Daily Security Intel

Archives
Log in
Subscribe
August 12, 2026

[SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, August 12, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Zero-Day and SharePoint RCE Patched

CRITICAL

5

C2 IPs

80

OTX IOCs

40

ARTICLES

■ ANALYST TLDR

This brief highlights Microsoft's massive August 2026 Patch Tuesday addressing over 400 vulnerabilities, including an actively exploited Windows kernel driver zero-day (afd.sys) and a critical SharePoint RCE vulnerability (CVE-2026-55040). Additionally, Russian threat group Sandworm (UAC-0145) is actively targeting IT professionals with trojanized WireGuard VPN clients, while the DeadLock ransomware group has adopted decentralized Polygon blockchain smart contracts to secure its extortion infrastructure against takedowns. Organizations must also prioritize immediate patching for critical zero-click execution flaws in Zoom's annotation tool and actively exploited denial-of-service bugs in Cisco ASA/FTD devices.

■ CRITICAL STORIES

CRITICAL#1

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

A critical vulnerability (CVE-2026-55040) with a CVSS score of 10.0 allows unauthenticated attackers to bypass authentication and gain administrative access to Microsoft SharePoint servers. The exploit chain was discovered with the assistance of an AI agent, highlighting the growing capability of AI-driven vulnerability research.

CRITICAL#2

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft addressed over 400 vulnerabilities, including an actively exploited use-after-free vulnerability in the afd.sys Windows kernel-mode driver. This zero-day allows attackers to escalate privileges to SYSTEM, posing an immediate threat to unpatched Windows environments.

HIGH#3

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

Russian state-sponsored group Sandworm is targeting IT administrators using social engineering disguised as recruitment. Victims are tricked into installing a trojanized WireGuard VPN client that grants attackers command execution capabilities on target systems.

HIGH#4

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The DeadLock ransomware operation has integrated decentralized infrastructure, using Polygon blockchain smart contracts and Session messaging. This makes their communication channels and data-leak operations highly resilient to traditional law enforcement takedown efforts.

■ CVEs IDENTIFIED

CVE-2026-55040

Microsoft SharePoint — Unauthenticated Remote Code Execution (RCE)

Critical

[CVE-TBD-AFD]

Microsoft Windows Kernel Driver (afd.sys) — Privilege Escalation to SYSTEM (Actively Exploited)

Critical

[CVE-TBD-CISCO]

Cisco Secure Firewall ASA and Threat Defense (FTD) — Denial of Service (Device Crash)

High

[CVE-TBD-ZOOM]

Zoom Client (Annotation Tool) — Zero-Click Remote Code Execution

Critical

■ THREAT ACTORS

Sandworm (UAC-0145)

Nation-state (Russia)

Targeting Ukrainian IT professionals with fake job offers to deliver trojanized WireGuard VPN clients.

DeadLock

Ransomware Group

Utilizing Polygon blockchain smart contracts and Session messaging for decentralized extortion infrastructure.

Kimwolf (AISURU)

Botnet Operator

Deploying v7 of an Android/IoT botnet utilizing HTTP/2 to masquerade DDoS traffic as legitimate browsing.

■ ATT&CK TTPs

T1204.002
User Execution: Malicious File | IT pros tricked into running trojanized WireGuard VPN installer.
T1566.002
Phishing: Spearphishing Link | Fake job offers and fake CCleaner websites used to distribute malware.
T1068
Exploitation for Privilege Escalation | Active exploitation of afd.sys Windows kernel driver for SYSTEM privileges.
T1190
Exploit Public-Facing Application | Unauthenticated RCE in Microsoft SharePoint (CVE-2026-55040).
T1498
Network Denial of Service | Kimwolf botnet launching HTTP/2 DDoS traffic; Cisco ASA/FTD targeted with device-crashing exploits.
T1584.005
Compromise Infrastructure: Botnet | Kimwolf v7 Android/IoT botnet expansion.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Microsoft Windows (afd.sys) — Actively exploited zero-day kernel driver privilege escalation to SYSTEM — [SW] August 2026 Patch Tuesday

[P1 PATCH NOW]≤24h

Microsoft SharePoint — CVE-2026-55040 unauthenticated RCE with CVSS 10.0 — [THN] Researchers Disclose AI-Assisted SharePoint Exploit Chain

[P1 PATCH NOW]≤24h

Zoom Client — Zero-click remote code execution vulnerability in Annotation tool — [SW] Zoom Patches Zero-Click Code Execution Vulnerability

[P2 PATCH NOW]≤72h

Cisco Secure Firewall ASA & FTD — Actively exploited denial-of-service vulnerability causing remote device crashes — [BC] Cisco warns of ASA and FTD VPN flaw

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply Microsoft August 2026 Patch Tuesday updates immediately to address the actively exploited afd.sys kernel driver vulnerability and CVE-2026-55040 in SharePoint.
2[P1] Update Cisco Secure Firewall ASA and Threat Defense (FTD) software to the latest version to mitigate actively exploited denial-of-service vulnerabilities.
3[P1] Update Zoom desktop clients immediately to patch the zero-click code execution vulnerability residing in the Annotation tool.
4[P2] Apply Adobe security updates for ColdFusion and Campaign Classic to prevent critical arbitrary code execution and denial-of-service attacks.
5[P2] Educate IT administrators and system engineers on the threat of trojanized WireGuard VPN clients distributed via fake job recruitment campaigns (Sandworm/UAC-0145).
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 11 Aug | Private APN pivot breaches Polish energy sector networks
Powered by Buttondown, the easiest way to start and grow your newsletter.