Weekly Threat Landscape Digest – Week 35

HawkEye CSOC Kuwait
  1. Multiple Vulnerabilities in OpenSSL

Overview

  • Multiple vulnerabilities in QUIC, CMS, CMP, DTLS, RPK, and cryptographic functions addressed in this update.
  • CVE-2026-18798: QUIC server double-free causing heap corruption and denial of service.
  • CVE-2026-63072: CMS heap buffer overflow during key unwrapping causing denial of service.
  • CVE-2026-63076: CMP invalid pointer dereference causing application crash.
  • CVE-2026-14457: RPK null pointer dereference resulting in denial of service.
  • CVE-2026-54874: DTLS crafted traffic causing excessive memory use and denial of service.
  • CVE-2026-63073: CMP format string vulnerability causing client crash.
  • CVE-2026-63074: CMP cache growth from repeated requests causing unbounded memory growth and denial of service.
  • CVE-2026-63075: QUIC memory exhaustion causing denial of service.
  • CVE-2026-75803: AEAD authentication tag bypass for empty ciphertext potentially allowing acceptance of forged messages.

Impact

  • Denial of service, heap corruption, memory exhaustion, or acceptance of forged messages depending on vulnerability.

Affected / Fixed Versions

  • Fixed in OpenSSL versions 4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22, 1.1.1zi, and 1.0.2zr.

Recommendations

  • Update affected OpenSSL versions to the fixed or latest releases without delay.

Reference Links

  1. Security Updates – Google Chrome 152

Overview

  • Google released Chrome 152 addressing 327 security issues including critical memory-safety bugs predominantly use-after-free flaws.
  • High-severity issues include memory corruption, improper authorization, race conditions, input validation errors, and information disclosure.
  • Components affected include ANGLE, Aura, Chromecast, Views, Safe Browsing, Mobile, V8, Chromoting, WebRTC, and Extensions.

Impact

  • Exploitation may lead to application crashes, arbitrary code execution, sensitive data disclosure, security control bypass, and system compromise.

Affected / Fixed Versions

  • Chrome 152.0.7977.64 for Linux, Windows, macOS, and Android.
  • Early Stable Update Chrome 153.0.8010.12/13 for Windows and macOS.
  • Chrome 152.0.7977.64 for iOS.

Recommendations

  • Update Google Chrome to the latest available stable version immediately.

Reference Links

  1. Critical Actively Exploited Vulnerability in Oracle HTTP Server (CVE-2026-21962)

Overview

  • CVE-2026-21962 is a critical vulnerability (CVSS 10.0) affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
  • Allows an unauthenticated remote attacker with HTTP network access to compromise systems.
  • Permits unauthorized creation, deletion, or modification of critical data, and unauthorized access to data.
  • The vulnerability is actively exploited in the wild.

Impact

  • Full system compromise through HTTP without authentication.
  • Unauthorized manipulation and access to critical and sensitive data.

Affected / Fixed Versions

  • Affected: Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0.
  • Affected: WebLogic Server Proxy Plug-in for IIS version 12.2.1.4.0.
  • Fixed: Apply Oracle security updates addressing CVE-2026-21962.

Recommendations

  • Immediately update affected Oracle HTTP Server and WebLogic Server Proxy Plug-in to the latest patched releases.
  • Monitor for signs of compromise associated with this vulnerability.

Reference Links

  1. Adobe Security Updates – Multiple Products

Overview

  • Adobe released security updates addressing multiple critical vulnerabilities across Content Credentials SDK, Substance 3D Designer, Substance 3D Sampler, Illustrator, Adobe XD, Substance 3D Painter, and Campaign Classic.
  • Vulnerabilities include arbitrary code execution, OS command injection, SSRF, buffer overflow, application denial-of-service, and memory exposure.
  • Several vulnerabilities have a CVSS score of 10.0.

Impact

  • Exploitation could allow attackers to execute arbitrary code with application or user privileges, compromise systems, disrupt applications, and disclose sensitive information.

Affected / Fixed Versions

  • Content Credentials Rust SDK: fixed in c2pa-v0.90.11.
  • C2PA Tool: fixed in c2patool-v0.27.11.
  • Adobe Substance 3D Designer: fixed in version 16.0.5.
  • Adobe Substance 3D Sampler: fixed in version 6.0.3.
  • Adobe Illustrator 2025: fixed in version 29.8.10.
  • Adobe Illustrator 2026: fixed in version 30.7.
  • Adobe XD: fixed in version 61.
  • Adobe Substance 3D Painter: fixed in version 12.1.3.
  • Adobe Campaign Classic ACC v7: fixed in version 7.4.4 build 9401.

Recommendations

  • Apply the security updates released by Adobe immediately to mitigate these critical vulnerabilities.

Reference Links

  1. Critical SMB Authentication Coercion Vulnerability in Veeam ONE (CVE-2026-65641)

Overview

  • CVE-2026-65641 is a critical vulnerability (CVSS v4.0 9.3) in Veeam ONE allowing unauthenticated network attackers to coerce SMB authentication from the Veeam ONE service account.
  • Exploitation may expose service account authentication details, enabling further unauthorized access to affected or connected systems.

Impact

  • Exposure of service account credentials.
  • Potential for unauthorized access and lateral movement within the network.

Affected / Fixed Versions

  • Affected: Veeam ONE 13.1.0.7034 and earlier 13 builds.
  • Fixed: Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159).

Recommendations

  • Update Veeam ONE installations to fixed versions or later releases to mitigate the vulnerability.

Reference Links

  1. Actively Exploited Zimbra SNMP Command Injection Vulnerability (CVE-2026-73570)

Overview

  • Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability (CVE-2026-73570) due to improper sanitization of untrusted input in SNMP notification processing.
  • An unauthenticated attacker can execute arbitrary OS commands by sending specially crafted SMTP requests.
  • The vulnerability is actively exploited in the wild. Severity: High, CVSS score 8.9.

Impact

  • Allows unauthenticated attackers to execute arbitrary commands with Zimbra user privileges.
  • Potential consequences include unauthorized access, data compromise, persistence, and further server compromise.

Affected / Fixed Versions

  • Affected: Zimbra Collaboration Suite versions prior to 10.1.20.
  • Fixed: Version 10.1.20 and later.

Recommendations

  • Update to Zimbra Collaboration Suite version 10.1.20 or later to remediate the vulnerability.

Reference Links

  1. Oracle August 2026 Critical Security Patch Update – 943 Vulnerabilities

Overview

  • Oracle released its August 2026 Critical Security Patch Update (CSPU) addressing 943 vulnerabilities across multiple product families.
  • Critical vulnerabilities include multiple RCE flaws exploitable without authentication in Oracle Essbase, Commerce Guided Search, Commerce Experience Manager, and Commerce Platform, all with CVSS scores of 9.8.
  • High-severity vulnerabilities also addressed in Oracle Database, Autonomous Health Framework, Application Testing Suite, Enterprise Manager, E-Business Suite, WebLogic Server, and others.

Impact

  • Attackers may execute arbitrary code, compromise confidentiality or integrity, cause denial of service, or gain unauthorized access.

Affected / Fixed Versions

  • Wide range of Oracle products including Database Server, Enterprise Manager, E-Business Suite, WebLogic Server, Commerce, Essbase, Java SE, Fusion Middleware, Communications, Hospitality, Retail, PeopleSoft, JD Edwards, and others.
  • Refer to Oracle’s official advisory for detailed version information and fixed releases.

Recommendations

  • Apply the August 2026 Critical Security Patch Update promptly.
  • Review Oracle’s official security advisory to identify affected products and implement updates.

Reference Links

  1. Multiple Critical Vulnerabilities in IBM AIX and PowerVM VIOS

Overview

  • Multiple critical- and high-severity vulnerabilities identified in IBM AIX and PowerVM VIOS including command injection, RCE, arbitrary file modification, privilege escalation, information disclosure, and denial of service.
  • Critical CVEs include CVE-2026-15068 (CVSS 9.9), CVE-2026-18835 (CVSS 9.9), CVE-2026-16882 (CVSS 9.8), CVE-2026-17142 (CVSS 9.8), CVE-2026-16894 (CVSS 9.8), CVE-2026-16903 (CVSS 9.6), CVE-2026-16926 (CVSS 9.1), and CVE-2026-17040/16840/17422 (CVSS 9.3–9.8).

Impact

  • Remote authenticated and unauthenticated attackers could execute arbitrary commands or code.
  • Potential for denial of service, arbitrary file manipulation, sensitive information exposure, and privilege escalation.

Affected / Fixed Versions

  • Affected: IBM AIX 7.2, 7.3; IBM PowerVM VIOS 4.1.
  • Fixed: AIX 7.3 TL04 SP2 / TL03 SP3 / TL02 SP5; AIX 7.2 TL05 SP13; VIOS 4.1.2.20, 4.1.1.30, 4.1.0.50.

Recommendations

  • Apply the latest IBM patches and upgrade to the fixed versions listed.
  • Review official IBM advisory for complete CVE details and mitigation guidance.

Reference Links

  1. Critical Actively Exploited GitLab Vulnerabilities (CVE-2026-19478, CVE-2026-19650)

Overview

  • GitLab CE and EE contain a critical code injection flaw (CVE-2026-19478, CVSS 9.4) allowing unauthenticated remote attackers to exploit a GraphQL directive to modify or delete public projects and user data.
  • CVE-2026-19478 is actively exploited in the wild with publicly available proof-of-concept exploits.
  • CVE-2026-19650 (CVSS 7.1) permits unauthenticated attackers to execute GraphQL mutations via GET requests due to improper request validation.

Impact

  • Unauthorized modification or deletion of GitLab projects and user data.
  • Unauthorized execution of GraphQL mutations.
  • Potential compromise of integrity and availability of affected GitLab instances.

Affected / Fixed Versions

  • Vulnerabilities fixed in GitLab versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

Recommendations

  • Update affected GitLab instances immediately to version 19.2.4 or the appropriate fixed release.

Reference Links

  1. Security Updates – Google Chrome (August 26, 2026)

Overview

  • Google released Chrome security updates addressing one Critical and six High severity vulnerabilities.
  • Critical: CVE-2026-76017 – use-after-free in Chromoting.
  • High severity: CVE-2026-76018 (privilege elevation), CVE-2026-76019 (incorrect authorization), CVE-2026-76020 (race condition), CVE-2026-76021 (use-after-free), CVE-2026-76022 (buffer overflow), CVE-2026-76023 (improper resource control).

Impact

  • Exploitation could lead to arbitrary code execution, privilege escalation, unauthorized access, memory corruption, or denial-of-service.

Affected / Fixed Versions

  • Windows and Mac: 151.0.7922.173/.174.
  • Linux and Android: 151.0.7922.173.

Recommendations

  • Update Google Chrome to the latest available versions immediately.

Reference Links

  1. Cisco Security Updates – Crosswork, Secure Workload, BroadWorks, and More

Overview

  • Cisco released security updates for Crosswork, Secure Workload, BroadWorks, Unified Intelligence Center, RoomOS, Industrial Ethernet 1000 Series Switches, and Contact Center Enterprise.
  • Vulnerabilities range from Critical (CVSS 10.0) to Medium severity including XML External Entity Injection, SQL Injection, stack overflow, stored XSS, DoS, and SSRF.
  • Critical CVEs in Crosswork: CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359.
  • Critical CVEs in Secure Workload: CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319.

Impact

  • Critical vulnerabilities could lead to unauthorized access, data compromise, arbitrary code execution, and complete system compromise.

Affected / Fixed Versions

  • Detailed affected product versions and fixed releases provided in the official Cisco security advisory.

Recommendations

  • Apply Cisco’s available security updates or mitigation workarounds promptly.
  • Share this information with subsidiaries and partners for coordinated mitigation.

Reference Links

  1. Critical cPanel Vulnerability Allows Attackers to Take Full Server Control (CVE-2026-65643)

Overview

  • A vulnerability in cPanel and WHM’s domain parking functionality (CVE-2026-65643) allows authenticated users with permission to add parked or addon domains to create arbitrary files anywhere on the server.
  • Exploitation does not require advanced skills, only a legitimate low-level cPanel account.
  • The flaw leads to root-level code execution, enabling full server compromise.

Impact

  • Complete server takeover on shared hosting environments.
  • Potential defacement, data theft, malware deployment, and lateral movement within hosting networks.
  • All websites, databases, and email accounts hosted on the compromised server become exposed.

Affected / Fixed Versions

  • Affects all currently supported cPanel and WHM versions.
  • Patched builds: 11.110.0.141+, 11.134.0.53+, 11.136.0.37+, 11.138.0.2+, WP2 11.138.1.7+.
  • Older, unsupported branches remain vulnerable if not upgraded.

Recommendations

  • Apply patched versions immediately.
  • Review and potentially restrict domain parking permissions temporarily until patches are deployed.
  • Prioritize rapid patching due to high risk.

Reference Links

  1. USN-8666-3: Linux Kernel (GCP FIPS) Vulnerabilities

Overview

  • Multiple security vulnerabilities in the Linux kernel affecting networking, filesystems, cryptographic API, and various drivers.
  • CVE-2025-27558: allows a physically proximate attacker to inject packets via flawed WiFi aggregated frame handling in mesh networks.
  • Other affected components include x86 architecture, InfiniBand, NVIDIA Tegra memory controller, NVME, Ext4, IPv4/IPv6 networking, TCP, SCTP, and Netfilter.

Impact

  • An attacker could use these flaws to compromise the affected system with potential for privilege escalation, denial of service, or unauthorized access.

Affected / Fixed Versions

  • Linux kernel versions impacted; update available addressing CVE-2025-27558 and CVE-2026-31405 through CVE-2026-53359.

Recommendations

  • Apply the security update promptly on affected Ubuntu systems.

Reference Links

  1. USN-8644-3: Linux Kernel (Azure) Vulnerabilities

Overview

  • Multiple security vulnerabilities found in the Linux kernel affecting file systems infrastructure, OCFS2 file system, B.A.T.M.A.N. meshing protocol, SCTP protocol, and TIPC protocol.

Impact

  • Potential system compromise through exploitation of vulnerabilities in kernel subsystems.

Affected / Fixed Versions

  • Specific versions detailed in the Ubuntu security notice.

Recommendations

  • Apply the security update provided by Ubuntu to remediate these vulnerabilities.

Reference Links

  1. PCI DSS 4.0.1: Application Security Requirements Assessed in 2026

Overview

  • Since March 31, 2025, all former PCI DSS 4.0 best practices have become fully scored requirements assessed during 2026 audits.
  • Application security requirements concentrate in Requirements 6 and 11, including inventory of custom applications and APIs, continuous protection of public-facing apps, payment page script inventory and integrity checking.
  • New requirements mandate comprehensive inventory of scripts running on payment pages and mechanisms to detect unauthorized changes.
  • PCI DSS 4.0.1 moves assessments toward continuous evidence and shifts focus from network to application-layer security.

Impact

  • Organizations lacking inventory or change detection of payment page scripts risk failed compliance assessments.
  • E-skimmer malware campaigns remain a practical threat, hijacking payment scripts to steal cardholder data.
  • Missing PCI DSS attestation affects acquiring bank relationships and contractual exposure.

Recommendations

  • Maintain a complete, current inventory of all custom web applications, APIs, and payment page scripts.
  • Implement automated, continuous detection and prevention of web-based attacks on public-facing apps.
  • Use authenticated vulnerability scanning internally and externally.
  • Deploy monitoring to detect unauthorized script modifications on payment pages.

Reference Links

  1. PaperCut NG/MF Zero-Day Vulnerability Actively Exploited in Attacks

Overview

  • An unpatched vulnerability in PaperCut NG and PaperCut MF print management software is being actively exploited in the wild.
  • The flaw affects all currently supported versions; exploitation involves remote attack against internet-facing servers.
  • Indicators of compromise include suspicious pc-app.exe activity, missing or truncated server.log files, and specific error log entries.
  • Emergency builds were issued for v25 and v26 branches across Windows, Linux, and macOS; v24 build is in progress.

Impact

  • Potential remote compromise of internet-exposed PaperCut servers.
  • Possible unauthorized access and post-exploitation activity.
  • High risk due to widespread deployment and active exploitation.

Affected / Fixed Versions

  • All currently supported versions of PaperCut NG and PaperCut MF.
  • Emergency patches released for v25 and v26 branches; patch for v24 branch forthcoming.

Recommendations

  • Immediately restrict Application Server access to trusted IP ranges using firewalls.
  • Apply emergency patches without delay.
  • Monitor for suspicious behavior using identified indicators of compromise.
  • Conduct thorough threat hunts for potential compromises.

Reference Links

  1. CISA Adds Citrix NetScaler ADC and Gateway Vulnerability to KEV (CVE-2026-8452)

Overview

  • CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26, 2026.
  • The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway and involves improper restriction of operations within a memory buffer (CWE-119).
  • Allows unauthenticated attackers to cause denial-of-service (DoS) conditions resulting in appliance unavailability.
  • CISA has mandated U.S. federal agencies to patch with a strict deadline.

Impact

  • Denial-of-service attacks interrupting internal and external user access to network services.
  • Operational disruption with possible accompaniment of other intrusion activities.
  • High risk for internet-exposed NetScaler instances.

Affected / Fixed Versions

  • Citrix NetScaler ADC and NetScaler Gateway (specific versions not listed).
  • Mitigation guidance provided in Citrix advisory CTX696604.

Recommendations

  • Identify all NetScaler ADC and Gateway assets and confirm exposure.
  • Apply vendor-recommended updates or mitigations immediately.
  • Restrict administrative interfaces and public accessibility of management services.
  • Monitor appliance availability, logs, and network telemetry for signs of exploitation.
  • Follow CISA’s Binding Operational Directive 26-04 for accelerated patching.

Reference Links

  1. Next.js Critical AVIF and Windows Path Traversal RCE Vulnerabilities

Overview

  • Vercel released patches for two critical vulnerabilities in the Next.js web framework.
  • One vulnerability allows unauthenticated RCE via specially crafted AVIF image files.
  • The other is a path traversal flaw (CVE-2026-75604) affecting servers using a Windows filesystem, also enabling unauthenticated RCE.

Impact

  • Remote attackers can execute arbitrary code on vulnerable Next.js servers without authentication.

Affected / Fixed Versions

  • Specific affected and fixed Next.js versions not detailed in the source.

Recommendations

  • Update Next.js to the latest patched versions released by Vercel.
  • Implement additional monitoring for unexpected remote code execution attempts.

Reference Links

  1. TeamPCP Supply Chain Cybercriminals Arrested

Overview

  • Two men from Western Australia — Ruben Ian Thomson and Louis Michael Gaebler — were arrested for their alleged roles in TeamPCP, which inserted malicious code into open-source software.
  • TeamPCP’s campaign compromised over 1,000 organizations globally by exploiting software supply chain vulnerabilities.
  • The group exploited a misconfigured workflow in Trivy (a vulnerability scanner by Aqua Security) to steal service-account tokens.
  • Malware known as ‘Mini Shai-Hulud’ targeted major software libraries, downloaded millions of times weekly.
  • The campaign exposed more than 500,000 credentials, exfiltrated at least 300 GB of data, and caused hundreds of millions in cleanup costs.
  • High-profile victims included the European Commission and GitHub.

Impact

  • Massive credential exposure and data theft from thousands of enterprises worldwide.
  • Severe disruption and financial damage due to injection of malicious code into automated build pipelines.

Recommendations

  • Review and harden software supply chain security practices.
  • Monitor for vulnerabilities and exploit attempts in open-source dependencies.
  • Conduct forensic analysis if affected to identify and remediate malicious changes.

Reference Links

  1. CVE-2026-0251: GlobalProtect App Local Privilege Escalation (High)

Overview

  • Multiple local privilege escalation vulnerabilities identified in the GlobalProtect App allowing local attackers to elevate privileges on affected systems.

Impact

  • Successful exploitation results in increased access rights, potentially allowing unauthorized actions with elevated privileges.

Affected / Fixed Versions

  • Details on affected versions not specified; users of GlobalProtect App should assume exposure until patched.

Recommendations

  • Apply security updates from Palo Alto Networks promptly once available.
  • Monitor for announcements regarding patches or mitigations.

Reference Links

  1. Critical Zero-Click Avada WordPress Theme RCE Vulnerability

Overview

  • A critical vulnerability in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code on the server.
  • The exploit does not require user interaction, indicating a zero-click remote code execution risk.

Impact

  • Complete server compromise allowing remote attackers to control WordPress installations running the affected Avada theme.

Affected / Fixed Versions

  • Specific affected or patched versions not detailed.

Recommendations

  • Update the Avada theme to the latest version addressing this critical flaw once available.
  • Monitor site activity and logs for signs of exploitation attempts.

Reference Links

  1. Beyond Patching: Patchless Remediation Strategies for Unpatchable Exposures

Overview

  • IT teams face operational pressure from the assumption that vulnerabilities can only be remediated by patching or accepting risk.
  • Patchless remediation strategies include configuration hardening, software removal, isolation, mitigation, and custom scripts.
  • These strategies enable same-day neutralization of exposures, especially for CISA KEV items, without emergency change control or system restarts.
  • AI-driven patch reliability scoring and contextual routing improve patch deployment success and reduce friction between Security and IT teams.

Impact

  • Vulnerabilities in end-of-life or fragile production software can be managed securely without immediate patches.
  • Large-scale deployments using AI-assisted reliability scoring have demonstrated rollback rates below 0.1%.
  • Improved remediation workflows lower mean time to respond (MTTR) by 30% and improve response times by 40%.

Recommendations

  • Implement patchless remediation strategies alongside traditional patching to close security gaps.
  • Utilize AI-driven patch reliability assessments to prioritize safe patch deployments.
  • Leverage automated prioritization and audit logging to meet CISA KEV deadlines without emergency operational disruptions.

Reference Links

  1. Edge Infrastructure Under Siege: State-Sponsored and Criminal Actors Exploiting the Same CVEs

Overview

  • Joint analysis by Tenable and SentinelOne of 93 CVE-actor attribution pairs shows convergence of state-sponsored and cybercriminal actors exploiting the same edge infrastructure vulnerabilities.
  • Both categories of attackers independently target the same vendor attack surfaces, with 79% overlap in vendor focus despite minimal CVE-level overlap.
  • Twelve CVEs have confirmed dual attribution across five nexus categories.
  • Vendors frequently targeted include Fortinet, F5, Check Point, Ivanti, and Citrix, with F5 showing 54% of customer environments having at least one actively exploited CVE.
  • Median patch times: Citrix products 461 days; high-priority CVEs 146 days to remediate.
  • Continuous re-exploitation on Ivanti products occurs every 8.5 to 13 months.

Impact

  • Shared attack surfaces create exposure to both state-sponsored espionage and criminal ransomware attacks.
  • Long remediation windows provide attackers substantial opportunity to exploit critical edge infrastructure vulnerabilities.

Affected / Fixed Versions

  • Targeted products include SonicWall SMA1000, JetBrains TeamCity, PAN-OS GlobalProtect, Check Point Quantum, Fortinet, Citrix, Cisco, Ivanti, Palo Alto Networks, Juniper, VMware, Microsoft, Oracle, and others.

Recommendations

  • Employ multi-layered defense-in-depth strategies: fast patching, minimizing feature sets, and running endpoints in protect mode.
  • Patch edge devices promptly despite operational challenges.
  • Monitor and prioritize remediation of high-priority CVEs.

Reference Links

  1. The Patch Window Is Collapsing: Why Security Needs a New Control Plane

Overview

  • Traditional vulnerability management assumes defenders can patch before widespread exploitation, but the timeline between disclosure and active attacks has shrunk dramatically.
  • AI accelerates attackers’ ability to analyze vulnerabilities and develop exploits, compressing the window even further.
  • Network-level controls are emerging as a faster adaptive layer of defense to restrict access, segment assets, and dynamically contain risk before patch deployment.

Impact

  • Increased risk of exploit during the compressed window between vulnerability disclosure and patch deployment.
  • Traditional remediation workflows may be too slow to keep pace with attacker automation.

Recommendations

  • Implement network-enforced controls to reduce attack surface during patching delays.
  • Adopt adaptive security systems that dynamically respond to changing risk contexts.
  • Use vulnerability prioritization and monitoring to better manage exposure until patches can be safely applied.

Reference Links

  1. ShieldBreak Zero-Day: Windows Defender Privilege Escalation with No Patch (CVE-2026-69414)

Overview

  • ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender.
  • Allows a low-privileged local attacker to gain SYSTEM-level privileges by exploiting how Defender processes files during cloud-file hydration.
  • A public proof-of-concept was released on August 12, 2026; no patch is currently available.
  • Affects Windows 11 25H2 and Windows Server 2025. CISA BOD 26-04 gives organizations 14 days to mitigate.

Impact

  • Successful exploitation results in SYSTEM-level code execution, enabling privilege escalation on impacted systems.

Affected / Fixed Versions

  • Affected: Microsoft Defender on Windows 11 version 25H2 and Windows Server 2025.
  • Fix: Pending Microsoft patch; no patch available yet.

Recommendations

  • Use Qualys VMDR to detect vulnerable assets.
  • Apply Qualys TruRisk Eliminate mitigation to close the gap until Microsoft releases an official patch.
  • Reassess affected systems after mitigation to verify remediation success.

Reference Links

  1. Rapid7 Analysis: Microsoft SharePoint RCE (CVE-2026-63520)

Overview

  • Microsoft SharePoint is affected by a critical remote code execution vulnerability tracked as CVE-2026-63520.
  • The vulnerability allows an attacker to execute arbitrary code remotely on affected SharePoint servers.

Impact

  • Successful exploitation could lead to full system compromise, enabling attackers to run code with elevated privileges.
  • Risks include data theft, service disruption, or lateral movement within enterprise networks.

Affected / Fixed Versions

  • Specific affected SharePoint versions and fixed versions are detailed in Microsoft advisories.

Recommendations

  • Apply Microsoft’s security updates addressing CVE-2026-63520 immediately.
  • Monitor systems for unusual activity and review SharePoint access logs.
  • Implement additional network segmentation and hardening to limit exposure.

Reference Links

AI Threat Landscape

  1. Unit 42: AI Has Shifted the Balance of Power from Defenders to Attackers

Overview

  • Unit 42 from Palo Alto Networks highlights a generational shift in cybersecurity due to frontier and agentic AI models.
  • Attackers are using AI to identify and exploit network weaknesses at machine speed, bypassing traditional defense readiness.
  • An ongoing investigation details an attacker leveraging an agentic AI framework to compromise 50 applications and vulnerabilities in under 10 hours — a process previously taking at least 10 days.
  • AI is integrated across the attack chain, including malware development, social engineering, and ransomware negotiations.
  • Threat landscape shifts include AI as a force multiplier, identity compromise as the main vector, and attackers targeting foundational libraries and software supply chains.

Impact

  • Accelerated attack speeds reduce defenders’ ability to detect and respond effectively.
  • Increased sophistication and scale of attacks amplify risks across enterprise systems.
  • Organizations are largely unprepared for the emerging AI-driven threat dynamics.

Recommendations

  • Enhance detection and response capabilities tailored to high-speed AI-driven attacks.
  • Prioritize protection of identity and critical software supply chain components.
  • Monitor evolving AI threat tactics and integrate intelligence to proactively defend against agentic AI attacks.

Reference Links

  1. Inside 90 Days of Attacks on AI Infrastructure

Overview

  • Wiz honeypots detected active attack campaigns targeting AI infrastructure components including LiteLLM, MCP servers, and AI frameworks.
  • Attack vectors observed include remote code execution (RCE), blind prompt injection, and memory credential theft.

Impact

  • Compromise of AI infrastructure could enable attackers to execute arbitrary code, manipulate AI outputs via prompt injection, and steal sensitive credentials from memory.

Recommendations

  • Monitor AI infrastructure for indicators of compromise related to RCE and prompt injection.
  • Harden AI model endpoints and MCP servers against exploitation.
  • Implement credential protection and memory security controls to mitigate theft risks.

Reference Links

  1. Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Overview

  • Researchers disclosed a prompt injection vulnerability in Amazon Kiro, an AI-powered agentic IDE.
  • The flaw enables attackers to exfiltrate sensitive data leveraging prompt injection techniques and Kiro Powers.
  • Affects Kiro IDE version 0.7.45 on Windows; no CVE identifier assigned yet.

Impact

  • Exploitation could allow unauthorized data leakage from the IDE environment.

Affected / Fixed Versions

  • Affected: Kiro IDE 0.7.45 on Windows.

Recommendations

  • Update once patches become available and monitor vendor advisories for mitigation guidance.
  • Exercise caution with untrusted inputs in prompt contexts.

Reference Links

  1. Building Security Operations Ready for AI-Powered Attacks

Overview

  • Advanced AI models enable attackers to rapidly discover vulnerabilities, generate exploit code, and accelerate lateral movement within target networks.
  • Traditional security processes are insufficient to keep pace with AI-enhanced attack techniques.

Impact

  • Reduced time for defenders to detect and respond before attackers exploit vulnerabilities.
  • Increased likelihood of successful compromise due to accelerated attack tactics powered by AI.

Recommendations

  • Security operations centers must adapt detection and response strategies to address AI-driven threats.
  • Enhance automation and AI-assisted defense capabilities to counter AI-accelerated attacks.

Reference Links

  1. When AI Infrastructure Becomes the Target: LiteLLM, RAGFlow, and Kestra Attacks

Overview

  • Microsoft observed targeted attacks against three AI workloads: LiteLLM gateway, RAGFlow deployment, and Kestra workflow environment.
  • Attackers exploited exposed AI infrastructure control planes concentrating credentials, data access, and privileges.
  • Techniques included credential theft, host compromise, code execution, and miner deployment.
  • LiteLLM attacks exploited CVE-2026-42271 (authenticated command-execution) and CVE-2026-48710 (Starlette host-header validation bypass) to achieve unauthenticated RCE.
  • Kestra attacks linked to CVE-2026-49869 exploitation. RAGFlow compromise involved SSRF-style reconnaissance and unauthorized credential interception.

Impact

  • Stolen model-provider keys, virtual keys, database connection strings, and tenant configuration.
  • Durable host access allowing persistence and lateral movement.
  • Deployment of cryptocurrency miners (XMRig) and interception of newly configured LLM provider credentials.

Affected / Fixed Versions

  • LiteLLM: CVE-2026-42271 and CVE-2026-48710.
  • Kestra: CVE-2026-49869.

Recommendations

  • Inventory and secure exposed AI management surfaces.
  • Restrict administrative and gateway access.
  • Monitor for unauthorized execution and secret access originating from AI gateways.
  • Apply patches addressing identified CVEs.
  • Implement egress controls and monitor for lateral movement and cryptomining activity.

Reference Links

Ready to get started?

Contact us to arrange a half day
Managed SOC and XDR workshop in Dubai

Ready to get started?

Contact us to arrange a half day Managed SOC and XDR workshop in Dubai

© 2026 HawkEye – Managed CSOC and XDR powered by DTS Solution. All Rights Reserved.
This is a staging environment