Remote Code Execution in OpenEMR Document Category Tree
8 TTPs 1 CVEOpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.