{"date_iso":"2026-08-24","date_human":"Monday, August 24, 2026","generated_utc":"2026-08-24 15:43 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Hackers Infect Android Car Screens Through Their Built-In Software Update System","link":"https://cybersecuritynews.com/hackers-infect-android-car-screens/","reason":"Android","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News","The Record"],"coverage":4,"cve_ids":[],"summary":"A newly uncovered Android malware campaign has turned car infotainment screens into an unexpected target. Rather than tricking drivers into installing a suspicious app, attackers used the software update path already\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Infect-Android-Car-Screens-Through-Their-Built-In-Software-Update-System.webp","description":"A newly uncovered Android malware campaign has turned car infotainment screens into an unexpected target. Rather than tricking drivers into installing a suspicious app, attackers used the software update path already built into Android-based head units. The malware is a multi-stage downloader for ad fraud and a proxy botnet. It targets connected vehicle screens that handle music, navigation, and some vehicle functions, exploiting the same internet access that enables routine software updates. That makes a trusted maintenance feature the entry point for a wider criminal operation. Analysts at\u2026","related":[{"title":"Hackers infecting Android car systems to build proxy botnet","link":"https://therecord.media/android-botnet-china-hackers","source":"The Record","date_rel":"13m ago"},{"title":"ToxicPanda Android malware uses VPN permissions to block Google Play","link":"https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Hackers infect Android car head units with proxy botnet malware","link":"https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/","source":"Bleeping Computer","date_rel":"22 Aug"},{"title":"Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet","link":"https://thehackernews.com/2026/08/android-car-malware-spreads-through.html","source":"The Hacker News","date_rel":"21 Aug"}]},{"title":"AWS Network Firewall Now Displays Count of Triggered Security Rules","link":"https://cybersecuritynews.com/aws-network-firewall-hit-counts/","reason":"Aws","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","The Register Security"],"coverage":4,"cve_ids":[],"summary":"AWS has introduced rule hit count support for AWS Network Firewall , giving security teams direct visibility into which stateful firewall rules are matching live network traffic. The new capability is enabled by default\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/AWS-Network-Firewall-Now-Shows-Which-Security-Rules-Are-Actually-Being-Triggered.webp","description":"AWS has introduced rule hit count support for AWS Network Firewall , giving security teams direct visibility into which stateful firewall rules are matching live network traffic. The new capability is enabled by default and helps organizations identify active, inactive, and potentially misconfigured rules without manually reviewing large volumes of firewall logs. As firewall policies grow, they often accumulate rules that are no longer needed, never trigger, or are placed incorrectly in the inspection order. Until now, teams had to search alert logs manually to determine whether a specific\u2026","related":[{"title":"Researchers Uncover Thousands of Leaked AWS Keys","link":"https://www.infosecurity-magazine.com/news/researchers-thousands-eaked-aws/","source":"Infosecurity Magazine","date_rel":"4h ago"},{"title":"AWS Security makes an inscrutable choice","link":"https://www.theregister.com/security/2026/08/22/aws-security-makes-an-inscrutable-choice-corey-quinn/5291446","source":"The Register Security","date_rel":"21 Aug"},{"title":"Hundreds of leaked AWS keys give full control over corporate accounts","link":"https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/","source":"Bleeping Computer","date_rel":"21 Aug"}]},{"title":"New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File","link":"https://cybersecuritynews.com/malware-as-a-service-adobe-themed-domain/","reason":"Windows","category":"News","sources":["Bleeping Computer","Cyber Security News","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-32202","CVE-2026-49183","CVE-2026-58547"],"summary":"A criminal service is hiding behind a website that appears to offer Adobe Acrobat Reader. The site, acrobatreaderonline.com, is not a document service. Instead, it appears to expose an operator panel for building and\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/New-Malware-as-a-service-Leveraging-Adobe-themed-Domain-to-Attack-Windows-Users-Using-.bat-File.webp","description":"A criminal service is hiding behind a website that appears to offer Adobe Acrobat Reader. The site, acrobatreaderonline.com, is not a document service. Instead, it appears to expose an operator panel for building and managing attacks against Windows users. The campaign uses a familiar trick: a trusted-looking document or payment theme leads a target toward a harmful download. Earlier activity tied to the same infrastructure used a Windows batch, or .bat, file through a WebDAV remote folder, turning a PDF or boleto lure into a possible malware entry point. Researchers at Clandestine identified\u2026","related":[{"title":"Named Pipes Under Attack: Securing Windows Interprocess Communication","link":"https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/","source":"Bleeping Computer","date_rel":"22 Aug"},{"title":"CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58547","source":"Microsoft Security","date_rel":"21 Aug"},{"title":"CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49183","source":"Microsoft Security","date_rel":"21 Aug"},{"title":"CVE-2026-32202 Windows Shell Spoofing Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202","source":"Microsoft Security","date_rel":"21 Aug"}]},{"title":"Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot","link":"https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems\u2026","source":"The Hacker News","date_rel":"21 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCbsmb6Wk8pQKWQmByAl5wnZQEVjS7ZYiHrlsHRM7VlcoPL7s30TaoTReoaQ4LI8Oy3KfKlIRHn9sN_7bjEKd_FWPHi1V0JR6LERepKBWSdJOk6cSUNgfIN2KVc6ydfbTILTy11owREYfpO7K11gFQV00l6qf1zl5rzF28jPhcN744yTvRAA-EjyDSBXs/s1600/windows.jpg","description":"Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a","related":[{"title":"Microsoft shares temporary fix for Windows 11 gaming issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-temporary-fix-for-windows-11-gaming-issues/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"New SynkLoader malware pushed in Microsoft Teams phishing campaign","link":"https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/","source":"Bleeping Computer","date_rel":"21 Aug"},{"title":"Microsoft blames Windows gaming issues on RGB lighting devices","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-windows-gaming-issues-on-rgb-lighting-devices/","source":"Bleeping Computer","date_rel":"21 Aug"}]},{"title":"TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit","link":"https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html","reason":"Settlement Million Privacy","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the\u2026","source":"The Hacker News","date_rel":"22 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuigeGBdB6K4zmYLAIVAQ2NR4LskJUGGLo94UiAtL1d89WIdT3ekZUY58J7Em-QxANVODEDSuLoEwVlBKiwEQCBss89hDYzpOuUWcAd8bUphqatYsgIA801ytGpe6c9Pr66CZicJqHx81XREePakS0n3RhYGdD_awrTW5UNGjUdSEmwcKo0K5UOrOIdyGo/s1600/tiktok.jpg","description":"The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million \"upon entry of an order vacating a prior consent decree entered against","related":[{"title":"TikTok Reaches $400 Million Settlement With US Justice Department Over Children\u2019s Privacy","link":"https://www.securityweek.com/tiktok-reaches-400-million-settlement-with-us-justice-department-over-childrens-privacy/","source":"SecurityWeek","date_rel":"3h ago"}]},{"title":"UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit","link":"https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html","reason":"Linux","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4-mx98ENuq77sCTBd49TSl4Ov5dD1Wua0Vf1MiyVVPfcFckY__TjnTEOeC5CIQWX4L_OLA-xZHHY5nAlp926SIpa3eK8Tvfw1HSHHK1GMot7noTz4Cg36t-ZuZ-NUh5mnsfzs0HJ8F7p410LgWFVPN39PYh8YR6qkDlE8duNKmKpOtJHW4NA9T_ddTGLp/s1600/hackers.jpg","description":"Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open","related":[{"title":"Malicious npm Packages Deploy AI-Powered RedC2 Linux Implant to Steal Credentials and Pivot Networks","link":"https://cybersecuritynews.com/malicious-npm-packages/","source":"Cyber Security News","date_rel":"6h ago"},{"title":"14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2","link":"https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html","source":"The Hacker News","date_rel":"21 Aug"}]},{"title":"Your Expired Visa Card Could Be \u2018Zombified\u2019 to Make Contactless Payments","link":"https://www.wired.com/story/security-news-this-week-your-expired-visa-card-could-be-zombiefied-to-make-contactless-payments/","reason":"Apple","category":"Media","sources":["CCCS Alerts & Advisories","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Plus: Apple sends out an \u201cunprecedented\u201d number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.","source":"Wired Security","date_rel":"22 Aug","thumbnail":"https://media.wired.com/photos/6a88b7f32773ab7e6c76bdb4/master/pass/SecurityRoundUp_Week0821_v1.jpg","description":"","related":[{"title":"Apple security advisory (AV26-839)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-839","source":"CCCS Alerts & Advisories","date_rel":"21 Aug"}]},{"title":"In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug","link":"https://www.securityweek.com/in-other-news-zombie-card-attack-t-mobile-cut-cable-to-stop-hackers-github-denies-ai-caused-bug/","reason":"Github","category":"News","sources":["Microsoft Security","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-70335"],"summary":"Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification.","source":"SecurityWeek","date_rel":"21 Aug","thumbnail":"","description":"","related":[{"title":"CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70335","source":"Microsoft Security","date_rel":"21 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-78167","vendor":"EFM","product":"ipTIME T16000M","severity":"CRITICAL","score":10.0,"description":"A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation \u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78167"},{"id":"CVE-2026-78155","vendor":"OnGres","product":"StackGres","severity":"CRITICAL","score":9.9,"description":"privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges","cwe":"CWE-426","kev":false,"kev_action":"","kev_due":"","epss":0.0048,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78155"},{"id":"CVE-2026-78169","vendor":"UTT","product":"HiPER 1250GW","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profil\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78169"},{"id":"CVE-2026-5388","vendor":"Microsoft","product":"justhtml","severity":"CRITICAL","score":9.8,"description":"justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cas\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-5388"},{"id":"CVE-2026-7808","vendor":"EmilStenstrom","product":"justhtml","severity":"CRITICAL","score":9.8,"description":"justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advan\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-7808"},{"id":"CVE-2026-8445","vendor":"EmilStenstrom","product":"justhtml","severity":"CRITICAL","score":9.8,"description":"justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacter\u2026","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-8445"},{"id":"CVE-2026-78168","vendor":"EFM","product":"ipTIME T24000M","severity":"CRITICAL","score":9.8,"description":"A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack \u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78168"},{"id":"CVE-2026-78211","vendor":"4MOSAn Security Technology","product":"4MOSAn GCB Doctor","severity":"CRITICAL","score":9.8,"description":"4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary s\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78211"},{"id":"CVE-2026-78207","vendor":"Microsoft","product":"exceljs","severity":"CRITICAL","score":9.4,"description":"exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious _\u2026","cwe":"CWE-1321","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78207"},{"id":"CVE-2026-19200","vendor":"Rapid7","product":"Velociraptor","severity":"HIGH","score":8.9,"description":"The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19200"}],"vendor_spikes":[{"vendor":"EmilStenstrom","count":10,"critical_count":2},{"vendor":"Unknown","count":10,"critical_count":0},{"vendor":"itsourcecode","count":5,"critical_count":0},{"vendor":"Microsoft","count":5,"critical_count":2},{"vendor":"SourceCodester","count":4,"critical_count":0},{"vendor":"code-projects","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":8,"new_cve_count":67,"has_news_data":true,"has_cve_data":true}