Critical Gitea RCE Actively Exploited in Cryptojacking Campaign

CISA warns of active exploitation of CVE-2026-60004 (CVSS 9.8) in Gitea, allowing repository write access to execute arbitrary commands via the diffpatch endpoint. Attackers leverage default open registration to gain access and deploy miner-like payloads, with U.S. federal agencies required to patch by August 28, 2026. Read more

GovCERT.HK Issues Alert on Veeam Backup & Replication Information Disclosure Flaw CVE-2026-58070

GovCERT.HK published Security Alert A26-08-44 on August 26, 2026, detailing an information disclosure vulnerability (CVE-2026-58070) in Veeam Backup & Replication version 13.0.2.29 and all earlier 13.x builds. The flaw, which could allow unauthorized data access if exploited, has been patched by Veeam via KB4902, with no evidence of active exploitation cited in the alert. The advisory underscores the risk posed by vulnerabilities in backup infrastructure, which may expose sensitive metadata and facilitate follow-on attacks even without direct system compromise. Read more

Operation QUICSILVER Exploits Graduation Lures and QUIC Backdoor in Myanmar Cyber Espionage Campaign

Cybersecurity researchers have identified Operation QUICSILVER, a China-nexus espionage campaign targeting Myanmar’s government and IT sectors since April 2026. The attack uses fake graduation ceremony invitations to deliver QUICAgent, a Go-based backdoor that abuses legitimate Windows binaries and communicates via QUIC over UDP port 443 to evade detection. Read more

GovCERT.HK Issues High-Threat Alert on Oracle CSPU August 2026 with Active PoC Exploits

GovCERT.HK has issued a High Threat Security Alert (A26-08-28) warning of multiple critical vulnerabilities in Oracle products with publicly available proof-of-concept exploit code, urging immediate patching across Java SE, Database, Fusion Applications, Middleware, MySQL, Linux, and Virtualization suites to prevent remote code execution, privilege escalation, and data exposure. Read more

Research Digest: Assessing Attack Surfaces in Generative Search Engines through Publisher Attributes in Political Domains

A new study evaluates how generative search engines (GSEs) are vulnerable to poisoning attacks by analyzing publisher authority and personalization effects, finding that ruling parties face broader attack surfaces than opposition parties in U.S. and Japan political domains, and that user profiles have minimal influence on citation behavior. Read more

Critical OS Command Injection in Siemens Siveillance Video Management Servers Enables Remote Code Execution

A critical OS command injection vulnerability (CVE-2026-3014, CVSS 9.1) in Siemens Siveillance Video Management Servers allows authenticated users with edit permissions to execute arbitrary code. Siemens has released patched versions for V2023 R3, V2024 R1, and V2025 product lines. CISA urges network isolation and VPN use for remote access. Read more

Siemens Desigo DXR and PXC Controllers Vulnerable to BACnet Packet DoS

A medium-severity denial-of-service vulnerability (CVE-2026-59693) in Siemens Desigo DXR and PXC controllers allows attackers to disrupt building automation systems via malformed BACnet packets, requiring device reset for recovery. Siemens has released patched versions and recommends network segmentation and VPN use for mitigation. Read more