CVE-2026-68820 WinSock Zero-Day: Lazarus Deploys Rootkit

CVE-2026-68820 WinSock zero-day

The CVE-2026-68820 WinSock zero-day was already being used by North Korea’s Lazarus Group to plant a kernel-mode rootkit weeks before Microsoft shipped a fix in its August 2026 Patch Tuesday. Any Windows endpoint that processes network sockets — which is to say, essentially every Windows machine on your network — was exposed until this month’s…

Read More

Swiss Federal SharePoint Breach Hits 200 Accounts

The Swiss Federal SharePoint Breach compromised 200 accounts at Switzerland's national IT agency, likely via a July Patch Tuesday flaw.

The Swiss federal SharePoint breach compromised roughly 200 accounts at Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT/FOITT), the agency confirmed in early August 2026. It is the first time DIESEC’s ongoing SharePoint vulnerability coverage has connected to a confirmed, named breach inside a DACH government body — not just a vendor advisory.…

Read More

Cybersecurity Buyer’s Remorse: 5 Tips to Help SMEs Avoid It

Cybersecurity buyer’s remorse is a real risk for SMEs comparing endpoint protection, email security, vulnerability scanners, cloud security platforms, and managed detection services — there’s no shortage of solutions promising to reduce cyber risk. The challenge is deciding which ones are actually worth your money. Unlike large enterprises with dedicated security teams and sizeable technology…

Read More

Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More

TeamCity CVE-2026-63077 RCE: Unauthenticated CI/CD Takeover

TeamCity CVE-2026-63077 RCE

TeamCity CVE-2026-63077 RCE lets an unauthenticated attacker send a single crafted request to a TeamCity On-Premises server and execute operating system commands — no login, no valid session, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline, and exploitation is now active in the…

Read More