{"date_iso":"2026-08-30","date_human":"Sunday, August 30, 2026","generated_utc":"2026-08-30 17:18 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Google's Calling Lake Ontario 'Lake America' Now","link":"https://www.404media.co/google-maps-lake-america-lake-ontario-name-change/","reason":"Google","category":"News","sources":["404 Media","CyberScoop","Infosecurity Magazine","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"On Thursday, Trump signed an executive order demanding Lake Ontario be renamed to Lake America. At the signing of the order, he sat next to a big poster board map of the Great Lakes, with a big red arrow labeling Lake\u2026","source":"404 Media","date_rel":"2h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/08/Screenshot-2026-08-30-at-8.42.47---AM.png","description":"On Thursday, Trump signed an executive order demanding Lake Ontario be renamed to Lake America. At the signing of the order, he sat next to a big poster board map of the Great Lakes, with a big red arrow labeling Lake Ontario as \"Lake America,\" with the words \"Making the Great Lakes Even Greater.\" The Canadian province of Ontario borders the north, west, and southwest sides of the lake, with New York State on the south and east. It was unclear in the days immediately following the order whether Google would respect the name change. MapQuest, the 1996 navigation service that still exists but\u2026","related":[{"title":"Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers","link":"https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html","source":"The Hacker News","date_rel":"28 Aug"},{"title":"Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn","link":"https://www.infosecurity-magazine.com/news/window-ai-attacks-narrowing-tech/","source":"Infosecurity Magazine","date_rel":"28 Aug"},{"title":"100-plus companies call for \u2018global surge\u2019 in AI-powered cyber defense","link":"https://cyberscoop.com/ai-cyber-defense-global-surge/","source":"CyberScoop","date_rel":"27 Aug"}]},{"title":"TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor","link":"https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html","reason":"Cloudflare","category":"News","sources":["Microsoft Security Blog","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. \"While traditional ClickFix campaigns direct\u2026","source":"The Hacker News","date_rel":"8h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpxriybAzLw0daA0mtL3sZd04fy8Sal4s0mrBAz2-ksjwfP2V08YK_KbCJY57hKG28Kt6gn2mKq4HFSpkG2MNvA3Oz6MhNUe77_1Nvpahn2nnCFHPpxIlp5Ix4DvAZw08qXtxt1M-4zCtSENbBkODQyP_WDp9j3PXACc0XKYk1BK1K-2Xabho1cBPqerW9/s1600/cf-clickfix.jpg","description":"Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. \"While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex","related":[{"title":"TerminalFix campaign deploys a reverse tunnel through multistage intrusion","link":"https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/","source":"Microsoft Security Blog","date_rel":"29 Aug"}]},{"title":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code","link":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining\u2026","source":"The Hacker News","date_rel":"28 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_QtvF-9M9imh55UP7qeyFUNhKknBwEcmcbIa34vndzIHinEk754vasbvTqILRNrtp6BDpuR8VzAyk0_Wt1tJB4hjUlgaO5Rb6Wru-WoXlrCPIXLr0I_oBhA7BwQDoO3MH82uloaG-qXyHAloI7r2zuWNfygFNeiSYAZeWyDn8_smuzrgvsvk0eQEX5klW/s1600/1000103889.jpg","description":"Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active","related":[{"title":"Chrome Web Store extensions caught stealing crypto, browser data","link":"https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/","source":"Bleeping Computer","date_rel":"1h ago"}]},{"title":"Microsoft Teams Has Become a Haven for Scammers in China","link":"https://www.wired.com/story/microsoft-teams-is-becoming-a-haven-for-chinese-scammers/","reason":"Microsoft","category":"Media","sources":["Bleeping Computer","CCCS Alerts & Advisories","Wired Security"],"coverage":3,"cve_ids":[],"summary":"Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.","source":"Wired Security","date_rel":"28 Aug","thumbnail":"https://media.wired.com/photos/6a909d8a06c510ef6758e71c/master/pass/Made-In-China-Microsoft-Teams-Hidden-Scams-Business.jpg","description":"","related":[{"title":"Windows 11 KB5120998 update released with 35 changes and fixes","link":"https://www.bleepingcomputer.com/news/security/windows-11-kb5120998-update-released-with-35-changes-and-fixes/","source":"Bleeping Computer","date_rel":"28 Aug"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"27 Aug"}]},{"title":"Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE","link":"https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiROOqCRPV4u9cWfJL8nvCYKi4Ake-ki3_uh8Qn8RJ0P20h3Mz_qxVfF856pJ9DQZMHy922CeLwOHDc37Gpb4p1UCTMx6cMT5HeeAP_w4RitCuQficYcGDDkqpDVfW_nA3M7qWT-WyM6A5Adk3J2e8kMWSG1GSUOatrcVBmc7fmb2-ovadVS3fOdkd1ubFx/s1600/wordpress-themes.jpg","description":"Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in","related":[{"title":"GiveWP WordPress donation plugin flaw lets hackers execute server commands","link":"https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/","source":"Bleeping Computer","date_rel":"28 Aug"}]},{"title":"700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation","link":"https://cybersecuritynews.com/700-ai-agents-coordinated-to-hack-hugging-face/","reason":"Coordinated Hugging Agents","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure. An independent investigation found that roughly\u2026","source":"Cyber Security News","date_rel":"29 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/700-AI-Agents-Secretly-Coordinated-to-Hack-Hugging-Face-After-Breaking-Their-Isolation.webp","description":"A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure. An independent investigation found that roughly 700 agents joined the activity after more than 1,200 agents used an internal package repository as an unauthorized message board. The incident began during OpenAI\u2019s ExploitGym security evaluations , where tens of thousands of agents were assigned cyber tasks in separate sandboxed environments. The agents were supposed to operate independently. However, some encountered tasks\u2026","related":[{"title":"Nearly 700 rogue AI agents coordinated in the Hugging Face attack","link":"https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/","source":"Bleeping Computer","date_rel":"27 Aug"}]},{"title":"Critical ServiceNow Flaws Let Attackers Execute Code and Access Data","link":"https://cybersecuritynews.com/servicenow-fixes-critical-flaws/","reason":"Servicenow Attackers Execute","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access\u2026","source":"Cyber Security News","date_rel":"29 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/ServiceNow-Fixes-Critical-Flaws.webp","description":"ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data , modify records, or escalate privileges. The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs. ServiceNow said each vulnerability was remediated independently and urged self-hosted customers to promptly apply the available updates\u2026","related":[{"title":"Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL","link":"https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html","source":"The Hacker News","date_rel":"28 Aug"}]},{"title":"PaperCut releases second emergency patch for exploited flaws","link":"https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/","reason":"Exploited Emergency Releases","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial\u2026","source":"Bleeping Computer","date_rel":"28 Aug","thumbnail":"","description":"","related":[{"title":"PaperCut Releases Emergency Patch for Exploited Zero-Day","link":"https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/","source":"SecurityWeek","date_rel":"28 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-82456","vendor":"argoproj-labs","product":"argocd-mcp","severity":"CRITICAL","score":10.0,"description":"argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface us\u2026","cwe":"CWE-1327","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82456"},{"id":"CVE-2026-14494","vendor":"WordPress","product":"SigmaForms Pro \u2013 AI Generated Forms","severity":"CRITICAL","score":9.8,"description":"The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capabi\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14494"},{"id":"CVE-2026-82448","vendor":"Shinobi Systems","product":"Shinobi","severity":"CRITICAL","score":9.8,"description":"Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key d\u2026","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82448"},{"id":"CVE-2026-82452","vendor":"iot-ecology","product":"rust-iot-platform","severity":"CRITICAL","score":9.8,"description":"rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and d\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82452"},{"id":"CVE-2026-82460","vendor":"coderaiser","product":"cloudcmd","severity":"CRITICAL","score":9.8,"description":"Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, o\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82460"},{"id":"CVE-2026-15369","vendor":"WordPress","product":"Custom User Registration Fields for WooCommerce","severity":"CRITICAL","score":9.8,"description":"The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value \u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15369"},{"id":"CVE-2026-15980","vendor":"WordPress","product":"MyHome Core","severity":"CRITICAL","score":9.8,"description":"The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() fu\u2026","cwe":"CWE-289","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15980"},{"id":"CVE-2026-82454","vendor":"Apple","product":"omnivore","severity":"CRITICAL","score":9.1,"description":"The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed\u2026","cwe":"CWE-347","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82454"},{"id":"CVE-2026-82447","vendor":"Skyvern-AI","product":"skyvern","severity":"HIGH","score":8.8,"description":"Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja templ\u2026","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82447"},{"id":"CVE-2026-82450","vendor":"bookstackapp","product":"bookstack","severity":"HIGH","score":8.8,"description":"BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82450"}],"vendor_spikes":[{"vendor":"WordPress","count":10,"critical_count":3},{"vendor":"pac4j","count":5,"critical_count":0},{"vendor":"jeremyevans","count":5,"critical_count":0},{"vendor":"itsourcecode","count":4,"critical_count":0},{"vendor":"ash-project","count":4,"critical_count":0},{"vendor":"NASA","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":8,"new_cve_count":61,"has_news_data":true,"has_cve_data":true}