THREAT FIELD NOTESINTELLIGENCE FOR DEFENDERS
Back to home

Threat brief

A concise view of the activity, vulnerabilities, and campaigns that deserve a defender’s attention.

Current reporting from trusted threat-research teams, refreshed at most once per hour.

CISA KEV · VulnerabilityAug 27, 2026

CVE-2026-53362: Linux Kernel Unspecified Vulnerability

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

CVE-2026-53362LinuxLinux
Brief overview

CISA added this Linux Kernel vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 27, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 30, 2026.

Defender next steps

  • Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Inventory Linux Kernel deployments and prioritize exposed or high-value systems.
Open this entry in the CISA KEV catalogue
CISA KEV · VulnerabilityAug 18, 2026

CVE-2026-65400: Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

CVE-2026-65400macOSApple
Brief overview

CISA added this Apple macOS vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 18, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 21, 2026.

Defender next steps

  • Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Inventory Apple macOS deployments and prioritize exposed or high-value systems.
Open this entry in the CISA KEV catalogue
CISA KEV · VulnerabilityAug 26, 2026

CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CVE-2019-1068MicrosoftMicrosoft
Brief overview

CISA added this Microsoft SQL Server vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 26, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 29, 2026.

Defender next steps

  • Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Inventory Microsoft SQL Server deployments and prioritize exposed or high-value systems.
Open this entry in the CISA KEV catalogue
CISA KEV · VulnerabilityAug 11, 2026

CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

CVE-2026-20349CiscoCisco
Brief overview

CISA added this Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 11, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 14, 2026.

Defender next steps

  • Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • Inventory Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) deployments and prioritize exposed or high-value systems.
Open this entry in the CISA KEV catalogue
SANS ISC · VulnerabilitySep 6, 2026

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is…

SANS ISCVulnerability
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at SANS ISC
SANS ISC · VulnerabilitySep 5, 2026

numbat - AI agent observability, (Fri, Sep 4th)

Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots. Absent agent-aware governance, modern…

SANS ISCVulnerability
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at SANS ISC
SANS ISC · ResearchSep 4, 2026

ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

SANS ISCResearch
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Compare the reported behavior with your environment and current detection coverage.
  • Validate important findings in the original research before taking disruptive action.
Read the original report at SANS ISC
Cisco Talos · VulnerabilitySep 3, 2026

The story behind the intelligence

Welcome to this week’s edition of the Threat Source newsletter. Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And…

Cisco TalosVulnerability
Brief overview

This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at Cisco Talos
Unit 42 · ResearchSep 3, 2026

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations.

Unit 42Research
Brief overview

This item was published by Unit 42. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Compare the reported behavior with your environment and current detection coverage.
  • Validate important findings in the original research before taking disruptive action.
Read the original report at Unit 42
SANS ISC · VulnerabilitySep 3, 2026

Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)

[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] Honeypot-Omaha is a DShied Sensor located at the Internet Storm Center (ISC) that is set up as a decoy for the original target and deployed over the internet. It is a flawed and very vulnerable system that…

SANS ISCVulnerability
Brief overview

This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.

Defender next steps

  • Confirm whether the affected product is present and internet-facing.
  • Review vendor guidance, patch status, and signs of exploitation before closing the item.
Read the original report at SANS ISC