{"date_iso":"2026-08-07","date_human":"Friday, August 7, 2026","generated_utc":"2026-08-07 14:15 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets","link":"https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html","reason":"Github","category":"News","sources":["Ars Technica Security","CCCS Alerts & Advisories","Malwarebytes Labs","Palo Alto Unit 42","SANS Internet Storm Center","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguukj-eRhx9RtAq9X96hAxHi0IU3ZWgM_W5XkdWhF8ezevuBQygkpv-ku5PSri9Gt5hRkNVxe6HmJJr5Mg33X_PhOGziqaho9bwm-mkRZSBl2jo94XF3jRwTZOb_PocueKWJkEtvl7kG_YqmbVfUxNht8_ODzLOERIqQteMdPxnWpobM-c9-fHhn0cLMQ/s1600/claude-github.jpg","description":"A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.","related":[{"title":"ChainDrop: Inside a Self-Propagating npm Worm","link":"https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/","source":"Palo Alto Unit 42","date_rel":"14h ago"},{"title":"GitHub security advisory (AV26-783)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-783","source":"CCCS Alerts & Advisories","date_rel":"23h ago"},{"title":"Anthropic\u2019s Mythos AI used social engineering to target real people","link":"https://www.malwarebytes.com/blog/news/2026/08/anthropics-mythos-ai-used-social-engineering-to-target-real-people","source":"Malwarebytes Labs","date_rel":"6 Aug"},{"title":"Anthropic\u2019s AI used fake identities, malware in rogue attack on GitHub project","link":"https://arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/","source":"Ars Technica Security","date_rel":"5 Aug"},{"title":"Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)","link":"https://isc.sans.edu/diary/rss/33218","source":"SANS Internet Storm Center","date_rel":"5 Aug"},{"title":"Leaked n8n API Tokens Exposed Live Instances to Credential Theft","link":"https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html","source":"The Hacker News","date_rel":"5 Aug"}]},{"title":"Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses","link":"https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html","reason":"Apple","category":"News","sources":["404 Media","Bleeping Computer","Graham Cluley","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to\u2026","source":"The Hacker News","date_rel":"6 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi53VbynsVNPTCihg9qrqybX7Yu90yM3Tm7KlJnJCHz2_MOUQPyJys1uK6H5QkVqxGekck8qe-pA55tcy19IDYQ4_ndOKasvoaFiPJCI_NJClfHv6G14Ga5P_FPr0zyNijjRMBM-GBlt-XYRqCGAcrZxm9ETsAAu4kPh829ZKABQonHDlx2GuWG9-B-V383/s1600/apple-relay.jpg","description":"Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from","related":[{"title":"Microsoft, Apple Release Fresh Security Updates","link":"https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"ClickFix attack pushes macOS infostealer for crypto theft attacks","link":"https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/","source":"Bleeping Computer","date_rel":"14h ago"},{"title":"Apple WebKit vulnerabilities reveal your IP address, despite Private Relay","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Apple\u2019s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits","link":"https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits","source":"Graham Cluley","date_rel":"6 Aug"},{"title":"Apple's \u2018Private Relay\u2019 Is Exposing Users\u2019 Real IP Addresses","link":"https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/","source":"404 Media","date_rel":"5 Aug"},{"title":"Apple battles it out again with the UK over encrypted iCloud access","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-battles-it-out-again-with-uk-over-encrypted-icloud-access","source":"Malwarebytes Labs","date_rel":"4 Aug"}]},{"title":"Attacker phished way into US defense supplier's Microsoft 365 account","link":"https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523","reason":"Exchange","category":"News","sources":["Cisco Security Advisories","Infosecurity Magazine","Tenable Blog","The Register Security"],"coverage":4,"cve_ids":[],"summary":"US defense and aerospace supplier IEH Corporation 'fessed up that a criminal managed to break into its Microsoft 365 mailbox in a filing with regulators. In a Form 8-K filed with the Securities and Exchange Commission\u2026","source":"The Register Security","date_rel":"1h ago","thumbnail":"https://image.theregister.com/?imageId=5284669&width=800","description":"US defense and aerospace supplier IEH Corporation 'fessed up that a criminal managed to break into its Microsoft 365 mailbox in a filing with regulators. In a Form 8-K filed with the Securities and Exchange Commission on Thursday, IEH said one of its staffers fell for a phishing scam that gave an attacker access to its M365 environment. The attacker \"impersonated a prospective business contact\" and sent the employee what appeared to be a genuine Microsoft sharing link. The accompanying fake login page duly harvested the victim's M365 credentials. \"The threat actor gained access to mailbox\u2026","related":[{"title":"Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026","link":"https://www.tenable.com/blog/agentic-ai-for-cyber-defenders-what-security-teams-built-at-black-hat-usa-2026","source":"Tenable Blog","date_rel":"40m ago"},{"title":"NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing","link":"https://www.infosecurity-magazine.com/news/safe-initiative-agentic-threat/","source":"Infosecurity Magazine","date_rel":"6 Aug"},{"title":"Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Blocks%20Extensible%20Exchange%20Protocol%20Denial%20of%20Service%20Vulnerability%26vs_k=1","source":"Cisco Security Advisories","date_rel":"5 Aug"}]},{"title":"Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails","link":"https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Cyber Security News","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Cybersecurity researchers have called attention to an active \"widespread email-driven phishing campaign\" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgH78NjDW1Q_sIk9dwQ1scYlCkNCMutfjGx_9flqrKbE42fEXqvHT8s5EeHTnWjbBGvzCuHPEWStR5r6wjwtIuuHF1hyphenhyphenot22E_Q98xedC1zXVhIhwglw6hLWQs45oSrPKPflK6Tt1BlHTj9iokMPpVaTehuemHGHDLL02cn2sqZJ5iIVstxiVf5IZ5Khodp/s1600/ms-phish.jpg","description":"Cybersecurity researchers have called attention to an active \"widespread email-driven phishing campaign\" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. \"The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,","related":[{"title":"UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions","link":"https://cybersecuritynews.com/unc6671-automates-microsoft-365/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access","link":"https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html","source":"The Hacker News","date_rel":"3h ago"},{"title":"Swiss government SharePoint breach compromised 200 accounts","link":"https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/","source":"Bleeping Computer","date_rel":"18h ago"},{"title":"Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk","link":"https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html","source":"The Hacker News","date_rel":"5 Aug"},{"title":"Microsoft Tells Engineers \u2018Tokenmaxxing Is Not What We Are Optimizing For\u2019","link":"https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/","source":"404 Media","date_rel":"4 Aug"},{"title":"AI helps Microsoft bug hunters chase a record $20M payday","link":"https://www.theregister.com/security/2026/08/04/ai-helps-microsoft-bug-hunters-chase-a-record-20m-payday/5282821","source":"The Register Security","date_rel":"4 Aug"}]},{"title":"Flaws in Google APK for Python Unlock Agent-to-Agent Attack","link":"https://www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack","reason":"Google","category":"News","sources":["Bleeping Computer","Dark Reading","Infosecurity Magazine","Malwarebytes Labs"],"coverage":4,"cve_ids":[],"summary":"Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.","source":"Dark Reading","date_rel":"5 Aug","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt9abdeefc15f542ea/6a7355e3a1a11b1319173fcc/AI_agent_concept_Brain_light_Alamy.png?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Google Links Redact Extortion Group to BlackFile Rebrand","link":"https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Google Blogger locks hundreds of blogs in malware false positive","link":"https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/","source":"Bleeping Computer","date_rel":"5 Aug"},{"title":"Google\u2019s synchronized passkeys can be stolen in \u2018Pass\u2011ta\u2011key\u2019 attacks","link":"https://www.malwarebytes.com/blog/news/2026/08/googles-synchronized-passkeys-can-be-stolen-in-pass-ta-key-attacks","source":"Malwarebytes Labs","date_rel":"5 Aug"},{"title":"AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls","link":"https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls","source":"Dark Reading","date_rel":"4 Aug"}]},{"title":"Top 10 Best DNS Security Solutions in 2026","link":"https://cybersecuritynews.com/best-dns-security-solutions/","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the\u2026","source":"Cyber Security News","date_rel":"9h ago","thumbnail":"https://i2.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQMZ593YhBRfEXBcbxtVpDeFa2CXQ1OWGPnssevXefPGPeHzFHPjIEtCGj-IkW6XWsQe-1F0-ZzNidBdB480KYYUkASAKxo5bRC1NSlW-YIteiIeBcTq4xkBlhKwOxR4SL60jvNHVDSjAMeCzyIfQ26ZLJ9S1t6xm9zLV7iXAd8aY2BH2zmGkp0KdL4d4/s1600/Best%20DNS%20Security%20Solutions%20(3).webp?ssl=1","description":"Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the strength of Talos-fed intelligence and proven scale, with Infoblox leading DDI-integrated security and Akamai delivering edge-scale protection. DNS security protects and exploits the DNS layer blocking resolution of malicious domains, detecting tunneling and DGA activity, and hardening DNS infrastructure. Below, the ten best DNS security solutions ranked. Quick Verdict \u2022 Best overall\u2026","related":[{"title":"Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs","link":"https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html","source":"The Hacker News","date_rel":"19h ago"},{"title":"Cisco security advisory (AV26-785)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-785","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"Bypassing AI guardrails is so easy a script kiddie can do it","link":"https://www.theregister.com/security/2026/08/04/bypassing-ai-guardrails-is-so-easy-a-script-kiddie-can-do-it/5282973","source":"The Register Security","date_rel":"4 Aug"}]},{"title":"Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025","link":"https://www.wiz.io/blog/wiz-brings-automated-disa-stig-assessment-to-amazon-linux-and-windows-server","reason":"Amazon","category":"Research","sources":["Malwarebytes Labs","The Hacker News","Wired Security","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.","source":"Wiz Research","date_rel":"6 Aug","thumbnail":"https://www.datocms-assets.com/75231/1785949574-disa-2x.png","description":"","related":[{"title":"Amazon and Apple impersonated in \u201c$149.99 unauthorized charge\u201d scam","link":"https://www.malwarebytes.com/blog/scams/2026/08/amazon-and-apple-impersonated-in-149-99-unauthorized-charge-scam","source":"Malwarebytes Labs","date_rel":"6 Aug"},{"title":"AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model","link":"https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html","source":"The Hacker News","date_rel":"6 Aug"},{"title":"OpenAI\u2019s Browser Could Be Hijacked to Spam Your WhatsApp Contacts","link":"https://www.wired.com/story/openais-browser-could-be-hijacked-to-spam-your-whatsapp-contacts/","source":"Wired Security","date_rel":"5 Aug"}]},{"title":"18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers","link":"https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html","reason":"Linux","category":"News","sources":["Bleeping Computer","SANS Internet Storm Center","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmTGemKyDLZPr_sBbt2AdOQMEBEcRFzic8_Ddtkx92vtPOfFdoiwxJ60b00usecTjHuIGUJuUIR2aB8MU2P7-GLc0NOuWsa3ctofrA2-wD38wgI4Fke3moSskWjiRJEXT8Yxl7Ye56NgGl9DZKr8zf974rHRsc1PtHie_iIPVyD18HMx49S02tGZ2EeDY/s1600/linux-sctp.jpg","description":"A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.","related":[{"title":"Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)","link":"https://isc.sans.edu/diary/rss/33226","source":"SANS Internet Storm Center","date_rel":"5h ago"},{"title":"New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes","link":"https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/","source":"Bleeping Computer","date_rel":"18h ago"},{"title":"New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts","link":"https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html","source":"The Hacker News","date_rel":"18h ago"},{"title":"New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs","link":"https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html","source":"The Hacker News","date_rel":"20h ago"}]},{"title":"Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports","link":"https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html","reason":"Teams","category":"News","sources":["Microsoft Security","The Hacker News","Wiz Research"],"coverage":3,"cve_ids":["CVE-2026-62896","CVE-2026-62918","CVE-2026-65667"],"summary":"Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both\u2026","source":"The Hacker News","date_rel":"5 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnNyDWyCEMrA99LxVQMqKNr188rBBjKa6Kg3nHdjVLxWCCVgfqa0cChHo_JWbHgbSLHgZVpcgWn0kw0FUySWhScczQi6LNme-wY9rkUAxE-IvoFLvfum-zWxEnppDBu6bAHBO0ObN39kCDwSK4jnsqdCAOhCPGG0FtoLX_2vvCi2DcoWPmzGUk6Hs_gB4/s1600/paperclipai.jpg","description":"Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes","related":[{"title":"CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62896","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-62918 Microsoft Teams Spoofing Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62918","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65667","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Wiz at Black Hat 2026: Driving AI Threat Readiness","link":"https://www.wiz.io/blog/wiz-at-black-hat-2026","source":"Wiz Research","date_rel":"4 Aug"}]},{"title":"Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service","link":"https://thehackernews.com/2026/08/ransom-cartel-creator-gets-16-years-in.html","reason":"Creator Prison Cartel","category":"News","sources":["Bleeping Computer","CyberScoop","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and\u2026","source":"The Hacker News","date_rel":"6 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsIRDdzzjtJRcq3kiouQy7I8wwCFvWIKA5VHAKEVdGC2OJL3WCGnKPZUvAHUi-Jrz9yLN5pfTtS0QI8MRUuSbGOlbg_3jNktHGZSb4wsOKvjcwehZYqL671hB0UgjVjUPnKju5QFDO4BXhjePhJuvGDw_mJs1scXXI_veItNxCej7uEwjKfTHzc9Nkm90/s1600/Ransom-Cartel.jpg","description":"A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.","related":[{"title":"Ransom Cartel creator sentenced to 16 years in prison","link":"https://cyberscoop.com/ransom-cartel-creator-sentenced-to-16-years-in-prison/","source":"CyberScoop","date_rel":"18h ago"},{"title":"Ransom Cartel ransomware creator sentenced to 16 years in prison","link":"https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/","source":"Bleeping Computer","date_rel":"5 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-5430","vendor":"HashiCorp","product":"WSO2 Universal Gateway","severity":"CRITICAL","score":10.0,"description":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading t\u2026","cwe":"CWE-347","kev":false,"kev_action":"","kev_due":"","epss":0.0022,"url":"https://cve.blackmesa.ca/?q=CVE-2026-5430"},{"id":"CVE-2026-65553","vendor":"WordPress","product":"Spider Analyser \u2013 WordPress\u641c\u7d22\u5f15\u64ce\u8718\u86db\u5206\u6790\u63d2\u4ef6","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress\u641c\u7d22\u5f15\u64ce\u8718\u86db\u5206\u6790\u63d2\u4ef6 <= 2.1.3 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65553"},{"id":"CVE-2026-66665","vendor":"Brandexponents","product":"Type Hub","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66665"},{"id":"CVE-2026-11976","vendor":"Unknown","product":"MonsterInsights Pro","severity":"CRITICAL","score":10.0,"description":"The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-sy\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-11976"},{"id":"CVE-2026-14812","vendor":"WordPress","product":"Premium SEO","severity":"CRITICAL","score":10.0,"description":"The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end scr\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14812"},{"id":"CVE-2026-56162","vendor":"Microsoft","product":"Azure SQL Database","severity":"CRITICAL","score":10.0,"description":"Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-56162"},{"id":"CVE-2026-63508","vendor":"Microsoft","product":"Microsoft Planetary Computer Pro (GeoCatalog)","severity":"CRITICAL","score":10.0,"description":"Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63508"},{"id":"CVE-2026-65667","vendor":"Microsoft","product":"Microsoft Teams","severity":"CRITICAL","score":10.0,"description":"Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65667"},{"id":"CVE-2026-65548","vendor":"Muffingroup","product":"Betheme","severity":"CRITICAL","score":9.9,"description":"Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65548"},{"id":"CVE-2026-48086","vendor":"open-reception","product":"appointment-booking-software","severity":"CRITICAL","score":9.9,"description":"OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-upda\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48086"}],"vendor_spikes":[{"vendor":"WordPress","count":87,"critical_count":8},{"vendor":"Google","count":45,"critical_count":2},{"vendor":"Microsoft","count":21,"critical_count":13},{"vendor":"Apache","count":18,"critical_count":7},{"vendor":"Unknown","count":17,"critical_count":2},{"vendor":"WSO2","count":17,"critical_count":4},{"vendor":"Linux","count":17,"critical_count":0},{"vendor":"HashiCorp","count":16,"critical_count":2},{"vendor":"open-reception","count":15,"critical_count":4},{"vendor":"itsourcecode","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":19,"new_cve_count":513,"has_news_data":true,"has_cve_data":true}