{"date_iso":"2026-08-16","date_human":"Sunday, August 16, 2026","generated_utc":"2026-08-16 13:36 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Vulnerability giving attackers full control of Macs is under active exploitation","link":"https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/","reason":"Macos","category":"Media","sources":["Ars Technica Security","Bleeping Computer","Infosecurity Magazine","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. \u201cThe NCSC has received a notification indicating that active abuse of\u2026","source":"Ars Technica Security","date_rel":"14 Aug","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/08/macbook-pro-500x500.jpg","description":"Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. \u201cThe NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,\u201d the Netherlands National Cyber Security Centrum warned earlier this week. \u201cIn all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.\u201d Do you know if your screen sharing is on? The vulnerability, tracked as\u2026","related":[{"title":"Hackers exploit macOS Screen Sharing flaw to deploy Monero miner","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/","source":"Bleeping Computer","date_rel":"14 Aug"},{"title":"Novel macOS Infostealer AmnesiaStealer Spread via ClickFix","link":"https://www.infosecurity-magazine.com/news/macos-infostealer-spread-clickfix/","source":"Infosecurity Magazine","date_rel":"14 Aug"},{"title":"AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions","link":"https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/","source":"SecurityWeek","date_rel":"14 Aug"}]},{"title":"Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication","link":"https://cybersecuritynews.com/microsoft-make-passkeys-default-in-entra-id/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. The company will also retire Microsoft-provided SMS and voice\u2026","source":"Cyber Security News","date_rel":"15 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Microsoft-to-make-passkeys-Default-in-Entra-ID-and-Retires-SMS-and-voice-authentication.webp","description":"Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. The company will also retire Microsoft-provided SMS and voice authentication for multifactor authentication, pushing organizations toward phishing-resistant credentials. Beginning September 1, 2026, users currently enabled for SMS or voice authentication will be automatically enabled for passkeys. During a future MFA sign-in, these users will see prompts encouraging them to register a passkey. Microsoft will manage the passkey\u2026","related":[{"title":"Microsoft patches LegacyHive Windows zero-day vulnerability","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/","source":"Bleeping Computer","date_rel":"13 Aug"},{"title":"The backup Microsoft never promised you","link":"https://www.theregister.com/security/2026/08/13/sponsored-the-backup-microsoft-never-promised-you/5284957","source":"The Register Security","date_rel":"13 Aug"}]},{"title":"VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI","link":"https://cybersecuritynews.com/vinclarity-publishes-investigation-into-alleged-scam-and-fraud-reputation-attack-across-search-and-ai/","reason":"Google","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"Selidan, USA, August 14th, 2026, CyberNewswire New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influencing how the vehicle history platform appears across Google\u2026","source":"Cyber Security News","date_rel":"14 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAKFffzGjkxmQtKa1Boy52FYRjPUhFH6nFz1T0VF8DnB764ZWWemdYgdjiQ-uUVNMjTlVv76-N6fQ9qtf7CXd-xBZoWBXB8Nkjs087J2Oo-M63ga9FdVcWOAU2obBOHwyRM87Gtv2OTYj9e3p1BCPJNcRIivDPv1_xtLYSR1BmTVXHMJ2YhUROHDu1a64/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20proj%20-%202026-08-14T213449.22.webp","description":"Selidan, USA, August 14th, 2026, CyberNewswire New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influencing how the vehicle history platform appears across Google and AI systems VINclarity has published a new investigation into what researchers describe as a coordinated online reputation attack targeting the vehicle history platform across Reddit, YouTube, Google Search and AI-powered discovery systems. The investigation, \u201cVINclarity Becomes the Next Target: Inside the Coordinated Reputation Attack Playbook\u201d , examines a cluster of\u2026","related":[{"title":"The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI","link":"https://www.bleepingcomputer.com/news/security/the-modern-attack-chain-rethinking-google-workspace-security-in-the-age-of-ai/","source":"Bleeping Computer","date_rel":"14 Aug"},{"title":"Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal","link":"https://www.securityweek.com/google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal/","source":"SecurityWeek","date_rel":"14 Aug"},{"title":"Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone","link":"https://www.infosecurity-magazine.com/news/google-cloud-post-quantum-roadmap/","source":"Infosecurity Magazine","date_rel":"13 Aug"}]},{"title":"New Evooo1Bot Linux botnet turns routers into traffic relay nodes","link":"https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/","reason":"Linux","category":"News","sources":["Bleeping Computer","Infosecurity Magazine"],"coverage":2,"cve_ids":[],"summary":"A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.","source":"Bleeping Computer","date_rel":"22h ago","thumbnail":"","description":"","related":[{"title":"New Mirai-Based Linux Botnet \u2018Evooo1Bot\u2019 Turns Victims Into Proxies","link":"https://www.infosecurity-magazine.com/news/new-linux-botnet-evooo1bot-victims/","source":"Infosecurity Magazine","date_rel":"14 Aug"}]},{"title":"Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC","link":"https://cybersecuritynews.com/hackers-exploit-sap-commerce-cloud/","reason":"Sap","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security fixes were released. Defused honeypot telemetry captured the\u2026","source":"Cyber Security News","date_rel":"22h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Exploit-SAP-Commerce-Cloud.webp","description":"Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security fixes were released. Defused honeypot telemetry captured the first wave of unauthenticated remote-execution traffic circulating across the web, despite the complete absence of a public proof of concept. Tracked as CVE-2026-58231 , the security defect carries a critical CVSS score of 10.0, representing the highest possible severity rating for enterprise software. The vulnerability enables unauthenticated adversaries to execute arbitrary code\u2026","related":[{"title":"Max severity SAP Commerce Cloud flaw now targeted in attacks","link":"https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/","source":"Bleeping Computer","date_rel":"14 Aug"}]},{"title":"APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit","link":"https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/","reason":"Windows","category":"Threat Intel","sources":["Kaspersky Securelist","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-61347","CVE-2026-62755","CVE-2026-62777"],"summary":"Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It\u2026","source":"Kaspersky Securelist","date_rel":"14 Aug","thumbnail":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/08/12120025/honeymyte-driver-overview_1-scaled.jpg","description":"Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023 , CoolClient has continued to evolve. In 2025 , we analyzed a newer variant that introduced clipboard theft and HTTP traffic\u2026","related":[{"title":"CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347","source":"Microsoft Security","date_rel":"14 Aug"},{"title":"CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755","source":"Microsoft Security","date_rel":"14 Aug"},{"title":"CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777","source":"Microsoft Security","date_rel":"14 Aug"}]},{"title":"Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root \u2013 PoC Released","link":"https://cybersecuritynews.com/citrix-netscaler-heap-overflow/","reason":"Citrix","category":"News","sources":["Cyber Security News","watchTowr Labs"],"coverage":2,"cve_ids":["CVE-2026-8452"],"summary":"A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE). The\u2026","source":"Cyber Security News","date_rel":"14 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Citrix-NetScaler-Heap-Overflow.webp","description":"A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE). The vulnerability was originally addressed in Cloud Software Group\u2019s June 30 security bulletin CTX696604, where Citrix described CVE-2026-8452 as a memory overflow that could result in denial-of-service (DoS) or \u201cunpredictable behavior.\u201d However, independent analysis confirms that the flaw is far more severe, granting remote attackers direct control over the core packet-processing\u2026","related":[{"title":"You\u2019re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))","link":"https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/","source":"watchTowr Labs","date_rel":"14 Aug"}]},{"title":"Apple now uses iPhone alerts for targets of mercenary spyware","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware","reason":"Apple","category":"Threat Intel","sources":["Bleeping Computer","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"Apple has expanded its threat-notification system for targets of mercenary spyware . Apple now shows a warning directly on an iPhone\u2019s Lock Screen and in Settings when it believes the device owner has been targeted by\u2026","source":"Malwarebytes Labs","date_rel":"14 Aug","thumbnail":"","description":"Apple has expanded its threat-notification system for targets of mercenary spyware . Apple now shows a warning directly on an iPhone\u2019s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user\u2019s Apple Account page. In the explanation, Apple states: \u201cApple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.\u201d\u2026","related":[{"title":"Apple sends new \u2018Threat Notification\u2019 alerts over mercenary spyware attacks","link":"https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/","source":"Bleeping Computer","date_rel":"14 Aug"}]},{"title":"RingCentral data breach exposed info of 1.6 million accounts","link":"https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/","reason":"Ringcentral Million Breach","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.","source":"Bleeping Computer","date_rel":"14 Aug","thumbnail":"","description":"","related":[{"title":"1.6 Million Likely Impacted by RingCentral Data Breach","link":"https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/","source":"SecurityWeek","date_rel":"14 Aug"}]},{"title":"Over 1,000 Charities Hit by Beacon CRM Data Breach","link":"https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/","reason":"Aws","category":"News","sources":["Infosecurity Magazine","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.","source":"SecurityWeek","date_rel":"14 Aug","thumbnail":"","description":"","related":[{"title":"Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities","link":"https://www.infosecurity-magazine.com/news/exposed-aws-key-data-charities/","source":"Infosecurity Magazine","date_rel":"13 Aug"}]}],"worth_reading":[{"title":"How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign","link":"https://www.wiz.io/blog/investigating-github-pat-compromise","reason":"Github","category":"Research","sources":["Bleeping Computer","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.","source":"Wiz Research","date_rel":"13 Aug","thumbnail":"https://www.datocms-assets.com/75231/1786570602-github-pat-compromise-2.png","description":"","related":[{"title":"AI 'watermark removers' flood the web. Almost none can prove they work","link":"https://www.bleepingcomputer.com/news/security/ai-watermark-removers-flood-the-web-almost-none-can-prove-they-work/","source":"Bleeping Computer","date_rel":"13 Aug"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-15826","vendor":"WordPress","product":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor","severity":"CRITICAL","score":9.8,"description":"The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_inse\u2026","cwe":"CWE-704","kev":false,"kev_action":"","kev_due":"","epss":0.008,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15826"},{"id":"CVE-2026-16142","vendor":"WordPress","product":"TrueBooker \u2013 Appointment Booking and Scheduler System","severity":"CRITICAL","score":9.8,"description":"The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":0.0038,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16142"},{"id":"CVE-2026-19598","vendor":"WordPress","product":"Pods \u2013 Custom Content Types and Fields","severity":"CRITICAL","score":9.8,"description":"The Pods \u2013 Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels \u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19598"},{"id":"CVE-2026-73046","vendor":"HashiCorp","product":"siyuan","severity":"CRITICAL","score":9.8,"description":"SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAu\u2026","cwe":"CWE-307","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73046"},{"id":"CVE-2026-19924","vendor":"Tenda","product":"AC10","severity":"CRITICAL","score":9.8,"description":"A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be ini\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19924"},{"id":"CVE-2026-16098","vendor":"WordPress","product":"ProSolution WP Client","severity":"CRITICAL","score":9.8,"description":"The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Conten\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16098"},{"id":"CVE-2026-18432","vendor":"WordPress","product":"Frontend Admin by DynamiApps","severity":"CRITICAL","score":9.8,"description":"The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_us\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18432"},{"id":"CVE-2026-18855","vendor":"WordPress","product":"Link Library","severity":"CRITICAL","score":9.1,"description":"The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthentic\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18855"},{"id":"CVE-2026-14524","vendor":"WordPress","product":"ProSolution WP Client","severity":"CRITICAL","score":9.1,"description":"The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible fo\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14524"},{"id":"CVE-2026-18316","vendor":"WordPress","product":"Solace Extra","severity":"CRITICAL","score":9.1,"description":"The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_a\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18316"}],"vendor_spikes":[{"vendor":"Linux","count":127,"critical_count":0},{"vendor":"WordPress","count":56,"critical_count":8},{"vendor":"siyuan-note","count":10,"critical_count":7},{"vendor":"Unknown","count":8,"critical_count":0},{"vendor":"code-projects","count":7,"critical_count":0},{"vendor":"Apache","count":4,"critical_count":0},{"vendor":"Microsoft","count":4,"critical_count":0},{"vendor":"SourceCodester","count":4,"critical_count":0},{"vendor":"Apple","count":3,"critical_count":0},{"vendor":"HashiCorp","count":3,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":11,"new_cve_count":252,"has_news_data":true,"has_cve_data":true}