Morning Brief

Tuesday, August 4, 2026 · generated 2026-08-04 21:15 UTC · ~5 min read

Patch today
22
WordPress
21
Microsoft
1 critical
19
Unknown
1 critical
12
HashiCorp
3 critical
10
Red Hat
7
TP-Link Systems Inc.
7
Adobe
6 critical
7
Eclipse Foundation
5
Apache
5
GL-iNet
5 critical

Top developments

Google dev kit spurs first-ever agent-on-agent violence

In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could…

CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks

CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577 , the flaw affects N-central servers running versions earlier than…

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for business email compromise (BEC) and large-scale wire fraud. The…

Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams

Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the…

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance…

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing…

Bypassing AI guardrails is so easy a script kiddie can do it

If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to researchers from Cisco Talos. Simply claiming you own the servers…

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able…

Apple launches new legal challenge against UK over iCloud access

Seeking to protect users' iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company's Advanced Data Protection feature.

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote…

Vulnerability watch

CVE-2026-48323 Adobe · Adobe Campaign Classic CWE-1336 CRITICAL 10.0 · EPSS 0%

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit t…

CVE-2026-48330 Adobe · Adobe Campaign Classic CWE-89 CRITICAL 10.0 · EPSS 0%

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker …

CVE-2026-48331 Adobe · Adobe Campaign Classic CWE-918 CRITICAL 10.0 · EPSS 0%

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48326 Adobe · Adobe Campaign Classic CWE-89 CRITICAL 9.9 · EPSS 0%

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privil…

CVE-2026-18602 GL.iNet · GL-MT3000 CWE-74 CRITICAL 9.8 · EPSS 1%

A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Host…

CVE-2026-41452 krayin · laravel-crm CWE-306 CRITICAL 9.8 · EPSS 0%

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Reque…

CVE-2026-18612 GL-iNet · GL-MT3000 CWE-74 CRITICAL 9.8 · EPSS 2%

A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes comm…

CVE-2026-18613 GL-iNet · GL-MT3000 CWE-74 CRITICAL 9.8 · EPSS 0%

A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be …

CVE-2026-18614 GL-iNet · GL-MT3000 CWE-74 CRITICAL 9.8 · EPSS 2%

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command in…

CVE-2026-18615 GL-iNet · GL-MT3000 CWE-74 CRITICAL 9.8 · EPSS 1%

A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argumen…

Full CVE Feed →

Worth reading

8 Best Password Managers (2026), Tested and Reviewed

Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →