{"date_iso":"2026-08-22","date_human":"Saturday, August 22, 2026","generated_utc":"2026-08-22 13:37 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot","link":"https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","Check Point Research","SANS Internet Storm Center","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems\u2026","source":"The Hacker News","date_rel":"20h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCbsmb6Wk8pQKWQmByAl5wnZQEVjS7ZYiHrlsHRM7VlcoPL7s30TaoTReoaQ4LI8Oy3KfKlIRHn9sN_7bjEKd_FWPHi1V0JR6LERepKBWSdJOk6cSUNgfIN2KVc6ydfbTILTy11owREYfpO7K11gFQV00l6qf1zl5rzF28jPhcN744yTvRAA-EjyDSBXs/s1600/windows.jpg","description":"Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a","related":[{"title":"New SynkLoader malware pushed in Microsoft Teams phishing campaign","link":"https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/","source":"Bleeping Computer","date_rel":"18h ago"},{"title":"Microsoft blames Windows gaming issues on RGB lighting devices","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-windows-gaming-issues-on-rgb-lighting-devices/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Microsoft rolls out Classic Outlook theme for New Outlook users","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-classic-outlook-theme-for-new-outlook-users/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Microsoft Patches Exploited Entra ID Vulnerability","link":"https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/","source":"SecurityWeek","date_rel":"21 Aug"},{"title":"Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution","link":"https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html","source":"The Hacker News","date_rel":"21 Aug"},{"title":"Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)","link":"https://isc.sans.edu/diary/rss/33266","source":"SANS Internet Storm Center","date_rel":"20 Aug"}]},{"title":"Apple Detected Something on These iPhones | Threat Wire","link":"https://www.youtube.com/watch?v=KRvXdSuvMgg","reason":"Apple","category":"Podcast","sources":["CCCS Alerts & Advisories","Hak5","The Register Security","Wired Security"],"coverage":4,"cve_ids":[],"summary":"\u2b07\ufe0f OPEN FOR LINKS TO ARTICLES TO LEARN MORE \u2b07\ufe0f @endingwithali \u2192 Twitch: https://twitch.tv/endingwithali Twitter: https://twitter.com/endingwithali YouTube: https://youtube.com/@endingwithali Everywhere else\u2026","source":"Hak5","date_rel":"20 Aug","thumbnail":"https://i4.ytimg.com/vi/KRvXdSuvMgg/hqdefault.jpg","description":"\u2b07\ufe0f OPEN FOR LINKS TO ARTICLES TO LEARN MORE \u2b07\ufe0f @endingwithali \u2192 Twitch: https://twitch.tv/endingwithali Twitter: https://twitter.com/endingwithali YouTube: https://youtube.com/@endingwithali Everywhere else: https://links.ali.dev Want to work with Ali? hak5@endingwithali.com [\u2757] Join the Patreon\u2192 https://patreon.com/threatwire 0:00 0 - Intro 1 - Apple\u2019s Threat Notifs 2 - US Hacks Back 3 - Worms R Back 4 - BSides News 5 - Outro LINKS \ud83d\udd17 Story 1: Apple\u2019s Threat Notifs https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html https://support.apple.com/en-us/102174 \ud83d\udd17 Story 2\u2026","related":[{"title":"Your Expired Visa Card Could Be \u2018Zombified\u2019 to Make Contactless Payments","link":"https://www.wired.com/story/security-news-this-week-your-expired-visa-card-could-be-zombiefied-to-make-contactless-payments/","source":"Wired Security","date_rel":"1h ago"},{"title":"Apple security advisory (AV26-839)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-839","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"Researcher tricks Apple\u2019s Find My into sharing location data with Linux","link":"https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496","source":"The Register Security","date_rel":"20 Aug"}]},{"title":"Top 10 Best Wireless / Wi-Fi Security Solutions in 2026","link":"https://cybersecuritynews.com/best-wireless-wifi-security-solutions/","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Cisco Meraki scores highest in our 2026 evaluation of automatic Wi-Fi security solutions , combining cloud-managed simplicity with strong policy enforcement, while HPE Aruba leads on enterprise-grade wireless security\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Best-Wireless-Wi-Fi-Security-Solutions-.webp","description":"Cisco Meraki scores highest in our 2026 evaluation of automatic Wi-Fi security solutions , combining cloud-managed simplicity with strong policy enforcement, while HPE Aruba leads on enterprise-grade wireless security depth, and Juniper Mist wins on AI-driven operations. Wi-Fi security solutions protect wireless networks through encryption (WPA3), authentication (802.1X), rogue access point detection, and client isolation, and in 2026 they increasingly enforce zero-trust policy at the point of connection. Here are the ten best, scored. The 2026 Wi-Fi Security Scorecard Each platform scored\u2026","related":[{"title":"Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0","link":"https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html","source":"The Hacker News","date_rel":"21 Aug"},{"title":"Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5","link":"https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838","source":"The Register Security","date_rel":"21 Aug"},{"title":"Cisco security advisory (AV26-834)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-834","source":"CCCS Alerts & Advisories","date_rel":"20 Aug"}]},{"title":"Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet","link":"https://thehackernews.com/2026/08/android-car-malware-spreads-through.html","reason":"Android","category":"News","sources":["Bleeping Computer","Infosecurity Magazine","Kaspersky Securelist","Malwarebytes Labs","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said\u2026","source":"The Hacker News","date_rel":"20h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1EQE-DqLXTzpjwGf3nQnM4CTnjibkKl_2ersn8abw3Gmqoc5MUaFC2LvkA7c6Xoa0XBPZeHL4wHHiXU7Pc9nGLcI1zTorwFTwvYXfww4Q68oSUrgcQhmBzQBNqYp-woIZFK_I1OOsnBNptiwA90VHhpE_hvlz3qdFomOmOMLreYe5YCenvR2CeawvRrMU/s1600/car.png","description":"Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. \"The malware spread through the built-in updaters of","related":[{"title":"The invisible passenger in your car","link":"https://securelist.com/android-head-unit-malware/121106/","source":"Kaspersky Securelist","date_rel":"21 Aug"},{"title":"Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","link":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","source":"The Hacker News","date_rel":"20 Aug"},{"title":"ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud","link":"https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html","source":"The Hacker News","date_rel":"20 Aug"},{"title":"New Manic Android malware can exfiltrate data through nearby devices","link":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","source":"Bleeping Computer","date_rel":"20 Aug"},{"title":"Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps","link":"https://www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/","source":"Infosecurity Magazine","date_rel":"20 Aug"},{"title":"Sideloading on Android: What it is, why it\u2019s risky, and how to do it more safely","link":"https://www.malwarebytes.com/blog/how-to/2026/08/sideloading-on-android-what-it-is-why-its-risky-and-how-to-do-it-more-safely","source":"Malwarebytes Labs","date_rel":"19 Aug"}]},{"title":"AWS Security makes an inscrutable choice","link":"https://www.theregister.com/security/2026/08/22/aws-security-makes-an-inscrutable-choice-corey-quinn/5291446","reason":"Github","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-70335"],"summary":"One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have\u2026","source":"The Register Security","date_rel":"12h ago","thumbnail":"https://image.theregister.com/?imageId=5291460&width=800","description":"One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have improved dramatically (my personal favorite being \"using non-ephemeral credentials derived from OIDC or SSO is an anti-pattern\"), but it still happens. On Friday, BleepingComputer reported on a Truffle Security finding that hundreds of leaked AWS keys are root keys and are somehow still active and valid. AWS Security is full of very smart people who care deeply about a number of\u2026","related":[{"title":"In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug","link":"https://www.securityweek.com/in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug/","source":"SecurityWeek","date_rel":"21h ago"},{"title":"CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE","link":"https://thehackernews.com/2026/08/isolated-vm-flaw-lets-sandboxed.html","source":"The Hacker News","date_rel":"20 Aug"}]},{"title":"What 45 Million wp2shell Exploit Attempts Reveal About the New Vulnerability Response Window","link":"https://cybersecuritynews.com/what-45-million-wp2shell-exploit-attempts-reveal-about-the-new-vulnerability-response-window/","reason":"Wordpress","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The latest wp2shell vulnerability was one of the biggest WordPress security events in history. The critical vulnerability chain combined two flaws that allowed unauthenticated attackers to exploit vulnerable sites and\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Joey-Stanford.webp","description":"The latest wp2shell vulnerability was one of the biggest WordPress security events in history. The critical vulnerability chain combined two flaws that allowed unauthenticated attackers to exploit vulnerable sites and ultimately execute malicious code remotely, potentially taking control of them. In the first week after the disclosure, more than 45 million exploit attempts from nearly 150,000 unique network sources were made. And as the volume continued climbing, we saw just how fast vulnerability disclosure can turn into mass exploitation. For comparison, this scale was roughly 20x what was\u2026","related":[{"title":"Critical Elementor Pro bug exposes WordPress sites to RCE attacks","link":"https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/","source":"Bleeping Computer","date_rel":"20 Aug"},{"title":"Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code","link":"https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html","source":"The Hacker News","date_rel":"20 Aug"}]},{"title":"41 deceptive download sites show a real link, then send you somewhere else","link":"https://www.malwarebytes.com/blog/threat-intel/2026/08/41-deceptive-download-sites-show-a-real-link-then-send-you-somewhere-else","reason":"Windows","category":"Threat Intel","sources":["Bleeping Computer","Malwarebytes Labs","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-32202","CVE-2026-49183","CVE-2026-58547"],"summary":"We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike\u2026","source":"Malwarebytes Labs","date_rel":"19 Aug","thumbnail":"","description":"We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see isn\u2019t the link you follow. One site promises Counter-Strike. Hover over its download button and the\u2026","related":[{"title":"CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58547","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49183","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-32202 Windows Shell Spoofing Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Hackers abuse FTP server banners to deliver new Windows malware","link":"https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/","source":"Bleeping Computer","date_rel":"21 Aug"}]},{"title":"14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2","link":"https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html","reason":"Linux","category":"News","sources":["Cisco Talos","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux\u2026","source":"The Hacker News","date_rel":"17h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvZpEOpS6_M3zQlIDwvD1wMhESnRAMTCz1nW2JFP__pGSVWOw28REaDTZ5lI7sdwvcRKSSUHI4sm1CUuWs6_gvOXE1c5BbvKnR75iyBl9Er1SckweDAxBEotnOlSikBeOE5WEBIIGlS74w4b85pvznpr3c4mj88LzLt-3pGr1HHXHQDg5v7T9FxdBSWSlK/s1600/linux-npm.jpg","description":"Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. \"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process,\" TrendAI, Trend Micro's","related":[{"title":"UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities","link":"https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/","source":"Cisco Talos","date_rel":"20 Aug"},{"title":"UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations","link":"https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/","source":"Cisco Talos","date_rel":"20 Aug"},{"title":"Exclusive: Linux Foundation's Akrites to Go Live in September","link":"https://www.infosecurity-magazine.com/news/linux-foundations-akrites-go-live/","source":"Infosecurity Magazine","date_rel":"19 Aug"}]},{"title":"AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure","link":"https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html","reason":"Siemens","category":"News","sources":["CyberScoop","Infosecurity Magazine","Tenable Blog","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"The U.S. government on Wednesday warned of an \"active threat\" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting\u2026","source":"The Hacker News","date_rel":"20 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSn562AFIpj2ldmT5inFv5tGgfNbaM4F1OBNvCW-80nP-YmFewnJd9VMlbgYnhgWrUpHS81bS6uEXRgEmg37c14OqmkO29XqY3FcBCl637vmAxfqB3UDtL3Rvgio6cPAQQv3bYtLUIyRdog4bpgD8MqJJYhTLish4L2Ljt6aJ_WpjFmTXYhmrA-TguqH98/s1600/plc.jpg","description":"The U.S. government on Wednesday warned of an \"active threat\" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That","related":[{"title":"Frequently asked questions about the active threat to Siemens S7 Series PLCs","link":"https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs","source":"Tenable Blog","date_rel":"20 Aug"},{"title":"ICS Operators Warned of AI-Driven Attacks on Siemens PLCs","link":"https://www.infosecurity-magazine.com/news/ics-ai-attacks-siemens/","source":"Infosecurity Magazine","date_rel":"20 Aug"},{"title":"'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers","link":"https://www.theregister.com/security/2026/08/19/not-a-theoretical-risk-feds-warn-as-attackers-use-ai-made-code-to-hack-critical-infrastructure-controllers/5289960","source":"The Register Security","date_rel":"19 Aug"},{"title":"AI-fueled attacks pose \u2018active threat\u2019 to water, other sectors, U.S. agencies warn","link":"https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/","source":"CyberScoop","date_rel":"19 Aug"}]},{"title":"Podcast: Amazon is Destroying Rare Books to Train AI","link":"https://www.404media.co/podcast-amazon-is-destroying-rare-books-to-train-ai/","reason":"Amazon","category":"News","sources":["404 Media","Bleeping Computer","Malwarebytes Labs"],"coverage":3,"cve_ids":[],"summary":"We start this week with Emanuel\u2019s big story about Amazon buying, and destroying, masses of books to train AI. After the break we talk about a couple of wild cases where people are using AI. In the subscribers-only\u2026","source":"404 Media","date_rel":"19 Aug","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/08/amazonbooks.png","description":"We start this week with Emanuel\u2019s big story about Amazon buying, and destroying, masses of books to train AI. After the break we talk about a couple of wild cases where people are using AI. In the subscribers-only section, we talk about Meta\u2019s new smart glasses patent and research into how perverts are using them. Listen to the weekly podcast on Apple Podcasts , Spotify , or YouTube . Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the\u2026","related":[{"title":"Hundreds of leaked AWS keys give full control over corporate accounts","link":"https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"Twitch wants your content for Amazon AI training. Here\u2019s how to opt out","link":"https://www.malwarebytes.com/blog/ai/2026/08/twitch-wants-your-content-for-amazon-ai-training-heres-how-to-opt-out","source":"Malwarebytes Labs","date_rel":"20 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-69502","vendor":"Microsoft","product":"Azure SQL Database","severity":"CRITICAL","score":10.0,"description":"Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-69502"},{"id":"CVE-2026-61539","vendor":"xorbitsai","product":"inference","severity":"CRITICAL","score":10.0,"description":"Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py \u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61539"},{"id":"CVE-2026-77683","vendor":"Comfast","product":"CF-N1-S","severity":"CRITICAL","score":9.9,"description":"A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command inje\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77683"},{"id":"CVE-2026-48749","vendor":"lxc","product":"incus","severity":"CRITICAL","score":9.9,"description":"Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48749"},{"id":"CVE-2026-48750","vendor":"lxc","product":"incus","severity":"CRITICAL","score":9.9,"description":"Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48750"},{"id":"CVE-2026-48751","vendor":"lxc","product":"incus","severity":"CRITICAL","score":9.9,"description":"Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel \u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48751"},{"id":"CVE-2026-48752","vendor":"lxc","product":"incus","severity":"CRITICAL","score":9.9,"description":"Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. \u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48752"},{"id":"CVE-2026-48753","vendor":"lxc","product":"incus","severity":"CRITICAL","score":9.9,"description":"Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary comma\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48753"},{"id":"CVE-2026-48755","vendor":"lxc","product":"incus","severity":"CRITICAL","score":9.9,"description":"Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file \u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48755"},{"id":"CVE-2026-48769","vendor":"lxc","product":"incus","severity":"CRITICAL","score":9.9,"description":"Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary comman\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48769"}],"vendor_spikes":[{"vendor":"WordPress","count":37,"critical_count":1},{"vendor":"Unknown","count":36,"critical_count":0},{"vendor":"Apache","count":21,"critical_count":0},{"vendor":"Combodo","count":18,"critical_count":0},{"vendor":"lxc","count":17,"critical_count":12},{"vendor":"Esri","count":13,"critical_count":0},{"vendor":"Microsoft","count":9,"critical_count":1},{"vendor":"HashiCorp","count":8,"critical_count":0},{"vendor":"yootheme.com","count":6,"critical_count":0},{"vendor":"j2commerce.com","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":18,"new_cve_count":291,"has_news_data":true,"has_cve_data":true}