Colombia's EMC guerrilla group claimed on August 30 to have captured a Colombian soldier of the French Foreign Legion, taken hostage on August 6 in Nariño department.
Global event network
Security
One evolving event. Every credible source. Your language.
CISA published an advisory for an authenticated OS command injection vulnerability (CVE-2026-76060) in ZoneMinder versions 1.37.48 and 1.38.3, which could allow remote code execution as the web server user. The vendor recommends upgrading to 1.38.3 or later.
CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, including CVEs in ownCloud, Linux Kernel, and JFrog Artifactory.
CISA published an advisory on August 25, 2026, disclosing three vulnerabilities in Bendix EC80 Brake ECU used in commercial vehicles. The flaws include a stack-based buffer overflow, an out-of-bounds write, and use of hard-coded credentials, which could allow an attacker to crash the ECU, execute arbitrary code, inject CAN bus traffic, or disable safety functions like ABS and traction control. Bendix has released firmware updates to address the issues.
CISA published an advisory for a high-severity vulnerability (CVE-2026-75960) in Rently Smart Home versions 20.1.0 and prior. The flaw could allow an attacker to retrieve pins, including the Master Pin, and override user permissions. Rently has patched the issue; no user action is required.
CISA published an advisory for a missing authorization vulnerability in PayRange API, which could allow remote attackers to access sensitive device information, modify devices, or cause denial of service. PayRange has not responded to mitigation requests.
Armed gangs killed at least 47 people in Kenscoff, Haiti, on August 24-25, 2026, while a UN report shows gang violence spreading beyond Port-au-Prince despite intensified security operations.
Siemens has disclosed a critical missing authentication vulnerability (CVE-2026-58115) in SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed. An unauthenticated remote attacker could exploit this to execute arbitrary code with maximum privileges. Siemens has released a fix in version V4.3.4.1.
CISA published an advisory on August 27, 2026, disclosing two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set (versions 2.25 through 2.37). The vulnerabilities, CVE-2018-1285 (XXE) and CVE-2026-18717 (improper certificate validation), could allow attackers to read/write arbitrary files, issue outbound requests, or intercept and modify TLS-protected communications. The vendor has released version 2.38 to fix both issues. No public exploitation has been reported.
CISA published an advisory on critical vulnerabilities in All-Line Equipment Company Fuel-Boss, affecting multiple product versions. Exploitation could allow remote code execution. Fixes are available for some versions, but not all.