Skip to content

Morning Brief

Friday, August 21, 2026 · generated 2026-08-21 13:51 UTC · ~4 min read

Top developments

Grok exfiltrates user data when malicious instructions are encrypted

Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user’s inbox. Now, a separate…

Apple’s Private Find My People Reversed to Decrypt Live Shared Locations on Linux

A security researcher has successfully reverse-engineered Apple’s private Find My People protocol, demonstrating that a Linux machine can register with Apple’s internal services, receive an existing location-sharing…

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting…

The invisible passenger in your car

While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate…

Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

Cybercriminals are abusing interest in generative AI to trick users into downloading malware. In a newly documented incident, a file posing as a Google Gemini installer delivered the Vidar information stealer, putting…

41 deceptive download sites show a real link, then send you somewhere else

We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike…

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect…

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing…

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as…

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS…

Vulnerability watch

CVE-2026-65770 Microsoft · Azure Managed Instance for Apache Cassandra CWE-88 CRITICAL 10.0

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

CVE-2026-65801 Microsoft · Microsoft Exchange Online CWE-918 CRITICAL 10.0

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-65816 Microsoft · Azure Web Apps CWE-706 CRITICAL 10.0

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69555 Microsoft · Azure ARC CWE-863 CRITICAL 10.0

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69836 Microsoft · Microsoft Entra CWE-502 CRITICAL 10.0

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

CVE-2026-73992 Jonathan Daggerhart · Query Wrangler CWE-94 CRITICAL 9.9

Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.

CVE-2026-74014 indithemes · IT Residence CWE-434 CRITICAL 9.9

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

CVE-2026-74016 themagnifico52 · Smart Cleaning CWE-434 CRITICAL 9.9

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

CVE-2026-74018 themagnifico52 · Warehouse Cargo CWE-434 CRITICAL 9.9

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

CVE-2026-77022 Comfast · CF-N1-S CWE-119 CRITICAL 9.9

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the ar…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →