Skip to content

Morning Brief

Friday, August 7, 2026 · generated 2026-08-07 14:15 UTC · ~5 min read

Top developments

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next…

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to…

Attacker phished way into US defense supplier's Microsoft 365 account

US defense and aerospace supplier IEH Corporation 'fessed up that a criminal managed to break into its Microsoft 365 mailbox in a filing with regulators. In a Form 8-K filed with the Securities and Exchange Commission…

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to…

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.

Top 10 Best DNS Security Solutions in 2026

Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the…

Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025

Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since…

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both…

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and…

Vulnerability watch

CVE-2026-5430 HashiCorp · WSO2 Universal Gateway CWE-347 CRITICAL 10.0 · EPSS 0%

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading t…

CVE-2026-65553 WordPress · Spider Analyser – WordPress搜索引擎蜘蛛分析插件 CWE-94 CRITICAL 10.0

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

CVE-2026-66665 Brandexponents · Type Hub CWE-434 CRITICAL 10.0

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

CVE-2026-11976 Unknown · MonsterInsights Pro CRITICAL 10.0

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-sy…

CVE-2026-14812 WordPress · Premium SEO CRITICAL 10.0

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end scr…

CVE-2026-56162 Microsoft · Azure SQL Database CWE-287 CRITICAL 10.0

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-63508 Microsoft · Microsoft Planetary Computer Pro (GeoCatalog) CWE-306 CRITICAL 10.0

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-65667 Microsoft · Microsoft Teams CWE-862 CRITICAL 10.0

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-65548 Muffingroup · Betheme CWE-94 CRITICAL 9.9

Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

CVE-2026-48086 open-reception · appointment-booking-software CWE-269 CRITICAL 9.9

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-upda…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →