daily cyber × ai intelligence

index

tagged

[CVE-2026-53414]

2 editions · 1 item

August 13, 2026

ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM

Microsoft Defender flaw CVE-2026-50656 was bypassed by a new ShieldBreak proof-of-concept that grants SYSTEM privileges on fully patched Windows 11 and Server 2025. SharePoint authentication-bypass CVE-2026-55040 is now actively exploited in the wild, allowing attackers to forge JWT tokens and impersonate admin users. LiteLLM malicious PyPI releases exposed over 2,100 organizations to credential-stealing code that harvested cloud keys, SSH credentials, and database passwords in a supply-chain attack traced to an earlier Trivy compromise. Midnight Blizzard (APT29) weaponized hotel Wi-Fi captive portals through CaptiveCrunch to harvest Microsoft 365 credentials and deploy malware.

August 12, 2026

  • An AI agent found a zero-click RCE in Zoom in under 24 hours, using fewer than 20 prompts against publicly available frontier models to produce a working exploit against Zoom's annotation protocol. The bugs — CVE-2026-53413 and CVE-2026-53414 in the annotation engine — let a meeting participant execute code on other attendees' native clients with a single malformed message; fixes are in Zoom 7.1.5+ (A Security, SecurityWeek, CyberInsider) (discussion). · AI, Agents & Offensive Security

in When the AI Is the One Finding the Zero-Days