Morning Brief

Sunday, August 2, 2026 · generated 2026-08-02 13:34 UTC · ~6 min read

Patch today
92
WordPress
1 critical
17
FreeRDP
1 critical
14
better-auth
1 critical
12
Apple
2 critical
5
gitpython-developers
1 critical
4
guzzle
4
ArcadeData
3 critical
4
ueberauth
4
Red Hat
3
Unknown

Top developments

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to…

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers…

Windows 11 Gets More Taskbar Control and AI Integration as Microsoft Details Quality Progress

Microsoft has released a detailed update on its Windows quality initiative, four months after committing in March to improve performance, reliability, and everyday user experiences across Windows 11 . The company says…

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The…

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions…

Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits

Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The…

Top 10 Best DNS Security Solutions in 2026

Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the…

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz…

Google Earth’s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images

On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a…

Anthropic says its AI hacked real-world companies in three incidents

Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.

Vulnerability watch

CVE-2026-67308 wazuh · wazuh CWE-78 CRITICAL 10.0

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharact…

CVE-2026-67330 better-auth · scim CWE-20 CRITICAL 9.9

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, …

CVE-2026-15964 WordPress · Single Sign On For TNG CWE-620 CRITICAL 9.8 · EPSS 0%

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_…

CVE-2026-66402 Apple · FreeRDP CWE-295 CRITICAL 9.8

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common N…

CVE-2026-67289 FreeRDP · FreeRDP CWE-113 CRITICAL 9.8

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client co…

CVE-2026-67324 gitpython-developers · GitPython CWE-78 CRITICAL 9.8

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.…

CVE-2026-67340 ArcadeData · arcadedb CWE-94 CRITICAL 9.8

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permissi…

CVE-2026-67341 ArcadeData · arcadedb CWE-863 CRITICAL 9.8

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION stateme…

CVE-2026-67342 ArcadeData · arcadedb CWE-639 CRITICAL 9.8

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify data…

CVE-2026-8457 Apple · WooCommerce - Social Login CWE-289 CRITICAL 9.8

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 …

Full CVE Feed →

Worth reading

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →