{"date_iso":"2026-08-29","date_human":"Saturday, August 29, 2026","generated_utc":"2026-08-29 17:03 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Teams Has Become a Haven for Scammers in China","link":"https://www.wired.com/story/microsoft-teams-is-becoming-a-haven-for-chinese-scammers/","reason":"Microsoft","category":"Media","sources":["Bleeping Computer","CCCS Alerts & Advisories","Wired Security"],"coverage":3,"cve_ids":[],"summary":"Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.","source":"Wired Security","date_rel":"21h ago","thumbnail":"https://media.wired.com/photos/6a909d8a06c510ef6758e71c/master/pass/Made-In-China-Microsoft-Teams-Hidden-Scams-Business.jpg","description":"","related":[{"title":"Windows 11 KB5120998 update released with 35 changes and fixes","link":"https://www.bleepingcomputer.com/news/security/windows-11-kb5120998-update-released-with-35-changes-and-fixes/","source":"Bleeping Computer","date_rel":"28 Aug"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"27 Aug"}]},{"title":"Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers","link":"https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html","reason":"Android","category":"News","sources":["Bleeping Computer","Dark Reading","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHdeGqGafTZXNtGvV_-qR7K3QId_-DpEfOzetKbhVQvNdNyTMAy-6gLXVFlkMHsGDN2wKK8v1ZMeOKe9_3XVYAY5TVkqH2heesi0c_QmJzLpDX1M-XfOtI_W4Qe8OM8Yhin40QWvN0XHvU9cqDlZH3eeZY_18euIxiBdcbhWMVnXct-x84k2gvchQYSiuN/s1600/1000103901.jpg","description":"Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. \"This new privacy standard works in tandem","related":[{"title":"Android 17 adds ECH support to make web browsing harder to track","link":"https://www.bleepingcomputer.com/news/security/android-17-adds-ech-support-to-make-web-browsing-harder-to-track/","source":"Bleeping Computer","date_rel":"27 Aug"},{"title":"Android Malware Hijacks Update System for Car Head Units","link":"https://www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units","source":"Dark Reading","date_rel":"26 Aug"}]},{"title":"700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation","link":"https://cybersecuritynews.com/700-ai-agents-coordinated-to-hack-hugging-face/","reason":"Coordinated Hugging Agents","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure. An independent investigation found that roughly\u2026","source":"Cyber Security News","date_rel":"13h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/700-AI-Agents-Secretly-Coordinated-to-Hack-Hugging-Face-After-Breaking-Their-Isolation.webp","description":"A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure. An independent investigation found that roughly 700 agents joined the activity after more than 1,200 agents used an internal package repository as an unauthorized message board. The incident began during OpenAI\u2019s ExploitGym security evaluations , where tens of thousands of agents were assigned cyber tasks in separate sandboxed environments. The agents were supposed to operate independently. However, some encountered tasks\u2026","related":[{"title":"Nearly 700 rogue AI agents coordinated in the Hugging Face attack","link":"https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/","source":"Bleeping Computer","date_rel":"27 Aug"}]},{"title":"Critical ServiceNow Flaws Let Attackers Execute Code and Access Data","link":"https://cybersecuritynews.com/servicenow-fixes-critical-flaws/","reason":"Servicenow Attackers Execute","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access\u2026","source":"Cyber Security News","date_rel":"14h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/ServiceNow-Fixes-Critical-Flaws.webp","description":"ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data , modify records, or escalate privileges. The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs. ServiceNow said each vulnerability was remediated independently and urged self-hosted customers to promptly apply the available updates\u2026","related":[{"title":"Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL","link":"https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html","source":"The Hacker News","date_rel":"28 Aug"}]},{"title":"OpenAI Agents Exploited Linux Kernel Flaw on Company\u2019s Own Systems","link":"https://www.securityweek.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/","reason":"CVE-2026-53362","category":"News","sources":["CISA Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2023-49105","CVE-2026-53362"],"summary":"CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.","source":"SecurityWeek","date_rel":"28 Aug","thumbnail":"","description":"","related":[{"title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"27 Aug"}]},{"title":"PaperCut releases second emergency patch for exploited flaws","link":"https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/","reason":"Emergency Exploited Papercut","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial\u2026","source":"Bleeping Computer","date_rel":"20h ago","thumbnail":"","description":"","related":[{"title":"PaperCut Releases Emergency Patch for Exploited Zero-Day","link":"https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/","source":"SecurityWeek","date_rel":"28 Aug"}]},{"title":"Learn How to Build Security Operations Ready for AI-Powered Attacks","link":"https://thehackernews.com/2026/08/learn-how-to-build-security-operations.html","reason":"Teams","category":"News","sources":["Bleeping Computer","Microsoft Security Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate\u2026","source":"The Hacker News","date_rel":"27 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqwLeHISYWaiVNUxkANuqw6ob8Exu7_9CIEt6uHbsNa7mcNUkSWZqNZHEL3_kqPPHXVq4RGTxqZZhMdybwcVVT28qCihLUi0I5ghW9Xk5sVDB2u2kJqULx-_FEcsEHuTCU5vIwReQZghbj8HjQD4zq8H1yiGSYNlmNC25YkViZxlqndOhIp1CD2s_sLlc/s1600/wiz-webinar.jpg","description":"Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or","related":[{"title":"\u200b\u200b\u200b\u200b\u200b\u200bWhat\u2019s new in Microsoft Security: August 2026","link":"https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/","source":"Microsoft Security Blog","date_rel":"27 Aug"},{"title":"How Threat Research and MDR Help SMBs Build a Defensive