# Badtech.org > Tracking cybersecurity. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [About Badtech.org](https://badtech.org/about.md) - Badtech Radar is an independent, AI-assisted project tracking cybersecurity vulnerabilities, breaches, ransomware, and the technology decisions behind them. Automated tools help discover, organize, and summarize potential stories. Articles are selected, reviewed, and edited by Adam Field before pub… ## Posts - [Active exploitation hits SonicWall SMA1000 vulnerability chain with unauthenticated RCE path](https://badtech.org/active-exploitation-hits-sonicwall-sma1000-vulnerability-chain-with-unauthenticated-rce-path.md) - Active exploitation is targeting SonicWall SMA1000 appliances through CVE-2026-83548 and CVE-2026-83549, a pre-authentication SSRF flaw and a post-authentication OS command-injection flaw that can be chained to reach unauthenticated remote code execution. Affected models are SMA 6210, SMA 7210 and… - [Aurora ransomware operator used Cursor Agent in 10 intrusions and targeted ESXi hosts](https://badtech.org/aurora-ransomware-operator-used-cursor-agent-in-10-intrusions-and-targeted-esxi-hosts.md) - Gambit Security says an Aurora ransomware operator used Cursor Agent inside 10 victim networks and paired it with tooling to find and encrypt VMware ESXi environments. According to Gambit Security, the operator used Cursor Agent, running Claude Sonnet, during hands-on activity across 10 organizatio… - [Microsoft Azure urges network-based compensating controls as patch windows shrink](https://badtech.org/microsoft-azure-urges-network-based-compensating-controls-as-patch-windows-shrink.md) - Microsoft Azure says patch validation and deployment timelines no longer match current exploitation speed and is urging enterprises to add adaptive, network-based compensating controls during remediation. In a Microsoft Azure Blog post, Microsoft argues the usual sequence of disclosure, exposure as… - [Oracle August 2026 CPU ships 943 patches, including critical unauthenticated flaws in Fusion Middlew](https://badtech.org/oracle-august-2026-cpu-ships-943-patches-including-critical-unauthenticated-flaws-in-fusion-middlew.md) - Oracle released its August 2026 Critical Security Patch Update on August 18 with 943 new patches across its enterprise software portfolio, including 262 for Fusion Middleware, 120 for E-Business Suite, and 66 for Commerce. Covered products include WebLogic Server, PeopleSoft Enterprise PeopleTools,… - [Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly](https://badtech.org/microsoft-august-patch-tuesday-includes-exploited-windows-privilege-escalation-flaw-and-two-publicly.md) - Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the differenc… - [Cisco patches critical Catalyst SD-WAN, IOS XE and Secure Firewall Management Center flaws](https://badtech.org/cisco-patches-critical-catalyst-sd-wan-ios-xe-and-secure-firewall-management-center-flaws.md) - SecurityWeek reported that Cisco released fixes for roughly two dozen vulnerabilities across its products, including critical issues in Catalyst SD-WAN, IOS XE and Secure Firewall Management Center. For Catalyst SD-WAN, SecurityWeek and Secure ISS said Cisco identified CVE-2026-20303, CVE-2026-2030… - [N-able N-central auth-bypass flaw is under active exploitation; customers told to verify 2026.3.1.7](https://badtech.org/n-able-n-central-auth-bypass-flaw-is-under-active-exploitation-customers-told-to-verify-2026-3-1-7.md) - N-able’s N-central RMM platform is under active exploitation through an authentication-bypass flaw, with Huntress reporting multiple affected organizations and observed follow-on activity including reconnaissance, process-list requests, and abuse of the Take Control remote-access feature on downstr… - [Water utility cyber incidents across at least seven U.S. states disrupted monitoring and control across at least seven U.S. states](https://badtech.org/water-utility-cyber-incidents-across-at-least-seven-u-s-states-disrupted-monitoring-and-control-across-at-least-seven-u-s-states.md) - CBS News, NBC News, and CNN Newsource via KEYT reported that the FBI and EPA said water and wastewater utilities in at least seven U.S. states experienced malicious cyber incidents, with some activity degrading operations. The reporting says the activity targeted internet-facing programmable logic… - [Broadcom patches critical VMware vCenter and ESXi flaws including auth bypass, RCE, and VM escape](https://badtech.org/broadcom-patches-critical-vmware-vcenter-and-esxi-flaws-including-auth-bypass-rce-and-vm-escape.md) - Security Affairs, Mallory.ai, and Field Effect reported that Broadcom released patches on July 29 for five VMware vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion, including three rated critical. They said the most severe issue, CVE-2026-59309, is a critical vCenter authentication b… ## Optional - [RSS Feed](https://badtech.org/rss/) - [Sitemap](https://badtech.org/sitemap.xml) - [Full content of pages and posts](https://badtech.org/llms-full.txt)