~/greenteam/nerd

Friday, August 7, 2026

Daily digest

A cluster of virtualization/container escape CVEs (Linux SCTP, KVM Zapscape) and Spectre v2 bypass research dropped today alongside major Cisco networking patches — worth prioritizing patch review this week.

cybersec The Hacker News

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux's SCTP networking code, present since 2008, can be exploited for full root access and container escape. Tencent researchers demonstrated escaping a container to reach the underlying host. Fixes shipped August 3 in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148.

Why it matters: Any Nutanix AHV nodes or container hosts running older kernels with SCTP reachable need patching now — this is a direct root/container-escape path relevant to CMMC boundary controls.

cybersec The Hacker News

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

A newly disclosed Linux kernel vulnerability (CVE-2026-64561) in KVM/x86's shadow MMU allows an attacker with kernel privileges inside an L1 guest VM to escape KVM isolation and execute code on the host. The risk applies specifically when nested virtualization is exposed to untrusted guests.

Why it matters: If nested virtualization is enabled anywhere in the AHV environment, this is a hypervisor-escape risk that should be checked against current kernel versions before it's weaponized.

cybersec The Hacker News

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs

Cisco released patches for 12 vulnerabilities in Catalyst SD-WAN and IOS XE Software found during an internal security review, including three rated 9.9 CVSS. The SD-WAN flaws affect devices regardless of configuration, and the IOS XE issues affect systems in autonomous or controller mode.

Why it matters: Near-max-severity CVEs on core network infrastructure warrant immediate patch scheduling and inclusion in the next POA&M review if any Cisco SD-WAN/IOS XE gear is in scope.

cybersec The Hacker News

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Entra ID researcher Dirk-jan Mollema showed that malware running in a signed-in Windows session can silently use a victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. This lets an attacker obtain a Primary Refresh Token, register a controlled device, and add further authentication methods depending on tenant policy.

Why it matters: This directly affects Intune-managed Windows 11 endpoints using WHfB — review Conditional Access and device compliance policies to limit blast radius from a compromised endpoint.

cybersec The Hacker News

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

An active adversary-in-the-middle phishing campaign is compromising Microsoft 365 accounts to identify finance and payroll personnel and harvest related email. The campaign uses residential proxies to make malicious sign-ins appear as ordinary consumer traffic, evading typical geo/IP-based detection.

Why it matters: Residential-proxy AitM defeats simple IP-reputation checks; ensure phishing-resistant MFA (FIDO2/certificate-based) is enforced for finance roles in GCC High tenants rather than relying on Conditional Access location rules alone.

cybersec BleepingComputer

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers disclosed TONTOU, a speculative-execution attack that bypasses current Spectre v2 mitigations on modern CPUs and successfully exfiltrated Linux password hashes in testing. A related technique, Interrupt Injection, timed hardware interrupts to re-poison branch predictors after mitigations ran.

Why it matters: Existing Spectre v2 mitigations on Nutanix AHV hosts and Linux VMs may not be sufficient; watch for microcode/kernel guidance from vendors before this becomes a checked item in vulnerability scans.

cybersec Krebs on Security

Canadian Man Pleads Guilty in Snowflake Extortions

Connor Riley Moucka, 26, pleaded guilty to computer fraud and conspiracy charges tied to extorting more than 165 organizations that used cloud provider Snowflake, including stealing call and text records of over 100 million AT&T customers. He was previously identified as one of the most consequential cybercrime actors of 2024.

cybersec BleepingComputer

Swiss government SharePoint breach compromised 200 accounts

Switzerland's federal IT office confirmed hackers exploited vulnerabilities to breach its Microsoft SharePoint servers, compromising approximately 200 accounts. The office did not detail the specific vulnerabilities exploited or the full scope of accessed data.

Why it matters: A reminder that on-prem/hybrid SharePoint remains a prime target for nation-adjacent actors; confirm all SharePoint Server instances (if any exist outside GCC High) are current on the July/August patch cycle.

cmmc The Register

Attacker phished way into US defense supplier's Microsoft 365 account

A phishing attack against a staffer at defense supplier IEH Corp gave an intruder access to the company's Microsoft 365 environment, including engineering files and potentially export-controlled technical data. The company disclosed the incident and is assessing scope of exposure.

Why it matters: A single phished credential exposing CUI/ITAR-adjacent data is exactly the scenario CMMC L2 access controls and phishing-resistant MFA requirements are meant to prevent — a useful case study for internal awareness training.

cmmc NextGov

CISA still finds water system controls exposed online amid multistate hacks

CISA acting director Nick Andersen said the agency continues to find internet-exposed water system industrial controls amid ongoing multistate hacks, and is working with the FBI to assist victims without attributing the intrusions to a specific group. Separately, Forescout found 22 exposed Rockwell PLCs in cities hit by these attacks, out of 4,407 exposed globally.

infrastructure AWS Security Blog

Automate certificates with ACME support in AWS Certificate Manager

AWS Certificate Manager now supports the ACME protocol for automated TLS certificate issuance and renewal, ahead of CA/Browser Forum mandates shortening max public certificate validity to 100 days by March 2027 and 47 days by March 2029. The feature targets customers managing certificates at scale.

Why it matters: Shrinking cert validity windows will make manual renewal untenable; if AWS GovCloud workloads use public certs, plan ACME-based automation now rather than scrambling closer to the 2027 deadline.

infrastructure The Register

Windows 10 LTSC 2021 has five months before security updates cost extra

Windows 10 LTSC 2021 will require paid Extended Security Updates starting in January, five months from now, except for the IoT edition. Organizations still running this LTSC branch will need to budget for ESU or migrate.

Why it matters: Confirm no endpoints in the Intune-managed fleet are still on Windows 10 LTSC 2021 outside the IoT edition; unpatched systems past January would be a NIST 800-171 finding.