Info
2026-08-12 02:08Z · last 4h · 60 findings
· glm-5.2:cloud
Threat Brief — 2026-08-12 — ICS RCE, KEV Expansion, and Chromium Patch Flood
Executive summary: N-able N-central's auth-bypass flaw (CVE-2026-18577KEV) is now CISA-KEV-listed with a second emergency patch still failing to stop active exploitation — patch or isolate immediately. A batch of ~20 Chromium-sourced Edge CVEs includes a V8 out-of-bounds write worth prioritising. Johnson Controls C-CURE 9000 access-control systems carry a network-reachable RCE. New research drops a Spectre v2 bypass for modern AMD/Intel CPUs and an SSTI-to-RCE chain in RAGFlow.
Top items
- N-able N-central CVE-2026-18577KEV now in CISA KEV — second patch still not enough. The auth-bypass flaw giving attackers admin-level access to managed systems was first reported 2026-08-03 (src: The Hacker News). Today's development: CISA added it to the Known Exploited Vulnerabilities catalog and N-able released a second emergency patch as Storm-1175 continues to exploit it for ransomware deployment. (src: xakep) (src: securitylab.ru)
- Johnson Controls C-CURE 9000 / Victor — network-reachable RCE. CISA advisory ICSA-26-204-01 details vulnerabilities allowing an attacker with network access to achieve remote code execution on the application server. These are widely deployed physical access control systems. (src: CISA)
- Chromium/Edge patch batch — V8 OOB write and multiple UAF flaws. Microsoft Edge ingested a large Chromium fix set including CVE-2026-19162 (out-of-bounds write in V8), CVE-2026-19174 (integer overflow in V8), and numerous use-after-free bugs across Views, Media, Skia, WebGL, Extensions, and Web Authentication. No KEV or public-exploit tags, but the V8 write and Skia OOB warrant priority patching. (src: MSRC CVE-2026-19162)
- TONTOU: new interrupt-injection technique bypasses Spectre v2 mitigations on AMD and Intel. MIT CSAIL researchers demonstrated a novel attack class that defeats existing Spectre v2 protections on both major CPU vendors. No immediate patch available; relevant for high-value endpoint and cloud-host isolation decisions. (src: xakep)
- RAGFlow SSTI enables one-line RCE in popular generative-AI RAG engine. A server-side template injection vulnerability in RAGFlow allows full remote code execution via a single crafted input string. Organisations running RAGFlow in production should audit exposure and apply vendor fixes. (src: xakep)
- Levi Strauss corporate data stolen via social engineering. Attackers compromised three employee workstations through targeted social engineering and exfiltrated corporate data. Low technical sophistication but confirms continued effectiveness of credential/phishing-driven initial access against major brands. (src: xakep)
- Mira Hormone Monitor Android app — unauthorised access to health profiles. CISA medical advisory ICSMA-26-223-01 covers vulnerabilities allowing attackers to access health data, modify records, cause DoS, and disclose session tokens in the Mira fertility-tracking app and device. (src: CISA)
- Pulsetto Vagus Nerve Stimulator — hidden commands disable electrical safety. Advisory ICSMA-26-223-02 warns that an attacker can use hidden commands to disable safety mechanisms or modify stimulation output on the Pulsetto device, posing a direct physical-safety risk to users. (src: CISA)
- Russian banks mandated to scan client devices for malware from March 2027. New regulation requires Russian banks to block card transfers, e-money, and fast-payment-system transactions if malware is detected on the customer's device. Implausible to enforce reliably and likely to generate false positives, but signals a regulatory push toward endpoint-integrity controls. (src: xakep)
Themes
- AI tooling as attack surface and attack tool: RAGFlow's SSTI-to-RCE, malicious MCP servers splitting instructions (reported yesterday), and Kimsuky's offline AI stack all reinforce that the generative-AI ecosystem is now both target and weapon. Secure AI infrastructure with the same rigour as any internet-facing service.
- Medical device safety commands keep coming: Two advisories on the same day — one for data exposure (Mira) and one for physical-safety bypass (Pulsetto) — highlight that consumer medical IoT remains chronically under-secured.
- Ransomware operators exploiting older, known flaws over novel zero-days: Gunra (Fortinet + Schneider Electric) and Storm-1175 (N-central) both succeed with patched-but-unpatched vulnerabilities already in KEV. Hygiene and patch latency remain the dominant risk multiplier.
