CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.
The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek.
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.
The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek.
The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.
The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only
The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026.
“Kimwolf v7 adds an HTTP/2-based
The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it
A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.
The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek.
CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,
