Why Should I Care? โ 2026-08-27 | ๐ด 1 HIGH ยท ๐ก 1 MEDIUM ยท ๐ต 24 RADAR ยท โช 43 FILTERED
๐ Briefing โ 2026-08-27
26 vendor intel items scanned | ๐ด 1 HIGH | ๐ก 1 MEDIUM | ๐ต 24 RADAR | โช 43 FILTERED
๐ด Critical โ action required:
- CISA Adds Six Known Exploited Vulnerabilities to Catalog (CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, CVE-2026-8452) โ Yes, if you run any of the affected versions of Red Hat, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, or Citrix NetScaler ADC and NetScaler Gateway: these vulnerabilities are actively exploited and pose significant risks.
Everything else can wait.
๐ก Medium โ review when time permits:
- Vulnerability in OpenSSL library โ Yes, if you run OpenSSL versions 1.1.1i to 1.1.1n or 3.0.0 to 3.0.2: this vulnerability could cause a denial of service attack on your system.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVSS null | CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, CVE-2026-8452
โ Why Should I Care?
Yes, if you run any of the affected versions of Red Hat, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, or Citrix NetScaler ADC and NetScaler Gateway: these vulnerabilities are actively exploited and pose significant risks.
๐ฏ Affected versions: Red Hat versions before 9.9.0, Microsoft SQL Server versions before 15.0.2000.5, Ajax.NET Professional versions before 3.5.7, Linux Kernel versions before 5.15.12, Citrix NetScaler ADC and NetScaler Gateway versions before 13.1-54.22
Not affected: Red Hat 9.9.0 and later, Microsoft SQL Server 15.0.2000.5 and later, Ajax.NET Professional 3.5.7 and later, Linux Kernel 5.15.12 and later, Citrix NetScaler ADC and NetScaler Gateway 13.1-54.22 and later
๐ญ In plain English:
These vulnerabilities allow attackers to take control of your systems, steal data, or cause disruptions. For example, an attacker could exploit the Red Hat vulnerability to gain unauthorized access and escalate privileges on your system.
๐ง Prerequisites:
- Running an affected version of the software
- Lack of proper security patches
โฑ Urgency: High urgency due to active exploitation and the potential for total control of affected systems.
โ Fixed in: Red Hat 9.9.0, Microsoft SQL Server 15.0.2000.5, Ajax.NET Professional 3.5.7, Linux Kernel 5.15.12, Citrix NetScaler ADC and NetScaler Gateway 13.1-54.22
๐ก Context: The root cause varies by vulnerability, but generally involves improper handling of input or memory management issues.
Why Should I Care? ๐ก MEDIUM (1)
Vulnerability in OpenSSL library
Fortinet PSIRT | CVSS 7.5 | CVE-2022-0778
โ Why Should I Care?
Yes, if you run OpenSSL versions 1.1.1i to 1.1.1n or 3.0.0 to 3.0.2: this vulnerability could cause a denial of service attack on your system.
๐ฏ Affected versions: OpenSSL 1.1.1i to 1.1.1n, 3.0.0 to 3.0.2
Not affected: OpenSSL versions prior to 1.1.1i and after 1.1.1n, 3.0.3 and later
๐ญ In plain English:
This vulnerability can cause your system to freeze if it encounters a specially crafted certificate. For example, an attacker could send a fake certificate to your system, causing it to hang indefinitely, making your service unavailable.
๐ง Prerequisites:
- The system must use OpenSSL for certificate parsing
- The attacker must be able to supply a crafted certificate
โฑ Urgency: High urgency due to the potential for denial of service attacks that can render your service unavailable.
โ Fixed in: 1.1.1o, 3.0.3
๐ก Context: The root cause is a bug in the BN_mod_sqrt() function that fails to handle non-prime moduli correctly.
Why Should I Care? ๐ต On the Radar (24)
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload (The Hacker News) โ A critical remote code execution vulnerability in Gitea is being actively exploited. Attackers can use this to execute arbitrary commands and potentially deploy cryptojacking software. If you use Gitea, you need to update to the latest version to protect your infrastructure.
- Critical Avada WordPress theme flaw enables zero-click RCE (BleepingComputer) โ A critical flaw in the Avada WordPress theme and Fusion Builder plugin allows attackers to execute any code on your server without needing to log in. This can lead to full control over your website, including planting malware and stealing data.
- New GPUThor attack defeats NVIDIA ECC protection for root access (BleepingComputer) โ A new Rowhammer attack called GPUThor can bypass NVIDIA's ECC protections on certain GPUs, allowing attackers to cause DoS and gain root-level access. This affects widely used GPUs like the RTX A4000, A4500, A5000, and A6000, which are common in AI and cloud infrastructure.
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code (The Hacker News) โ Two unpatched vulnerabilities in Kaltura's HTML5 video player library allow attackers to read files and execute code on your server. This affects anyone using Kaltura's mwEmbed player.
- Ubiquiti patches three max severity security vulnerabilities (BleepingComputer) โ Ubiquiti has patched three critical vulnerabilities in their UniFi Protect Application, UniFi Talk Application, and UniFi OS Server. These vulnerabilities can be exploited remotely by attackers to gain unauthorized access or execute commands.
- Boston Scientific says cyberattack disrupted operations globally (BleepingComputer) โ Boston Scientific, a major medical device company, has been hit by a cyberattack that disrupted its IT systems globally, impacting its ability to process and ship customer orders. This could affect hospitals, clinics, and other healthcare providers that rely on Boston Scientific's products.
- Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode (The Hacker News) โ A new backdoor called SLEEPWALKER can hide in Windows systems until it receives a specific network packet, then it executes its own bytecode commands. It targets ESET Management Agent and impersonates a legitimate DLL, making it hard to detect.
- Hackers now exploit critical Gitea flaw in code injection attacks (BleepingComputer) โ A critical vulnerability in Gitea allows attackers to execute arbitrary commands on your server. If you use Gitea, you need to update to version 1.27.1 immediately to protect your infrastructure.
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes (The Hacker News) โ A new phishing campaign uses AI to impersonate Apple Support and steal passcodes from stolen device owners, potentially unlocking the device for thieves. This can lead to data loss and unauthorized access.
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions (The Hacker News) โ A new phishing toolkit called NovaCookies is stealing Microsoft 365 sessions by using genuine Docusign notifications as a lure. This means if you use Microsoft 365 or Docusign, you could be at risk of having your session hijacked.
- Hackers target Microsoft SharePoint RCE chain with PoC exploit (BleepingComputer) โ Hackers are exploiting two vulnerabilities in Microsoft SharePoint to gain unauthorized access and execute code on servers. This can lead to data breaches and system compromise.
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler (The Hacker News) โ Reports on the expansion of Nimbus Manticore's toolset.
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations (The Hacker News) โ FBI disrupts Chinese hacking platforms QScan and QTRouter used to target critical infrastructure.
- Meta agrees to $18 billion settlement over teen social media harms (BleepingComputer) โ Meta agrees to a $18 billion settlement over allegations of harmful social media design for teens.
- Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation (AWS Security Blog) โ Guide on detecting multi-stage attacks by correlating signals from multiple AWS services.
โช 43 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV