{"date_iso":"2026-08-17","date_human":"Monday, August 17, 2026","generated_utc":"2026-08-17 13:00 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"ShieldBreak bypasses Microsoft\u2019s patch for earlier Defender flaw","link":"https://www.malwarebytes.com/blog/bugs/2026/08/shieldbreak-bypasses-microsofts-patch-for-earlier-defender-flaw","reason":"Microsoft","category":"Threat Intel","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Malwarebytes Labs","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-69414"],"summary":"Microsoft Defender\u2019s latest patch bypass shows a familiar problem. A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn\u2019t always close every route to the same result\u2026","source":"Malwarebytes Labs","date_rel":"","thumbnail":"","description":"","related":[{"title":"Microsoft Edge security advisory (AV26-822)","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-edge-security-advisory-av26-822","source":"CCCS Alerts & Advisories","date_rel":""},{"title":"Windows Server 2022 reaches end of mainstream support in 60 days","link":"https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/","source":"Bleeping Computer","date_rel":""},{"title":"Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely","link":"https://cybersecuritynews.com/microsoft-sccm-vulnerability/","source":"Cyber Security News","date_rel":""},{"title":"Microsoft working on Defender patch for ShieldBreak zero-day","link":"https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/","source":"Bleeping Computer","date_rel":""},{"title":"Code fixers have fired up the AI warp drive. Strange new worlds await","link":"https://www.theregister.com/columnists/2026/08/17/code-fixers-have-fired-up-the-ai-warp-drive-strange-new-worlds-await/5287681","source":"The Register Security","date_rel":""},{"title":"Microsoft blames AI for delayed Exchange update, can\u2019t say when it will arrive","link":"https://www.theregister.com/software/2026/08/17/microsoft-blames-ai-for-delayed-exchange-update-cant-say-when-it-will-arrive/5288227","source":"The Register Security","date_rel":""}]},{"title":"Hacker claims 3.6 million Azure account records stolen from major companies","link":"https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/","reason":"Azure","category":"News","sources":["Bleeping Computer","SecurityWeek","Tenable Blog","The Register Security"],"coverage":4,"cve_ids":[],"summary":"A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.","source":"Bleeping Computer","date_rel":"","thumbnail":"","description":"","related":[{"title":"Detecting cloud ransomware in Azure with Tenable One\u2019s cloud detection and response capabilities","link":"https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response","source":"Tenable Blog","date_rel":""},{"title":"Crook hawks millions of records allegedly plundered from corporate Azure tenants","link":"https://www.theregister.com/security/2026/08/17/crook-hawks-millions-of-records-allegedly-plundered-from-corporate-azure-tenants/5288305","source":"The Register Security","date_rel":""},{"title":"Fortune 500 Companies Hit in Azure Data Theft Campaign","link":"https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/","source":"SecurityWeek","date_rel":""}]},{"title":"Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection","link":"https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html","reason":"Github","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a\u2026","source":"The Hacker News","date_rel":"","thumbnail":"","description":"","related":[{"title":"GitHub Outage Disrupts Developers Worldwide Amid Ongoing Investigation","link":"https://cybersecuritynews.com/github-outage-worldwide/","source":"Cyber Security News","date_rel":""},{"title":"Microsoft confirms GitHub is down worldwide","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/","source":"Bleeping Computer","date_rel":""},{"title":"Wiz Red Agent Finds Its Way Into Snowflake\u2019s Internal Jira Through a Flaw in a GitHub Copilot\u2013Assisted PR","link":"https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug","source":"Wiz Research","date_rel":""}]},{"title":"Apple Patches iOS and macOS, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33254","reason":"Apple","category":"Research","sources":["CCCS Alerts & Advisories","Malwarebytes Labs","SANS Internet Storm Center"],"coverage":3,"cve_ids":[],"summary":"Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing\u2026","source":"SANS Internet Storm Center","date_rel":"","thumbnail":"","description":"","related":[{"title":"Apple security advisory (AV26-823)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823","source":"CCCS Alerts & Advisories","date_rel":""},{"title":"Apple Screen Sharing Security, (Mon, Aug 17th)","link":"https://isc.sans.edu/diary/rss/33252","source":"SANS Internet Storm Center","date_rel":""},{"title":"Update your Mac: Screen Sharing vulnerability exploited in the wild","link":"https://www.malwarebytes.com/blog/bugs/2026/08/update-your-mac-screen-sharing-vulnerability-exploited-in-the-wild","source":"Malwarebytes Labs","date_rel":""}]},{"title":"Video Call Exploit Chains Two Flaws in Unisoc Modems","link":"https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems","reason":"Android","category":"News","sources":["Dark Reading","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.","source":"Dark Reading","date_rel":"","thumbnail":"","description":"","related":[{"title":"Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access","link":"https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html","source":"The Hacker News","date_rel":""},{"title":"A week in security (August 10 \u2013 August 16)","link":"https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-10-august-16","source":"Malwarebytes Labs","date_rel":""}]},{"title":"\u26a1 Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More","link":"https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-40400","CVE-2026-56188"],"summary":"The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading\u2026","source":"The Hacker News","date_rel":"","thumbnail":"","description":"","related":[{"title":"CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400","source":"Microsoft Security","date_rel":""},{"title":"CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188","source":"Microsoft Security","date_rel":""},{"title":"HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic","link":"https://cybersecuritynews.com/honeymyte-coolclient-backdoor/","source":"Cyber Security News","date_rel":""}]},{"title":"Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure","link":"https://www.securityweek.com/critical-sap-commerce-cloud-vulnerability-exploited-3-days-after-disclosure/","reason":"Sap","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-58231"],"summary":"The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.","source":"SecurityWeek","date_rel":"","thumbnail":"","description":"","related":[{"title":"SAP security advisory \u2013 August 2026 monthly rollup (AV26-798) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-august-2026-monthly-rollup-av26-798","source":"CCCS Alerts & Advisories","date_rel":""}]},{"title":"Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads","link":"https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html","reason":"Wordpress","category":"News","sources":["Infosecurity Magazine","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The\u2026","source":"The Hacker News","date_rel":"","thumbnail":"","description":"","related":[{"title":"WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover","link":"https://www.infosecurity-magazine.com/news/wordpress-plugin-flaw-40000-sites/","source":"Infosecurity Magazine","date_rel":""}]},{"title":"Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies","link":"https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html","reason":"Linux","category":"News","sources":["Dark Reading","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices\u2026","source":"The Hacker News","date_rel":"","thumbnail":"","description":"","related":[{"title":"Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS","link":"https://www.darkreading.com/cyber-risk/linux-botnet-evooo1bot-mirai-capabilities-beyond-ddos","source":"Dark Reading","date_rel":""}]},{"title":"French tax authority data breach affects 678,000 individuals","link":"https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/","reason":"Authority Breach French","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.","source":"Bleeping Computer","date_rel":"","thumbnail":"","description":"","related":[{"title":"680,000 Impacted by French Tax Authority Data Breach","link":"https://www.securityweek.com/680000-impacted-by-french-tax-authority-data-breach/","source":"SecurityWeek","date_rel":""}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-19977","vendor":"EFM","product":"ipTIME A3004T","severity":"CRITICAL","score":10.0,"description":"A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19977"},{"id":"CVE-2026-19959","vendor":"Edimax","product":"EW-7478APC","severity":"CRITICAL","score":9.9,"description":"A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitati\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19959"},{"id":"CVE-2026-19961","vendor":"Edimax","product":"EW-7478APC","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to \u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19961"},{"id":"CVE-2024-13784","vendor":"WordPress","product":"Contact Form, Survey, Quiz & Popup Form Builder \u2013 ARForms","severity":"CRITICAL","score":9.8,"description":"The Contact Form, Survey, Quiz & Popup Form Builder \u2013 ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0052,"url":"https://cve.blackmesa.ca/?q=CVE-2024-13784"},{"id":"CVE-2026-73056","vendor":"siyuan-note","product":"siyuan","severity":"CRITICAL","score":9.8,"description":"SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/B\u2026","cwe":"CWE-307","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73056"},{"id":"CVE-2026-73061","vendor":"scriban","product":"scriban","severity":"CRITICAL","score":9.8,"description":"Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, \u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73061"},{"id":"CVE-2026-74790","vendor":"scriban","product":"scriban","severity":"CRITICAL","score":9.1,"description":"Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by\u2026","cwe":"CWE-693","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-74790"},{"id":"CVE-2026-74791","vendor":"scriban","product":"scriban","severity":"HIGH","score":8.6,"description":"Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations \u2026","cwe":"CWE-226","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-74791"},{"id":"CVE-2026-19979","vendor":"GL.iNet","product":"A1300","severity":"HIGH","score":8.3,"description":"A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function \u2026","cwe":"CWE-285","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19979"},{"id":"CVE-2026-19983","vendor":"GL.iNet","product":"A1300","severity":"HIGH","score":8.3,"description":"A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulatio\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19983"}],"vendor_spikes":[{"vendor":"scriban","count":15,"critical_count":2},{"vendor":"WordPress","count":12,"critical_count":1},{"vendor":"Unknown","count":6,"critical_count":0},{"vendor":"Edimax","count":5,"critical_count":2},{"vendor":"GL.iNet","count":5,"critical_count":0},{"vendor":"Open Asset Import Library","count":4,"critical_count":0},{"vendor":"opentofu","count":3,"critical_count":0},{"vendor":"stoatchat","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":10,"new_cve_count":77,"has_news_data":true,"has_cve_data":true,"reconstructed":true,"reconstruction_note":"Rebuilt 2026-08-18 after a GitHub incident left the original run empty. News clustered from the 94 articles timestamped 2026-08-17 still present in the live news build, using news/generate.py compute_trending(). CVE data from cve/docs/last_updated.json as committed at d1d504d (2026-08-17 06:53 UTC). EPSS risers are absent: that needs the previous day's state.json snapshot, which did not survive."}