Morning Brief

Wednesday, August 5, 2026 · generated 2026-08-05 13:37 UTC · ~5 min read

Patch today
32
WordPress
3 critical
18
FlowiseAI
17
Unknown
1 critical
16
NVIDIA
1 critical
14
HashiCorp
3 critical
12
open-webui
11
Qualcomm
1 critical
10
Veeam
8
H3C
8
Apache

Top developments

1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks

A critical one-click remote code execution (RCE) vulnerability affects three of the world’s most widely used code editors: Cursor, Microsoft VS Code, and Google Antigravity . The flaw, uncovered by AISLE, exposes an…

Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation

Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted Windows tools to launch a second stage of an intrusion. The…

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix…

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to start without a Windows SmartScreen prompt. ZIP…

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing…

8 Best Password Managers (2026), Tested and Reviewed

Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.

Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams

Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the…

Apple launches new legal challenge against UK over iCloud access

Seeking to protect users' iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company's Advanced Data Protection feature.

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list…

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance…

Vulnerability watch

CVE-2026-16618 WordPress · Improve SEO CWE-434 CRITICAL 9.8 · EPSS 0%

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauth…

CVE-2026-14175 HashiCorp · HUMANIST Digital Human Resources CWE-434 CRITICAL 9.8 · EPSS 0%

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resource…

CVE-2026-15721 HashiCorp · HUMANIST Digital Human Resources CWE-312 CRITICAL 9.8 · EPSS 0%

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVE-2026-61514 Puwell Technology Inc. · IP Camera CWE-306 CRITICAL 9.8

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentia…

CVE-2026-61515 Puwell Technology Inc. · IP Camera CWE-912 CRITICAL 9.8

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell i…

CVE-2026-69098 Cinnamon · kotaemon CWE-502 CRITICAL 9.8

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ f…

CVE-2025-29296 Unknown CWE-77 CRITICAL 9.8

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple command injection vulnerabilities in the /…

CVE-2026-63455 HP · EdgeConnect SD-WAN Orchestrator CWE-306 CRITICAL 9.8

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow…

CVE-2026-63456 HP · EdgeConnect SD-WAN Orchestrator CWE-287 CRITICAL 9.8

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow…

CVE-2026-24254 NVIDIA · Dynamo CWE-288 CRITICAL 9.8

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, da…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →