{"date_iso":"2026-08-25","date_human":"Tuesday, August 25, 2026","generated_utc":"2026-08-25 13:55 UTC","read_minutes":4,"patch_tuesday":false,"top_stories":[{"title":"EvilTokens Doesn\u2019t Just Steal Microsoft Sessions\u2014Its AI Tells Attackers Who to Scam Next","link":"https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","Rapid7 Blog","Zero Day Initiative"],"coverage":6,"cve_ids":["CVE-2026-63520"],"summary":"EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised mailbox to help criminals choose the contacts, payments, and\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/EvilTokens-Doesnt-Just-Steal-Microsoft-Sessions\u2014Its-AI-Tells-Attackers-Who-to-Scam-Next.webp","description":"EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised mailbox to help criminals choose the contacts, payments, and conversations most likely to produce fraud. Unlike a conventional credential-stealing kit, the operation uses a real Microsoft sign-in process. A lure sends the target to a controlled page, where a device code is created and the user is directed to Microsoft\u2019s authentic login site to approve it. That same OAuth device code phishing pattern leaves victims at a genuine destination, not\u2026","related":[{"title":"Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)","link":"https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520","source":"Rapid7 Blog","date_rel":"20h ago"},{"title":"Fake Microsoft security scans trick victims into uninstalling their antivirus","link":"https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus","source":"Malwarebytes Labs","date_rel":"21h ago"},{"title":"Microsoft Teams now lets admins block external bots from meetings","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-now-lets-admins-block-external-bots-from-meetings/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Doubloon Dredger Abuses Notion to Harvest Authentication Tokens","link":"https://www.infosecurity-magazine.com/news/doubloon-dredger-notion/","source":"Infosecurity Magazine","date_rel":"23h ago"},{"title":"Microsoft: August updates break printing, PDF export in WPF apps","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-august-updates-break-printing-pdf-export-in-wpf-apps/","source":"Bleeping Computer","date_rel":"23h ago"},{"title":"Microsoft shares temporary fix for Windows 11 gaming issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-temporary-fix-for-windows-11-gaming-issues/","source":"Bleeping Computer","date_rel":"24 Aug"}]},{"title":"Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages","link":"https://cybersecuritynews.com/hackers-abuse-google-sites/","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Infosecurity Magazine","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Cybercriminals are using Google Sites to host fake download pages for OpenAI Codex, turning a familiar search into a malware trap. The campaign targets macOS users and relies on paid search placements to steer them\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Abuse-Google-Sites-to-Host-Fake-OpenAI-Codex-Download-Pages.webp","description":"Cybercriminals are using Google Sites to host fake download pages for OpenAI Codex, turning a familiar search into a malware trap. The campaign targets macOS users and relies on paid search placements to steer them toward a convincing but fraudulent installer page. The page does not simply deliver a harmful app. It tells visitors to copy a command, open Terminal, and run it themselves. That approach, known as ClickFix, shifts the final execution step to the victim and can bypass the suspicion normally raised by an unexpected download. Cato analysts identified the activity after tracking\u2026","related":[{"title":"Crooks push Mac malware through fake OpenAI Codex ads","link":"https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads/5291899","source":"The Register Security","date_rel":"3h ago"},{"title":"Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds","link":"https://cybersecuritynews.com/google-results-minecraft-client/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"Google security advisory (AV26-844)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-844","source":"CCCS Alerts & Advisories","date_rel":"17h ago"},{"title":"Fake Codex Download Uses Google Sites to Deliver macOS Malware","link":"https://www.infosecurity-magazine.com/news/fake-codex-download-google-sites/","source":"Infosecurity Magazine","date_rel":"21h ago"}]},{"title":"You don't want this Sleepwalker backdoor on your Windows machine","link":"https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021","reason":"Windows","category":"News","sources":["Bleeping Computer","Microsoft Security","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-50661"],"summary":"Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the\u2026","source":"The Register Security","date_rel":"14h ago","thumbnail":"https://image.theregister.com/?imageId=5292027&width=800","description":"Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor, which also has its own command language, and detailed Sleepwalker in a technical analysis on Monday. \u201cWhat makes it worth writing up is what that packet carries: not a readable\u2026","related":[{"title":"CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661","source":"Microsoft Security","date_rel":"22h ago"},{"title":"WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords","link":"https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html","source":"The Hacker News","date_rel":"23h ago"},{"title":"Named Pipes Under Attack: Securing Windows Interprocess Communication","link":"https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/","source":"Bleeping Computer","date_rel":"22 Aug"}]},{"title":"CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw","link":"https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/5292107","reason":"Oracle","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity\u2026","source":"The Register Security","date_rel":"1h ago","thumbnail":"https://image.theregister.com/?imageId=1682641&width=800","description":"The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs. Tracked as CVE-2026-21962 (10.0), the improper access control (CWE-284) flaw affects Oracle\u2019s HTTP Server and WebLogic Server Proxy Plug-in. Successful attacks targeting CVE-2026-21962 can allow miscreants to create, delete, or modify access to critical data, and even gain \u201ccomplete access\u201d to all data stored on the affected systems. Oracle\u2026","related":[{"title":"Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data","link":"https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html","source":"The Hacker News","date_rel":"6h ago"},{"title":"Oracle security advisory \u2013 January 2026 quarterly rollup (AV26-042) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-january-2026-quarterly-rollup-av26-042","source":"CCCS Alerts & Advisories","date_rel":"17h ago"}]},{"title":"CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/oracle-http-and-weblogic-server-vulnerability-exploited/","reason":"CVE-2026-21962","category":"News","sources":["CISA Alerts & Advisories","Cyber Security News","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2026-21962"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CISA-Warns-of-Oracle-HTTP-and-Weblogic-Server-Vulnerability-Exploited-in-Attacks.png","description":"The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition confirms that attackers are actively exploiting the vulnerability in real-world attacks. Organizations with affected Oracle infrastructure should identify exposed systems and apply available Oracle security updates or mitigations as a priority. CVE-2026-21962 affects components commonly deployed in enterprise environments to route and\u2026","related":[{"title":"CISA Warns of Exploited Oracle WebLogic Vulnerability","link":"https://www.securityweek.com/cisa-warns-of-exploited-oracle-weblogic-vulnerability/","source":"SecurityWeek","date_rel":"4h ago"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"24 Aug"}]},{"title":"ToxicPanda Banking Trojan Matures Into Enterprise Threat","link":"https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat","reason":"Android","category":"News","sources":["Bleeping Computer","Dark Reading","Malwarebytes Labs","The Record"],"coverage":4,"cve_ids":[],"summary":"The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.","source":"Dark Reading","date_rel":"21h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltd1dbd4251686aed8/6a8c90973725ccfa2c8aef7d/panda_Oneinchpunch_Alamy_16_X_9_VERSION.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"ToxicPanda 2.0 can take over your Android phone and banking apps","link":"https://www.malwarebytes.com/blog/mobile/2026/08/toxicpanda-2-0-can-take-over-your-android-phone-and-banking-apps","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Hackers infecting Android car systems to build proxy botnet","link":"https://therecord.media/android-botnet-china-hackers","source":"The Record","date_rel":"24 Aug"},{"title":"ToxicPanda Android malware uses VPN permissions to block Google Play","link":"https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/","source":"Bleeping Computer","date_rel":"23 Aug"},{"title":"Hackers infect Android car head units with proxy botnet malware","link":"https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/","source":"Bleeping Computer","date_rel":"22 Aug"}]},{"title":"Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts","link":"https://cybersecuritynews.com/hackers-exploit-critical-miniorange-saml-sso-flaws/","reason":"Wordpress","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, tracked as\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Exploit-Critical-miniOrange-SAML-SSO-Flaws-to-Hijack-WordPress-Admin-Accounts.webp","description":"Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have been linked to attempted exploitation activity in the wild. The vulnerabilities affect miniOrange\u2019s SAML-based single sign-on software, which lets WordPress sites authenticate users through an external Identity Provider. By exploiting weaknesses in the plugin\u2019s SAML signature validation, attackers can forge an\u2026","related":[{"title":"Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access","link":"https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html","source":"The Hacker News","date_rel":"3h ago"},{"title":"Hackers target WordPress sites in miniOrange auth bypass attacks","link":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/","source":"Bleeping Computer","date_rel":"17h ago"}]},{"title":"Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account","link":"https://cybersecuritynews.com/red-hat-keycloak-flaw/","reason":"Unauthenticated Attackers Keycloak","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-18963"],"summary":"Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Critical-Red-Hat-Keycloak-Flaw-Lets-Unauthenticated-Attackers-Take-Over-Any-User-Account.webp","description":"Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the password recovery process and carries a CVSS v3.1 score of 9.1. The vulnerability exists in the reset-credentials flow of the keycloak-services component, the core identity and access management engine used by Red Hat Build of Keycloak. According to Red Hat, an attacker can trigger a password reset for any target account and bypass the email verification action that should\u2026","related":[{"title":"Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account","link":"https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html","source":"The Hacker News","date_rel":"24 Aug"}]},{"title":"UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit","link":"https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html","reason":"Linux","category":"News","sources":["The Hacker News","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming\u2026","source":"The Hacker News","date_rel":"24 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4-mx98ENuq77sCTBd49TSl4Ov5dD1Wua0Vf1MiyVVPfcFckY__TjnTEOeC5CIQWX4L_OLA-xZHHY5nAlp926SIpa3eK8Tvfw1HSHHK1GMot7noTz4Cg36t-ZuZ-NUh5mnsfzs0HJ8F7p410LgWFVPN39PYh8YR6qkDlE8duNKmKpOtJHW4NA9T_ddTGLp/s1600/hackers.jpg","description":"Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open","related":[{"title":"ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-609/","source":"Zero Day Initiative","date_rel":"24 Aug"},{"title":"ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-608/","source":"Zero Day Initiative","date_rel":"24 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-66897","vendor":"Canonical","product":"LXD","severity":"CRITICAL","score":9.9,"description":"A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target \u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":0.0062,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66897"},{"id":"CVE-2026-32559","vendor":"tophive","product":"UltimateAI","severity":"CRITICAL","score":9.9,"description":"Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-32559"},{"id":"CVE-2026-28165","vendor":"UnitedOver, LLC","product":"Digits","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Privilege Escalation in Digits <= 9.2 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28165"},{"id":"CVE-2026-32558","vendor":"WordPress","product":"Affiliate Pro - Affiliate Program for WooCommerce & WordPress","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-32558"},{"id":"CVE-2026-66587","vendor":"WPCafe","product":"WP Cafe Pro","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.","cwe":"CWE-98","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66587"},{"id":"CVE-2026-66648","vendor":"MVPThemes","product":"Jawn","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66648"},{"id":"CVE-2026-66650","vendor":"Theme-Rex","product":"FreightCo","severity":"CRITICAL","score":9.8,"description":"Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66650"},{"id":"CVE-2026-76070","vendor":"Netis Systems","product":"NC63","severity":"CRITICAL","score":9.8,"description":"Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler\u2026","cwe":"CWE-121","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76070"},{"id":"CVE-2026-76071","vendor":"Netis Systems","product":"NC63","severity":"CRITICAL","score":9.8,"description":"Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod ac\u2026","cwe":"CWE-121","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76071"},{"id":"CVE-2026-77915","vendor":"rconfig","product":"rconfig","severity":"CRITICAL","score":9.8,"description":"rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php tha\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77915"}],"vendor_spikes":[{"vendor":"DrayTek Corporation","count":40,"critical_count":3},{"vendor":"WordPress","count":24,"critical_count":3},{"vendor":"Unknown","count":18,"critical_count":0},{"vendor":"getgrav","count":15,"critical_count":1},{"vendor":"Red Hat","count":11,"critical_count":0},{"vendor":"ransomlook","count":11,"critical_count":0},{"vendor":"Dolibarr","count":10,"critical_count":0},{"vendor":"Apache","count":9,"critical_count":0},{"vendor":"vrana","count":9,"critical_count":1},{"vendor":"Microsoft","count":8,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":9,"new_cve_count":344,"has_news_data":true,"has_cve_data":true}