Skip to content

Morning Brief

Thursday, August 27, 2026 · generated 2026-08-27 22:54 UTC · ~5 min read

Top developments

CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability , tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming…

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially…

Android Malware Hijacks Update System for Car Head Units

Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix…

Learn How to Build Security Operations Ready for AI-Powered Attacks

Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate…

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via…

Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data

A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear research body and a marine engineering company that serves the…

GitLab Fixes Claude AI Agent Flaw That Could Execute Arbitrary Commands in CI Pipeline

GitLab has released security updates to fix a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to execute arbitrary commands within CI pipeline contexts. The flaw, tracked…

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command…

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as…

Vulnerability watch

CVE-2026-60004 Gitea · Gitea CWE-94 CRITICAL 9.8 · EPSS 82%

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVE-2026-32566 WordPress · ACPT (Pro) - Custom Post Types Plugin for WordPress CWE-266 CRITICAL 9.8 · EPSS 0%

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

CVE-2026-78286 INFINITUM FORM · Geo Controller CWE-502 CRITICAL 9.8 · EPSS 0%

Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

CVE-2026-78292 hashthemes · Hash Form CWE-502 CRITICAL 9.8 · EPSS 0%

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

CVE-2026-74232 Zbtlink · L3_V2_8 CWE-300 CRITICAL 9.8

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2…

CVE-2026-74233 Zbtlink · WE1326 CWE-78 CRITICAL 9.8

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and M…

CVE-2026-59354 Broadcom · Spring Security (OAuth2 Authorization Server module) CWE-20 CRITICAL 9.6 · EPSS 0%

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields su…

CVE-2026-59270 Spring · Spring Security CRITICAL 9.4 · EPSS 0%

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spr…

CVE-2026-32479 CODEPRESS IT Solutions LLC · Visitor Traffic Real Time Statistics Pro CWE-89 CRITICAL 9.3 · EPSS 0%

Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

CVE-2026-78260 ePayco · Epayco CWE-89 CRITICAL 9.3 · EPSS 0%

Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →