Skip to content

Morning Brief

Tuesday, August 25, 2026 · generated 2026-08-25 13:55 UTC · ~4 min read

Top developments

EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next

EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised mailbox to help criminals choose the contacts, payments, and…

Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages

Cybercriminals are using Google Sites to host fake download pages for OpenAI Codex, turning a familiar search into a malware trap. The campaign targets macOS users and relies on paid search placements to steer them…

You don't want this Sleepwalker backdoor on your Windows machine

Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the…

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity…

CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited…

ToxicPanda Banking Trojan Matures Into Enterprise Threat

The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.

Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts

Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, tracked as…

Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account

Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the…

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming…

Vulnerability watch

CVE-2026-66897 Canonical · LXD CWE-22 CRITICAL 9.9 · EPSS 0%

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target …

CVE-2026-32559 tophive · UltimateAI CWE-434 CRITICAL 9.9

Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

CVE-2026-28165 UnitedOver, LLC · Digits CWE-266 CRITICAL 9.8

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

CVE-2026-32558 WordPress · Affiliate Pro - Affiliate Program for WooCommerce & WordPress CWE-266 CRITICAL 9.8

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

CVE-2026-66587 WPCafe · WP Cafe Pro CWE-98 CRITICAL 9.8

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

CVE-2026-66648 MVPThemes · Jawn CWE-266 CRITICAL 9.8

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

CVE-2026-66650 Theme-Rex · FreightCo CWE-502 CRITICAL 9.8

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

CVE-2026-76070 Netis Systems · NC63 CWE-121 CRITICAL 9.8

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler…

CVE-2026-76071 Netis Systems · NC63 CWE-121 CRITICAL 9.8

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod ac…

CVE-2026-77915 rconfig · rconfig CWE-306 CRITICAL 9.8

rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php tha…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →