PTC Windchill CVE-2026-12569 Extortion Hits Shell, Philips

Clops PTC Windchill CVE-2026-12569 Erpressung nennt Shell, Philips, GE und Fiserv als Opfer — Monate nachdem die Lücke gepatcht wurde.

The PTC Windchill CVE-2026-12569 extortion campaign run by the Clop ransomware group went fully public on August 12–13, when Clop named Shell, Philips, General Electric, Fiserv and roughly 45 other organizations on its leak site as victims of a data-theft operation running through the same PTC Windchill/FlexPLM flaw DIESEC has already covered twice this year.…

Read More

SAP Commerce Cloud CVE-2026-58231: CVSS 10.0 RCE

SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) lets unauthenticated attackers hit the Data Hub import endpoint for code execution. Patch and mitigation steps.

SAP Commerce Cloud CVE-2026-58231, a maximum-severity (CVSS 10.0) flaw disclosed on SAP’s August 2026 Security Patch Day, lets an unauthenticated attacker with network access reach the Data Hub import endpoint and potentially execute arbitrary code — no login, no user interaction, just a crafted request to a component many DACH e-commerce and manufacturing storefronts run…

Read More

Top 5 Cybersecurity News Stories August 14, 2026

Cybersecurity News Stories August 14, 2026 featured image showing five connected attack vectors — Windows kernel rootkit, OT network lateral movement, ERP platform RCE, analytics credential exposure, and MSP management plane bypass — unified by an amber threat thread in a dark enterprise security environment`

This week’s Cybersecurity News Stories August 14, 2026 arrives during a week when defenders discovered something uncomfortable: the tools and infrastructure they depend on to manage, monitor, and protect their environments were themselves the target. A nation-state rootkit disabled Windows security callbacks at the kernel level. A heating plant lost control of its steam turbine…

Read More

CVE-2026-68820 WinSock Zero-Day: Lazarus Deploys Rootkit

CVE-2026-68820 WinSock zero-day

The CVE-2026-68820 WinSock zero-day was already being used by North Korea’s Lazarus Group to plant a kernel-mode rootkit weeks before Microsoft shipped a fix in its August 2026 Patch Tuesday. Any Windows endpoint that processes network sockets — which is to say, essentially every Windows machine on your network — was exposed until this month’s…

Read More

Swiss Federal SharePoint Breach Hits 200 Accounts

The Swiss Federal SharePoint Breach compromised 200 accounts at Switzerland's national IT agency, likely via a July Patch Tuesday flaw.

The Swiss federal SharePoint breach compromised roughly 200 accounts at Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT/FOITT), the agency confirmed in early August 2026. It is the first time DIESEC’s ongoing SharePoint vulnerability coverage has connected to a confirmed, named breach inside a DACH government body — not just a vendor advisory.…

Read More