{"date_iso":"2026-08-09","date_human":"Sunday, August 9, 2026","generated_utc":"2026-08-09 13:53 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default","link":"https://www.theregister.com/ai-and-ml/2026/08/08/devs-to-anthropic-openai-cursor-and-friends-make-security-and-privacy-the-default/5285107","reason":"Github","category":"News","sources":["CCCS Alerts & Advisories","Palo Alto Unit 42","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary\u2026","source":"The Register Security","date_rel":"23h ago","thumbnail":"https://image.theregister.com/?imageId=5281583&width=800","description":"Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary in Canada decided to sift through developers' concerns about LLM-based integrated development environments (LIDEs) by analyzing Reddit discussions for common themes. Their findings suggest that the builders of such tools failed to prioritize security and privacy, leaving developers to defend themselves. Gias Uddin, associate professor at York University and a co-author of the\u2026","related":[{"title":"Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets","link":"https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"ChainDrop: Inside a Self-Propagating npm Worm","link":"https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/","source":"Palo Alto Unit 42","date_rel":"6 Aug"},{"title":"GitHub security advisory (AV26-783)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-783","source":"CCCS Alerts & Advisories","date_rel":"6 Aug"}]},{"title":"18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host","link":"https://cybersecuritynews.com/18-year-old-linux-kernel-sctp-vulnerability/","reason":"CVE-2026-64564","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-64564"],"summary":"A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers to compromise the\u2026","source":"Cyber Security News","date_rel":"7 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/18-Year-Old-Linux-Kernel-SCTP-Vulnerability.webp","description":"A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers to compromise the underlying host. The flaw is a use-after-free bug in the kernel\u2019s SCTP Dynamic Address Reconfiguration feature, and remarkably, its root cause traces back to code introduced in Linux 2.6.25 in December 2007, making it nearly 18 years old before discovery. The vulnerability lives in how the kernel handles ASCONF chunks, a mechanism defined in RFC 5061 that lets SCTP associations add\u2026","related":[{"title":"CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64564","source":"Microsoft Security","date_rel":"3h ago"}]},{"title":"CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges","link":"https://cybersecuritynews.com/zapscape-kvm-escape-root-privileges/","reason":"CVE-2026-64561","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-64561"],"summary":"A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux host with root privileges. The issue affects\u2026","source":"Cyber Security News","date_rel":"7 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CVE-2026-64561-Zapscape-Lets-KVM-Guests-Escape-to-Linux-Host-With-Root-Privileges-1.webp","description":"A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux host with root privileges. The issue affects KVM/x86, a virtualization technology that separates guest systems from the physical server. The flaw is especially serious for cloud providers and enterprises that run untrusted workloads. Zapscape was discovered by security researcher Hyunwoo Kim, known as V4bel. It exists in KVM\u2019s shadow memory management unit, or shadow MMU. It manages memory translations when nested\u2026","related":[{"title":"CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64561","source":"Microsoft Security","date_rel":"3h ago"}]},{"title":"AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day","link":"https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html","reason":"Apache","category":"News","sources":["Microsoft Security","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-34191","CVE-2026-34501","CVE-2026-34502"],"summary":"PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync\u2026","source":"The Hacker News","date_rel":"7 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgynSSg0CZ1sssmMR8F0u09LmQ82liuj5nt2aor3klmi-xPcKTmalo4JLFQ7jd2mU9Ycnltsrnw2MiVVjmlT-wcYR74Ob7NMN31KNnny14lqVRdrmj30r3yqTSxapzCmQPk9lPG7v9GDSVKQwE4ufB-jWfsx1lc2O5GNd0bHd5M6FbMNah3dcLzu2EAFXo/s1600/Desync.jpg","description":"PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where","related":[{"title":"CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34502","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34501","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34191","source":"Microsoft Security","date_rel":"4h ago"}]},{"title":"ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets","link":"https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html","reason":"Apple","category":"News","sources":["Bleeping Computer","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused\u2026","source":"The Hacker News","date_rel":"7 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKQGTQ6AquoAvAeMWXXITPacYsdChgFUpg7MLwKkfb2AylEuwQTk9av5GqMSdgtsB_tr_6QC70DrJkEo02t-Wo67z1gumix6FKKlOPSWo4fLEUHCibBoTrf1zCdmn72ESzo5CzCKKEgyETZ0FeVD_3QLfCNit7vIwlMA7MmwGYg2JGbeYOBrjSHmOnfpWl/s1600/macos.jpg","description":"ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. \"","related":[{"title":"In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street","link":"https://www.securityweek.com/in-other-news-ai-slop-limits-apple-bounties-north-carolina-port-attacks-hackers-target-wall-street/","source":"SecurityWeek","date_rel":"7 Aug"},{"title":"Microsoft, Apple Release Fresh Security Updates","link":"https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/","source":"SecurityWeek","date_rel":"7 Aug"},{"title":"ClickFix attack pushes macOS infostealer for crypto theft attacks","link":"https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/","source":"Bleeping Computer","date_rel":"6 Aug"},{"title":"Apple WebKit vulnerabilities reveal your IP address, despite Private Relay","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay","source":"Malwarebytes Labs","date_rel":"6 Aug"}]},{"title":"Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer","link":"https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html","reason":"Linux","category":"News","sources":["Bleeping Computer","SANS Internet Storm Center","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. \"These packages appear to\u2026","source":"The Hacker News","date_rel":"7 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIEXaa59LRblZ0rcBVbKDdH4w9Rszk27anNt20Onx7Li8D7FXbf3Ipod53uo3N2aa6Hj1QLJaNFDIBlrcgM3YZg0UJCsjI3maDKkFEdOeyhzis15St3QDg6WCXcYlbDRlw2WvgiOH-BL_v8I21QoSTE9kmJzzKqQwstqn11JWkAL1_9W41ZF04T-9ImaiL/s1600/npms.jpg","description":"A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. \"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,\" OpenSourceMalware researcher Paul","related":[{"title":"18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers","link":"https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)","link":"https://isc.sans.edu/diary/rss/33226","source":"SANS Internet Storm Center","date_rel":"7 Aug"},{"title":"New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes","link":"https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/","source":"Bleeping Computer","date_rel":"6 Aug"},{"title":"New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts","link":"https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html","source":"The Hacker News","date_rel":"6 Aug"}]},{"title":"Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID","link":"https://cybersecuritynews.com/malware-abuses-windows-hello-key/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to authenticate to Microsoft Entra ID, enabling attackers to gain\u2026","source":"Cyber Security News","date_rel":"7 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Malware-Abuses-Windows-Hello-for-Business-key-to-authenticate-Microsoft-Entra-ID.webp","description":"A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to authenticate to Microsoft Entra ID, enabling attackers to gain cloud access without the victim\u2019s password, PIN, or biometric data. Windows Hello for Business is designed as a passwordless authentication system. It normally stores a user\u2019s private key in the device\u2019s Trusted Platform Module, or TPM, making the key difficult to export or steal. Users unlock access to that key with a PIN, fingerprint, facial recognition, or another local\u2026","related":[{"title":"Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails","link":"https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access","link":"https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"Swiss government SharePoint breach compromised 200 accounts","link":"https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/","source":"Bleeping Computer","date_rel":"6 Aug"}]},{"title":"Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers","link":"https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html","reason":"Atlassian","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior\u2026","source":"The Hacker News","date_rel":"8 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFYjJTxVoOMkR9DDRPZ5PkeR_EWAqmBScR3TPw3mlweipGlnQKq0OdfVqR2f26QIV3kBJWQIM65f8XwMSFq3zT6Bl4fsTvkPHxJiU2LilhK9s0tcreXt2gotEpE8sKoDrLQJ3SSVY9B-RS0FsS2dC480op8OV-caeaZvNyTiIipQbeNFJGMnAcjWEVq7g/s1600/rovo.jpg","description":"Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was","related":[{"title":"Critical One-Click Vulnerability in Atlassian\u2019s Rovo AI Exposed Enterprise Data","link":"https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/","source":"SecurityWeek","date_rel":"8 Aug"}]},{"title":"Google Links Redact Extortion Group to BlackFile Rebrand","link":"https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine"],"coverage":2,"cve_ids":[],"summary":"BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns","source":"Infosecurity Magazine","date_rel":"7 Aug","thumbnail":"","description":"","related":[{"title":"Google security advisory (AV26-787)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-787","source":"CCCS Alerts & Advisories","date_rel":"7 Aug"}]},{"title":"Unlimited Technology Systems breach impacts 3.8 million people","link":"https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/","reason":"Technology Unlimited Million","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.","source":"Bleeping Computer","date_rel":"7 Aug","thumbnail":"","description":"","related":[{"title":"3.8 Million Impacted by Unlimited Technology Systems Data Breach","link":"https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/","source":"SecurityWeek","date_rel":"7 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-14526","vendor":"WordPress","product":"AI Copilot \u2013 Content Generator","severity":"CRITICAL","score":9.8,"description":"The AI Copilot \u2013 Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":0.0061,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14526"},{"id":"CVE-2026-71944","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary maliciou\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71944"},{"id":"CVE-2026-71945","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary maliciou\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71945"},{"id":"CVE-2026-71946","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious co\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71946"},{"id":"CVE-2026-71947","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malici\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71947"},{"id":"CVE-2026-71948","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious c\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71948"},{"id":"CVE-2026-71949","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands i\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71949"},{"id":"CVE-2026-71950","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands i\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71950"},{"id":"CVE-2026-71951","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands i\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71951"},{"id":"CVE-2026-71952","vendor":"D-Link","product":"DWR-M961","severity":"CRITICAL","score":9.8,"description":"D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious comma\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71952"}],"vendor_spikes":[{"vendor":"WordPress","count":33,"critical_count":1},{"vendor":"D-Link","count":15,"critical_count":15},{"vendor":"MSI","count":11,"critical_count":11}],"epss_risers":[],"developing_map":{},"trending_count":14,"new_cve_count":96,"has_news_data":true,"has_cve_data":true}