SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThree Microsoft flaws are under recent active exploitation. CVE-2026-55040, CVSS score 9.1, allows an unauthorized attacker to bypass a security feature over a network due to weak authentication in SharePoint. This vulnerability was patched in Microsoft's July 2026 Patch Tuesday, but researchers from Defused Cyber reported on August 12 that they observed a proof-of-concept (PoC) exploit in use against their honeypots within 24 hours of Rapid7 publishing it. This flaw has not yet been added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog (CISA KEV) at the time of this writing. CVE-2026-45659, CVSS score 8.8, allows an authorized attacker to execute code over a network by exploiting deserialization of untrusted input in SharePoint. This vulnerability was patched in May and was first added to the KEV on July 1 with a three-day remediation deadline for Federal Civilian Executive Branch (FCEB) agencies. CISA released another advisory on July 16 urging organizations to harden SharePoint against this and four other vulnerabilities, and also updated the KEV entry for this flaw on August 11 to note that it has been observed in use in ransomware campaigns. CVE-2026-68820, CVSS score 7.0, allows an authorized attacker to elevate privileges locally by exploiting a use-after-free flaw in the Windows Ancillary Function Driver for Winsock. This is the only flaw addressed in Microsoft's August 2026 Patch Tuesday that is known to be exploited, and it has been added to the KEV with a three-day remediation deadline. Check Point released a simultaneous report that describes a long-running campaign by North Korean state-affiliated hackers to target the defense sector with fake job interviews, leveraging CVE-2026-68820 to elevate privileges as part of a backdoor malware payload.

The SharePoint authentication flaw was addressed in the July Patch Tuesday update, and there was a POC exploit published. Make sure that your on-premises SharePoint 2016 and 2019 servers were patched. It's August, so the July patches should be ancient history, but make sure. Then, after you've had your coffee, see if there is (still) a valid reason you're hosting your own SharePoint servers. If you really still need them, then don't expose them to the Internet — put some layer of application security control in front of them.

For organizations beginning to pilot VulnOps programs, it helps to pick real vulnerabilities as exercises for the process: identify exposure, assess context, prioritize, remediate, validate, and learn from the cycle. These actively exploited SharePoint and Winsock flaws would make pretty good candidates for your VulnOps pilot to address quickly. But don’t worry if you miss this particular opportunity. At the current pace of vulnerability discovery and exploitation, we’re going to have hundreds more examples to practice on in the coming weeks. Sigh.
We’ve reached a point where software patches must be deployed immediately upon release. Waiting for a CISA KEV catalog entry is no longer a viable strategy — cybercriminals are actively reverse-engineering patches and weaponizing vulnerabilities in real time. Organizations must prioritize automated patch management to stay ahead of the threat.
BleepingComputer
Rapid7
NIST
BleepingComputer
CISA KEV
NIST
The Record
Check Point
CISA KEV
NIST
The QUIRSO Threat Research team has observed a campaign that is actively exploiting a known vulnerability in VMware vCenter Syslog server. The flaw, CVE-2026–59310, CVSS score 9.8, is a critical directory traversal issue that could be exploited to achieve arbitrary code execution. QUIRSO Threat Research has identified 361 compromised IP addresses in 47 countries, including 55 in Germany, 41 in the US, 38 in Turkey, 26 in Iran, and 25 in France. Broadcom released fixes to address this vulnerability, along with four others in VMware products, on July 29, 2026. The researchers write, "Affected systems in the campaign observed by QUIRSO first connected to the attacker’s infrastructure only five calendar days later on 3 August. The campaign peaked the following day, when 151 additional victim IPs were first observed. By 5 August, 343 of the 361 identified victim IPs — approximately 95% — had appeared." They also note that the attackers are using reverse_ssh for persistence and remote access. VMware vCenter users are advised to update to fixed versions.

If you have vCenter, you have two tasks. First, apply the update, Second, make sure that you don't have the reverse_ssh in your environment. After that's set, make sure that you're restricting access to your vCenter management services, and verify the cron entries are clean and accounts are all legit. Consider that your vCenter server is as critical as a Domain Controller, a prime resource for lateral movement when compromised. Have a DR tabletop with that as an entry point.

Five days. That is how long defenders apparently had between Broadcom releasing the fix and compromised systems communicating with the attackers' infrastructure. Within another two days, approximately 95% of the victims identified in this campaign had appeared. The lesson is simple and reinforces many other recent stories covered by SANS NewsBites: Patching critical internet-facing infrastructure cannot operate on a monthly timetable. Your vulnerability management programme needs a fast-track facility for vulnerabilities affecting critical and exposed systems.

Good ol’ directory traversal rears its ugly head yet again, this time in a particularly valuable target: VMware vCenter. Five or so days from patch release to widespread exploitation is a painfully short window, especially for a product that serves as a control plane for virtualized infrastructure. This should jump to the front of the remediation queue. Patch urgently, but also investigate for compromise. Once exploitation is occurring, installing the fix closes the door but doesn’t tell you whether someone walked through it yesterday. For high-value management planes, accelerated patching and post-patch threat hunting should go together.
SCWorld
SecurityWeek
BleepingComputer
The Hacker News
Medium
NVD
Broadcom
On Tuesday, August 11, Zoom released security bulletins to address four vulnerabilities. CVE-2026-53413, CVSS score 8.3, is a high-severity buffer over-write flaw in Zoom Clients that could be exploited to achieve remote code execution. CVE-2026-53414, CVSS score 6.5, is a medium-severity buffer over-read flaw in Zoom Clients that could be exploited to create denial-of-service conditions. CVE-2026-53415, CVSS score 8.3, is a high-severity use after free flaw in Zoom Clients that could be exploited to achieve remote code execution. CVE-2026-53416, CVSS score 7.1, is a high-severity path traversal flaw in Zoom VDI that could be exploited to achieve information disclosure. To address CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, Zoom has released Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, and Meeting SDK version 7.1.5. To address CVE-2026-53416, Zoom has released and Workplace VDI Client for Windows versions 7.0.11 and 6.6.16, and Workplace VDI Plugins versions 7.0.11 and 6.6.15. Zoom indicates that CVE-2026-53413 and CVE-2026-53414 were reported by Idan Levcovich from A Security; CVE-2026-53415 was reported from by Zoom Offensive Security; and CVE-2026-53416 was reported by CK Tan from the XOR team at JPMorgan Chase.

Hey look at that, another AI-discovered vulnerability. Come on, I heard that eyeroll, it's still cool. But now we need to do something — Zoom made the updates, so you're going to want to make sure the updates have been applied. Don't assume someone will stop and install the update when they're trying to get connected to a meeting, or that they did the “restart Zoom” part of the update. Beyond finding a good outage window, you're likely going to have to send out an announcement as a CYA. This could be a good time to get everyone to Zoom 7.1.5.

Gosh, this edition of NewsBites feels like an endless series of high-CVSS flaws. Welcome to the new normal. At Black Hat and DEF CON last week, I asked many people associated with patching and software security at major vendors and in the industry more generally how long they thought this storm would last. Every single person said, "I have no idea." I followed up by asking, "Do you think we might get lucky, and it’ll be short, like 3 or 6 months?" Each one said, "No way… this will be at least a year, and maybe two or three." I was hoping for another answer, but it looks like we're in for quite a slog.

And here was me thinking that the risk in using Zoom was leaking of meeting content. (I use the Apple iOS client, but I will update it anyway).
SecurityWeek
SCWorld
Zoom
Zoom
Zoom
Zoom
Zoom
A Security
On Tuesday, August 11, Microsoft released security updates to address a total of more than 400 vulnerabilities. Of those, 62 are rated critical, one is being actively exploited, and two were disclosed prior to Microsoft's updates. The exploited vulnerability, CVE-2026-68820, CVSS score 7.0, is a use-after-free issue in Windows Ancillary Function Driver for WinSock that could lead to privilege elevation, also mentioned in another story in this issue of NewsBites. The publicly disclosed vulnerabilities are CVE-2026-62832 (CVSS score 6.8), an elevation of privilege vulnerability in Windows User Profile Service, and CVE-2026-72971 (CVSS score 4.8), a tampering vulnerability in Windows Container Isolation FS Filter Driver (unionfs.sys).

421 vulnerabilities in one month is an extraordinary volume for defenders to absorb, prioritize, test, and remediate. AI-assisted vulnerability discovery is helping us uncover flaws at a remarkable pace, which makes beginning to build VulnOps processes increasingly important for deciding what needs attention first and validating that remediation actually worked. I also want to thank the Microsoft security and engineering teams doing the hard, often invisible work behind these releases. They are draining a very large swamp of vulnerabilities accumulated over decades of software development, while simultaneously trying to produce patches that are safe, reliable, and deployable across an enormous installed base. That is a formidable undertaking, and the sheer scale of Patch Tuesday gives us a glimpse of just how much work is happening behind the scenes.

I am not sure the actual numbers matter these days — focus on getting the updates deployed, as POCs aren't far behind. With the current volume of patches, your grouping/prioritization of systems is how you're going to keep your head above water. The majority have to be in the auto-update category; then you can focus on more sensitive systems with regression testing and defined outage windows. Make sure these have other security layers to help deflect unwelcome advances. Remember, those defenses need to be top tier in terms of updates and security posture, but they will save your bacon if done right.

Back when Microsoft Windows (and most software) was riddled with simple (such as buffer overflow, etc.) vulnerabilities, waves of successful attacks forced Microsoft to both improve security focus in its software development process and move to monthly patch releases, which was vigorously resisted by CIOs. This AI-assisted wave points out the need for the software industry to make big leaps forward in ease of patching legacy software and vulnerability avoidance in new applications.

Echoing John Pescatore's words to also point out a "...need for the software industry to make big leaps forward in" initial software quality. Patching transfers the cost of quality from the developers to the customer and multiplies that cost by the number of customers. CIOs would have to be blind not to resist it. The use of AI in software development and testing is necessary and efficient. Because AI tends to be literal, rigorous specification is necessary.
SANS ISC
KrebsOnSecurity
The Register
The Record
ZDNET
Dark Reading
SecurityWeek
Help Net Security
MSRC
The US National Institute of Standards and Technology (NIST) has published a Request for Information (RFI) in the Federal Register seeking "stakeholder perspectives on how the NVD [National Vulnerability Database] can grow to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility." The RFI described NIST's current process for gathering information about CVEs and enriching those records, while noting that "the inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent, ... [and that] ... the advancement of AI presents an opportunity to transform the vulnerability management ecosystem." The document poses questions about the vulnerability management process; vulnerability information dissemination; risk assessment and prioritization; remediation development, deployment, and monitoring; vulnerability data and standards; the technology development process; and a vision for the NVD. NIST will be accepting comments through Tuesday, October 13, 2026.

NIST is on the right track, seeking to improve their process and leveraging the gains seen in other areas by the use of AI. Now is your chance to provide guidance from your experiences to help them choose wisely. Comments need to be entered through the federal e-Rulemaking portal. Go to www.regulations.gov and enter NIST-2026-0100 in the search field. Don't wait — October 13 is a hard deadline.

For all of its shortcomings, the NVD is a critical resource for many vulnerability management programs. Authoritative, standards-based enrichment of vulnerability data is a critical service to the community, and I hope NIST can form an alliance between industry and academia to continue supporting NVD, even amid the current surge in vulnerabilities.

AI is going to change vulnerability management far more profoundly than simply helping us find more bugs. In my 30-minute SANS webcast on VulnOps on August 12, I discussed some of the growing strain on the NVD as vulnerability discovery accelerates. So, I’m very heartened to see NIST taking on this modernization effort. In our VulnOps work, some of the biggest gains come from tightening the entire loop: discovery, validation, contextual prioritization, remediation, retesting, and deployment, with humans reviewing and steering throughout. The NVD can be enormously valuable in that work, but only if its data is timely, machine-consumable, trustworthy, and rich enough to support decisions beyond a static severity score. This looks like a noteworthy and useful project for the community. As vulnerability discovery accelerates, the rest of our vulnerability management ecosystem needs to evolve right along with it.
https://www.sans.org/mlp/vulnops-cisos-guide-to-starting-implementation
NIST’s take on vulnerability management in the age of AI hits the mark. The ultimate goal for the security industry must be end-to-end patch automation. Once achieved, it will force us to rethink the value proposition of the NVD altogether. But until full automation is a reality, the NVD remains essential, and applying AI to its internal operations is critical to keeping pace.
Local governments in several US states have reported cyberattacks affecting their IT networks. Suisun City, California reported that its IT systems became infected with malware and were compromised on the morning of Friday, August 7. The incident affected "critical public safety operations, including 911 routing, police and fire dispatch, records and City services." Suisun City shut down its entire IT network to contain the breach and preserve evidence. The city declared a state of emergency on August 8. As of Tuesday, August 11, the city said that many services would remain unavailable through Friday, August 14. Public safety services and response systems are operating, and the incident is under investigation. Coweta, Oklahoma reported that a ransomware attack on Wednesday, August 5, "affected all City computers, files, and computer-based services, except the City website and [the city's] third-party online billing portal." Police and fire departments were not affected by the attack. Coweta plans to restore its systems from offsite backups once the ransomware has been removed. Mitchell, South Dakota is investigating a cybersecurity incident that occurred on Friday, August 7. The city shut down its network as a precaution. Critical and emergency services are not affected, and the city is investigating the incident. Coryell County, Texas experienced a "technology disruption" last week. County emergency services and public-safety systems are not affected, and the incident is under investigation. Washburn County, Wisconsin became aware of a cyber incident on Thursday, August 6. The county has launched an investigation.

The recent attacks against water utilities and these incidents involving local governments expose a common underlying problem: Small public-sector organizations are being asked to defend increasingly complex systems with limited technical staff and resources. There are differences in impact, of course — attacks against water systems can disrupt physical processes, while attacks against local governments can affect public safety and essential services. I think that the common lesson is what we call community resilience. While protecting computer systems remains important, leaders need to plan for keeping communities and facilities functioning when those computers are not available.

Take a look around at your city, county, and state's adoption of technology for what used to be a lot of manual processes. It's pretty amazing. It also raises the likelihood of disruptions close to home. Meet the IT staff behind these systems, heck, buy them a beer or something, then see how they are with cyber security. Some have amazing programs — I love hearing my local folks talk about Operation Cyber Idaho or election security — while others are stuck. We need to help the stuck ones get hooked up with the right ISAC, apply for grants for services, locate needed talent, or maybe just brainstorm and vet ideas. The goal is to help them raise the bar, not to interfere or cause harm.

Only healthcare and schools rank ahead of municipalities as ransomware targets of choice. Strong authentication, layered network, and least-privilege access control are necessary and efficient.
The Record
Suisun
City of Coweta
Dakota News Now
KCEN TV
Washburn
Winnipeg's Health Sciences Centre has suffered a ransomware attack that is affecting the facility's heating, ventilation, and air conditioning (HVAC) systems as well as door access. Last year, the Manitoba Nurses Union found that the Health Sciences Centre was too dangerous for workers due to recent violent incidents; Health Sciences Centre has placed security and institutional safety officers at hospital entrances. Shared Health, which operates the Health Sciences Centre, has launched an investigation into the incident and has notified provincial government. The organization has also consulted with third-party experts. The attack appears not to have affected patient care or clinical services. In 2024, Manitoba's auditor general cautioned Shared Health to improve its cybersecurity posture, as it was not conducting incident response testing at that time; the auditor general warned that the absence of testing could lead to "delays in responding to cybersecurity incidents at Shared Health." Winnipeg's Health Sciences Centre is the largest hospital in Manitoba, Canada.

This feels like an extension of the violent physical attacks on the facility, which makes me sad as those same attackers are likely to have to turn to this facility when they are in need of healthcare. For the rest of us, it is a reminder that OT hacks and attacks are real, so don't make things easy to reach. Sure your systems are hardened and isolated, but if I can turn off your data center's CRAC units, or prevent physical access by locking your doors or changing the access list, you're not going to be happy. Make sure that you've got this, and that handling compromise of your OT systems is part of your incident response/DR playbook.

Cyber resilience is not just about keeping IT systems running. When a cyberattack affects doors, ventilation, and air conditioning in a hospital, cybersecurity quickly becomes an operational and potentially physical safety issue. Particularly in this case where the centre is under threat of physical violence, losing the ability to control their doors is a major safety concern. This is exactly why the EU NIS2 places such emphasis on resilience and incident preparedness. Organisations operating essential services need to regularly test whether they can continue delivering those services when technology fails, rather than discovering the answer during an actual attack.
CBC
Winnipeg Sun
Gov Infosecurity
OAG Manitoba
OAG Manitoba
The UK Information Commissioner's Office (ICO) has reprimanded the ACRO Criminal Records Office for security shortcomings that led to the office being breached three times between July 2021 and June 2023. ACRO was found not to have applied available updates to the Kentico content management system that was running at the time of the breaches, and also found not to have heeded security warnings from cybersecurity firms. The breaches affected personal data of nearly 11,000 individuals. "The ICO found ACRO had engaged third-party providers to deliver certain security services, including patch management. However, ACRO did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier." Certain factors contributed to ICO's decision to reprimand ACRO rather than impose a fine: Network segmentation kept the intruders from accessing ACRO's core systems, and ACRO had taken steps to improve its cybersecurity posture following discovery of the breaches.

Under the EU GDPR and UK data protection legislation, personal data relating to criminal convictions and offences is subject to additional protections. As a result, a breach involving this type of information could have a particularly serious impact on the people whose data ACRO is meant to protect. Outsourcing a security function does not mean outsourcing responsibility for it. ACRO had third parties providing security services, yet responsibility for identifying and monitoring critical security updates was unclear. "We thought the supplier was doing it" is not a convincing explanation to a regulator after a breach.

Outsourcing patch management does not outsource accountability. Every third-party security service needs an unambiguous owner on the customer side who knows what must happen, how quickly, and how completion is verified. Sadly, "the vendor handles that" is not a control.

When you outsource security/patching, you do need to allow improvements to be made. Even if you just hire an assessment, that report isn't intended to just look good on the shelf; you need to act on it. Business system owners don't like downtime, but they like having their data exfiltrated or altered even less. Work together to find a palatable way to do regular updates, and your credibility will build over time with a smooth experience. Avoid unnecessary fire drills; play to win the long game.
Network segmentation saved the day here, but it doesn't replace the need for critical hygiene like patch management. If you outsource patching to a third party, auditing their work is non-negotiable. Secure configuration is another vital control — while not highlighted in the report, system misconfigurations remain a top initial access vector for attackers. Hopefully this reprimand serves as the necessary catalyst for ACRO to uphold an appropriate standard cyber duty of care for the sensitive records they protect.
On August 10, 2026, the pilots of Delta flight 591 from Las Vegas to Atlanta sent mid-flight messages to air traffic control at 12:34 and 12:51 UTC, reporting that a passenger had created an unauthorized "Delta WiFi Fast" network and blocked passengers from accessing the legitimate onboard Wi-Fi. After sending the reports via the plane's Aircraft Communications Addressing and Reporting System (ACARS), the crew deactivated official Wi-Fi for about 30 minutes, and once the plane landed, federal authorities boarded to conduct questioning and seize unauthorized equipment. A spokesperson from Delta has since stated that there was never a threat to aircraft operating systems nor the safety of the flight, and that the airline is continuing to investigate. The pilots associated the incident with the recent DEF CON conference in Las Vegas; DEF CON's head of press, Monika Hathaway, has since told news sources, "Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations. If we had caught them doing this at DEF CON we would have removed and banned them from the conference." Willful interference with Wi-Fi is a violation of section 333 of the US Federal Communications Act and may be punished by a fine of $10,000 and/or a prison sentence of one year.

It's really tempting to go apply the tools and techniques you just learned at a conference or class, and an airplane feels like a target-rich environment/opportunity. It's also a bad idea: We're talking a closed box with no exits that is heavily regulated and involves real consequences for disruption, including fines, prison times, arrest, and the possibility you could wind up on TSA's No-Fly List. As the rogue hotspot was itself online, and as they have a validated list of passengers, it shouldn't be too hard to see which accounts were (still) online during the incident and track back to the hacker. Remember those sessions on ethical hacking? I'm having flashbacks of my instructors like Ed Skoudis and Larry Pesce reminding me about approved scope, permission, and keeping activities legal.

I was very disappointed to hear about this incident. I was at DEF CON myself, and one of my Counter Hack teammates was actually on this flight heading home, although he didn’t notice the Wi-Fi issue at the time (he was probably catching some much-needed sleep after the con!). Some people may dismiss this sort of thing as silly hacker hijinks, but deliberately interfering with communications aboard an aircraft is a serious matter. Beyond the immediate disruption, incidents like this damage the reputation of the hacker community, reinforcing exactly the stereotypes that so many ethical hackers have worked hard for decades to overcome. Curiosity, experimentation, and pushing boundaries are wonderful parts of hacker culture. Messing with systems on a commercial aircraft crosses a line, in my estimation.

It does not help when major AI companies just the week before bragged about breaking all the rules of ethical testing. But remember that you will probably never be a better pentester than AI. So let's focus on being better humans, and not violate the universal "don’t be an idiot" rule.

To quote Spiderman's uncle Ben, "With great power comes great responsibility." There is an important difference between security research and interfering with systems you do not own or have permission to test. Being able to do something does not mean you should do it. Responsible security research requires clear boundaries, permission, and, occasionally, the common sense to know when to leave the laptop in the bag.

Obvious stupid behavior, but also a good indicator to both DEF CON (a $10M+ revenue event) and the airlines who charge hefty Wi-Fi fees to do a better job both protecting their customers and having logging/auditing capabilities to support law enforcement efforts to go after vandals and criminals.
Testing cyberattack theories on a privately owned network — especially an aircraft in mid-flight — is reckless. Attending a top-tier hacking conference and wanting to apply what you’ve learned is understandable, but that experimentation belongs strictly in a controlled lab environment. Hopefully they face the full legal consequences for their actions.
Airframes
Airframes
The Register
BleepingComputer
Ars Technica
CyberScoop
On Monday, August 10, 2026, Mozilla announced an early transition to a new GPG signing subkey for Linux tarballs, RPM packages, and checksums files for Firefox and Thunderbird, because an unencrypted copy of the existing subkey had been added to a GitHub repository. While the repository was private and only accessible to "a small group within Mozilla, all of whom already had authorized access to the key through other means," the company has revoked the old key and taken measures to prevent this occurring again. Users who manually verify GPG signatures need to import the new key and the revocation for the old key. Users who install Firefox with RPM packages should consult Mozilla's announcement for specific instructions on how to rotate the key in Fedora 42 and 43, RHEL/Rocky/Almalinux, and openSUSE/SUSE distributions. For users outside these cases, no action is required.

This is a good proactive step by Mozilla. Even with nominal exposure, revoking and replacing the signing key immediately renders the use moot. So, make sure that you've got the new signing key in your GPG signatures — if you're using RPM packages or manually verifying GPG signatures, this means you. The steps are pretty simple and easy to push out/automate: erase the key from rpm, import the new one, and clean up the caches.

The disruption should be minor. This will only affect users installing Firefox and Thunderbird from source, and maybe some users using RPM. Everybody else should be good. Mozilla did the right thing by rotating the key when it was exposed, rather than waiting until it was proven compromised.
Revoking the exposed key was a smart, necessary move by Mozilla to prevent potential harm. Thankfully, most users won't notice a difference, and updating to the new key is a simple fix for those who do. Hopefully Mozilla releases an after-action review so the community can learn how to prevent this moving forward.
Mozilla
The Hacker News
SecurityWeek
The Register
SANS Internet Storm Center StormCast Friday, August 14, 2026
AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion
https://isc.sans.edu/podcastdetail/10052
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI
CPU Privilege Escalation
https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii
https://github.com/xoreaxeaxeax/skitter-creek-bath-salts
GeoServer Vulnerability
https://x.com/q1uf3ng/status/2087490992723407096
Windows USB Driver Vulnerability
https://x.com/0xedh/status/2085842285481062887
SANS Internet Storm Center StormCast Thursday, August 13, 2026
Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI Regulation
https://isc.sans.edu/podcastdetail/10050
Linux Kernel Process Accounting
https://isc.sans.edu/diary/Linux+Kernel+Process+Accounting/33240
ShieldBreak - Windows Defender 0day vulnerability
Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
California law puts digital fingerprints on AI fakes
https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content
https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
SANS Internet Storm Center StormCast Wednesday, August 12, 2026
Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wi-Fi
https://isc.sans.edu/podcastdetail/10048
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+August+2026/33236
Zoom Vulnerabilities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes GPG Key
Rogue Inflight Wifi
My Upcoming Classes
Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.
AI Threat Readiness 101 Machine-speed attacks need machine-speed defense. AI is reshaping how applications are built and how attackers operate. As exploit windows shrink and AI adoption expands the attack surface, security teams need new approaches that move beyond traditional vulnerability management. The new AI Threat Readiness 101 is a one-page visual breakdown of machine-speed threats, why traditional security can't keep up, and the four pillars of AI threat readiness.
Webinar | From Framework to Action: Applying the SANS AI Security Maturity Model | Wednesday, September 16 | Chris Cochran, Diana Kelley, Malcolm Harkins, and Kyriakos "Rock" Lambros
Webinar | Deleting the Attacker’s Advantage | Thursday, August 27 | Kurtis Minder
Survey | The State of Cybersecurity at the Human Edge: A 2026 SANS/Sidekick Survey | Your participation will help build an industry-wide picture of where human-layer defenses stand today, where the biggest gaps remain, and where organizations plan to invest next.