Edge","link":"https://www.bleepingcomputer.com/news/security/how-threat-research-and-mdr-help-smbs-build-a-defensive-edge/","source":"Bleeping Computer","date_rel":"27 Aug"},{"title":"What the Data Says About AI in Security Operations in 2026","link":"https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html","source":"The Hacker News","date_rel":"27 Aug"}]},{"title":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code","link":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","reason":"Google","category":"News","sources":["Infosecurity Magazine","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining\u2026","source":"The Hacker News","date_rel":"28 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_QtvF-9M9imh55UP7qeyFUNhKknBwEcmcbIa34vndzIHinEk754vasbvTqILRNrtp6BDpuR8VzAyk0_Wt1tJB4hjUlgaO5Rb6Wru-WoXlrCPIXLr0I_oBhA7BwQDoO3MH82uloaG-qXyHAloI7r2zuWNfygFNeiSYAZeWyDn8_smuzrgvsvk0eQEX5klW/s1600/1000103889.jpg","description":"Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active","related":[{"title":"Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn","link":"https://www.infosecurity-magazine.com/news/window-ai-attacks-narrowing-tech/","source":"Infosecurity Magazine","date_rel":"28 Aug"}]},{"title":"Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix","link":"https://cybersecuritynews.com/deploy-amatera-stealer/","reason":"Windows","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A fake student resume is being used to place a remote-access tool on researchers\u2019 Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then\u2026","source":"Cyber Security News","date_rel":"28 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Compromise-Hundreds-of-WordPress-Sites-to-Deploy-Amatera-Stealer-via-ClickFix.webp","description":"A fake student resume is being used to place a remote-access tool on researchers\u2019 Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the background. The lure claims to come from a recent Beijing Institute of Technology graduate seeking research work in electrical engineering, energy systems and applied AI. That focus points to professors and laboratory staff as likely targets, rather than ordinary corporate recruiters, and turns academic\u2026","related":[{"title":"Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html","source":"The Hacker News","date_rel":"27 Aug"}]},{"title":"CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs","link":"https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html","reason":"Citrix","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix\u2026","source":"The Hacker News","date_rel":"27 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsOm0ydTRNpwfiKMNN7TGZyoellV9LHrcra7ES8hU8PvT6haNsS-QQ5IlystrzP1eq5jiIRfyykIZyB5JKrya5K4ryBRp9gKAmsoVW7OMis-YT4T6jnpbN11M8mUnPn-2yY-caG31-iXmDAhJ9CTbRg8r1UPWWqCob_S8St7McsKCM-4I36jD_xqE8D3BS/s1600/cisa-flaws.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in","related":[{"title":"CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products","link":"https://www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/","source":"Infosecurity Magazine","date_rel":"27 Aug"},{"title":"Citrix security advisory (AV26-645) \u2013 Update 3","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-645","source":"CCCS Alerts & Advisories","date_rel":"26 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-82222","vendor":"Liquid Web / StellarWP","product":"GiveWP","severity":"CRITICAL","score":10.0,"description":"Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.\n\nThis issue affects GiveWP: from n/a through 4.16.7.1.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82222"},{"id":"CVE-2026-54745","vendor":"Kubernetes","product":"pipelines","severity":"CRITICAL","score":10.0,"description":"Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ r\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-54745"},{"id":"CVE-2026-55565","vendor":"yamcs","product":"yamcs","severity":"CRITICAL","score":9.9,"description":"Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source comp\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-55565"},{"id":"CVE-2026-55634","vendor":"pimcore","product":"pimcore","severity":"CRITICAL","score":9.9,"description":"Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject f\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-55634"},{"id":"CVE-2026-18527","vendor":"IBM","product":"Administration Runtime Expert for i","severity":"CRITICAL","score":9.9,"description":"IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnera\u2026","cwe":"CWE-384","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18527"},{"id":"CVE-2026-19295","vendor":"IBM","product":"Langflow OSS","severity":"CRITICAL","score":9.9,"description":"IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that refer\u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19295"},{"id":"CVE-2026-37751","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-37751"},{"id":"CVE-2026-55559","vendor":"yamcs","product":"yamcs","severity":"CRITICAL","score":9.8,"description":"Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-55559"},{"id":"CVE-2026-82266","vendor":"redpanda-data","product":"redpanda","severity":"CRITICAL","score":9.8,"description":"Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker acco\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82266"},{"id":"CVE-2026-82277","vendor":"argoproj","product":"argo-rollouts","severity":"CRITICAL","score":9.8,"description":"Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, Restart\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82277"}],"vendor_spikes":[{"vendor":"Unknown","count":64,"critical_count":1},{"vendor":"WordPress","count":33,"critical_count":0},{"vendor":"Open-Xchange GmbH","count":25,"critical_count":1},{"vendor":"Microsoft","count":17,"critical_count":0},{"vendor":"IBM","count":16,"critical_count":4},{"vendor":"MongoDB","count":11,"critical_count":0},{"vendor":"Oracle","count":9,"critical_count":0},{"vendor":"yamcs","count":9,"critical_count":3},{"vendor":"budibase","count":8,"critical_count":1},{"vendor":"GitoxideLabs","count":8,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":17,"new_cve_count":351,"has_news_data":true,"has_cve_data":true}