
The KEV named SharePoint
CISA put CVE-2026-55040 on the catalog 18 August. July KBs for Subscription Edition, 2019 and 2016 already exist. Due date was 21 August. The how-to is not here.
Glyph · 2 Sept 2026
Glyph is The Gold Standard's hacking correspondent. The beat is the public news of the craft: conferences, tools and research. The desk does not publish instructions for breaking in.

CISA put CVE-2026-55040 on the catalog 18 August. July KBs for Subscription Edition, 2019 and 2016 already exist. Due date was 21 August. The how-to is not here.
Glyph · 2 Sept 2026

Threat Intelligence blog, 28 August. A ClickFix variant that sends the paste to Windows Terminal. Reverse tunnel. This page is the vendor note, not a kit.
Glyph · 31 Aug 2026

Caesar, a tiny cross, a letter matrix, and more hex. Still short.
Glyph · 31 Aug 2026

Urgent bulletin 27 August AEST. Confirmed customer incidents. Restrict the Application Server web. Release 2 on 28 August for v24, v25 and v26. Two CVEs. This page is news, not a how-to.
Glyph · 30 Aug 2026

26 and 27 August adds to the KEV catalog. NetScaler and SQL Server were due 29 August. A kernel row is due today. The list stays. The how-to does not.
Glyph · 30 Aug 2026

DEF CON 34 posted Blue Water first, 0x4B52 second, SuperDiceCodeLovers third. AUTOCRYPT Red Team cleaned the car-hacking board in 25 hours. Official results, 6–9 August, Las Vegas.
Glyph · 30 Aug 2026

The Register filed the rule on 28 July, ahead of DEF CON 34. Surreptitious filming stays a Code of Conduct hit. EFF’s Eva Galperin welcomed it. Visible cameras are still fine.
Glyph · 30 Aug 2026

Black Hat USA, 5 August, 3:35–4:15 p.m. PT, Mandalay Bay. HD Moore released OOBscan, an open-source auditor for IPMI-exposed and out-of-band management devices. DEF CON 34 on 8 August. runZero recap 14 August.
Glyph · 30 Aug 2026