Information

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate…

Read More

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched…

Read More

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is the paid version that offers additional features, including a Form widget with support for File Upload fields. The bug, tracked as CVE-2026-32475 (CVSS score of 9.8), is described as an arbitrary file upload issue…

Read More

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Microsoft releases cloud patches Microsoft has released patches for nine vulnerabilities…

Read More

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are tracked together under single CVEs. Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The critical security defects are rooted…

Read More

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations,…

Read More

I’ve been deepfaked: What do I do?

Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal Phil Muncaster 02 Sep 2026  •  , 5 min. read Tackling deepfakes has become something of a common cause across the political spectrum, in America and elsewhere. That’s down in part to the fact these fabricated videos and images are becoming both more commonplace and realistic. Thanks to generative AI (GenAI) tools, it’s…

Read More

OpenLeash Adds a Human Check to Risky AI Agent Actions

AI Agents can be incredibly useful, but their autonomous actions can be incredibly dangerous if not adequately controlled. Max Brin is developing a product he describes as an ‘AV for AI’. The analogy with antivirus can be a little confusing since this product is nothing like a traditional antivirus – but the designation is at least well-known, and the purpose of protecting networks from software mishaps is well understood by security practitioners. The name of…

Read More

This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month’s cybersecurity news 31 Aug 2026 With August coming to a close, it’s time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month. Here’s some of what caught Tony’s attention: OpenAI has disclosed more details about how its agents…

Read More

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau…

Read More