Skip to content

Morning Brief

Tuesday, August 18, 2026 · generated 2026-08-18 14:46 UTC · ~5 min read

Top developments

Windows 11 File Explorer Gets Faster, Customizable Right-Click Menu With App Extension Controls

Microsoft has introduced a redesigned File Explorer context menu for Windows 11 Insiders , promising faster right-click performance, less clutter, and new controls over built-in commands and third-party app extensions…

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the…

Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks

A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files , potentially enabling them to take full control of vulnerable websites. The issue…

Video Call Exploit Chains Two Flaws in Unisoc Modems

Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.

Crook hawks millions of records allegedly plundered from corporate Azure tenants

A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans…

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing…

Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects

GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user data remotely. The issue, tracked as…

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a…

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian…

CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks

CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593 , to its Known Exploited Vulnerabilities catalog after confirming exploitation in the wild. The flaw can allow remote code execution on…

Vulnerability watch

CVE-2026-66792 Red Hat · Multicluster Global Hub CWE-863 CRITICAL 9.9 · EPSS 0%

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation g…

CVE-2026-47686 patriksimek · vm2 CWE-693 CRITICAL 9.9 · EPSS 0%

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sand…

CVE-2026-65974 HashiCorp · erpnext CWE-1336 CRITICAL 9.9 · EPSS 0%

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forci…

CVE-2026-75843 ArcadeData · arcadedb CWE-269 CRITICAL 9.9

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers ca…

CVE-2026-75851 ArcadeData · arcadedb CWE-269 CRITICAL 9.9

ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on …

CVE-2026-32444 Cwicly · Cwicly CWE-94 CRITICAL 9.9

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

CVE-2026-32463 Kamlesh Parmar · Sync Post With Other Site CWE-434 CRITICAL 9.9

Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

CVE-2026-50768 Unknown CWE-434 CRITICAL 9.8 · EPSS 0%

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

CVE-2026-47698 patriksimek · vm2 CWE-913 CRITICAL 9.8 · EPSS 0%

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing san…

CVE-2026-75110 MemTensor · MemOS CWE-697 CRITICAL 9.8 · EPSS 0%

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request()…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →