RSS Amplifier

The CyberWire · Aug 13, 2026

President Trump deputizes private-sector companies to target cybercriminals.

0
Sign in to vote or save

The CyberWire Staff · The CyberWire

Top stories.

  1. Patch Tuesday notes: Microsoft fixes three zero-days.
  2. Attackers target SharePoint vulnerability following PoC release.
  3. Business news: Visa and Deel both acquire identity verification companies.

Microsoft’s Patch Tuesday addressed a total of 421 vulnerabilities across its products, including Windows, Hyper-V, Microsoft Exchange Server, and Azure. Of these, 62 are rated critical and 357 are marked as important, with the most significant being three zero-day vulnerabilities. The zero-days include a tampering flaw in the Windows Container Isolation FS Filter Driver, an elevation of privilege bug in the Windows User Profile Service, and an actively exploited privilege escalation flaw in the Windows Ancillary Function Driver for WinSock. CISA has added the latter flaw to its Known Exploited Vulnerabilities Catalog, and ordered Federal agencies to apply patches by August 25th. Check Point has attributed the exploitation to North Korea’s Lazarus Group, in a campaign targeting the defense sector in Europe and India.

Adobe addressed 51 vulnerabilities across five of its products: Adobe ColdFusion, Adobe Commerce, Adobe Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. Of these, 33 vulnerabilities are classified as critical.

SAP fixed 29 vulnerabilities, led by a maximum-severity flaw in SAP Commerce Cloud's Data Hub Adapter, CSO reports. This improper authorization issue allows unauthenticated remote attackers to submit crafted data, potentially leading to arbitrary code execution.

In the ICS space, Siemens, Schneider Electric, and Phoenix Contact released patches for various products, and CISA published advisories covering vulnerabilities in products from other vendors such as Pulsetto and Johnson Controls. Notably, Siemens issued a fix for a maximum-severity missing-authentication flaw in its Simatic IoT gateways, SecurityWeek notes.

Attackers target SharePoint vulnerability following PoC release.

Threat actors have already started weaponizing a proof-of-concept exploit for a critical Microsoft SharePoint flaw (CVE-2026-55040) that was published by Rapid7 yesterday, BleepingComputer reports. The flaw is an authentication bypass vulnerability that affects the JWT token validation pipeline in SharePoint Enterprise Server 2016 and 2019. It allows attackers without privileges to impersonate users or administrators to disclose files and modify data.

Microsoft issued a patch for the flaw on July 14th following a responsible disclosure by Rapid7. Administrators who haven’t already applied patches are urged to do so promptly.

Business news: Visa and Deel both acquire identity verification companies.

Visa has agreed to acquire Israeli biometric verification firm BioCatch. Visa stated, "The acquisition of BioCatch complements Visa’s existing cyber, fraud, risk and security solutions and is expected to help clients better protect themselves and their customers from the growing threat of account takeovers, scams, money mules and application fraud."

San Francisco-based HR platform Deel has acquired Israeli AI identity verification startup Clarity. The company stated, "Deel is already using Clarity’s product, making this a strategic acquisition grounded in real-world performance. We're bringing that technology and expertise further into Deel to embed continuous identity security across the entire hiring and workforce lifecycle."

Read more in the Business Briefing at 4pm ET.

Read the original on thecyberwire.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.