Skip to content

Morning Brief

Sunday, August 16, 2026 · generated 2026-08-16 13:36 UTC · ~6 min read

Top developments

Vulnerability giving attackers full control of Macs is under active exploitation

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. “The NCSC has received a notification indicating that active abuse of…

Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication

Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. The company will also retire Microsoft-provided SMS and voice…

VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI

Selidan, USA, August 14th, 2026, CyberNewswire New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influencing how the vehicle history platform appears across Google…

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.

Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC

Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security fixes were released. Defused honeypot telemetry captured the…

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It…

Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released

A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE). The…

Apple now uses iPhone alerts for targets of mercenary spyware

Apple has expanded its threat-notification system for targets of mercenary spyware . Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by…

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.

Over 1,000 Charities Hit by Beacon CRM Data Breach

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Vulnerability watch

CVE-2026-15826 WordPress · User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor CWE-704 CRITICAL 9.8 · EPSS 0%

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_inse…

CVE-2026-16142 WordPress · TrueBooker – Appointment Booking and Scheduler System CWE-639 CRITICAL 9.8 · EPSS 0%

The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary…

CVE-2026-19598 WordPress · Pods – Custom Content Types and Fields CWE-863 CRITICAL 9.8

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels …

CVE-2026-73046 HashiCorp · siyuan CWE-307 CRITICAL 9.8

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAu…

CVE-2026-19924 Tenda · AC10 CWE-287 CRITICAL 9.8

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be ini…

CVE-2026-16098 WordPress · ProSolution WP Client CWE-434 CRITICAL 9.8

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Conten…

CVE-2026-18432 WordPress · Frontend Admin by DynamiApps CWE-269 CRITICAL 9.8

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_us…

CVE-2026-18855 WordPress · Link Library CWE-22 CRITICAL 9.1

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthentic…

CVE-2026-14524 WordPress · ProSolution WP Client CWE-22 CRITICAL 9.1

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible fo…

CVE-2026-18316 WordPress · Solace Extra CWE-862 CRITICAL 9.1

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_a…

Full CVE Feed →

Worth reading

How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign

A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →