{"date_iso":"2026-08-08","date_human":"Saturday, August 8, 2026","generated_utc":"2026-08-08 13:50 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets","link":"https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html","reason":"Github","category":"News","sources":["Ars Technica Security","CCCS Alerts & Advisories","Malwarebytes Labs","Palo Alto Unit 42","SANS Internet Storm Center","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next\u2026","source":"The Hacker News","date_rel":"7 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguukj-eRhx9RtAq9X96hAxHi0IU3ZWgM_W5XkdWhF8ezevuBQygkpv-ku5PSri9Gt5hRkNVxe6HmJJr5Mg33X_PhOGziqaho9bwm-mkRZSBl2jo94XF3jRwTZOb_PocueKWJkEtvl7kG_YqmbVfUxNht8_ODzLOERIqQteMdPxnWpobM-c9-fHhn0cLMQ/s1600/claude-github.jpg","description":"A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.","related":[{"title":"ChainDrop: Inside a Self-Propagating npm Worm","link":"https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/","source":"Palo Alto Unit 42","date_rel":"6 Aug"},{"title":"GitHub security advisory (AV26-783)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-783","source":"CCCS Alerts & Advisories","date_rel":"6 Aug"},{"title":"Anthropic\u2019s Mythos AI used social engineering to target real people","link":"https://www.malwarebytes.com/blog/news/2026/08/anthropics-mythos-ai-used-social-engineering-to-target-real-people","source":"Malwarebytes Labs","date_rel":"6 Aug"},{"title":"Anthropic\u2019s AI used fake identities, malware in rogue attack on GitHub project","link":"https://arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/","source":"Ars Technica Security","date_rel":"5 Aug"},{"title":"Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)","link":"https://isc.sans.edu/diary/rss/33218","source":"SANS Internet Storm Center","date_rel":"5 Aug"}]},{"title":"ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets","link":"https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html","reason":"Apple","category":"News","sources":["404 Media","Bleeping Computer","Graham Cluley","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused\u2026","source":"The Hacker News","date_rel":"17h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKQGTQ6AquoAvAeMWXXITPacYsdChgFUpg7MLwKkfb2AylEuwQTk9av5GqMSdgtsB_tr_6QC70DrJkEo02t-Wo67z1gumix6FKKlOPSWo4fLEUHCibBoTrf1zCdmn72ESzo5CzCKKEgyETZ0FeVD_3QLfCNit7vIwlMA7MmwGYg2JGbeYOBrjSHmOnfpWl/s1600/macos.jpg","description":"ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. \"","related":[{"title":"In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street","link":"https://www.securityweek.com/in-other-news-ai-slop-limits-apple-bounties-north-carolina-port-attacks-hackers-target-wall-street/","source":"SecurityWeek","date_rel":"22h ago"},{"title":"Microsoft, Apple Release Fresh Security Updates","link":"https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/","source":"SecurityWeek","date_rel":"7 Aug"},{"title":"ClickFix attack pushes macOS infostealer for crypto theft attacks","link":"https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/","source":"Bleeping Computer","date_rel":"6 Aug"},{"title":"Apple WebKit vulnerabilities reveal your IP address, despite Private Relay","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay","source":"Malwarebytes Labs","date_rel":"6 Aug"},{"title":"Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses","link":"https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html","source":"The Hacker News","date_rel":"6 Aug"},{"title":"Apple\u2019s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits","link":"https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-missing-exploits","source":"Graham Cluley","date_rel":"6 Aug"}]},{"title":"Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer","link":"https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html","reason":"Linux","category":"News","sources":["Bleeping Computer","Cyber Security News","SANS Internet Storm Center","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-64561","CVE-2026-64564"],"summary":"A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. \"These packages appear to\u2026","source":"The Hacker News","date_rel":"17h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIEXaa59LRblZ0rcBVbKDdH4w9Rszk27anNt20Onx7Li8D7FXbf3Ipod53uo3N2aa6Hj1QLJaNFDIBlrcgM3YZg0UJCsjI3maDKkFEdOeyhzis15St3QDg6WCXcYlbDRlw2WvgiOH-BL_v8I21QoSTE9kmJzzKqQwstqn11JWkAL1_9W41ZF04T-9ImaiL/s1600/npms.jpg","description":"A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. \"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,\" OpenSourceMalware researcher Paul","related":[{"title":"18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host","link":"https://cybersecuritynews.com/18-year-old-linux-kernel-sctp-vulnerability/","source":"Cyber Security News","date_rel":"19h ago"},{"title":"CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges","link":"https://cybersecuritynews.com/zapscape-kvm-escape-root-privileges/","source":"Cyber Security News","date_rel":"22h ago"},{"title":"18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers","link":"https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)","link":"https://isc.sans.edu/diary/rss/33226","source":"SANS Internet Storm Center","date_rel":"7 Aug"},{"title":"New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes","link":"https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/","source":"Bleeping Computer","date_rel":"6 Aug"},{"title":"New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts","link":"https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html","source":"The Hacker News","date_rel":"6 Aug"}]},{"title":"Attacker phished way into US defense supplier's Microsoft 365 account","link":"https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523","reason":"Exchange","category":"News","sources":["Cisco Security Advisories","Infosecurity Magazine","Tenable Blog","The Register Security"],"coverage":4,"cve_ids":[],"summary":"US defense and aerospace supplier IEH Corporation 'fessed up that a criminal managed to break into its Microsoft 365 mailbox in a filing with regulators. In a Form 8-K filed with the Securities and Exchange Commission\u2026","source":"The Register Security","date_rel":"7 Aug","thumbnail":"https://image.theregister.com/?imageId=5284669&width=800","description":"US defense and aerospace supplier IEH Corporation 'fessed up that a criminal managed to break into its Microsoft 365 mailbox in a filing with regulators. In a Form 8-K filed with the Securities and Exchange Commission on Thursday, IEH said one of its staffers fell for a phishing scam that gave an attacker access to its M365 environment. The attacker \"impersonated a prospective business contact\" and sent the employee what appeared to be a genuine Microsoft sharing link. The accompanying fake login page duly harvested the victim's M365 credentials. \"The threat actor gained access to mailbox\u2026","related":[{"title":"Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026","link":"https://www.tenable.com/blog/agentic-ai-for-cyber-defenders-what-security-teams-built-at-black-hat-usa-2026","source":"Tenable Blog","date_rel":"7 Aug"},{"title":"NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing","link":"https://www.infosecurity-magazine.com/news/safe-initiative-agentic-threat/","source":"Infosecurity Magazine","date_rel":"6 Aug"},{"title":"Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Blocks%20Extensible%20Exchange%20Protocol%20Denial%20of%20Service%20Vulnerability%26vs_k=1","source":"Cisco Security Advisories","date_rel":"5 Aug"}]},{"title":"Flaws in Google APK for Python Unlock Agent-to-Agent Attack","link":"https://www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Infosecurity Magazine"],"coverage":3,"cve_ids":[],"summary":"Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.","source":"Dark Reading","date_rel":"5 Aug","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt9abdeefc15f542ea/6a7355e3a1a11b1319173fcc/AI_agent_concept_Brain_light_Alamy.png?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Google security advisory (AV26-787)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-787","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"Google Links Redact Extortion Group to BlackFile Rebrand","link":"https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/","source":"Infosecurity Magazine","date_rel":"7 Aug"}]},{"title":"Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025","link":"https://www.wiz.io/blog/wiz-brings-automated-disa-stig-assessment-to-amazon-linux-and-windows-server","reason":"Amazon","category":"Research","sources":["Malwarebytes Labs","The Hacker News","Wired Security","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.","source":"Wiz Research","date_rel":"6 Aug","thumbnail":"https://www.datocms-assets.com/75231/1785949574-disa-2x.png","description":"","related":[{"title":"Amazon and Apple impersonated in \u201c$149.99 unauthorized charge\u201d scam","link":"https://www.malwarebytes.com/blog/scams/2026/08/amazon-and-apple-impersonated-in-149-99-unauthorized-charge-scam","source":"Malwarebytes Labs","date_rel":"6 Aug"},{"title":"AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model","link":"https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html","source":"The Hacker News","date_rel":"6 Aug"},{"title":"OpenAI\u2019s Browser Could Be Hijacked to Spam Your WhatsApp Contacts","link":"https://www.wired.com/story/openais-browser-could-be-hijacked-to-spam-your-whatsapp-contacts/","source":"Wired Security","date_rel":"5 Aug"}]},{"title":"Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID","link":"https://cybersecuritynews.com/malware-abuses-windows-hello-key/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to authenticate to Microsoft Entra ID, enabling attackers to gain\u2026","source":"Cyber Security News","date_rel":"20h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Malware-Abuses-Windows-Hello-for-Business-key-to-authenticate-Microsoft-Entra-ID.webp","description":"A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to authenticate to Microsoft Entra ID, enabling attackers to gain cloud access without the victim\u2019s password, PIN, or biometric data. Windows Hello for Business is designed as a passwordless authentication system. It normally stores a user\u2019s private key in the device\u2019s Trusted Platform Module, or TPM, making the key difficult to export or steal. Users unlock access to that key with a PIN, fingerprint, facial recognition, or another local\u2026","related":[{"title":"Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails","link":"https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access","link":"https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"Swiss government SharePoint breach compromised 200 accounts","link":"https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/","source":"Bleeping Computer","date_rel":"6 Aug"}]},{"title":"Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers","link":"https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html","reason":"Atlassian","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFYjJTxVoOMkR9DDRPZ5PkeR_EWAqmBScR3TPw3mlweipGlnQKq0OdfVqR2f26QIV3kBJWQIM65f8XwMSFq3zT6Bl4fsTvkPHxJiU2LilhK9s0tcreXt2gotEpE8sKoDrLQJ3SSVY9B-RS0FsS2dC480op8OV-caeaZvNyTiIipQbeNFJGMnAcjWEVq7g/s1600/rovo.jpg","description":"Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was","related":[{"title":"Critical One-Click Vulnerability in Atlassian\u2019s Rovo AI Exposed Enterprise Data","link":"https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/","source":"SecurityWeek","date_rel":"57m ago"}]},{"title":"Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)","link":"https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077","reason":"CVE-2026-63077","category":"Research","sources":["Rapid7 Blog","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-63077"],"summary":"Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over\u2026","source":"Rapid7 Blog","date_rel":"21h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg","description":"Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process. JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, confirming exploitation in\u2026","related":[{"title":"CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild","link":"https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html","source":"The Hacker News","date_rel":"6 Aug"}]},{"title":"Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones","link":"https://cybersecuritynews.com/fake-pdfs-chat-apps-let-patchwork-spy/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-40400"],"summary":"Patchwork, also known as Dropping Elephant, is using fake documents and chat applications to spy on computer and phone users. The long-running espionage group has built separate attack paths for Windows systems and\u2026","source":"Cyber Security News","date_rel":"7 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Fake-PDFs-and-Chat-Apps-Let-Patchwork-Spy-on-PCs-and-Android-Phones.webp","description":"Patchwork, also known as Dropping Elephant, is using fake documents and chat applications to spy on computer and phone users. The long-running espionage group has built separate attack paths for Windows systems and Android devices, allowing it to collect sensitive information from both environments. On Windows, the operation starts with a shortcut file disguised as a PDF document. Opening it launches a hidden PowerShell downloader, displays a decoy file, and quietly installs malware in the background. The technique resembles other malicious shortcut file campaigns that use familiar documents\u2026","related":[{"title":"CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400","source":"Microsoft Security","date_rel":"22h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-64637","vendor":"WebPros","product":"Plesk","severity":"CRITICAL","score":9.9,"description":"Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-64637"},{"id":"CVE-2026-71558","vendor":"Apache","product":"Fory","severity":"CRITICAL","score":9.8,"description":"Heap type confusion vulnerability in Apache Fory C++ deserialization.\n\nThis issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deser\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0021,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71558"},{"id":"CVE-2022-4995","vendor":"Weaver Network Co., Ltd.","product":"E-cology 9.0","severity":"CRITICAL","score":9.8,"description":"Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to \u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2022-4995"},{"id":"CVE-2026-19264","vendor":"gitroomhq","product":"postiz-app","severity":"CRITICAL","score":9.8,"description":"Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19264"},{"id":"CVE-2026-61808","vendor":"Microsoft","product":"LightRAG","severity":"CRITICAL","score":9.8,"description":"LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read i\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61808"},{"id":"CVE-2026-50540","vendor":"kata-containers","product":"kata-containers","severity":"CRITICAL","score":9.6,"description":"Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-50540"},{"id":"CVE-2026-46409","vendor":"openyak","product":"openyak","severity":"CRITICAL","score":9.6,"description":"OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-46409"},{"id":"CVE-2026-71560","vendor":"Apache","product":"Fory","severity":"CRITICAL","score":9.1,"description":"Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.\n\nThis issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an o\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0018,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71560"},{"id":"CVE-2026-48039","vendor":"pipeboard-co","product":"meta-ads-mcp","severity":"CRITICAL","score":9.1,"description":"Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48039"},{"id":"CVE-2026-48170","vendor":"thomaspoignant","product":"scim-patch","severity":"CRITICAL","score":9.1,"description":"`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `\"__proto__.someProp\"`. After one such patch,\n`Object.prototype\u2026","cwe":"CWE-1321","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48170"}],"vendor_spikes":[{"vendor":"Tobit Laboratories AG","count":21,"critical_count":0},{"vendor":"HashiCorp","count":12,"critical_count":0},{"vendor":"Sonatype","count":11,"critical_count":0},{"vendor":"Unknown","count":8,"critical_count":0},{"vendor":"WordPress","count":7,"critical_count":0},{"vendor":"Cisco","count":7,"critical_count":0},{"vendor":"Microsoft","count":6,"critical_count":1},{"vendor":"SourceCodester","count":6,"critical_count":0},{"vendor":"Google","count":6,"critical_count":0},{"vendor":"klever-io","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":186,"has_news_data":true,"has_cve_data":true}