๐ต๏ธ RESEARCH & DEEP DIVES
- Plug & Pwn chains Windows PnP installs into SYSTEM access
Researchers demonstrated Plug & Pwn chains that turn Windows PnP driver installation into SYSTEM execution.
- Fully updated Windows 11 systems are affected, including RDP and VDI environments with USB redirection enabled.
- Windows Plug and Play can automatically install signed vendor packages containing insecure services, co-installers, and privileged components.
- Researchers chained emulated Sierra Wireless and Sony FeliCa devices to redirect DNS, write a malicious DLL as SYSTEM, and load it before logon.
- A remote variant forges Intel RealSense USB descriptors over RDP; a user-writable installer directory enables CRYPTBASE.dll sideloading as SYSTEM.
- Additional Wacom and Atheros package weaknesses register a malicious print-monitor DLL that the Windows Print Spooler loads as SYSTEM. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ ADVISORIES
-
Palo Alto Networks patches 11 flaws in PAN-OS and security products Palo Alto Networks patched 11 vulnerabilities across its security product portfolio.
- PAN-OS, GlobalProtect App, Prisma Access Agent, and Prisma Browser are affected.
- The August 12, 2026 bulletin covers 11 vulnerabilities.
- Flaws include information disclosure, local privilege escalation, buffer overflow, certificate validation bypass, and anti-tamper bypass issues.
- The release also includes a monthly Chromium update rollup. ๐ Source: cnbc.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Lazarus exploited Windows zero-day in Operation Dream Job attacks ๐ Source: msrc.microsoft.com
-
WordPress 7.0.4 Fixes Author-Level Imagick RCE ๐ Source: wordpress.org
๐ CVEs & KEV
- CVE-2026-73294 โ CVSS 9.9 โ Semaphore U: OS Command InjectionSemaphore UI is a web interface for managing...
- CVE-2026-64639 โ CVSS 9.3 โ Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and...
- CVE-2026-73293 โ CVSS 8.8 โ Semaphore UI: Manager-to-owner privilege escalation via custom-role slug coll...
- CVE-2026-65941 โ CVSS 8.8 โ WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code ...
- CVE-2026-15803 โ CVSS 8.7 โ In Eclipse RDF4J, several XML parser entry points do not fully restrict XML E...
- CVE-2026-73325 โ CVSS 8.4 โ Fujitsu OneCompression 1.2.0 Arbitrary Code Execution via torch.load Deserial...
- CVE-2026-73292 โ CVSS 8.3 โ Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token ...
- CVE-2026-67260 โ CVSS 7.3 โ Apache Airflow: DAG-author remote code execution on the Scheduler via awaitin...