August 7, 2026 by sig9

Hacker Wars - August 07, 2026

bulletin-feature-image

Your daily dose of infosec chaos


Today hits close to home: the Swiss federal government’s own SharePoint sprang a leak, a fresh CPU side-channel walks straight through the Spectre v2 patches we all trusted, and a VM-escape bug reminds us that “isolated” is a strong word. Throw in financially motivated extortion aimed straight at hedge funds and a Cisco patch dump, and it is a busy one.

Swiss Federal Government SharePoint Breach Hits 200 Accounts

Switzerland’s federal IT office confirmed attackers exploited flaws in its on-prem Microsoft SharePoint servers and compromised around 200 accounts. When the public sector runs known-vulnerable collaboration platforms, the blast radius is everyone who ever exchanged a document with them.

What to do: If you host on-prem SharePoint or collaboration suites, treat patching as a deadline, not a suggestion - and assume any stale instance is already a foothold.


TONTOU CPU Attack Punches Through Spectre v2 Defenses

Researchers demonstrated TONTOU, a speculative-execution side-channel that bypasses the Spectre v2 mitigations shipping in modern CPUs, and built a working exploit to leak secrets like Linux password hashes. The uncomfortable truth is that hardware mitigations are partial by design, and “patched” never quite meant “fixed” in the silicon world.

What to do: Keep IBRS and related mitigations enabled, isolate sensitive workloads on separate cores, and stop assuming kernel memory is safe on shared hardware.


Zapscape KVM Flaw Lets Guests Break Out To The Linux Host

A new Linux kernel vulnerability lets code with kernel privileges inside an L1 guest escape KVM isolation and run on the host, provided nested virtualization is exposed to untrusted tenants. Cloud and hosting providers that pass nested virt through to customers are the ones really in the crosshairs here.

What to do: Update the kernel, and if you don’t strictly need nested virtualization exposed to untrusted guests, turn it off - it is an attack surface you probably don’t need.


UNC6671 Extortion Crew Targets Hedge Funds And Private Equity

A wave of intrusions against hedge funds, private-equity firms, and other financial outfits has been pinned on UNC6671, an extortion group linked to the BlackFile actors. Finance has always been a juicy mark, but the shift toward quiet data theft followed by extortion suggests these crews are skipping the noisy encryption entirely.

What to do: Focus detection on data exfiltration, not just ransomware, and pressure-test your DLP and egress monitoring before the bad guys do it for you.


Cisco Plugs 12 Flaws In SD-WAN And IOS XE, Three At CVSS 9.9

Cisco’s internal security review turned up a dozen bugs across Catalyst SD-WAN and IOS XE, three of them scoring 9.9 - about as close to maximum as it gets. These run the network backbone, so a single unpatched device can hand an attacker the keys to the whole routing fabric.

What to do: Inventory every Catalyst and IOS XE device, then patch in maintenance windows starting now - the 9.9s are not the ones to leave for next quarter.


That’s a wrap. Back tomorrow with more digital warfare.


Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown

This bulletin is provided for informational purposes. Contact us for tailored security analysis.