Morning Brief

Monday, August 3, 2026 · generated 2026-08-03 13:55 UTC · ~5 min read

Patch today
34
MediaTek, Inc.
31
Legion of the Bouncy Castle Inc.
3
better-auth
3
ArcadeData

Top developments

Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says

Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, Microsoft said.

Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft

A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing them to reconstruct victims’…

MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets

Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on a legitimate Claude sharing page to persuade victims to paste a…

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577…

XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands

XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once activated, it can spread through…

AI is 'both the weapon and the target' in latest wave of cyberattacks

AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal…

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers…

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The…

Google Earth’s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images

On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a…

Vulnerability watch

CVE-2026-65321 laughingman7743 · PyAthena CWE-89 CRITICAL 9.8

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statemen…

CVE-2026-68579 Microsoft · FreeRDP CWE-787 CRITICAL 9.6

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a f…

CVE-2026-67356 ArcadeData · arcadedb CWE-269 HIGH 8.8

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission ca…

CVE-2025-71399 better-auth · better-auth CWE-20 HIGH 8.6

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to …

CVE-2026-68581 go-vikunja · vikunja CWE-863 HIGH 8.1

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-s…

CVE-2026-67357 ArcadeData · arcadedb CWE-200 HIGH 7.5

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it wi…

CVE-2026-68578 ArcadeData · arcadedb CWE-306 HIGH 7.5

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, sche…

CVE-2026-68580 FreeRDP · FreeRDP CWE-122 HIGH 7.5

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers…

CVE-2026-3245 Palo Alto · PRISMAproduction CWE-502 HIGH 7.5

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

CVE-2025-71400 better-auth · passkey CWE-639 HIGH 7.1

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submi…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →