Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 06/08/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.
Điểm nóng bảo mật
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild — A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question i Nguồn: The Hacker News (06/08 13:51).
- Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) — Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory Nguồn: Help Net Security (06/08 17:38).
- AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory — A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. Nguồn: The Hacker News (06/08 18:30).
- Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability — Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek . Nguồn: SecurityWeek (06/08 13:37).
- Flaws in Google APK for Python Unlock Agent-to-Agent Attack — Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain. Nguồn: Dark Reading (06/08 01:03).
- Hackers run khunt post-exploitation toolkit from Oracle database — Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. […] Nguồn: BleepingComputer (06/08 02:55).
Ưu tiên xử lý trong 24–48 giờ
- Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
- Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
- Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
- Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.
CISA KEV / lỗ hổng cần theo dõi
- CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.
Nguồn tham khảo
- The Hacker News — CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
- Help Net Security — Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
- The Hacker News — AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
- SecurityWeek — Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
- Dark Reading — Flaws in Google APK for Python Unlock Agent-to-Agent Attack
- BleepingComputer — Hackers run khunt post-exploitation toolkit from Oracle database
Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.
