400 Microsoft Flaws, Malicious SIMs & a Polish Plant Shutdown (08/11/2026)

August 11, 2026
400 Microsoft Flaws, Malicious SIMs & a Polish Plant Shutdown (08/11/2026)
Key Intel / TL;DR
  • Microsoft's August Patch Tuesday covers 400 flaws, including one actively exploited zero-day and two that were publicly disclosed before the fix.
  • Researchers showed a malicious SIM card can run attacker code inside the cellular modules built into EV chargers, industrial routers, and car telematics units.
  • Attackers reached a Polish combined heat and power plant over the private cellular network its grid operator uses for remote equipment, and shut down a steam turbine.
  • Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was committed to one of its own private repositories.
  • Gunra ransomware is exploiting Fortinet and Schneider Electric flaws and bypassing multi-factor authentication, with a joint US and South Korean warning on government targeting.

Patch Tuesday is the headline at 400 flaws, and the two stories underneath it are the ones that should change a plan. Researchers turned an ordinary SIM card into a way to run code inside the modem it sits in, on the cellular modules built into chargers, routers, and vehicles. Attackers walked into a Polish power plant over exactly that kind of private cellular link and stopped a turbine. We spent last week arguing that the cellular modem is the forgotten asset in operational technology. This week it stopped being theoretical.

Top 5 Critical Security Alerts

1. Microsoft Ships 400 Fixes and One Is Already Being Used

Microsoft’s August update covers 400 vulnerabilities, including one actively exploited zero-day and two that were publicly disclosed ahead of the patch. Coverage puts the exploited flaw in a Windows driver. BleepingComputer

Operator Note: At 400 items nobody patches everything this week. Sort by the three zero-days first, then anything reachable from an untrusted network, then the rest on your normal cadence. A volume number this size is an argument for ranking, not for panic.

2. A Malicious SIM Card Can Own the Modem It Sits In

Researchers demonstrated that a SIM card can instruct its host device to run commands of the attacker’s choosing, using standards-compliant functionality rather than a flaw. On the cellular modules built into electric vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device. The same work covers shutting down phones, stealing files, and forcing a connection to downgrade from 5G to 2G. The Hacker News

Operator Note: Nobody treats a SIM as an untrusted component. They arrive in envelopes, get installed by whoever was on site, and never appear on an asset register. If your field equipment has a slot, the supply chain for those cards is now part of your threat model.

3. Attackers Stopped a Turbine at a Polish Power Plant

Intruders shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant, entering over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat. The Hacker News

Operator Note: A private cellular network feels like a closed system because you pay for it and nobody advertises it. It is still a network with an edge, and this is the second time this month a cellular link has turned out to be the path into operational equipment, after the exposed controllers we covered in exposed PLCs.

4. Mozilla Burns Its Own Linux Signing Key

Mozilla revoked the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy was committed by mistake to one of the company’s private repositories. That key is how a Linux distribution or a careful user verifies a download is genuine. Audit logs found no unexpected access, and release verification still needs updating. The Register

Operator Note: Mozilla caught it, revoked it, and said so, which is the response you want. Worth asking the same question at home: if a signing key left your repository today, would anything tell you.

5. Gunra Ransomware Works Fortinet Flaws and Walks Past MFA

The Gunra ransomware-as-a-service operation is having success against critical infrastructure using leaked Conti code and older flaws in firewalls and VPN appliances, and is bypassing multi-factor authentication. The United States and South Korea issued a joint warning about government agency targeting, and healthcare organizations received their own alert. Dark Reading

Additional Security Alerts

Threat Intelligence

  • DeadLock puts its infrastructure on a blockchain: The operation uses Polygon smart contracts to hold victim communication and leak-site addresses, so a takedown of conventional hosting does not reach it. BleepingComputer
  • Sandworm targets IT staff with a trojanized VPN client: UAC-0145 is using fake job interviews to push a WireGuard client that can run attacker code. BleepingComputer

Vulnerabilities

  • CISA says the SharePoint flaw is now in ransomware hands: The remote code execution bug has been flagged as actively exploited since early July and gangs have now picked it up. BleepingComputer
  • A Cisco ASA and FTD VPN flaw is being used to crash devices: Cisco is warning of active exploitation causing denial of service on the appliances sitting at the network edge. BleepingComputer

Security Breaches & Incidents

  • Someone stood up a fake Wi-Fi network on a Delta flight: The airline is investigating a deauthentication attack on a flight carrying DEF CON attendees. TechCrunch
  • Local governments in four states are dealing with shutdowns: Multiple municipalities have services offline following cyberattacks. The Record

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)