{"date_iso":"2026-08-03","date_human":"Monday, August 3, 2026","generated_utc":"2026-08-03 13:55 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says","link":"https://therecord.media/russian-wifi-hackers-hotels","reason":"Microsoft","category":"News","sources":["Malwarebytes Labs","SecurityWeek","The Hacker News","The Record"],"coverage":4,"cve_ids":[],"summary":"Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, Microsoft said.","source":"The Record","date_rel":"1h ago","thumbnail":"http://cms.therecord.media/uploads/Hotel_room_5c31b73771.jpg","description":"","related":[{"title":"Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking","link":"https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"A week in security (July 27 \u2013 August 2)","link":"https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-july-27-august-2","source":"Malwarebytes Labs","date_rel":"5h ago"},{"title":"Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware","link":"https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html","source":"The Hacker News","date_rel":"1 Aug"}]},{"title":"Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft","link":"https://cybersecuritynews.com/coldcard-hardware-wallet-rng-flaw-bitcoin-theft/","reason":"Coldcard Bitcoin Million","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing them to reconstruct victims\u2019\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Coldcard-Hardware-Wallet-RNG-Flaw-Linked-to-88.6-Million-Bitcoin-Theft-1-1.webp","description":"A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing them to reconstruct victims\u2019 private keys without ever accessing their devices. Digital asset research firm Galaxy Research first noted unusual activity on July 30, when an attacker drained about 1,082.65 BTC, valued at around $70.2 million, from 1,196 addresses in a rapid sweep lasting just 41 minutes. By August 1, Galaxy detected additional waves of transactions, bringing the total theft to 1,367.05 BTC\u2026","related":[{"title":"COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft","link":"https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/","source":"Bleeping Computer","date_rel":"15h ago"},{"title":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes","link":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html","source":"The Hacker News","date_rel":"1 Aug"}]},{"title":"MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets","link":"https://cybersecuritynews.com/macsync-uses-fake-claude-guide/","reason":"Macos","category":"News","sources":["Cyber Security News","SANS Internet Storm Center"],"coverage":2,"cve_ids":[],"summary":"Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on a legitimate Claude sharing page to persuade victims to paste a\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/MacSync-macOS-Stealer-Uses-Fake-Claude-Guide-to-Steal-Passwords-and-Crypto-Wallets.webp","description":"Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on a legitimate Claude sharing page to persuade victims to paste a command into Terminal. That action started the MacSync information-stealing malware. The campaign shows how software searches can become an entry point for account theft. Rather than exploiting a flaw, the operators relied on trust in a familiar domain, a convincing guide, and a command that looked like an installation step. The result can be stolen browser sessions, passwords\u2026","related":[{"title":"Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)","link":"https://isc.sans.edu/diary/rss/33208","source":"SANS Internet Storm Center","date_rel":"2 Aug"}]},{"title":"N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete","link":"https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html","reason":"CVE-2026-18577","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-18577"],"summary":"N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjs1H8Wx5_ZrUFksG2Tgb_6qho5XHULdP13qVeYXx1xWPPt8B2rH68XC6IhzBk-dczgsdWvpZ_dVTI7AIMsgK1EeU3B89WVUJu2N5B71FQ4GnlZDRlvNiD4pGO2hBCJGVowjUVDMSHAO_0CPlYthpa8jx-Af5OwB6ZMDr-PKTYDJKjP4pGCZZolbjbGi44/s1600/n-able.jpg","description":"N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform","related":[{"title":"N\u2011able Patches Vulnerability Exploited to Hack N-central Servers","link":"https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/","source":"SecurityWeek","date_rel":"26m ago"}]},{"title":"XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands","link":"https://cybersecuritynews.com/xcsset-v40-abuses-chrome-devtools/","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once activated, it can spread through\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/XCSSET-v40-Abuses-Chrome-DevTools-Protocol-to-Steal-Cookies-and-Run-Commands.webp","description":"XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once activated, it can spread through other projects, raising risk for developers and the organizations that use their code. The malware family was first documented in 2020, but its campaign shows a move toward stealth and scale. It uses memory-based execution, changing payloads, and short-lived files to reduce visible traces. Developers across South Asia have seen heightened targeting, while infected projects have\u2026","related":[{"title":"Google Chrome may soon block New Tab hijacker extensions by default","link":"https://www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/","source":"Bleeping Computer","date_rel":"22h ago"}]},{"title":"AI is 'both the weapon and the target' in latest wave of cyberattacks","link":"https://www.theregister.com/cyber-crime/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks/5281534","reason":"Crowdstrike","category":"News","sources":["CyberScoop","The Register Security"],"coverage":2,"cve_ids":[],"summary":"AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal\u2026","source":"The Register Security","date_rel":"5h ago","thumbnail":"https://image.theregister.com/?imageId=258436&width=800","description":"AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal gangs and nation states using AI throughout the attack chain. Attackers are also targeting organizations' AI infrastructure and poisoning popular software packages to compromise their users. \"AI is both the weapon and the target,\" CrowdStrike counter adversary division senior VP Adam Meyers told reporters. \"AI is a high-value attack surface, and it's being used by more and more\u2026","related":[{"title":"CrowdStrike: AI is now both the weapon and the target in cyberattacks","link":"https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/","source":"CyberScoop","date_rel":"5h ago"}]},{"title":"Cheap Android TV Boxes Pose as Phones and Turn Owners\u2019 Broadband Into Proxies","link":"https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html","reason":"Android","category":"News","sources":["The Hacker News","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers\u2026","source":"The Hacker News","date_rel":"31 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhxfc7_NuArKSujgjgzPzENagYVTlBxcvnFBXSbptnFs_TI1o-Zt5SINHtPEO5MNkJ3vwkKUTX68vwmCzVxRQVFcgnb9eXwAsLKayCtzMLVRuqwV3RDaWTgQNOm0CVXcV_jX1v4x4mgEthTDjAsZdF4BSPSuTTRqKnM6qbIhPVjZP38dHmpptNurSmXRM/s1600/android-tv.jpg","description":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box","related":[{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","source":"Wired Security","date_rel":"2 Aug"}]},{"title":"Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction","link":"https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html","reason":"Adobe","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The\u2026","source":"The Hacker News","date_rel":"1 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW/s1600/adobe-flaw.jpg","description":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in","related":[{"title":"In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research","link":"https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/","source":"SecurityWeek","date_rel":"31 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"31 Jul","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. \ud83d\udca1 Do you work at Google? I would love to hear\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"31 Jul"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-65321","vendor":"laughingman7743","product":"PyAthena","severity":"CRITICAL","score":9.8,"description":"PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statemen\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65321"},{"id":"CVE-2026-68579","vendor":"Microsoft","product":"FreeRDP","severity":"CRITICAL","score":9.6,"description":"FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a f\u2026","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68579"},{"id":"CVE-2026-67356","vendor":"ArcadeData","product":"arcadedb","severity":"HIGH","score":8.8,"description":"ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission ca\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67356"},{"id":"CVE-2025-71399","vendor":"better-auth","product":"better-auth","severity":"HIGH","score":8.6,"description":"Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to \u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-71399"},{"id":"CVE-2026-68581","vendor":"go-vikunja","product":"vikunja","severity":"HIGH","score":8.1,"description":"Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-s\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68581"},{"id":"CVE-2026-67357","vendor":"ArcadeData","product":"arcadedb","severity":"HIGH","score":7.5,"description":"ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it wi\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67357"},{"id":"CVE-2026-68578","vendor":"ArcadeData","product":"arcadedb","severity":"HIGH","score":7.5,"description":"ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, sche\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68578"},{"id":"CVE-2026-68580","vendor":"FreeRDP","product":"FreeRDP","severity":"HIGH","score":7.5,"description":"FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers\u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68580"},{"id":"CVE-2026-3245","vendor":"Palo Alto","product":"PRISMAproduction","severity":"HIGH","score":7.5,"description":"A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-3245"},{"id":"CVE-2025-71400","vendor":"better-auth","product":"passkey","severity":"HIGH","score":7.1,"description":"better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submi\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-71400"}],"vendor_spikes":[{"vendor":"MediaTek, Inc.","count":34,"critical_count":0},{"vendor":"Legion of the Bouncy Castle Inc.","count":31,"critical_count":0},{"vendor":"better-auth","count":3,"critical_count":0},{"vendor":"ArcadeData","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":9,"new_cve_count":92,"has_news_data":true,"has_cve_data":true}