{"date_iso":"2026-08-11","date_human":"Tuesday, August 11, 2026","generated_utc":"2026-08-11 14:22 UTC","read_minutes":5,"patch_tuesday":true,"top_stories":[{"title":"Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition","link":"https://cybersecuritynews.com/multiple-clamav-vulnerabilities-dos/","reason":"Cisco","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions. The flaws affect\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Multiple-ClamAV-Vulnerabilities-Alow-remote-attacker-to-Trigger-DoS-condition-.webp","description":"Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions. The flaws affect the ClamAV parsers used by Cisco Secure Endpoint Connector on Windows, Linux, and macOS. The advisory, tracked as cisco-sa-clamav-WuuvVd26, was first published on August 7, 2026, and updated on August 10. Cisco assigned a High security impact rating to affected Windows systems, while Linux and macOS environments received a Medium rating. The company said the difference is due to\u2026","related":[{"title":"Cisco warns of high-severity ClamAV flaws with public exploits","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaws-with-public-exploits/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Cisco security advisory (AV26-794)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-794","source":"CCCS Alerts & Advisories","date_rel":"20h ago"},{"title":"Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC","link":"https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/","source":"SecurityWeek","date_rel":"22h ago"}]},{"title":"BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins","link":"https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh96gU64z_xM5LiLI39IXPndJ1felnUkfQmWxQ2sGfE9r_yYK6AKPLV3x6uVWeZxZoEsJwy0h7OUHILX1sAbwc6MYHpIeeTvCVeH52TnCInqqjjRPW4-Sx7gPPq4abN7ltCnClrjRhDDqyON8UBxcKFjoyubm7CeEgaZos3j4OCLJdRozfEOrDX1rPsnSoF/s1600/wordpress.jpg","description":"Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. \"Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository,\" Wordfence researcher Paolo Tresso said.","related":[{"title":"BdThemes plugins supply-chain hack creates rogue WordPress admins","link":"https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/","source":"Bleeping Computer","date_rel":"15h ago"},{"title":"WordPress Plugins Compromised Without a Single File Change","link":"https://www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/","source":"Infosecurity Magazine","date_rel":"22h ago"},{"title":"WordPress security advisory (AV26-792)","link":"https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-792","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw","link":"https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from\u2026","source":"The Hacker News","date_rel":"20h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNv5C82jT_6YlarerdXnoAR_tT3E8xP65ZWuJfpvOKU9baBT5UACUTb88XvDQgQA6RrYuqPK3FstaqwacR9gDjD0qwk3HUYl0wK848phyphenhyphenFuqRrOA1AqdISQaA6tpEqg0n2XJIA22NeNNbhei1bAgcyghnc2qaVfSvh4fd9J1oD4xVi-DQcNSOYWQovyUst/s1600/strom-ransomware.jpg","description":"Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. \"StormEncryptor is written in C++ and appends the file name extension .encrypted","related":[{"title":"CISA: Microsoft SharePoint flaw now exploited in ransomware attacks","link":"https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/","source":"Bleeping Computer","date_rel":"30m ago"},{"title":"Edge is dropping older extensions, affecting popular privacy tools","link":"https://www.malwarebytes.com/blog/news/2026/08/edge-is-dropping-older-extensions-affecting-popular-privacy-tools","source":"Malwarebytes Labs","date_rel":"23h ago"},{"title":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials","link":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html","source":"The Hacker News","date_rel":"10 Aug"}]},{"title":"Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo","link":"https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html","reason":"Firefox","category":"News","sources":["SecurityWeek","The Hacker News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is\u2026","source":"The Hacker News","date_rel":"37m ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV1-B4O1t_ddtTQg7WCfQLhdWxNygkI3C3DHfugd_0ogZbFCixAf-J9IffSq3KuSSPDofAEj5wNrVHlzRx3qbj7cPQhbBfnvOXOAJxjTSJ_7rdtZe3ne_R4Yz7Gv_7VrNH8CyB8psfzpejy9EbohuyYW3G1pg4FChDRVv8WPxp8B449rGIXnS4WSoD5JI/s1600/firefox.jpg","description":"Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with. That decision carries a cost for","related":[{"title":"Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub","link":"https://www.theregister.com/security/2026/08/11/mozilla-revokes-firefox-signing-key-after-unencrypted-copy-lands-in-github/5285908","source":"The Register Security","date_rel":"1h ago"},{"title":"Mozilla Issues New Firefox GPG Key Following Exposure","link":"https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/","source":"SecurityWeek","date_rel":"6h ago"}]},{"title":"Shipping 10\u201350\u00d7 More Code? Watch This Webinar on Securing AI-Speed Development","link":"https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html","reason":"Teams","category":"News","sources":["CyberScoop","Microsoft Security Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output\u2026","source":"The Hacker News","date_rel":"19h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy3fcUJacnxspYO1ssk2-ESCQ9QYb5BBCB0-3Jk8UyWQFmKZxt8RCeYemwUlJ08y_hnkyVm4LaAq6a_oyz5BPmpuwkmephJ0K7iy6cFvPjAe-b3pQ4Q28jh3KzNqLhZ6qtecuG9jenDpeVsjpUrG9ZBEwe2WStxgh6RiOwhI_rlsxYelFv2BD31o9rhd8/s1600/chain-webinar.jpg","description":"AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.","related":[{"title":"Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise","link":"https://www.microsoft.com/en-us/security/blog/2026/08/10/microsoft-named-a-leader-in-the-2026-idc-marketscape-for-mdr-mxdr-for-the-enterprise/","source":"Microsoft Security Blog","date_rel":"20h ago"},{"title":"Why transparent AI agents matter more than you think","link":"https://cyberscoop.com/transparent-ai-agent-security-op-ed/","source":"CyberScoop","date_rel":"22h ago"}]},{"title":"Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection","link":"https://securelist.com/project-cav3rn-continues/120991/","reason":"Google","category":"Threat Intel","sources":["Kaspersky Securelist","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence\u2026","source":"Kaspersky Securelist","date_rel":"2h ago","thumbnail":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/08/11062112/project-CAV3RN-continues_2-scaled.jpg","description":"Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service , and the second was published on Securelist the following month, further documenting the framework\u2019s evolving architecture and C2 capabilities. Continued tracking of this cluster in early August 2026 uncovered several previously undocumented components that expanded the framework\u2019s communication and orchestration capabilities. The main finding is a complex C2 module\u2026","related":[{"title":"Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities","link":"https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/","source":"SecurityWeek","date_rel":"1h ago"}]},{"title":"Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default","link":"https://www.theregister.com/ai-and-ml/2026/08/08/devs-to-anthropic-openai-cursor-and-friends-make-security-and-privacy-the-default/5285107","reason":"Github","category":"News","sources":["Microsoft Security","The Register Security"],"coverage":2,"cve_ids":["CVE-2026-64652","CVE-2026-64653"],"summary":"Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary\u2026","source":"The Register Security","date_rel":"8 Aug","thumbnail":"https://image.theregister.com/?imageId=5281583&width=800","description":"Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary in Canada decided to sift through developers' concerns about LLM-based integrated development environments (LIDEs) by analyzing Reddit discussions for common themes. Their findings suggest that the builders of such tools failed to prioritize security and privacy, leaving developers to defend themselves. Gias Uddin, associate professor at York University and a co-author of the\u2026","related":[{"title":"CVE-2026-64652 GitHub CLI: Partial token disclosure in `gh auth status` output","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64652","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-64653 GitHub CLI: Unescaped variable components in request URLs could allow path traversal","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64653","source":"Microsoft Security","date_rel":"4h ago"}]},{"title":"Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11","link":"https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html","reason":"Windows","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIoEoCsvghUx_eKGXl-WAFq7pyoOLwg_Sk9a5Ne8vX1Cb7l_DOib3wtO_5NwoogbHqFvU_VWJZd3ceL5ftpWOX5qNx5HNJCmD4_RR7GaiExk0ph2F3sp5eKPthiuTcmnDlJQyvUdkTMfxBUsIlXp_I9-qkSi4zxwVnLPb9bG-T3zFC7oFCI1Mps4VJf1s/s1600/pnp.gif","description":"Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that","related":[{"title":"Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware","link":"https://cybersecuritynews.com/hacking-group-attacking-fake-deepseek/","source":"Cyber Security News","date_rel":"2h ago"},{"title":"Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access","link":"https://cybersecuritynews.com/abyssos-rat-rdpwrap/","source":"Cyber Security News","date_rel":"5h ago"}]},{"title":"FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure","link":"https://therecord.media/ransomware-south-korea-fbi-gunra","reason":"Ransomware Targeting South","category":"News","sources":["Bleeping Computer","The Record"],"coverage":2,"cve_ids":[],"summary":"The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea\u2019s government warned.","source":"The Record","date_rel":"17h ago","thumbnail":"http://cms.therecord.media/uploads/Lock_55f8399c01.jpg","description":"","related":[{"title":"US and South Korea warn of Gunra ransomware targeting govt agencies","link":"https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/","source":"Bleeping Computer","date_rel":"2h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-72898","vendor":"Metabase","product":"Metabase","severity":"CRITICAL","score":10.0,"description":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72898"},{"id":"CVE-2026-72899","vendor":"Metabase","product":"Metabase","severity":"CRITICAL","score":10.0,"description":"Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72899"},{"id":"CVE-2026-72733","vendor":"Dokploy","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription builds database restore shell pipelines from the user-controlled databaseName and backupFile fields without \u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72733"},{"id":"CVE-2026-72735","vendor":"Dokploy","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interpola\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72735"},{"id":"CVE-2026-72736","vendor":"Dokploy","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Sw\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72736"},{"id":"CVE-2026-72738","vendor":"Dokploy","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter through normalizeS3Path and interpolates it i\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72738"},{"id":"CVE-2026-72740","vendor":"Dokploy","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interpolates its domain into the ssh-keyscan co\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72740"},{"id":"CVE-2026-72862","vendor":"Oracle","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions pass user-controlled dockerImage fields \u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72862"},{"id":"CVE-2026-72863","vendor":"HashiCorp","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateR\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72863"},{"id":"CVE-2026-72864","vendor":"Dokploy","product":"dokploy","severity":"CRITICAL","score":9.9,"description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authoriz\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72864"}],"vendor_spikes":[{"vendor":"Linux","count":316,"critical_count":0},{"vendor":"WordPress","count":51,"critical_count":1},{"vendor":"Unknown","count":49,"critical_count":0},{"vendor":"Red Hat","count":33,"critical_count":2},{"vendor":"SAP","count":33,"critical_count":2},{"vendor":"Dokploy","count":28,"critical_count":16},{"vendor":"Samsung Mobile","count":24,"critical_count":0},{"vendor":"Apache","count":15,"critical_count":0},{"vendor":"Microsoft","count":12,"critical_count":0},{"vendor":"HashiCorp","count":12,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":9,"new_cve_count":769,"has_news_data":true,"has_cve_data":true}