Skip to content

Morning Brief

Sunday, August 30, 2026 · generated 2026-08-30 17:18 UTC · ~5 min read

Top developments

Google's Calling Lake Ontario 'Lake America' Now

On Thursday, Trump signed an executive order demanding Lake Ontario be renamed to Lake America. At the signing of the order, he sat next to a big poster board map of the Great Lakes, with a big red arrow labeling Lake…

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct…

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining…

Microsoft Teams Has Become a Haven for Scammers in China

Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover…

700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation

A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure. An independent investigation found that roughly…

Critical ServiceNow Flaws Let Attackers Execute Code and Access Data

ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access…

PaperCut releases second emergency patch for exploited flaws

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial…

Vulnerability watch

CVE-2026-82456 argoproj-labs · argocd-mcp CWE-1327 CRITICAL 10.0

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface us…

CVE-2026-14494 WordPress · SigmaForms Pro – AI Generated Forms CWE-434 CRITICAL 9.8

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capabi…

CVE-2026-82448 Shinobi Systems · Shinobi CWE-798 CRITICAL 9.8

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key d…

CVE-2026-82452 iot-ecology · rust-iot-platform CWE-306 CRITICAL 9.8

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and d…

CVE-2026-82460 coderaiser · cloudcmd CWE-22 CRITICAL 9.8

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, o…

CVE-2026-15369 WordPress · Custom User Registration Fields for WooCommerce CWE-269 CRITICAL 9.8

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value …

CVE-2026-15980 WordPress · MyHome Core CWE-289 CRITICAL 9.8

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() fu…

CVE-2026-82454 Apple · omnivore CWE-347 CRITICAL 9.1

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed…

CVE-2026-82447 Skyvern-AI · skyvern CWE-1336 HIGH 8.8

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja templ…

CVE-2026-82450 bookstackapp · bookstack CWE-434 HIGH 8.8

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →