Wednesday, August 12, 2026
Daily digest
Microsoft's August Patch Tuesday (398/421 CVEs) dominates today's cycle, compounded by active exploitation of a SharePoint RCE and a Defender zero-day PoC — prioritize patching this week.
Microsoft Plugs Nearly 400 Security Holes, One Under Active Attack
Microsoft's August 2026 Patch Tuesday addressed 398 vulnerabilities (62 critical), including CVE-2026-68820, a Windows kernel driver flaw already exploited in the wild for SYSTEM privilege escalation, plus two other flaws publicly disclosed before the release.
Why it matters: Deploy this month's cumulative update across the Intune-managed Windows 11 fleet on an accelerated schedule given active exploitation and the sheer critical-flaw volume.
CISA Gives Federal Agencies Two Weeks to Patch Microsoft Bug Exploited by DPRK
CISA added a Microsoft vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch it within two weeks, after researchers linked exploitation to a North Korean campaign that targets job applicants.
Why it matters: CMMC L2 contractors should treat CISA KEV remediation deadlines as a de facto compliance benchmark even when not directly bound by BOD 22-01, since assessors increasingly reference KEV timeliness.
AI-Assisted Research Uncovers Unauthenticated RCE Chain in SharePoint, Already Exploited
Researchers disclosed CVE-2026-55040 (CVSS 9.1), an exploit chain in SharePoint Server Subscription Edition, 2019, and 2016 that allows attackers to impersonate any user, including administrators, without valid credentials. A PoC published by Rapid7 is already being used in active attacks against unpatched servers.
Why it matters: Any on-prem SharePoint Server instances feeding into or federated with M365 GCC High need immediate patching and isolation checks — unauthenticated admin impersonation is a direct path to broader tenant compromise.
Cisco ASA/FTD Flaw Exploited in the Wild for Remote DoS
Cisco confirmed active exploitation of CVE-2026-20349 (CVSS 8.6), a high-severity flaw in Secure Firewall ASA and Threat Defense software caused by insufficient error checking in HTTP request handling, allowing unauthenticated remote attackers to crash devices.
Why it matters: Perimeter firewall availability loss can cascade into VPN and remote-access outages for CUI-handling environments — check exposed ASA/FTD management interfaces and apply Cisco's patch or workaround now.
Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe released updates fixing multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic, including CVE-2026-48362, an OS command injection flaw in ColdFusion rated CVSS 10.0 that enables arbitrary code execution.
Malicious LiteLLM PyPI Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM packages sat on PyPI for roughly 40 minutes in March with credential-stealing code that harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords. Threat intel firm CloudSEK analyzed ~434,000 captured files and mapped potential exposure across more than 2,100 organizations.
Why it matters: If LiteLLM is anywhere in your self-hosted AI stack's dependency chain, audit build logs and rotate any secrets (SSH keys, cloud/K8s credentials) that could have been present on systems around the affected window.
Sandworm-Linked Group Uses Fake Job Interviews to Push Malicious WireGuard VPN Client
CERT-UA and BleepingComputer detailed a campaign by UAC-0145, a Sandworm subgroup, targeting IT professionals and sysadmins since May with fake recruiter outreach that delivers a trojanized WireGuard VPN client capable of running attacker commands.
Why it matters: This campaign specifically targets people in your role via fake job offers — flag unsolicited recruiter contact requesting VPN client installs or technical assessments as a phishing vector for staff with privileged access.
Contractors Confused by Inconsistent Certification Demands Under Pentagon's Anthropic Restrictions
Defense contractors report receiving materially different certification requirements from government customers regarding compliance with Pentagon restrictions on Anthropic AI tools, creating uncertainty about which standard actually applies.
Why it matters: If your organization uses any Anthropic-based tooling within CUI-touching workflows, expect inconsistent contracting officer guidance — document your own AI usage policy now rather than waiting for a uniform standard.
Agencies Set Divergent Policies as TikTok Returns to Government Phones
Following a DOJ opinion permitting TikTok on government devices, federal agencies have disclosed a wide range of management policies, from permissive access to blanket prohibition, with no unified federal standard yet in place.
Why it matters: Review your Intune app-protection and compliance policies for government-issued devices before assuming a default-allow or default-block posture — the lack of a unified federal standard means your organization's own policy decision carries compliance weight.
AWS Publishes Summer 2026 SOC 1 Report Covering 185 Services
AWS announced availability of its Summer 2026 SOC 1 report, covering 185 services over the twelve-month period from July 2025 through June 2026, providing customers a full year of control assurance documentation.
Why it matters: Pull the updated SOC 1 report into your AWS GovCloud compliance evidence library — useful for supporting your NIST 800-171 assessment and customer due-diligence requests without waiting on AWS Artifact refresh cycles.
AWS Landing Zone Accelerator Gets Independent C5:2020 Assessment Report
AWS announced a new independent assessment report for its Landing Zone Accelerator against Germany's C5:2020 cloud compliance criteria, now available via AWS Artifact, building on last year's digital sovereignty support features.
Malicious MCP Servers Can Split Instructions to Exfiltrate Secrets via AI Coding Agents
Researchers demonstrated that a malicious MCP tool server connected to an AI coding assistant can steal SSH keys, environment secrets, and source code by splitting exfiltration requests into innocuous-looking fragments delivered through channels the assistant already trusts, bypassing blunt-refusal safeguards.
Why it matters: If your self-hosted AI stack integrates MCP servers for coding assistance, audit which tool servers are trusted and restrict their access to secrets stores — this technique defeats simple prompt-based guardrails.