{"date_iso":"2026-08-23","date_human":"Sunday, August 23, 2026","generated_utc":"2026-08-23 13:37 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot","link":"https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","Check Point Research","SANS Internet Storm Center","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems\u2026","source":"The Hacker News","date_rel":"21 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCbsmb6Wk8pQKWQmByAl5wnZQEVjS7ZYiHrlsHRM7VlcoPL7s30TaoTReoaQ4LI8Oy3KfKlIRHn9sN_7bjEKd_FWPHi1V0JR6LERepKBWSdJOk6cSUNgfIN2KVc6ydfbTILTy11owREYfpO7K11gFQV00l6qf1zl5rzF28jPhcN744yTvRAA-EjyDSBXs/s1600/windows.jpg","description":"Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a","related":[{"title":"New SynkLoader malware pushed in Microsoft Teams phishing campaign","link":"https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/","source":"Bleeping Computer","date_rel":"21 Aug"},{"title":"Microsoft blames Windows gaming issues on RGB lighting devices","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-windows-gaming-issues-on-rgb-lighting-devices/","source":"Bleeping Computer","date_rel":"21 Aug"},{"title":"Microsoft rolls out Classic Outlook theme for New Outlook users","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-classic-outlook-theme-for-new-outlook-users/","source":"Bleeping Computer","date_rel":"21 Aug"},{"title":"Microsoft Patches Exploited Entra ID Vulnerability","link":"https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/","source":"SecurityWeek","date_rel":"21 Aug"},{"title":"Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution","link":"https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html","source":"The Hacker News","date_rel":"21 Aug"},{"title":"Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)","link":"https://isc.sans.edu/diary/rss/33266","source":"SANS Internet Storm Center","date_rel":"20 Aug"}]},{"title":"Apple Detected Something on These iPhones | Threat Wire","link":"https://www.youtube.com/watch?v=KRvXdSuvMgg","reason":"Apple","category":"Podcast","sources":["CCCS Alerts & Advisories","Hak5","The Register Security","Wired Security"],"coverage":4,"cve_ids":[],"summary":"\u2b07\ufe0f OPEN FOR LINKS TO ARTICLES TO LEARN MORE \u2b07\ufe0f @endingwithali \u2192 Twitch: https://twitch.tv/endingwithali Twitter: https://twitter.com/endingwithali YouTube: https://youtube.com/@endingwithali Everywhere else\u2026","source":"Hak5","date_rel":"20 Aug","thumbnail":"https://i4.ytimg.com/vi/KRvXdSuvMgg/hqdefault.jpg","description":"\u2b07\ufe0f OPEN FOR LINKS TO ARTICLES TO LEARN MORE \u2b07\ufe0f @endingwithali \u2192 Twitch: https://twitch.tv/endingwithali Twitter: https://twitter.com/endingwithali YouTube: https://youtube.com/@endingwithali Everywhere else: https://links.ali.dev Want to work with Ali? hak5@endingwithali.com [\u2757] Join the Patreon\u2192 https://patreon.com/threatwire 0:00 0 - Intro 1 - Apple\u2019s Threat Notifs 2 - US Hacks Back 3 - Worms R Back 4 - BSides News 5 - Outro LINKS \ud83d\udd17 Story 1: Apple\u2019s Threat Notifs https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html https://support.apple.com/en-us/102174 \ud83d\udd17 Story 2\u2026","related":[{"title":"Your Expired Visa Card Could Be \u2018Zombified\u2019 to Make Contactless Payments","link":"https://www.wired.com/story/security-news-this-week-your-expired-visa-card-could-be-zombiefied-to-make-contactless-payments/","source":"Wired Security","date_rel":"22 Aug"},{"title":"Apple security advisory (AV26-839)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-839","source":"CCCS Alerts & Advisories","date_rel":"21 Aug"},{"title":"Researcher tricks Apple\u2019s Find My into sharing location data with Linux","link":"https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496","source":"The Register Security","date_rel":"20 Aug"}]},{"title":"Top 10 Best Wireless / Wi-Fi Security Solutions in 2026","link":"https://cybersecuritynews.com/best-wireless-wifi-security-solutions/","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Cisco Meraki scores highest in our 2026 evaluation of automatic Wi-Fi security solutions , combining cloud-managed simplicity with strong policy enforcement, while HPE Aruba leads on enterprise-grade wireless security\u2026","source":"Cyber Security News","date_rel":"22 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Best-Wireless-Wi-Fi-Security-Solutions-.webp","description":"Cisco Meraki scores highest in our 2026 evaluation of automatic Wi-Fi security solutions , combining cloud-managed simplicity with strong policy enforcement, while HPE Aruba leads on enterprise-grade wireless security depth, and Juniper Mist wins on AI-driven operations. Wi-Fi security solutions protect wireless networks through encryption (WPA3), authentication (802.1X), rogue access point detection, and client isolation, and in 2026 they increasingly enforce zero-trust policy at the point of connection. Here are the ten best, scored. The 2026 Wi-Fi Security Scorecard Each platform scored\u2026","related":[{"title":"Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0","link":"https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html","source":"The Hacker News","date_rel":"21 Aug"},{"title":"Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5","link":"https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838","source":"The Register Security","date_rel":"21 Aug"},{"title":"Cisco security advisory (AV26-834)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-834","source":"CCCS Alerts & Advisories","date_rel":"20 Aug"}]},{"title":"Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet","link":"https://thehackernews.com/2026/08/android-car-malware-spreads-through.html","reason":"Android","category":"News","sources":["Bleeping Computer","Kaspersky Securelist","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said\u2026","source":"The Hacker News","date_rel":"21 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1EQE-DqLXTzpjwGf3nQnM4CTnjibkKl_2ersn8abw3Gmqoc5MUaFC2LvkA7c6Xoa0XBPZeHL4wHHiXU7Pc9nGLcI1zTorwFTwvYXfww4Q68oSUrgcQhmBzQBNqYp-woIZFK_I1OOsnBNptiwA90VHhpE_hvlz3qdFomOmOMLreYe5YCenvR2CeawvRrMU/s1600/car.png","description":"Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. \"The malware spread through the built-in updaters of","related":[{"title":"Hackers infect Android car head units with proxy botnet malware","link":"https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"The invisible passenger in your car","link":"https://securelist.com/android-head-unit-malware/121106/","source":"Kaspersky Securelist","date_rel":"21 Aug"}]},{"title":"AWS Security makes an inscrutable choice","link":"https://www.theregister.com/security/2026/08/22/aws-security-makes-an-inscrutable-choice-corey-quinn/5291446","reason":"Github","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-70335"],"summary":"One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have\u2026","source":"The Register Security","date_rel":"21 Aug","thumbnail":"https://image.theregister.com/?imageId=5291460&width=800","description":"One of the best ways to lower your AWS bill by 99 percent or more is by not checking your keys into public GitHub repositories. Many of us have done this inadvertently over the years, and the defenses against it have improved dramatically (my personal favorite being \"using non-ephemeral credentials derived from OIDC or SSO is an anti-pattern\"), but it still happens. On Friday, BleepingComputer reported on a Truffle Security finding that hundreds of leaked AWS keys are root keys and are somehow still active and valid. AWS Security is full of very smart people who care deeply about a number of\u2026","related":[{"title":"In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug","link":"https://www.securityweek.com/in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug/","source":"SecurityWeek","date_rel":"21 Aug"},{"title":"CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335","source":"Microsoft Security","date_rel":"21 Aug"},{"title":"Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE","link":"https://thehackernews.com/2026/08/isolated-vm-flaw-lets-sandboxed.html","source":"The Hacker News","date_rel":"20 Aug"}]},{"title":"Named Pipes Under Attack: Securing Windows Interprocess Communication","link":"https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/","reason":"Windows","category":"News","sources":["Bleeping Computer","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-32202","CVE-2026-49183","CVE-2026-58547"],"summary":"Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict\u2026","source":"Bleeping Computer","date_rel":"23h ago","thumbnail":"","description":"Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication.","related":[{"title":"CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58547","source":"Microsoft Security","date_rel":"21 Aug"},{"title":"CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49183","source":"Microsoft Security","date_rel":"21 Aug"},{"title":"CVE-2026-32202 Windows Shell Spoofing Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202","source":"Microsoft Security","date_rel":"21 Aug"},{"title":"Hackers abuse FTP server banners to deliver new Windows malware","link":"https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/","source":"Bleeping Computer","date_rel":"21 Aug"}]},{"title":"What 45 Million wp2shell Exploit Attempts Reveal About the New Vulnerability Response Window","link":"https://cybersecuritynews.com/what-45-million-wp2shell-exploit-attempts-reveal-about-the-new-vulnerability-response-window/","reason":"Wordpress","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"The latest wp2shell vulnerability was one of the biggest WordPress security events in history. The critical vulnerability chain combined two flaws that allowed unauthenticated attackers to exploit vulnerable sites and\u2026","source":"Cyber Security News","date_rel":"22 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Joey-Stanford.webp","description":"The latest wp2shell vulnerability was one of the biggest WordPress security events in history. The critical vulnerability chain combined two flaws that allowed unauthenticated attackers to exploit vulnerable sites and ultimately execute malicious code remotely, potentially taking control of them. In the first week after the disclosure, more than 45 million exploit attempts from nearly 150,000 unique network sources were made. And as the volume continued climbing, we saw just how fast vulnerability disclosure can turn into mass exploitation. For comparison, this scale was roughly 20x what was\u2026","related":[{"title":"Critical Elementor Pro bug exposes WordPress sites to RCE attacks","link":"https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/","source":"Bleeping Computer","date_rel":"20 Aug"}]},{"title":"GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure","link":"https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html","reason":"Gitlab","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-19478"],"summary":"A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code\u2026","source":"The Hacker News","date_rel":"21 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8jpyIqzuMd0vBKcxrQRj7eBbEebcRgNHLRFpx7YuxJlTPksUDEar7HPu4unQPNaOzpChBl1-dYyPHwuyjhgetrrh6PZ9OHPRqnc6nXeNdaX9f8AcSDe6gpmRecFfryf3-3BgsNoxvOyNc6xz703Qzsd7hJLuKbQt4Q6bgVxRZDGdpFzy8O2SByvUouC3J/s1600/gitlab-cve.jpg","description":"A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring","related":[{"title":"GitLab security advisory (AV26-827) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-827","source":"CCCS Alerts & Advisories","date_rel":"21 Aug"}]},{"title":"Microsoft Expands Mailbox Storage From 50 GB to 100 GB for Users","link":"https://cybersecuritynews.com/microsoft-expands-mailbox-storage-50gb-to-100gb/","reason":"Exchange","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-33824","CVE-2026-65801"],"summary":"Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users can now receive up to 100 GB of Exchange Online mailbox capacity \u2026","source":"Cyber Security News","date_rel":"21 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Microsoft-Expands-Mailbox-Storage-from-50gb-to-100gb-for-Users.webp","description":"Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users can now receive up to 100 GB of Exchange Online mailbox capacity , doubling the previous 50 GB entitlement. The change is part of Microsoft\u2019s 2026 packaging updates, which began rolling out in June and are expected to continue through September. Microsoft also issued advance tenant notifications through the Message Center before the service-plan changes became available. The increased capacity applies only to the primary mailbox. It does not\u2026","related":[{"title":"CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65801","source":"Microsoft Security","date_rel":"20 Aug"},{"title":"CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824","source":"Microsoft Security","date_rel":"20 Aug"}]},{"title":"Twitch wants your content for Amazon AI training. Here\u2019s how to opt out","link":"https://www.malwarebytes.com/blog/ai/2026/08/twitch-wants-your-content-for-amazon-ai-training-heres-how-to-opt-out","reason":"Amazon","category":"Threat Intel","sources":["Bleeping Computer","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI. Twitch launched as a live-video platform and is currently owned by Amazon. Its core product is live\u2026","source":"Malwarebytes Labs","date_rel":"20 Aug","thumbnail":"","description":"The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI. Twitch launched as a live-video platform and is currently owned by Amazon. Its core product is live broadcasting with a built-in chat culture: streamers broadcast gameplay, commentary, performances or other live content while viewers interact in real time. Twitch is one of the world\u2019s largest livestreaming platforms, with millions of people broadcasting and watching content every month. Last week we learned that Twitch allows Amazon to use content from its platform to train\u2026","related":[{"title":"Hundreds of leaked AWS keys give full control over corporate accounts","link":"https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/","source":"Bleeping Computer","date_rel":"21 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-77946","vendor":"TRENDnet","product":"TEW-821DAP","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation o\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77946"},{"id":"CVE-2026-78050","vendor":"Comfast","product":"CF-N1-S","severity":"CRITICAL","score":9.9,"description":"A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78050"},{"id":"CVE-2026-78003","vendor":"WordPress","product":"Mailgun for WordPress","severity":"CRITICAL","score":9.8,"description":"The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which acce\u2026","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":0.0053,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78003"},{"id":"CVE-2026-4703","vendor":"WordPress","product":"WS Form LITE \u2013 Drag & Drop Contact Form Builder","severity":"CRITICAL","score":9.8,"description":"The WS Form LITE \u2013 Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-4703"},{"id":"CVE-2026-59808","vendor":"WWBN","product":"AVideo","severity":"HIGH","score":8.8,"description":"AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin()\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-59808"},{"id":"CVE-2026-71513","vendor":"nltk","product":"nltk","severity":"HIGH","score":8.8,"description":"NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables out\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71513"},{"id":"CVE-2026-0551","vendor":"WordPress","product":"PPWP \u2013 Password Protect Pages","severity":"HIGH","score":8.8,"description":"The PPWP \u2013 Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This mak\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-0551"},{"id":"CVE-2026-16149","vendor":"WordPress","product":"Security Hardener","severity":"HIGH","score":8.8,"description":"The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16149"},{"id":"CVE-2026-60084","vendor":"siyuan-note","product":"siyuan","severity":"HIGH","score":8.7,"description":"SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply a\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-60084"},{"id":"CVE-2026-57998","vendor":"jeemok","product":"better-npm-audit","severity":"HIGH","score":7.8,"description":"better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passe\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-57998"}],"vendor_spikes":[{"vendor":"Linux","count":138,"critical_count":0},{"vendor":"fabrikar.com","count":17,"critical_count":0},{"vendor":"WordPress","count":16,"critical_count":2},{"vendor":"nltk","count":11,"critical_count":0},{"vendor":"Unknown","count":9,"critical_count":0},{"vendor":"WWBN","count":7,"critical_count":0},{"vendor":"HashiCorp","count":5,"critical_count":0},{"vendor":"siyuan-note","count":4,"critical_count":0},{"vendor":"SourceCodester","count":4,"critical_count":0},{"vendor":"TRENDnet","count":3,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":245,"has_news_data":true,"has_cve_data":true}