{"date_iso":"2026-08-10","date_human":"Monday, August 10, 2026","generated_utc":"2026-08-10 14:22 UTC","read_minutes":4,"patch_tuesday":false,"top_stories":[{"title":"Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage","link":"https://cybersecuritynews.com/apple-private-cloud-compute-vulnerability/","reason":"Apple","category":"News","sources":["Cyber Security News","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-20685"],"summary":"CVE-2026-20685 is a path traversal vulnerability affecting Apple\u2019s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an\u2026","source":"Cyber Security News","date_rel":"46m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Apple-Private-Cloud-Compute-Flaw-Enables-Root-File-Writes-and-AI-Inference-Telemetry-Leakage.webp","description":"CVE-2026-20685 is a path traversal vulnerability affecting Apple\u2019s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server. Sentry Security researcher Drinor received a $150,000 Apple Security Bounty for discovering and reporting CVE-2026-20685, a flaw that could expose sensitive data and allow unauthorized access. PCC is Apple\u2019s server-side platform for Apple Intelligence requests that are too complex to run entirely on an iPhone, iPad, or Mac. Apple describes the system as an\u2026","related":[{"title":"A week in security (August 3 \u2013 August 9)","link":"https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-3-august-9","source":"Malwarebytes Labs","date_rel":"5h ago"},{"title":"ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets","link":"https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html","source":"The Hacker News","date_rel":"7 Aug"},{"title":"In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street","link":"https://www.securityweek.com/in-other-news-ai-slop-limits-apple-bounties-north-carolina-port-attacks-hackers-target-wall-street/","source":"SecurityWeek","date_rel":"7 Aug"}]},{"title":"Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption","link":"https://cybersecuritynews.com/ransomware-operators-disable-edr/","reason":"Windows","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and response tools, interrupt Windows telemetry, and target backup\u2026","source":"Cyber Security News","date_rel":"11m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Ransomware-Operators-Disable-EDR-Backup-Software-and-Windows-Telemetry-Before-Encryption.webp","description":"Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and response tools, interrupt Windows telemetry, and target backup services to reduce the chance that defenders spot or contain the intrusion in time. The findings focus on ten ransomware families that were least often prevented in 2026 testing data. Play had the lowest prevention score at 13 percent, followed by BlackByte at 25 percent, while LockBit, BabLock, Magniber, FAUST, Sodinokibi or REvil, Hive, BlackKingdom, and Maori also featured in\u2026","related":[{"title":"Interlock Turns the Tools Incident Responders Use Into Weapons for Stealing Windows Passwords","link":"https://cybersecuritynews.com/interlock-turns-the-tools/","source":"Cyber Security News","date_rel":"1h ago"},{"title":"Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer","link":"https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html","source":"The Hacker News","date_rel":"7 Aug"}]},{"title":"Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach","link":"https://cybersecuritynews.com/valve-steam-ceva-data-breach/","reason":"Hardware Breach Valve","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Valve has confirmed that a cyberattack on CEVA Logistics, its European shipping partner for Steam hardware such as the Steam Deck, Steam Machine, and Steam Controller, exposed customer data belonging to buyers across\u2026","source":"Cyber Security News","date_rel":"13m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Valve-Steam-CEVA-Data-Breach.webp","description":"Valve has confirmed that a cyberattack on CEVA Logistics, its European shipping partner for Steam hardware such as the Steam Deck, Steam Machine, and Steam Controller, exposed customer data belonging to buyers across Europe. The breach occurred between July 29 and August 1, 2026, and Valve says it learned of the compromise on August 7, prompting the company to notify all customers it believes were affected through a direct security email. According to Valve\u2019s disclosure, the attacker likely accessed delivery-related information that CEVA retains for up to ninety days after an order is placed\u2026","related":[{"title":"Valve notifies Steam hardware customers of a data breach","link":"https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/","source":"Bleeping Computer","date_rel":"57m ago"}]},{"title":"Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails","link":"https://cybersecuritynews.com/payroll-pirates-aitm-phishing/","reason":"Microsoft","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Payroll-Pirates-AiTM-Phishing-Hijacks-Microsoft-365-Sessions-and-Targets-Payroll-Emails.webp","description":"Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor authentication is enabled. The messages imitate an automated call notification and invite recipients to open a voicemail portal. A click passes through redirect services before reaching a fake sign-in page that relays the real Microsoft login process, as in the new AiTM attack campaign . Arctic Wolf analysts identified activity across healthcare, education, manufacturing, government, and\u2026","related":[{"title":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials","link":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html","source":"The Hacker News","date_rel":"5h ago"}]},{"title":"Levi Strauss & Co. says hackers stole corporate data in cyberattack","link":"https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/","reason":"Cyberattack Corporate Strauss","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.","source":"Bleeping Computer","date_rel":"7 Aug","thumbnail":"","description":"","related":[{"title":"Corporate Data Stolen in Levi Strauss Cyberattack","link":"https://www.securityweek.com/corporate-data-stolen-in-levi-strauss-cyberattack/","source":"SecurityWeek","date_rel":"3h ago"}]},{"title":"Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers","link":"https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html","reason":"Atlassian","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior\u2026","source":"The Hacker News","date_rel":"8 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFYjJTxVoOMkR9DDRPZ5PkeR_EWAqmBScR3TPw3mlweipGlnQKq0OdfVqR2f26QIV3kBJWQIM65f8XwMSFq3zT6Bl4fsTvkPHxJiU2LilhK9s0tcreXt2gotEpE8sKoDrLQJ3SSVY9B-RS0FsS2dC480op8OV-caeaZvNyTiIipQbeNFJGMnAcjWEVq7g/s1600/rovo.jpg","description":"Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was","related":[{"title":"Critical One-Click Vulnerability in Atlassian\u2019s Rovo AI Exposed Enterprise Data","link":"https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/","source":"SecurityWeek","date_rel":"8 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-19348","vendor":"Shenzhen Aitemi","product":"M300 Wi-Fi Repeater","severity":"CRITICAL","score":9.8,"description":"A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulati\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19348"},{"id":"CVE-2026-19346","vendor":"Tenda","product":"CH22","severity":"HIGH","score":8.8,"description":"A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated re\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19346"},{"id":"CVE-2026-19381","vendor":"Kingston","product":"FURY CTRL RGB Control Software","severity":"HIGH","score":7.8,"description":"A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper priv\u2026","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19381"},{"id":"CVE-2026-19387","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","severity":"HIGH","score":7.6,"description":"A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV fil\u2026","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19387"},{"id":"CVE-2026-19342","vendor":"code-projects","product":"Task Management System","severity":"HIGH","score":7.3,"description":"A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. \u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.004,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19342"},{"id":"CVE-2026-19343","vendor":"code-projects","product":"Task Management System","severity":"HIGH","score":7.3,"description":"A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injecti\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0026,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19343"},{"id":"CVE-2026-19344","vendor":"code-projects","product":"Task Management System","severity":"HIGH","score":7.3,"description":"A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It i\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0041,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19344"},{"id":"CVE-2026-19351","vendor":"dresende","product":"node-sql-query","severity":"HIGH","score":7.3,"description":"A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Per\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19351"},{"id":"CVE-2026-19355","vendor":"MingSoft","product":"MCMS","severity":"HIGH","score":7.3,"description":"A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19355"},{"id":"CVE-2026-19374","vendor":"Apple","product":"api-mcp","severity":"HIGH","score":7.3,"description":"A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of t\u2026","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19374"}],"vendor_spikes":[{"vendor":"WordPress","count":47,"critical_count":0},{"vendor":"code-projects","count":5,"critical_count":0},{"vendor":"Apple","count":4,"critical_count":0},{"vendor":"Unknown","count":3,"critical_count":0},{"vendor":"MingSoft","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":6,"new_cve_count":99,"has_news_data":true,"has_cve_data":true}