Skip to content

Morning Brief

Saturday, August 15, 2026 · generated 2026-08-15 13:36 UTC · ~6 min read

Top developments

VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI

Selidan, USA, August 14th, 2026, CyberNewswire New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influencing how the vehicle history platform appears across Google…

Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication

Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. The company will also retire Microsoft-provided SMS and voice…

Vulnerability giving attackers full control of Macs is under active exploitation

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. “The NCSC has received a notification indicating that active abuse of…

Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals

Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it. Their operators promise customers a way around…

ZDI-26-576: Linux Kernel XFRM Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to…

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that…

AWS key exposed in JavaScript may have lit way to Beacon's charity data

Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach. The revelation came in the company's…

Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released

A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE). The…

Apple now uses iPhone alerts for targets of mercenary spyware

Apple has expanded its threat-notification system for targets of mercenary spyware . Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by…

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.

Vulnerability watch

CVE-2026-72811 siyuan-note · siyuan CWE-89 CRITICAL 10.0

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into…

CVE-2026-19188 Haiwell · Haiwell IoT Cloud HMI Gateway CWE-78 CRITICAL 10.0

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to …

CVE-2026-73678 MindsDB · Minds Platform CWE-94 CRITICAL 10.0

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /…

CVE-2026-19626 Tenable, Inc. · Security Center CWE-95 CRITICAL 9.9

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsaf…

CVE-2026-19681 Tenable, Inc. · Security Center CWE-78 CRITICAL 9.9

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution o…

CVE-2026-19682 Tenable, Inc. · Security Center CWE-78 CRITICAL 9.9

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.

CVE-2026-17186 IBM · Db2 Mirror for i CWE-78 CRITICAL 9.9

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

CVE-2026-72822 getgrav · grav CWE-306 CRITICAL 9.8

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely …

CVE-2026-72824 HashiCorp · grav CWE-862 CRITICAL 9.8

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-…

CVE-2026-72826 getgrav · grav CWE-266 CRITICAL 9.8

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline …

Full CVE Feed →

Worth reading

ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →