Skip to content

Morning Brief

Monday, August 10, 2026 · generated 2026-08-10 14:22 UTC · ~4 min read

Top developments

Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage

CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an…

Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption

Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and response tools, interrupt Windows telemetry, and target backup…

Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach

Valve has confirmed that a cyberattack on CEVA Logistics, its European shipping partner for Steam hardware such as the Steam Deck, Steam Machine, and Steam Controller, exposed customer data belonging to buyers across…

Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails

Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor…

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior…

Vulnerability watch

CVE-2026-19348 Shenzhen Aitemi · M300 Wi-Fi Repeater CWE-74 CRITICAL 9.8

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulati…

CVE-2026-19346 Tenda · CH22 CWE-74 HIGH 8.8

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated re…

CVE-2026-19381 Kingston · FURY CTRL RGB Control Software CWE-266 HIGH 7.8

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper priv…

CVE-2026-19387 Red Hat · Red Hat Enterprise Linux 10 CWE-787 HIGH 7.6

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV fil…

CVE-2026-19342 code-projects · Task Management System CWE-287 HIGH 7.3 · EPSS 0%

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. …

CVE-2026-19343 code-projects · Task Management System CWE-74 HIGH 7.3 · EPSS 0%

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injecti…

CVE-2026-19344 code-projects · Task Management System CWE-74 HIGH 7.3 · EPSS 0%

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It i…

CVE-2026-19351 dresende · node-sql-query CWE-74 HIGH 7.3

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Per…

CVE-2026-19355 MingSoft · MCMS CWE-74 HIGH 7.3

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead…

CVE-2026-19374 Apple · api-mcp CWE-918 HIGH 7.3

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of t…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →