{"date_iso":"2026-08-21","date_human":"Friday, August 21, 2026","generated_utc":"2026-08-21 13:51 UTC","read_minutes":4,"patch_tuesday":false,"top_stories":[{"title":"Grok exfiltrates user data when malicious instructions are encrypted","link":"https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/","reason":"Microsoft","category":"Media","sources":["Ars Technica Security","Bleeping Computer","CCCS Alerts & Advisories","Check Point Research","Dark Reading","Palo Alto Unit 42","SANS Internet Storm Center","SecurityWeek","The Hacker News","The Register Security"],"coverage":10,"cve_ids":[],"summary":"Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user\u2019s inbox. Now, a separate\u2026","source":"Ars Technica Security","date_rel":"23h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/06/xai-grok-500x500.jpg","description":"Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user\u2019s inbox. Now, a separate team has devised a similar attack against Grok. The new data theft hack employs a deceptively simple trick to force the Elon Musk-owned large language model to steal user chats and other personal information. At the time this post went live, the assistant continued to cough up the data, despite xAI being informed of it in June. The lesson from both this week\u2019s episodes\u2014and the\u2026","related":[{"title":"Microsoft warns of max severity Entra ID flaw exploited in attacks","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Microsoft Rolls Out 22 Fresh Security Patches","link":"https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/","source":"SecurityWeek","date_rel":"4h ago"},{"title":"Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)","link":"https://isc.sans.edu/diary/rss/33266","source":"SANS Internet Storm Center","date_rel":"23h ago"},{"title":"BTR Reforged: Weaponizing Defender\u2019s Remediation Driver as a Kernel Operation Primitive","link":"https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/","source":"Check Point Research","date_rel":"23h ago"},{"title":"Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)","link":"https://isc.sans.edu/diary/rss/33264","source":"SANS Internet Storm Center","date_rel":"23h ago"},{"title":"Microsoft says August Windows updates may cause gaming issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-august-windows-updates-may-cause-gaming-issues-reboots/","source":"Bleeping Computer","date_rel":"20 Aug"}]},{"title":"Apple\u2019s Private Find My People Reversed to Decrypt Live Shared Locations on Linux","link":"https://cybersecuritynews.com/apple-find-my-people-reversed/","reason":"Apple","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Hak5","Malwarebytes Labs","The Register Security","Wired Security"],"coverage":6,"cve_ids":[],"summary":"A security researcher has successfully reverse-engineered Apple\u2019s private Find My People protocol, demonstrating that a Linux machine can register with Apple\u2019s internal services, receive an existing location-sharing\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Apple-Find-My-People-Reversed.webp","description":"A security researcher has successfully reverse-engineered Apple\u2019s private Find My People protocol, demonstrating that a Linux machine can register with Apple\u2019s internal services, receive an existing location-sharing key, and decrypt a friend\u2019s live location without ever touching a Mac or iPhone. The project began innocently: the researcher wanted to build Discord geofence alerts using location data a friend was already sharing via Apple\u2019s Find My app. What looked like a simple authenticated API call turned into roughly a week of reverse-engineering Apple\u2019s private device-identity and\u2026","related":[{"title":"Apple Detected Something on These iPhones | Threat Wire","link":"https://www.youtube.com/watch?v=KRvXdSuvMgg","source":"Hak5","date_rel":"20h ago"},{"title":"Researcher tricks Apple\u2019s Find My into sharing location data with Linux","link":"https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496","source":"The Register Security","date_rel":"20h ago"},{"title":"Apple security advisory (AV26-823) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823","source":"CCCS Alerts & Advisories","date_rel":"18 Aug"},{"title":"Apple plugs image-processing hole ripe for spyware abuse","link":"https://www.theregister.com/security/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse/5289031","source":"The Register Security","date_rel":"18 Aug"},{"title":"Apple fixes another image-processing flaw that could allow code execution","link":"https://www.malwarebytes.com/blog/bugs/2026/08/apple-fixes-another-image-processing-flaw-that-could-allow-code-execution","source":"Malwarebytes Labs","date_rel":"18 Aug"},{"title":"Meta Ran Ads for an App That Promised to Nudify Female Politicians","link":"https://www.wired.com/story/meta-ran-ads-for-an-app-promising-to-nudify-female-politicians/","source":"Wired Security","date_rel":"18 Aug"}]},{"title":"AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure","link":"https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html","reason":"Siemens","category":"News","sources":["CISA Alerts & Advisories","CyberScoop","Infosecurity Magazine","Tenable Blog","The Hacker News","The Record","The Register Security"],"coverage":7,"cve_ids":[],"summary":"The U.S. government on Wednesday warned of an \"active threat\" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting\u2026","source":"The Hacker News","date_rel":"19h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSn562AFIpj2ldmT5inFv5tGgfNbaM4F1OBNvCW-80nP-YmFewnJd9VMlbgYnhgWrUpHS81bS6uEXRgEmg37c14OqmkO29XqY3FcBCl637vmAxfqB3UDtL3Rvgio6cPAQQv3bYtLUIyRdog4bpgD8MqJJYhTLish4L2Ljt6aJ_WpjFmTXYhmrA-TguqH98/s1600/plc.jpg","description":"The U.S. government on Wednesday warned of an \"active threat\" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That","related":[{"title":"Frequently asked questions about the active threat to Siemens S7 Series PLCs","link":"https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs","source":"Tenable Blog","date_rel":"22h ago"},{"title":"ICS Operators Warned of AI-Driven Attacks on Siemens PLCs","link":"https://www.infosecurity-magazine.com/news/ics-ai-attacks-siemens/","source":"Infosecurity Magazine","date_rel":"20 Aug"},{"title":"'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers","link":"https://www.theregister.com/security/2026/08/19/not-a-theoretical-risk-feds-warn-as-attackers-use-ai-made-code-to-hack-critical-infrastructure-controllers/5289960","source":"The Register Security","date_rel":"19 Aug"},{"title":"AI-fueled attacks pose \u2018active threat\u2019 to water, other sectors, U.S. agencies warn","link":"https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/","source":"CyberScoop","date_rel":"19 Aug"},{"title":"NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology","link":"https://therecord.media/nsa-fbi-warns-of-hackers-using-ai-generated-tools-critical-infrastructure","source":"The Record","date_rel":"19 Aug"},{"title":"Defending Against an Active Threat to Siemens S7 Series PLCs","link":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a","source":"CISA Alerts & Advisories","date_rel":"19 Aug"}]},{"title":"The invisible passenger in your car","link":"https://securelist.com/android-head-unit-malware/121106/","reason":"Android","category":"Threat Intel","sources":["Bleeping Computer","Infosecurity Magazine","Kaspersky Securelist","Malwarebytes Labs","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate\u2026","source":"Kaspersky Securelist","date_rel":"4h ago","thumbnail":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/08/21071446/android-head-unit-malware-scaled.jpg","description":"While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users\u2019 devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain. Key findings: We identified new Android malware: a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet\u2026","related":[{"title":"Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","link":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","source":"The Hacker News","date_rel":"20 Aug"},{"title":"ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud","link":"https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html","source":"The Hacker News","date_rel":"20 Aug"},{"title":"New Manic Android malware can exfiltrate data through nearby devices","link":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","source":"Bleeping Computer","date_rel":"20 Aug"},{"title":"Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps","link":"https://www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/","source":"Infosecurity Magazine","date_rel":"20 Aug"},{"title":"Sideloading on Android: What it is, why it\u2019s risky, and how to do it more safely","link":"https://www.malwarebytes.com/blog/how-to/2026/08/sideloading-on-android-what-it-is-why-its-risky-and-how-to-do-it-more-safely","source":"Malwarebytes Labs","date_rel":"19 Aug"}]},{"title":"Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials","link":"https://cybersecuritynews.com/fake-google-gemini-installer/","reason":"Google","category":"News","sources":["Cyber Security News","Graham Cluley","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Cybercriminals are abusing interest in generative AI to trick users into downloading malware. In a newly documented incident, a file posing as a Google Gemini installer delivered the Vidar information stealer, putting\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Use-Fake-Google-Gemini-Installer-to-Deploy-Vidar-Stealer-and-Steal-Browser-Credentials.webp","description":"Cybercriminals are abusing interest in generative AI to trick users into downloading malware. In a newly documented incident, a file posing as a Google Gemini installer delivered the Vidar information stealer, putting saved browser passwords and other sensitive data at risk. The attack did not begin with a phishing email. Instead, it relied on a normal-looking software search and download path, showing how criminals can turn routine searches for AI tools into a route for credential theft. The tactic mirrors recent campaigns that used fake AI installers and search manipulation to distribute\u2026","related":[{"title":"Russian snoops add OAuth abuse to targeted phishing campaigns","link":"https://www.theregister.com/security/2026/08/21/russian-snoops-add-oauth-abuse-to-targeted-phishing-campaigns/5290706","source":"The Register Security","date_rel":"12h ago"},{"title":"Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts","link":"https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html","source":"The Hacker News","date_rel":"16h ago"},{"title":"Smashing Security podcast #481: Never say this to a robot dog","link":"https://grahamcluley.com/smashing-security-podcast-481/","source":"Graham Cluley","date_rel":"19 Aug"}]},{"title":"41 deceptive download sites show a real link, then send you somewhere else","link":"https://www.malwarebytes.com/blog/threat-intel/2026/08/41-deceptive-download-sites-show-a-real-link-then-send-you-somewhere-else","reason":"Windows","category":"Threat Intel","sources":["Bleeping Computer","Malwarebytes Labs","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-62703","CVE-2026-62747","CVE-2026-62754"],"summary":"We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike\u2026","source":"Malwarebytes Labs","date_rel":"19 Aug","thumbnail":"","description":"We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see isn\u2019t the link you follow. One site promises Counter-Strike. Hover over its download button and the\u2026","related":[{"title":"Hackers abuse FTP server banners to deliver new Windows malware","link":"https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62703","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62754","source":"Microsoft Security","date_rel":"22h ago"}]},{"title":"Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0","link":"https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEis5Ujhq79PHPVr7VjuOjS0fOAyYm0aDTCJi9c5ieu-uya3FUM4Dh58yAT5U5J3VaXaGfNb4XowkyJ1lj3UTy8bOoF-u0O-5qdl-O7leomQjQw5jAI3m8WpZvC3se70f8mRP_KKIcScS0Nf9wJcsq4TWgiS_li3K6CSUbbG643IMhZBVGzW5XflwAbz0d1M/s1600/cisco.jpg","description":"Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -","related":[{"title":"Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5","link":"https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838","source":"The Register Security","date_rel":"6h ago"},{"title":"Cisco security advisory (AV26-834)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-834","source":"CCCS Alerts & Advisories","date_rel":"23h ago"}]},{"title":"Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers","link":"https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html","reason":"Citrix","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Rapid7 Blog","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-19490"],"summary":"Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing\u2026","source":"The Hacker News","date_rel":"22h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoCXrYMA_j7aJrrdIZKt2gQwTWYXhhHZTfBvrNcgpLLBTa5hzcmDNguBKwBhiD8p7kO5K2OeQYVbIPg2HHDBwu9LNzR6oAFE-znmFWIgjY_XzA0qdy-rA8XzV_uGvsxLWRNXCyyOlUKdDV0LGrXPN15wxYsTuZslyecGQ1cqE2OKdX5cocpp74uXenwdj0/s1600/citrix.jpg","description":"Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess","related":[{"title":"Citrix urges admins to patch new NetScaler flaws as soon as possible","link":"https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/","source":"Bleeping Computer","date_rel":"20 Aug"},{"title":"Citrix security advisory (AV26-833)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-833","source":"CCCS Alerts & Advisories","date_rel":"19 Aug"},{"title":"CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway","link":"https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway","source":"Rapid7 Blog","date_rel":"19 Aug"}]},{"title":"Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code","link":"https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","Check Point Research","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as\u2026","source":"The Hacker News","date_rel":"20 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitKWjeNJOL_DEahUmMAYpH9qh94s2iFi8igtfSlAzOVWiUBU-EIM0MWMsFYPmA5NDL6Rs9E-w9vvCmw3Cc6Og0q-TDt87Q2hwYIePNAQ0xQ3OJYHzgCizDFm-YK9SxW4ncWnuVLaOzgb3SPO7Qpx17zHMaFzBQfYllgz5IP-p1jMALgWlasRkj1nV3Tq3G/s1600/wordpress.jpg","description":"Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. \"The flaw lives in the Forms module's File","related":[{"title":"Critical Elementor Pro bug exposes WordPress sites to RCE attacks","link":"https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data","link":"https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html","source":"The Hacker News","date_rel":"19 Aug"},{"title":"Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect","link":"https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/","source":"Check Point Research","date_rel":"18 Aug"}]},{"title":"Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution","link":"https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html","reason":"CVE-2026-69836","category":"News","sources":["Microsoft Security","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-69836"],"summary":"Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEid22xatm4tPGWO1VA9heA8p7i0iK4au3br36QORRasXlUO2uY5836xkZe6gywLOId9oHICopC6jZ8J-di4JI9O3CPOSOGsqoOR4Ps4DrEbKCXSXwMxX_wOGo0fY3zaTW4By4nzbY6jldD58kLAlBYfFxMOEeZOglaQu8R0TtT23Q2jLbQjHwJSoS21pqu5/s1600/entraid.jpg","description":"Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory","related":[{"title":"CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836","source":"Microsoft Security","date_rel":"22h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-65770","vendor":"Microsoft","product":"Azure Managed Instance for Apache Cassandra","severity":"CRITICAL","score":10.0,"description":"Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.","cwe":"CWE-88","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65770"},{"id":"CVE-2026-65801","vendor":"Microsoft","product":"Microsoft Exchange Online","severity":"CRITICAL","score":10.0,"description":"Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65801"},{"id":"CVE-2026-65816","vendor":"Microsoft","product":"Azure Web Apps","severity":"CRITICAL","score":10.0,"description":"Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-706","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65816"},{"id":"CVE-2026-69555","vendor":"Microsoft","product":"Azure ARC","severity":"CRITICAL","score":10.0,"description":"Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-69555"},{"id":"CVE-2026-69836","vendor":"Microsoft","product":"Microsoft Entra","severity":"CRITICAL","score":10.0,"description":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-69836"},{"id":"CVE-2026-73992","vendor":"Jonathan Daggerhart","product":"Query Wrangler","severity":"CRITICAL","score":9.9,"description":"Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73992"},{"id":"CVE-2026-74014","vendor":"indithemes","product":"IT Residence","severity":"CRITICAL","score":9.9,"description":"Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-74014"},{"id":"CVE-2026-74016","vendor":"themagnifico52","product":"Smart Cleaning","severity":"CRITICAL","score":9.9,"description":"Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-74016"},{"id":"CVE-2026-74018","vendor":"themagnifico52","product":"Warehouse Cargo","severity":"CRITICAL","score":9.9,"description":"Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-74018"},{"id":"CVE-2026-77022","vendor":"Comfast","product":"CF-N1-S","severity":"CRITICAL","score":9.9,"description":"A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the ar\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77022"}],"vendor_spikes":[{"vendor":"IBM","count":75,"critical_count":13},{"vendor":"Microsoft","count":27,"critical_count":12},{"vendor":"Red Hat","count":16,"critical_count":5},{"vendor":"n8n-io","count":16,"critical_count":0},{"vendor":"Unknown","count":15,"critical_count":0},{"vendor":"ATutor","count":13,"critical_count":0},{"vendor":"Apple","count":11,"critical_count":0},{"vendor":"GIMP","count":10,"critical_count":0},{"vendor":"libevent","count":10,"critical_count":0},{"vendor":"Apache","count":9,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":481,"has_news_data":true,"has_cve_data":true}