Desk live·
ForensicPost
Digital forensics and incident response news
LeadFile 26-0817 · VoLTE modem firmware to kernel · Sev 4

Unisoc Modem Flaw Gives Android Kernel Access Through a Video Call, With No Fix

Researchers published the second stage of a chain that turns a VoLTE video call into full Android kernel access on three Unisoc chipsets. The modem and application processor share memory with no hardware boundary, and the vendor has not answered.

D. Kennedy10 min readConfidence: highRead the file →
Open case filesSorted by escalation
02
SEV 5
Healthcare · Healthcare
13 August 2026·Poland
MyDr·Unattributed

19 Million Medical Records Stolen in Polish MyDr Hack

19 million patients, 12,000 clinics, 2.5 terabytes — and a government that will not call it an attack.

03
SEV 5
Espionage · Defence
12 August 2026·Not established
Defence, aerospace and aviation firms·Lazarus Group

Lazarus Paired a Windows Zero-Day With Post-Quantum Encryption Against Defence Firms

Adopting ML-KEM cost the attacker one library. It costs a defence contractor its entire estate.

04
SEV 5
Supply chain · Technology
11 August 2026·United States
Metabase deployments·Unattributed

Metabase Zero-Day Hit Five Companies Before the Flaw Was Disclosed

A CVSS 10.0 flaw in a reporting tool that stores the credentials for every warehouse behind it.

05
SEV 4
Method · Multiple
10 August 2026·United States
Multiple critical infrastructure sectors·Gunra

Six Agencies Warn Gunra Ransomware Runs on Leaked Conti Source Code

Conti’s leaked source is still producing operations four years on, and this one gets in through patched CVEs.

06
SEV 5
Exploitation · Multiple
10 August 2026·Germany
VMware vCenter operators·Unattributed

VMware vCenter Flaw Exploited in 47 Countries Within a Week of the Patch

361 hosts in 47 countries, and 95% of them taken inside two days of the first exploitation.

07
SEV 4
Infrastructure · Energy
8 August 2026·Poland
Polish combined heat and power plant·Unattributed

Polish Heat Plant Attackers Reached the PLCs Through a Private APN

A private network is still a network. Once anything inside it could reach anything else, the isolation was a route.

08
SEV 4
Verification · Finance
7 August 2026·India
Bank of Baroda·Unattributed

Bank of Baroda Confirms Leak After Employee Email Compromise, With 700GB Claimed

A dispute about volume is a dispute about the wrong axis. Ask instead which fields can be reissued.

09
SEV 2
Verification · Retail
7 August 2026·United States
Levi Strauss & Co.·Unattributed

Levi Strauss Says Social Engineering Compromised Three Employee Computers

Three compromised laptops, corporate data taken, and a filing that answers the shareholder question only.

Analysis & longreadsAll analysis →
570
Flaws closed in July’s Patch Tuesday — three exploited before release
700 TB
Claimed stolen from Telus, including call records and source code
11 mo
Length of Singapore’s counter-operation against UNC3886
1.2 M
French bank-registry accounts exposed via stolen credentials
// the chain of custody — tuesdays

One incident, taken apart properly.

Logs, timelines, and what the filing left out. Read by 41,200 examiners, counsel and reporters.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · tips@forensicpost.comGlossary