[SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched
SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Wednesday, August 12, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY Active Zero-Day and SharePoint RCE Patched CRITICAL 5 C2 IPs 80 OTX IOCs 40 ARTICLES ■ ANALYST TLDR This brief highlights Microsoft's massive August 2026 Patch Tuesday addressing over 400 vulnerabilities, including an actively exploited Windows kernel driver zero-day (afd.sys) and a critical SharePoint RCE vulnerability (CVE-2026-55040). Additionally, Russian threat group Sandworm (UAC-0145) is actively targeting IT professionals with trojanized WireGuard VPN clients, while the DeadLock ransomware group has adopted decentralized Polygon blockchain smart contracts to secure its extortion infrastructure against takedowns. Organizations must also prioritize immediate patching for critical zero-click execution flaws in Zoom's annotation tool and actively exploited denial-of-service bugs in Cisco ASA/FTD devices. ■ CRITICAL STORIES CRITICAL #1 Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE A critical vulnerability (CVE-2026-55040) with a CVSS score of 10.0 allows unauthenticated attackers to bypass authentication and gain administrative access to Microsoft SharePoint servers. The exploit chain was discovered with the assistance of an AI agent, highlighting the growing capability of AI-driven vulnerability research. CRITICAL #2 August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Microsoft addressed over 400 vulnerabilities, including an actively exploited use-after-free vulnerability in the afd.sys Windows kernel-mode driver. This zero-day allows attackers to escalate privileges to SYSTEM, posing an immediate threat to unpatched Windows environments. HIGH #3 Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Russian state- group Sandworm is targeting IT administrators using social engineering disguised as recruitment. Victims are tricked into installing a trojanized WireGuard VPN client that grants attackers command execution capabilities on target systems. HIGH #4 DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware operation has integrated decentralized infrastructure, using Polygon blockchain smart contracts and Session messaging. This makes their communication channels and data-leak operations highly resilient to traditional law enforcement takedown efforts. ■ CVEs IDENTIFIED CVE-2026-55040 Microsoft SharePoint — Unauthenticated Remote Code Execution (RCE) Critical [CVE-TBD-AFD] Microsoft Windows Kernel Driver (afd.sys) — Privilege Escalation to SYSTEM (Actively Exploited) Critical [CVE-TBD-CISCO] Cisco Secure Firewall ASA and Threat Defense (FTD) — Denial of Service (Device Crash) High [CVE-TBD-ZOOM] Zoom Client (Annotation Tool) — Zero-Click Remote Code Execution Critical ■ THREAT ACTORS Sandworm (UAC-0145) Nation-state (Russia) Targeting Ukrainian IT professionals with fake job offers to deliver trojanized WireGuard VPN clients. DeadLock Ransomware Group Utilizing Polygon blockchain smart contracts and Session messaging for decentralized extortion infrastructure. Kimwolf (AISURU) Botnet Operator Deploying v7 of an Android/IoT botnet utilizing HTTP/2 to masquerade DDoS traffic as legitimate browsing. ■ ATT&CK TTPs T1204.002 User Execution: Malicious File | IT pros tricked into running trojanized WireGuard VPN installer. T1566.002 Phishing: Spearphishing Link | Fake job offers and fake CCleaner websites used to distribute malware. T1068 Exploitation for Privilege Escalation | Active exploitation of afd.sys Windows kernel driver for SYSTEM privileges. T1190 Exploit Public-Facing Application | Unauthenticated RCE in Microsoft SharePoint (CVE-2026-55040). T1498 Network Denial of Service | Kimwolf botnet launching HTTP/2 DDoS traffic; Cisco ASA/FTD targeted with device-crashing exploits. T1584.005 Compromise Infrastructure: Botnet | Kimwolf v7 Android/IoT botnet expansion. ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h Microsoft Windows (afd.sys) — Actively exploited zero-day kernel driver privilege escalation to SYSTEM — [SW] August 2026 Patch Tuesday [P1 PATCH NOW] ≤24h Microsoft SharePoint — CVE-2026-55040 unauthenticated RCE with CVSS 10.0 — [THN] Researchers Disclose AI-Assisted SharePoint Exploit Chain [P1 PATCH NOW] ≤24h Zoom Client — Zero-click remote code execution vulnerability in Annotation tool — [SW] Zoom Patches Zero-Click Code Execution Vulnerability [P2 PATCH NOW] ≤72h Cisco Secure Firewall ASA & FTD — Actively exploited denial-of-service vulnerability causing remote device crashes — [BC] Cisco warns of ASA and FTD VPN flaw ■ RECOMMENDED ACTIONS TODAY 1 [P1] Apply Microsoft August 2026 Patch Tuesday updates immediately to address the actively exploited afd.sys kernel driver vulnerability and CVE-2026-55040 in SharePoint. 2 [P1] Update Cisco Secure Firewall ASA and Threat Defense (FTD) software to the latest version to mitigate actively exploited denial-of-service vulnerabilities. 3 [P1] Update Zoom desktop clients immediately to patch the zero-click code execution vulnerability residing in the Annotation tool. 4 [P2] Apply Adobe security updates for ColdFusion and Campaign Classic to prevent critical arbitrary code execution and denial-of-service attacks. 5 [P2] Educate IT administrators and system engineers on the threat of trojanized WireGuard VPN clients distributed via fake job recruitment campaigns (Sandworm/UAC-0145). LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
SECURITYINTEL DAILY BRIEF
Wednesday, August 12, 2026
INTEL CONFIDENCE 100%
Active Zero-Day and SharePoint RCE Patched
This brief highlights Microsoft's massive August 2026 Patch Tuesday addressing over 400 vulnerabilities, including an actively exploited Windows kernel driver zero-day (afd.sys) and a critical SharePoint RCE vulnerability (CVE-2026-55040). Additionally, Russian threat group Sandworm (UAC-0145) is actively targeting IT professionals with trojanized WireGuard VPN clients, while the DeadLock ransomware group has adopted decentralized Polygon blockchain smart contracts to secure its extortion infrastructure against takedowns. Organizations must also prioritize immediate patching for critical zero-click execution flaws in Zoom's annotation tool and actively exploited denial-of-service bugs in Cisco ASA/FTD devices.
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
A critical vulnerability (CVE-2026-55040) with a CVSS score of 10.0 allows unauthenticated attackers to bypass authentication and gain administrative access to Microsoft SharePoint servers. The exploit chain was discovered with the assistance of an AI agent, highlighting the growing capability of AI-driven vulnerability research.
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft addressed over 400 vulnerabilities, including an actively exploited use-after-free vulnerability in the afd.sys Windows kernel-mode driver. This zero-day allows attackers to escalate privileges to SYSTEM, posing an immediate threat to unpatched Windows environments.
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Russian state- group Sandworm is targeting IT administrators using social engineering disguised as recruitment. Victims are tricked into installing a trojanized WireGuard VPN client that grants attackers command execution capabilities on target systems.
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The DeadLock ransomware operation has integrated decentralized infrastructure, using Polygon blockchain smart contracts and Session messaging. This makes their communication channels and data-leak operations highly resilient to traditional law enforcement takedown efforts.
Microsoft SharePoint — Unauthenticated Remote Code Execution (RCE)
Microsoft Windows Kernel Driver (afd.sys) — Privilege Escalation to SYSTEM (Actively Exploited)
Cisco Secure Firewall ASA and Threat Defense (FTD) — Denial of Service (Device Crash)
Zoom Client (Annotation Tool) — Zero-Click Remote Code Execution
Targeting Ukrainian IT professionals with fake job offers to deliver trojanized WireGuard VPN clients.
Utilizing Polygon blockchain smart contracts and Session messaging for decentralized extortion infrastructure.
Deploying v7 of an Android/IoT botnet utilizing HTTP/2 to masquerade DDoS traffic as legitimate browsing.
Microsoft Windows (afd.sys) — Actively exploited zero-day kernel driver privilege escalation to SYSTEM — [SW] August 2026 Patch Tuesday
Microsoft SharePoint — CVE-2026-55040 unauthenticated RCE with CVSS 10.0 — [THN] Researchers Disclose AI-Assisted SharePoint Exploit Chain
Zoom Client — Zero-click remote code execution vulnerability in Annotation tool — [SW] Zoom Patches Zero-Click Code Execution Vulnerability
Cisco Secure Firewall ASA & FTD — Actively exploited denial-of-service vulnerability causing remote device crashes — [BC] Cisco warns of ASA and FTD VPN flaw
■ RECOMMENDED ACTIONS TODAY
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5
FULL IOC EXPORT — GOOGLE SHEET
All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
