Skip to content

Morning Brief

Monday, August 31, 2026 · generated 2026-08-31 19:29 UTC · ~5 min read

Top developments

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct…

Security Risk Advisors Launches SCALR AI as a Free SOC AI Platform for Security Teams

Philadelphia, Pennsylvania, United States, August 24th, 2026, CyberNewswire Security Risk Advisors (SRA) , the authors of the free VECTR platform, announce today another great free platform launch: SCALR AI. Security…

Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India

Hackers are using adware to deliver ValleyRAT, a Windows backdoor. The campaign primarily affects users in China and India, turning a program expected to display ads into a route for spying, theft, and further malware…

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

Microsoft Investigating New Exchange Online Outage Tracked as EX1464935 [Updated]

Microsoft has opened an active investigation into a new Exchange Online disruption after a wave of user reports flagged access and mail-flow problems across the cloud-based email service. The incident, logged in the…

HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11

HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or…

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS)…

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.

Google's Calling Lake Ontario 'Lake America' Now

On Thursday, Trump signed an executive order demanding Lake Ontario be renamed to Lake America. At the signing of the order, he sat next to a big poster board map of the Great Lakes, with a big red arrow labeling Lake…

Vulnerability watch

CVE-2026-82542 Tenda · HG10 CWE-119 CRITICAL 10.0

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buff…

CVE-2026-82592 D-Link · DIR-825M CWE-119 CRITICAL 9.9

A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-ba…

CVE-2026-82593 D-Link · DIR-825M CWE-119 CRITICAL 9.9

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based b…

CVE-2026-82616 TOTOLINK · NR1800X CWE-119 CRITICAL 9.9

A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack ca…

CVE-2026-82874 ToolJet · ToolJet CWE-639 CRITICAL 9.9

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenan…

CVE-2026-82689 D-Link · DNS-320L CWE-77 CRITICAL 9.9

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIso…

CVE-2026-58574 Dell · PowerStore 500T CWE-306 CRITICAL 9.8

Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal syst…

CVE-2026-82854 nodemailer · nodemailer CWE-93 CRITICAL 9.8

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is…

CVE-2026-82855 hulumi · policies CWE-693 CRITICAL 9.8

@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers…

CVE-2026-82856 hulumi · policies CWE-284 CRITICAL 9.8

@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject condit…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →