Skip to content

Morning Brief

Wednesday, August 19, 2026 · generated 2026-08-19 13:51 UTC · ~5 min read

Top developments

Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks.

Apple plugs image-processing hole ripe for spyware abuse

Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector. The most notable patch is for…

Hackers Use Fake Claude Install Guide to Deploy MacSync Stealer and Trojanize Crypto Wallet Apps

Mac users searching for help with Claude Code are being lured into a malware campaign that turns a routine installation task into a full device compromise. The operation uses paid Google search results and a convincing…

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging…

BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges

BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with local access to elevate privileges or bypass anti-tamper…

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents…

Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability

Oracle has released 943 new security patches in its August 2026 Critical Security Patch Update , addressing flaws across its enterprise software portfolio. The release includes several critical Oracle WebLogic Server…

Google Fixes Two Critical Chrome Flaws in WebGL and Dawn — Update Your Browser

Google has released a new Chrome Stable channel update that fixes two critical security vulnerabilities affecting graphics-related components. Users should update their browsers as soon as the release becomes available…

Crook hawks millions of records allegedly plundered from corporate Azure tenants

A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans…

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a…

Vulnerability watch

CVE-2026-75874 Mozilla · Firefox CWE-693 CRITICAL 10.0

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

CVE-2026-73343 AresIT · WP Compress CWE-94 CRITICAL 10.0

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

CVE-2026-75784 F5 · TEW-WLC100 CWE-119 CRITICAL 10.0

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in st…

CVE-2026-61241 Oracle · Oracle Internet Directory CRITICAL 10.0

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated a…

CVE-2026-70880 Oracle · Oracle Hyperion Data Relationship Management CRITICAL 10.0

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticate…

CVE-2026-70921 Oracle · Oracle Hyperion Financial Management CRITICAL 10.0

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with net…

CVE-2026-76008 Comfast · CF-N1-S CWE-119 CRITICAL 10.0

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer …

CVE-2026-75843 ArcadeData · arcadedb CWE-269 CRITICAL 9.9

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers ca…

CVE-2026-75851 ArcadeData · arcadedb CWE-269 CRITICAL 9.9

ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on …

CVE-2026-32444 Cwicly · Cwicly CWE-94 CRITICAL 9.9

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →