Skip to content

Morning Brief

Friday, August 14, 2026 · generated 2026-08-14 14:18 UTC · ~5 min read

Top developments

Download More RAM Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing

A new attack dubbed “Download More RAM” can bypass Windows Virtualization-Based Security (VBS), weaken Hypervisor-Enforced Code Integrity (HVCI), and disable Microsoft Defender. Microsoft tracked the issue as…

Passwords stored in public Google Doc then showed up in search results

PWNED Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Have a story about…

Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals

Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it. Their operators promise customers a way around…

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that…

AWS key exposed in JavaScript may have lit way to Beacon's charity data

Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach. The revelation came in the company's…

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption.

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and…

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw…

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct…

Vulnerability watch

CVE-2026-15413 WordPress · Link Factory CWE-912 CRITICAL 10.0 · EPSS 0%

The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a h…

CVE-2026-59500 Priority · Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-287 CRITICAL 10.0 · EPSS 0%

CWE-287: Improper Authentication

CVE-2026-27544 QuarkA · QA Analytics CWE-94 CRITICAL 10.0

Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.

CVE-2026-61962 Hakan Ozevin · WP BASE Booking CWE-94 CRITICAL 10.0

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

CVE-2026-72851 budibase · server CWE-89 CRITICAL 10.0

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads tha…

CVE-2026-73656 triggerdotdev · trigger.dev CWE-639 CRITICAL 9.9

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/…

CVE-2026-72841 openwrt · luci CWE-73 CRITICAL 9.9

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious pay…

CVE-2026-72842 openwrt · luci CWE-73 CRITICAL 9.9

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E`…

CVE-2026-49827 SMEWebify · WebErpMesv2 CWE-20 CRITICAL 9.8

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Cod…

CVE-2026-28008 miniOrange · OAuth Single Sign On – SSO (OAuth Client) CWE-290 CRITICAL 9.8

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.

Full CVE Feed →

Worth reading

Researchers found a way to hijack devices through Zoom screen sharing

As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them , and even carry out autonomous hacking sprees , researchers offered a sobering new example on Tuesday…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →