Morning Brief

Saturday, August 1, 2026 · generated 2026-08-01 13:34 UTC · ~6 min read

Patch today
48
HashiCorp
1 critical
43
WordPress
3 critical
20
Unknown
1 critical
15
Red Hat
6
pgadmin.org
3 critical
5
PHP Jabbers
5
HCL Software
5
thumbor
4
ANDRITZ
4
decidim

Top developments

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest…

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions…

Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits

Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The…

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The…

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz…

Google Earth’s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images

On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a…

Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely – Update Now

JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects…

USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports

The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.

North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials

A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine…

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable…

Vulnerability watch

CVE-2026-18452 Rich Source · DMS+ (Non-Mobile) CWE-798 CRITICAL 10.0 · EPSS 0%

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

CVE-2026-17566 pgadmin.org · pgAdmin 4 CWE-78 CRITICAL 9.9

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (.…

CVE-2026-52855 pterodactyl · wings CWE-200 CRITICAL 9.9

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{confi…

CVE-2026-14483 WordPress · Realtyna Organic IDX plugin + WPL Real Estate CWE-434 CRITICAL 9.8 · EPSS 0%

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload fun…

CVE-2026-14919 WordPress · ShopMonitor.io CWE-287 CRITICAL 9.8 · EPSS 0%

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers…

CVE-2026-17561 HashiCorp · Logsign SIEM CWE-94 CRITICAL 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.

CVE-2026-67822 Unknown CWE-121 CRITICAL 9.8

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer witho…

CVE-2026-68770 Hugging Face · sentence-transformers CWE-94 CRITICAL 9.8

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where t…

CVE-2026-68771 Comfy-Org · ComfyUI CWE-502 CRITICAL 9.8

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserializa…

CVE-2026-17349 pgadmin.org · pgAdmin 4 CWE-522 CRITICAL 9.6

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user…

Full CVE Feed →

Worth reading

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →