Skip to content

Morning Brief

Tuesday, August 11, 2026 · generated 2026-08-11 14:22 UTC · ~5 min read

Top developments

Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition

Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions. The flaws affect…

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their…

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from…

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is…

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output…

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence…

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary…

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11…

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.

Vulnerability watch

CVE-2026-72898 Metabase · Metabase CWE-89 CRITICAL 10.0

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

CVE-2026-72899 Metabase · Metabase CWE-89 CRITICAL 10.0

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

CVE-2026-72733 Dokploy · dokploy CWE-78 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines from the user-controlled databaseName and backupFile fields without …

CVE-2026-72735 Dokploy · dokploy CWE-77 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interpola…

CVE-2026-72736 Dokploy · dokploy CWE-77 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Sw…

CVE-2026-72738 Dokploy · dokploy CWE-78 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter through normalizeS3Path and interpolates it i…

CVE-2026-72740 Dokploy · dokploy CWE-78 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interpolates its domain into the ssh-keyscan co…

CVE-2026-72862 Oracle · dokploy CWE-78 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions pass user-controlled dockerImage fields …

CVE-2026-72863 HashiCorp · dokploy CWE-269 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateR…

CVE-2026-72864 Dokploy · dokploy CWE-862 CRITICAL 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authoriz…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →