Skip to content

Morning Brief

Sunday, August 23, 2026 · generated 2026-08-23 13:37 UTC · ~5 min read

Top developments

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems…

Apple Detected Something on These iPhones | Threat Wire

⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️ @endingwithali → Twitch: https://twitch.tv/endingwithali Twitter: https://twitter.com/endingwithali YouTube: https://youtube.com/@endingwithali Everywhere else…

Top 10 Best Wireless / Wi-Fi Security Solutions in 2026

Cisco Meraki scores highest in our 2026 evaluation of automatic Wi-Fi security solutions , combining cloud-managed simplicity with strong policy enforcement, while HPE Aruba leads on enterprise-grade wireless security…

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said…

AWS Security makes an inscrutable choice

One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have…

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict…

What 45 Million wp2shell Exploit Attempts Reveal About the New Vulnerability Response Window

The latest wp2shell vulnerability was one of the biggest WordPress security events in history. The critical vulnerability chain combined two flaws that allowed unauthenticated attackers to exploit vulnerable sites and…

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code…

Microsoft Expands Mailbox Storage From 50 GB to 100 GB for Users

Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users can now receive up to 100 GB of Exchange Online mailbox capacity …

Twitch wants your content for Amazon AI training. Here’s how to opt out

The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI. Twitch launched as a live-video platform and is currently owned by Amazon. Its core product is live…

Vulnerability watch

CVE-2026-77946 TRENDnet · TEW-821DAP CWE-119 CRITICAL 10.0

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation o…

CVE-2026-78050 Comfast · CF-N1-S CWE-119 CRITICAL 9.9

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr…

CVE-2026-78003 WordPress · Mailgun for WordPress CWE-918 CRITICAL 9.8 · EPSS 0%

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which acce…

CVE-2026-4703 WordPress · WS Form LITE – Drag & Drop Contact Form Builder CWE-502 CRITICAL 9.8

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes…

CVE-2026-59808 WWBN · AVideo CWE-306 HIGH 8.8

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin()…

CVE-2026-71513 nltk · nltk CWE-502 HIGH 8.8

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables out…

CVE-2026-0551 WordPress · PPWP – Password Protect Pages CWE-502 HIGH 8.8

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This mak…

CVE-2026-16149 WordPress · Security Hardener CWE-269 HIGH 8.8

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the…

CVE-2026-60084 siyuan-note · siyuan CWE-22 HIGH 8.7

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply a…

CVE-2026-57998 jeemok · better-npm-audit CWE-78 HIGH 7.8

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passe…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →