U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
2026-07-17T08:51:55Z•e9a282150678a3820a4bdb4a0cb9932da93597b77a78fd514838a6f36a8c65a6
AI-assisted malwareAsyncAPICISACVE-2023-4346CVE-2026-53412Chinese APTIoT botnetKEVLegacyHiveRussian APTScattered SpiderSonicWallTuxBotWindows Privilege EscalationZoomcybercrimeespionagenetwork devicesnpmsentencingsupply-chainvulnerabilitieszero-day
What happened
Feed of mid-July 2026 security headlines: CISA added multiple vulnerabilities (including a KNX protocol issue and Oracle-related flaws) to its Known Exploited Vulnerabilities catalog; SonicWall reported active exploitation of two SMA 1000 zero-days; Zoom patched a critical account-takeover bug (CVE-2026-53412, CVSS 9.8); Microsoft/SonicWall flaws were added to CISA KEV. Other notable items: an AsyncAPI npm supply‑chain compromise that injected malware into widely downloaded packages; a new Windows Privilege Escalation PoC “LegacyHive” affecting fully patched systems; Palo Alto Unit 42’s TuxBot
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- e9a282150678a3820a4bdb4a0cb9932da93597b77a78fd514838a6f36a8c65a6
- Enrichment time
- 2026-07-17T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.