Info
2026-08-21 14:01Z · last 4h · 29 findings
· glm-5.2:cloud
Threat Brief — 2026-08-21 — Cisco CVSS-10 Flaws, KEV-Exploited Windows Shell
Executive summary: Cisco patched nine Crosswork and Secure Workload vulnerabilities, five scoring a perfect 10.0 CVSS — urgent patching required for affected deployments. Separately, a Windows Shell spoofing flaw (CVE-2026-32202KEV) has landed in CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation. On the research front, a developer demonstrated Linux-based tracking of Apple's Find My network, breaking the iOS exclusivity assumption and raising questions about the platform's security model.
Top items:
- Cisco patches nine Crosswork/Secure Workload flaws, five at CVSS 10.0 — Cisco released fixes spanning Crosswork Data Gateway and Secure Workload Software as part of a comprehensive internal security review. Five of the nine score 10.0 on CVSS, meaning unauthenticated remote code execution or full compromise may be possible. Organizations running either product should treat this as an immediate-priority patch. (src: The Hacker News)
- Windows Shell Spoofing (CVE-2026-32202KEV) confirmed in CISA KEV — actively exploited — An MSRC informational acknowledgement update confirms this Windows Shell spoofing vulnerability is now listed in CISA's Known Exploited Vulnerabilities catalog, meaning it is being actively exploited in the wild. Federal agencies are ordered to patch; private-sector teams should follow suit. This continues the ongoing MSRC informational-update series first reported 2026-08-20 via MSRC. (src: MSRC)
- Linux forces Apple's Find My network to accept non-iOS trackers — A 22-year-old hacker demonstrated that Apple's Find My location network can be queried from Linux, eliminating the iOS exclusivity assumption. The technique could enable unauthorised location tracking using commodity hardware, raising concerns about the Find My ecosystem's security boundaries. (src: SecurityLab)
- Rollbit co-founder doxxed amid CS:GO skins fraud allegations — An independent researcher unmasked the pseudonymous co-founder of crypto casino Rollbit, alleging the platform defrauded customers with rigged games and links to CS:GO skins scandals. While primarily a reputational and regulatory story, it underscores persistent fraud risk in unregulated crypto-gambling ecosystems. (src: Xakep)
Themes:
- Patch pressure persists: Cisco's CVSS-10 batch and the CISA KEV addition for Windows Shell spoofing reinforce that August's patch workload remains heavy. Prioritise both the Cisco network-management and Microsoft Shell updates this week.
- Platform boundary erosion: The Find My network research follows a recent pattern of closed-ecosystem assumptions being challenged (similar to Android malware exfiltrating via nearby devices). Teams should not assume platform exclusivity provides a security boundary.
