{"date_iso":"2026-08-02","date_human":"Sunday, August 2, 2026","generated_utc":"2026-08-02 13:34 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware","link":"https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html","reason":"Macos","category":"News","sources":["Palo Alto Unit 42","SANS Internet Storm Center","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCHbm6QCC9jjGwa-7P1N2PwhDjRvpC2hlS2hl09-DUZa5xdDeHt9qH1zISepl2ERqDzmDbdQ_zfE2vkHDsvE7G8QsetJHjzC45DpPr5-83lc1BGaLHfEwMfdYEA04d5xc7GL02_qkz1HjhIenSKBWF0FZqHnICaLn9agLEoEGnnN2n-smXxYFuQQaYNd8A/s1600/all-secure.jpg","description":"Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily","related":[{"title":"Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)","link":"https://isc.sans.edu/diary/rss/33208","source":"SANS Internet Storm Center","date_rel":"8h ago"},{"title":"The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version","link":"https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/","source":"Palo Alto Unit 42","date_rel":"31 Jul"}]},{"title":"Cheap Android TV Boxes Pose as Phones and Turn Owners\u2019 Broadband Into Proxies","link":"https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html","reason":"Android","category":"News","sources":["The Hacker News","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers\u2026","source":"The Hacker News","date_rel":"31 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhxfc7_NuArKSujgjgzPzENagYVTlBxcvnFBXSbptnFs_TI1o-Zt5SINHtPEO5MNkJ3vwkKUTX68vwmCzVxRQVFcgnb9eXwAsLKayCtzMLVRuqwV3RDaWTgQNOm0CVXcV_jX1v4x4mgEthTDjAsZdF4BSPSuTTRqKnM6qbIhPVjZP38dHmpptNurSmXRM/s1600/android-tv.jpg","description":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box","related":[{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","source":"Wired Security","date_rel":"50m ago"}]},{"title":"Windows 11 Gets More Taskbar Control and AI Integration as Microsoft Details Quality Progress","link":"https://cybersecuritynews.com/windows-11-quality-initiative/","reason":"Microsoft","category":"News","sources":["Cyber Security News","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Microsoft has released a detailed update on its Windows quality initiative, four months after committing in March to improve performance, reliability, and everyday user experiences across Windows 11 . The company says\u2026","source":"Cyber Security News","date_rel":"23h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Windows-11-Quality-Initiative.webp","description":"Microsoft has released a detailed update on its Windows quality initiative, four months after committing in March to improve performance, reliability, and everyday user experiences across Windows 11 . The company says early improvements are already reaching Windows Insiders and will begin rolling out more broadly to Windows 11 PCs this fall, while stressing that work is far from finished. In March, Microsoft outlined immediate priorities that included greater taskbar customization, more intentional AI integration, less disruptive Windows Updates, a faster and more dependable File Explorer\u2026","related":[{"title":"Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware","link":"https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html","source":"The Hacker News","date_rel":"1 Aug"},{"title":"Malwarebytes for Windows, now available on the Microsoft Store","link":"https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"30 Jul"}]},{"title":"Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction","link":"https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The\u2026","source":"The Hacker News","date_rel":"1 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW/s1600/adobe-flaw.jpg","description":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in","related":[{"title":"In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research","link":"https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"Adobe security advisory (AV26-760)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-760","source":"CCCS Alerts & Advisories","date_rel":"30 Jul"}]},{"title":"Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined","link":"https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","SecurityWeek","The Hacker News","Wired Security"],"coverage":4,"cve_ids":[],"summary":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions\u2026","source":"The Hacker News","date_rel":"31 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx/s1600/chrome.jpg","description":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the","related":[{"title":"Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace","link":"https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"Google says AI helped Chrome fix 1,072 security bugs in two releases","link":"https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting","link":"https://www.wired.com/story/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now/","source":"Wired Security","date_rel":"30 Jul"},{"title":"ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories","link":"https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html","source":"The Hacker News","date_rel":"30 Jul"}]},{"title":"Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits","link":"https://cybersecuritynews.com/arch-linux-disables-aur-package/","reason":"Linux","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine"],"coverage":3,"cve_ids":[],"summary":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The\u2026","source":"Cyber Security News","date_rel":"1 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Arch-Linux-Disables-AUR-Package.webp","description":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The move, announced by Robin Candau (known online as Antiz) on behalf of the Arch Linux DevOps team, comes as attackers increasingly exploit an abandoned or unmaintained package as an entry point for supply-chain attacks. Last month, a massive supply chain attack targeting the Arch User Repository (AUR) compromised more than 400 community-maintained packages , with attackers injecting\u2026","related":[{"title":"Arch Linux disables AUR package adoption to stop malware flood","link":"https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/","source":"Bleeping Computer","date_rel":"31 Jul"},{"title":"Cryptominer Abuses Linux PAM to Hide From SOC Analysts","link":"https://www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/","source":"Infosecurity Magazine","date_rel":"30 Jul"}]},{"title":"Top 10 Best DNS Security Solutions in 2026","link":"https://cybersecuritynews.com/best-dns-security-solutions/","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the\u2026","source":"Cyber Security News","date_rel":"21h ago","thumbnail":"https://i2.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQMZ593YhBRfEXBcbxtVpDeFa2CXQ1OWGPnssevXefPGPeHzFHPjIEtCGj-IkW6XWsQe-1F0-ZzNidBdB480KYYUkASAKxo5bRC1NSlW-YIteiIeBcTq4xkBlhKwOxR4SL60jvNHVDSjAMeCzyIfQ26ZLJ9S1t6xm9zLV7iXAd8aY2BH2zmGkp0KdL4d4/s1600/Best%20DNS%20Security%20Solutions%20(3).webp?ssl=1","description":"Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the strength of Talos-fed intelligence and proven scale, with Infoblox leading DDI-integrated security and Akamai delivering edge-scale protection. DNS security protects and exploits the DNS layer blocking resolution of malicious domains, detecting tunneling and DGA activity, and hardening DNS infrastructure. Below, the ten best DNS security solutions ranked. Quick Verdict \u2022 Best overall\u2026","related":[{"title":"Cisco security advisory (AV26-757)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-757","source":"CCCS Alerts & Advisories","date_rel":"30 Jul"}]},{"title":"Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database","link":"https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html","reason":"Azure","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-24304","CVE-2026-66803"],"summary":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_dFT-y76kGOf4rFOAu6NYNsE2s57G-7dl0a03tULY-f2ZGTbpPeEvu-NUCLVh-bgEdBvecIt28BJLQXUHclBc_IfGP9tBSZyMIm971Myrp2_zhSPyXhCJkhYmSfvLWNRewSsCip2YJfBEWocEEKdXPUL-y_mK8ZcHbBAaTWt8SzXmDJeQoYc6r5ceC6A/s1600/wiz-cosmodb.jpg","description":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a","related":[{"title":"Critical Flaw Allowed to Azure Cosmos DB Pwnage","link":"https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"31 Jul","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. \ud83d\udca1 Do you work at Google? I would love to hear\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"31 Jul"}]},{"title":"Anthropic says its AI hacked real-world companies in three incidents","link":"https://therecord.media/anthropic-ai-hacked-three-real-companies","reason":"Companies Anthropic Hacked","category":"News","sources":["CyberScoop","The Record"],"coverage":2,"cve_ids":[],"summary":"Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.","source":"The Record","date_rel":"31 Jul","thumbnail":"http://cms.therecord.media/uploads/anthropic_logo_daaf076757.jpg","description":"","related":[{"title":"Anthropic says its AI accidentally hacked three companies during safety tests","link":"https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/","source":"CyberScoop","date_rel":"31 Jul"}]}],"worth_reading":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/","reason":"Exchange","category":"Media","sources":["Ars Technica Security","Proofpoint Threat Insight"],"coverage":2,"cve_ids":[],"summary":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security\u2026","source":"Ars Technica Security","date_rel":"30 Jul","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2023/07/exploit-vulnerability-security-500x500.jpg","description":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday . Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email\u2026","related":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://www.proofpoint.com/us/newsroom/news/max-severity-exchange-server-flaw-under-active-exploitation-kremlin-hackers","source":"Proofpoint Threat Insight","date_rel":"30 Jul"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-67308","vendor":"wazuh","product":"wazuh","severity":"CRITICAL","score":10.0,"description":"Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharact\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67308"},{"id":"CVE-2026-67330","vendor":"better-auth","product":"scim","severity":"CRITICAL","score":9.9,"description":"@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, \u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67330"},{"id":"CVE-2026-15964","vendor":"WordPress","product":"Single Sign On For TNG","severity":"CRITICAL","score":9.8,"description":"The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function \u2014 registered on `wp_ajax_\u2026","cwe":"CWE-620","kev":false,"kev_action":"","kev_due":"","epss":0.0049,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15964"},{"id":"CVE-2026-66402","vendor":"Apple","product":"FreeRDP","severity":"CRITICAL","score":9.8,"description":"FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common N\u2026","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66402"},{"id":"CVE-2026-67289","vendor":"FreeRDP","product":"FreeRDP","severity":"CRITICAL","score":9.8,"description":"FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client co\u2026","cwe":"CWE-113","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67289"},{"id":"CVE-2026-67324","vendor":"gitpython-developers","product":"GitPython","severity":"CRITICAL","score":9.8,"description":"GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67324"},{"id":"CVE-2026-67340","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.8,"description":"ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permissi\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67340"},{"id":"CVE-2026-67341","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.8,"description":"ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION stateme\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67341"},{"id":"CVE-2026-67342","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.8,"description":"ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify data\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67342"},{"id":"CVE-2026-8457","vendor":"Apple","product":"WooCommerce - Social Login","severity":"CRITICAL","score":9.8,"description":"The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 \u2026","cwe":"CWE-289","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-8457"}],"vendor_spikes":[{"vendor":"WordPress","count":92,"critical_count":1},{"vendor":"FreeRDP","count":17,"critical_count":1},{"vendor":"better-auth","count":14,"critical_count":1},{"vendor":"Apple","count":12,"critical_count":2},{"vendor":"gitpython-developers","count":5,"critical_count":1},{"vendor":"guzzle","count":4,"critical_count":0},{"vendor":"ArcadeData","count":4,"critical_count":3},{"vendor":"ueberauth","count":4,"critical_count":0},{"vendor":"Red Hat","count":4,"critical_count":0},{"vendor":"Unknown","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":176,"has_news_data":true,"has_cve_data":true}