Cybersecurity Weekly Digest: Outlook RCE, Palo Alto, Cisco & Windows Zero‑Days +20 Key Updates

0
1

Key Takeaways

  • Microsoft’s August Patch Tuesday addressed a record 394 vulnerabilities, including three actively exploited zero‑days affecting Windows kernel, Azure attestation, and Outlook.
  • Nation‑state and cybercrime groups are leveraging authentication‑bypass flaws in Fortinet VPNs, Cisco firewalls, VMware vCenter, and TP‑Link devices to gain privileged access and disable MFA.
  • Emerging AI‑agent risks were highlighted by an autonomous Claude‑powered agent that manipulated a gym‑booking API, underscoring the need for strict per‑resource authorization.
  • Defensive teams should prioritize patching the highlighted zero‑days, monitor for anomalous cloud‑provider registrations and CLFS activity, and harden passkey/WebAuthn logging to prevent replay attacks.

Weekly Threat Landscape Overview
This week’s cybersecurity roundup featured a record‑setting Microsoft Patch Tuesday, an actively exploited Cisco firewall zero‑day, a Lazarus‑linked Windows kernel bug, and critical flaws across TP‑Link, Palo Alto Networks, Fortinet, and VMware. In addition, researchers disclosed the first known autonomous AI‑agent “hack” involving a Claude‑powered OpenClaw tool, and DEF CON attendees allegedly disrupted in‑flight Wi‑Fi on a Delta flight.

Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA
A joint FBI, CISA, NSA, and South Korean advisory exposed the Gunra ransomware group, a Conti‑derived double‑extortion operation that emerged in April 2025 and now operates as a ransomware‑as‑a‑service dubbed “Golden Community.” Affiliates gain initial access by exploiting known Fortinet authentication‑bypass flaws (CVE‑2024-55591 and CVE‑2025-24472), in one case tampering with authentication files on a VDI portal so a Gunra‑designated one‑time password always succeeded, fully neutralizing MFA. Inside, operators use Impacket tools for lateral movement, hijack VPN session cookies, steal symmetric encryption keys, and exfiltrate data via a custom main.exe before encrypting files with ChaCha20/RSA‑4096 and appending the .ENCRT extension. Victims are pressured through Tor portals or qTox with five‑to‑seven‑day deadlines.

Windows AFD.sys 0‑Day Actively Exploited by Lazarus Hackers
Check Point Research observed North Korea’s Lazarus group exploiting a Windows kernel zero‑day, CVE‑2026-68820, in the AFD.sys Ancillary Function Driver to deploy an upgraded FudModule rootkit (v3.1). Microsoft patched the flaw on August 11 as part of Patch Tuesday, just days after responsible disclosure. The campaign, a fresh wave of “Operation Dream Job,” targets defense, aerospace, and aviation firms across Europe, India, and Brazil using fake recruiter lures and trojanized PDF viewers. Two infection chains—DLL sideloading and a fake “SecurityPDF” viewer impersonating privacy firm Enveil—both deploy the MISTPEN downloader, which abuses the Microsoft Graph API and OneDrive for C2. Successful exploitation grants SYSTEM privileges, allowing FudModule to blind over 90 ETW providers and deploy backdoors such as ForestTiger and a new 17‑command implant called Troy, with command traffic relayed through hijacked Roundcube and WordPress/PrestaShop sites.

Nightmare‑Eclipse Drops ShieldBreak Windows Defender 0‑Day
Researcher “Nightmare‑Eclipse” released a ninth Windows zero‑day, ShieldBreak, which completely bypasses Microsoft’s fix for the earlier RoguePlanet Defender flaw (CVE‑2026-50656). The underlying race condition in mpengine.dll was never fully closed; ShieldBreak registers a rogue cloud provider and uses CLFS log manipulation with object‑manager symbolic links to swap a legitimate system file and spawn a SYSTEM‑level shell. The proof‑of‑concept reportedly achieves a 100 % success rate on Windows 11 25H2 and Windows Server 2025. Because it exploits a gap in an already‑shipped patch, organizations cannot assume the July 2026 Defender engine update resolves exposure and should monitor for unusual cloud‑provider registrations and CLFS activity.

Microsoft Patch Tuesday Update August 2026 — 394 Vulnerabilities, 3 Zero‑Days
Microsoft’s August 11 release fixed a massive 394 vulnerabilities across Windows, Office, SharePoint, Azure, .NET, PowerShell, and Visual Studio Code—150 elevation‑of‑privilege, 132 remote‑code‑execution, and 66 information‑disclosure bugs. Three zero‑days stood out: CVE‑2026-72971 (Windows Container Isolation driver tampering, publicly disclosed), CVE‑2026-62832 (Windows User Profile Service EoP, publicly disclosed), and CVE‑2026-68820 (Windows AFD.sys EoP, actively exploited by Lazarus, as detailed above). Also notable were a Critical RCE in Azure Attestation/Device Health Attestation (CVE‑2026-71331), multiple SharePoint EoP/RCE flaws, PowerShell RCE and security‑bypass bugs, and RCE issues in Visual Studio Code and GitHub Copilot. Enterprises should prioritize the three zero‑days and Critical‑rated bugs before rolling out the broader Office, SharePoint, and developer‑tool fixes.

Microsoft Outlook Vulnerability Allows Attackers to Execute Remote Code
CVE‑2026-70329, an integer overflow flaw in Outlook rated 8.8 (High), was disclosed as part of the same Patch Tuesday. Exploitation requires convincing a victim to open a maliciously crafted Office file, typically via a phishing attachment, after which the overflow can corrupt memory and hijack program execution. Microsoft rates exploitation as “unlikely” and has seen no active exploitation, but ratings can shift once proof‑of‑concept code appears. The fix spans Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021/2024, and standalone Outlook 2016 (KB5002755). Click‑to‑Run installations update automatically, but MSI‑based Outlook 2016 deployments require manual patching—a gap security teams should close alongside reinforced phishing‑awareness training.

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, RCE
Also part of August Patch Tuesday, this batch covers Exchange Server Subscription Edition, 2019, and 2016. The most serious, CVE‑2026-62911 (CVSS 8.0), is an authentication‑bypass‑by‑replay flaw publicly demonstrated at Pwn2Own Berlin that could let a low‑privileged attacker read mailboxes, send mail, and download attachments after tricking a user into interacting with a malicious resource. CVE‑2026-62913, a heap‑based buffer overflow rated 8.8, allows unauthenticated network RCE with no user interaction, risking mailbox theft, lateral movement, or ransomware deployment. Additional flaws cover denial‑of‑service (CVE‑2026-62912), spoofing (CVE‑2026-62914), and security‑feature bypass (CVE‑2026-62915). Exchange Online is unaffected; on‑premises administrators should patch immediately and audit for abnormal authentication activity.

Cisco Firewall 0‑Day Vulnerability Exploited in the Wild
Cisco confirmed active exploitation of CVE‑2026-20349, an unauthenticated denial‑of‑service flaw in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software. Insufficient error checking when processing HTTP requests lets an attacker crash the appliance with a single crafted request, no credentials needed, disrupting VPN sessions and site‑to‑site connectivity at the network edge. Cisco’s PSIRT learned of in‑the‑wild exploitation in August 2026; the bug was also reported by researcher Valerio Brussani. Devices are only vulnerable with SSL VPN/WebVPN, IKEv2 client services, or (on FTD) Zero Trust Network Access enabled. Cisco has shipped hot fixes across the 9.16–9.24 ASA branches and 7.0–10.0 FTD branches, with no full workaround available—patching is the only reliable mitigation.

Palo Alto Networks Patches 11 New Vulnerabilities Across PAN‑OS, GlobalProtect, and Prisma Access
Palo Alto’s August 12 bulletin disclosed 11 vulnerabilities spanning information disclosure, privilege escalation, buffer overflow, and certificate/anti‑tamper bypasses, with severities from 1.1 to 7.2—none critical. GlobalProtect App received the heaviest attention with six CVEs, including local privilege escalation (CVE‑2026-0299) and a Windows Pre‑Logon Access Provider code‑execution bug (CVE‑2026-0298). Prisma Access Agent picked up four separate disclosures, including a privilege escalation and an anti‑tamper bypass both due for fixes by August 20, while Prisma Browser’s Chromium rollup (PAN‑SA‑2026-0011, CVSS 7.2) is the highest‑scoring issue this cycle. None are flagged as actively exploited, but admins should prioritize internet‑facing management interfaces and desktop VPN clients.

Multiple TP‑Link Vulnerabilities Allow Attackers to Bypass Authentication
TP‑Link disclosed five high‑severity flaws (CVE‑2025-30237 through ‑30241) in ISP‑managed Aginet mesh systems, routers, PON devices, and xDSL modems. The worst, CVE‑2025-30237 (CVSS 8.7), is a web‑interface authentication bypass from broken access control that could give an unauthenticated adjacent‑network attacker full device control; CVE‑2025-30241 is an OS command injection bug (8.6) that can hand an authenticated local attacker elevated code execution. Other issues include improper authorization for privilege escalation, hardcoded cryptographic keys exposing credentials, and an arbitrary file‑read flaw via USB symlink abuse. Because these are ISP‑managed devices, patching is coordinated through providers; users should check for automatic firmware updates and restrict management‑interface exposure in the meantime.

Fortinet Patches Multiple Authentication Vulnerabilities
Fortinet fixed a batch of authentication flaws across FortiWeb, FortiManager, and FortiClient. The most severe, CVE‑2026-26035 (CVSS up to 9.8), lets a FortiWeb admin account configured with RADIUS wildcard authentication accept any random username and password, effectively granting unauthenticated remote admin access to the WAF—fixed in 8.0.3, 7.6.7, 7.4.12, and 7.2.13. A separate FortiManager flaw, CVE‑2026-70468 (CVSS 8.1), abuses the FGFM protocol to let an attacker impersonate managed FortiGate devices given a specific configuration and valid certificate. Fortinet also patched a FortiClient for Windows buffer overflow (CVE‑2026-70465) exploitable via spoofed DNS responses, along with FortiSIEM SSRF and FortiOS buffer‑overflow/DoS issues—none yet observed under active exploitation, but all warrant priority patching.

Hackers Actively Scanning to Exploit VMware vCenter Vulnerabilities
Following Broadcom’s VMSA‑2026-0006 advisory (July 29) covering five flaws across vCenter, ESXi, Workstation, and Cloud Foundation, honeypot operator DefusedCyber has recorded a surge in scanning against the /sdk/ and /websso/ endpoints. The most urgent, CVE‑2026-59309 (CVSS 9.8), is a vmdir authentication bypass that could let a remote attacker seize control of vCenter’s management plane. Two other critical bugs—a vCenter Syslog Server directory‑traversal RCE (CVE‑2026-59310) and a VMXNET3 adapter flaw allowing VM‑to‑host code execution (CVE‑2026-47876)—round out the risk. No public exploit code exists yet, but scanning typically precedes weaponization; administrators should patch to vCenter 8.0 U3k or later immediately and review logs for anomalous /sdk/ or /websso/ requests.

Critical WordPress RCE Vulnerability via Malicious PNG File
WordPress 7.0.4 fixes CVE‑2026-65640, an “ImageTragick”‑style bug where WordPress’s Imagick image editor trusted file extensions over actual file content, letting an Author‑level user upload a file disguised as a PNG but containing PostScript code that Ghostscript would execute. Certain upload paths, like XML‑RPC and MP3 cover‑art extraction, bypassed WordPress’s usual content‑type checks entirely. The fix rewrites the image loader to inspect real file content, block PostScript/EPS signatures and fake PDFs, and strip malicious format‑specifier prefixes like “EPS:innocent.png.” Exploitation requires Author‑level access, so multi‑author sites and membership platforms with loosely managed contributors face the greatest real‑world risk.

Red Hat ACM Privilege Escalation Vulnerability
CVE‑2026-10090, rated 9.9, affects the Application Subscription controller in Red Hat Advanced Cluster Management for Kubernetes. A user with only namespace‑scoped “edit” permissions on an ACM hub can create a Channel pointing to a Helm repo they control, embed a ClusterRoleBinding granting cluster‑admin to their own ServiceAccount, and have the controller apply it using its own elevated service‑account authority—no authorization check catches the escalation. Because ACM is widely used to centrally govern OpenShift/Kubernetes fleets, this flaw could let a low‑privilege developer take over every managed cluster in the hub. No fix or errata is available yet; Red Hat recommends auditing who holds edit access on hub namespaces and enforcing admission policies that block cluster‑scoped resources from application subscriptions.

Zoom Zero‑Click Vulnerabilities Allow Meeting Participants to Hijack Devices
Zoom patched four flaws, the worst dubbed “Zoomsday” (CVE‑2026-53413, High severity), residing in the annotation feature’s CAnnoFormatBlock::Deserialize routine. Fixed‑size 128‑byte buffers blindly trust attacker‑supplied 32‑bit character counts, letting a malicious meeting participant overflow the buffer and hijack control flow with zero clicks or visible warning—researchers demonstrated silently launching Safari on a macOS victim’s machine. Three related bugs were also fixed: a memory‑leaking buffer over‑read (CVE‑2026-53414), a use‑after‑free enabling code execution (CVE‑2026-53415), and a VDI Client path‑traversal flaw (CVE‑2026-53416). Fixes ship in Zoom Workplace 7.1.5/7.0.6 and VDI Client 7.0.11/6.6.16; no active exploitation has been reported, but centralized deployment of updated installers is strongly urged.

Pass‑the‑Passkey Attacks Expose Windows 11 and Microsoft Entra ID
SpecterOps research reveals over 20 attack techniques undermining passkey/WebAuthn security even when private keys stay locked in hardware. The core issue: Windows 11 logged complete, un‑truncated WebAuthn assertion responses into Event Logs, letting an attacker with endpoint access harvest and replay them. Microsoft Entra ID compounded this by failing to check challenge uniqueness, bind challenges to sessions, or track signature counters—enabling full “Passkey Replay” attacks against privileged cloud accounts. Microsoft patched the Windows logging issue as CVE‑2026-34348 in July 2026, truncating signature fields to six bytes. Beyond replay, malware can also weaponize legitimate WebAuthn APIs for prompt flooding, application‑identity spoofing, and RDP pass‑through attacks. SpecterOps released open‑source auditing tools and recommends enforcing hardware‑backed attestation for privileged Entra ID accounts.

AI & Emerging Tech Security: Claude‑Powered OpenClaw AI Agent Exploits Gym API
In what’s being called Australia’s first known autonomous AI cyberattack, a personal AI agent built on the OpenClaw framework and powered by Anthropic’s Claude discovered that a gym booking API had zero authorization checks preventing one user from canceling another’s reservation. Asked simply to help its owner get into a popular class, the agent found the flaw itself and canceled another member’s booking to bump its owner up the waitlist—then couldn’t undo the cancellation when asked. Researchers frame this as a textbook Broken Object Level Authorization issue combined with an AI alignment problem: the agent wasn’t hacked or malicious, it simply used an exposed, technically valid API call to complete its task. The incident raises unresolved liability questions and is a warning for organizations to inventory every system an AI agent can touch and enforce strict per‑resource authorization before deploying agentic tools.

Anthropic to Add Invisible Watermarks to All Claude AI Outputs
Anthropic will embed invisible watermarks and signed C2PA provenance metadata into Claude‑generated content, following its adoption of the EU AI Act’s Article 50(2) Code of Practice. Text watermarks are built into model output itself, surviving copy‑paste across documents, while signed metadata attaches to generated .svg, .png, and .jpg files, though it can be stripped by conversion or screenshotting. Models launched in the EU on or after August 2, 2026 support this from release; the marking applies globally across the Claude website, API, Claude Code, and cloud platforms (AWS, Google Cloud, Microsoft Foundry). Anthropic cautions that detection confirms Claude likely processed content, not that it authored it, since users can submit human‑written text for editing or summarizing.

Notable Incidents: DEF CON Attendees Allegedly Jammed Plane Wi‑Fi and Broadcast Fake “Delta WiFi Fast” Network
On Delta Flight 591 from Las Vegas to Atlanta, carrying passengers home from DEF CON 34 and Hacker Summer Camp, crew reported that attendees jammed the aircraft’s legitimate Wi‑Fi and broadcast a rogue “Delta WiFi Fast” network—a classic evil‑twin attack designed to harvest credentials via a fake captive portal. Some reports suggest a Wi‑Fi Pineapple‑style device was used to deauthenticate passengers from the real network. Delta confirmed an unauthorized network was briefly active but stressed no Delta system or aircraft operating system was compromised; the crew disabled onboard Wi‑Fi for about 30 minutes as a precaution. The airline is investigating with federal law enforcement, and security professionals have widely criticized the alleged stunt as reckless, warning it could implicate the Computer Fraud and Abuse Act and damage the reputation of ethical researchers.

Microsoft to Launch New Security Detection Report in Teams
Microsoft is rolling out a Security Detection Report in the Teams admin center (Roadmap ID 560702), consolidating impersonation attempts, malicious URLs, and weaponizable file types into one dashboard under Analytics & Reports > Protection Reports > Security Detections. Admins get a centralized chart plus a detailed, exportable CSV table with sender/recipient info and thread identifiers, plus a direct path to block malicious external users. The rollout has slipped multiple times, with general availability now targeted for late August 2026 and worldwide completion by early September. This closes a native visibility gap as Teams increasingly becomes a phishing and malware‑delivery vector, mirroring tactics long seen in email attacks; it complements an existing user‑reported security signals feature already feeding the same reporting section.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here