[{"date_iso":"2026-08-05","date_human":"Wednesday, August 5, 2026","generated_utc":"2026-08-05 13:37 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks","link":"https://cybersecuritynews.com/1-click-rce-vulnerability-in-code-editors/","reason":"Google","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","Malwarebytes Labs","Proofpoint Threat Insight","The Hacker News","The Register Security"],"coverage":7,"cve_ids":[],"summary":"A critical one-click remote code execution (RCE) vulnerability affects three of the world\u2019s most widely used code editors: Cursor, Microsoft VS Code, and Google Antigravity . The flaw, uncovered by AISLE, exposes an\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/1-Click-RCE-Vulnerability-in-Code-Editors.webp","description":"A critical one-click remote code execution (RCE) vulnerability affects three of the world\u2019s most widely used code editors: Cursor, Microsoft VS Code, and Google Antigravity . The flaw, uncovered by AISLE, exposes an estimated 50 million software developers at risk of silent, total system compromise with nothing more than a single click on a malicious link. The vulnerability has since been patched across all three platforms, but its discovery highlights how quickly security flaws can propagate across AI-native developer tooling. 1-Click RCE Vulnerability in Code Editors The exploit hinged on a\u2026","related":[{"title":"AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls","link":"https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls","source":"Dark Reading","date_rel":"21h ago"},{"title":"Online backlash ends in Google rolling back Google Earth AI tool after a day","link":"https://www.malwarebytes.com/blog/news/2026/08/online-backlash-ends-in-google-rolling-back-google-earth-ai-tool-after-a-day","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today\u2019s Most Sophisticated Threats","link":"https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-joins-google-unified-security-recommended-program-help","source":"Proofpoint Threat Insight","date_rel":"23h ago"},{"title":"New Pass-ta-key attacks let malware hijack Google-synced passkeys","link":"https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"Google dev kit spurs first-ever agent-on-agent violence","link":"https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496","source":"The Register Security","date_rel":"3 Aug"},{"title":"Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts","link":"https://thehackernews.com/2026/08/google-password-manager-attacks-could.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation","link":"https://cybersecuritynews.com/microsoft-defender-stops-qnet-ransomware-attack/","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Cyber Security News","Malwarebytes Labs","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted Windows tools to launch a second stage of an intrusion. The\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Microsoft-Defender-Stops-QNET-Ransomware-Attack-in-128-Seconds-With-Automatic-Device-Isolation.webp","description":"Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted Windows tools to launch a second stage of an intrusion. The attack began after a user opened a malicious file, likely delivered through email or a browser download. It launched mshta.exe, a legitimate Windows utility, which contacted attacker-controlled infrastructure to collect a remote payload and prepare persistent activity. Microsoft analysts noted that the operation used a living-off-the-land method, meaning it relied on a built-in\u2026","related":[{"title":"Phishing service spoofs RingCentral to steal Microsoft 365 accounts","link":"https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/","source":"Bleeping Computer","date_rel":"12h ago"},{"title":"Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers","link":"https://cybersecuritynews.com/hackers-weaponize-microsoft-copilot/","source":"Cyber Security News","date_rel":"17h ago"},{"title":"Microsoft Tells Engineers \u2018Tokenmaxxing Is Not What We Are Optimizing For\u2019","link":"https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/","source":"404 Media","date_rel":"18h ago"},{"title":"AI helps Microsoft bug hunters chase a record $20M payday","link":"https://www.theregister.com/security/2026/08/04/ai-helps-microsoft-bug-hunters-chase-a-record-20m-payday/5282821","source":"The Register Security","date_rel":"19h ago"},{"title":"Travelers targeted when logging into hotel Wi-Fi networks","link":"https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts","link":"https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/","source":"Bleeping Computer","date_rel":"4 Aug"}]},{"title":"CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild","reason":"CVE-2026-18577","category":"Research","sources":["Bleeping Computer","CISA Alerts & Advisories","Dark Reading","Rapid7 Blog","Sophos Threat Research","The Hacker News"],"coverage":6,"cve_ids":["CVE-2026-18577"],"summary":"Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix\u2026","source":"Rapid7 Blog","date_rel":"23h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments. N-able N-central is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and\u2026","related":[{"title":"N-able N-central exploitation results in RMM tool deployment","link":"https://www.sophos.com/en-us/blog/nable-ncentral-exploitation-results-in-rmm-tool-deployment","source":"Sophos Threat Research","date_rel":"4 Aug"},{"title":"Attackers Exploit N-able Patch Bypass Flaw on RMM Servers","link":"https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw","source":"Dark Reading","date_rel":"3 Aug"},{"title":"N-able warns of N-central auth bypass flaw exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"3 Aug"},{"title":"N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete","link":"https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen","link":"https://cybersecuritynews.com/7-zip-mark-of-the-web-bypass/","reason":"Windows","category":"News","sources":["Bleeping Computer","Cyber Security News","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-50341"],"summary":"Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to start without a Windows SmartScreen prompt. ZIP\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/7-Zip-Mark-of-the-Web-Bypass-Lets-Malicious-Files-Evade-Windows-SmartScreen.webp","description":"Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to start without a Windows SmartScreen prompt. ZIP archives are common in phishing campaigns. The gap grows when an archive looks like an invoice, update, or shared document. An attacker sends a link or attachment that leads to an archive, persuades the recipient to extract it with 7-Zip, then relies on the unmarked file being launched. This is not a newly disclosed exploit in 7-Zip code, but a security-control gap caused by the\u2026","related":[{"title":"QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer","link":"https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html","source":"The Hacker News","date_rel":"4h ago"},{"title":"New DOUBLECUP ClickFix service hides malware in browser cache images","link":"https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50341","source":"Microsoft Security","date_rel":"3 Aug"}]},{"title":"Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent","link":"https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html","reason":"Github","category":"News","sources":["Bleeping Computer","CyberScoop","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLUUlqxE9AYL9PyFAlWMsG9czDcrU9p2kMUsumVIYx5SnlMAO0z-n_weUWeX-CiMHQBbkGK1lV-78vp003-bAeRP4gQRyGXlq5blzx5dJdd9zFttd2tjhGlNUFLNk-6ro9GfXMkRCFVLs-ex3gWHoJh-87sZifOeTKohLNoypvvqLUUPLkGUsjKXfAj7A/s1600/google.gif","description":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied","related":[{"title":"Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack","link":"https://www.securityweek.com/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Massive supply-chain attack compromises 440 packages under four hours","link":"https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/","source":"CyberScoop","date_rel":"12h ago"},{"title":"New XCSSET variant targets macOS devs via compromised Xcode projects","link":"https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/","source":"Bleeping Computer","date_rel":"15h ago"}]},{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","reason":"Android","category":"Media","sources":["Bleeping Computer","Malwarebytes Labs","Wired Security"],"coverage":3,"cve_ids":[],"summary":"Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.","source":"Wired Security","date_rel":"2 Aug","thumbnail":"https://media.wired.com/photos/690270685216e0070a31d8d0/master/pass/The%20Best%20Password%20Managers%20to%20Secure%20Your%20Digital%20Life.png","description":"","related":[{"title":"Junk Cleaner clears the clutter from your Android","link":"https://www.malwarebytes.com/blog/product/2026/08/junk-cleaner-clears-the-clutter-from-your-android","source":"Malwarebytes Labs","date_rel":"1h ago"},{"title":"Inside the Underground Business of the Android BTMOB RAT malware","link":"https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/","source":"Bleeping Computer","date_rel":"3 Aug"}]},{"title":"Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams","link":"https://cybersecuritynews.com/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/","reason":"Teams","category":"News","sources":["Cyber Security News","Elastic Security Labs","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the\u2026","source":"Cyber Security News","date_rel":"17h ago","thumbnail":"https://i3.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilQYFaXQzJutaH7hl-0b-fZNl9Pj2QFfhn8y0WC8tl8petfT-OsvUOQBOGQqs-J5TihxgGHU0eLHls9Pq6UQHMGfCs10CqW7G_A93fDrInS8ydHhPGYfbK5Pts0WxUvLKUW6swCn2i9Z00hQZTZH7yiqEoz_K80W2Oy7GaElclO45TC0rgZhGEwFhjI1c/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20project,%20one%20team,%20o%20(81).webp?ssl=1","description":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the tools security teams already run Mallory , the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams. The architecture has three parts: a context graph that correlates attack surface, threat, and vulnerability data; an intelligent reasoning layer that determines what matters and why; and a policy and\u2026","related":[{"title":"Wiz at Black Hat 2026: Driving AI Threat Readiness","link":"https://www.wiz.io/blog/wiz-at-black-hat-2026","source":"Wiz Research","date_rel":"21h ago"},{"title":"When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted","link":"https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html","source":"The Hacker News","date_rel":"22h ago"},{"title":"FOMO in the SOC: Where AI Platforms like Claude Actually Fit","link":"https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html","source":"The Hacker News","date_rel":"3 Aug"},{"title":"SOC case management and detection rule history in Elastic Security","link":"https://www.elastic.co/security-labs/soc-case-management-detection-rule-history","source":"Elastic Security Labs","date_rel":"3 Aug"}]},{"title":"Apple launches new legal challenge against UK over iCloud access","link":"https://therecord.media/apple-uk-tcn-icloud-new-legal-challenge","reason":"Apple","category":"News","sources":["Malwarebytes Labs","The Hacker News","The Record"],"coverage":3,"cve_ids":[],"summary":"Seeking to protect users' iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company's Advanced Data Protection feature.","source":"The Record","date_rel":"21h ago","thumbnail":"http://cms.therecord.media/uploads/apple_logo_pexels_tim_gouw_be4c718ff6.jpg","description":"","related":[{"title":"Apple battles it out again with the UK over encrypted iCloud access","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-battles-it-out-again-with-uk-over-encrypted-icloud-access","source":"Malwarebytes Labs","date_rel":"13h ago"},{"title":"Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS","link":"https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited","link":"https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html","reason":"Exploited Langflow Ncentral","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU9CZ3zh4mWF0SVRdcylBR7IyGB6j797LrHqyND8vcsBbiE6mcDlqaufSOBg2Av4Ej_HZ_gMxbzR-KS6GvXX0hLPgSFlh5gwxKwhjx3FvcdsQ7XP65x70cxeadgTM7uETFglAUoZrxwq9Rmx6i1T4yS-E7c7Szx9igRmM_GqG-8L5xfKYk2i3fhQGEHjez/s1600/cisa.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote","related":[{"title":"CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities","link":"https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/","source":"SecurityWeek","date_rel":"41m ago"}]},{"title":"Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access","link":"https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance\u2026","source":"The Hacker News","date_rel":"21h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi35nnI5-o_HtA0Eunk4tOFM1lg12NrqY7HrDNBbee-kPWR-BHHxXQtd-Tj3b7FrMlTOcWNC63XgVV9n0FEoD-G4ydCpmBv2g1PjvS-lzopLbMnODHbNL2bGMJ6nOYXST9M83vc9IYZaUOjkUqaa4Xo-LaAOtXu3bRhYAcVIUwxgDNMifc6xWI27VVca_B4/s1600/screenconnect.jpg","description":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat","related":[{"title":"Adobe security advisory (AV26-776)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-776","source":"CCCS Alerts & Advisories","date_rel":"14h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-16618","vendor":"WordPress","product":"Improve SEO","severity":"CRITICAL","score":9.8,"description":"The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauth\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.002,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16618"},{"id":"CVE-2026-14175","vendor":"HashiCorp","product":"HUMANIST Digital Human Resources","severity":"CRITICAL","score":9.8,"description":"Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.\n\nThis issue affects HUMANIST Digital Human Resource\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.004,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14175"},{"id":"CVE-2026-15721","vendor":"HashiCorp","product":"HUMANIST Digital Human Resources","severity":"CRITICAL","score":9.8,"description":"Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cwe":"CWE-312","kev":false,"kev_action":"","kev_due":"","epss":0.0023,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15721"},{"id":"CVE-2026-61514","vendor":"Puwell Technology Inc.","product":"IP Camera","severity":"CRITICAL","score":9.8,"description":"Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentia\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61514"},{"id":"CVE-2026-61515","vendor":"Puwell Technology Inc.","product":"IP Camera","severity":"CRITICAL","score":9.8,"description":"Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell i\u2026","cwe":"CWE-912","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61515"},{"id":"CVE-2026-69098","vendor":"Cinnamon","product":"kotaemon","severity":"CRITICAL","score":9.8,"description":"kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ f\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-69098"},{"id":"CVE-2025-29296","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple command injection vulnerabilities in the /\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-29296"},{"id":"CVE-2026-63455","vendor":"HP","product":"EdgeConnect SD-WAN Orchestrator","severity":"CRITICAL","score":9.8,"description":"Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63455"},{"id":"CVE-2026-63456","vendor":"HP","product":"EdgeConnect SD-WAN Orchestrator","severity":"CRITICAL","score":9.8,"description":"Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63456"},{"id":"CVE-2026-24254","vendor":"NVIDIA","product":"Dynamo","severity":"CRITICAL","score":9.8,"description":"NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, da\u2026","cwe":"CWE-288","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-24254"}],"vendor_spikes":[{"vendor":"WordPress","count":32,"critical_count":3},{"vendor":"FlowiseAI","count":18,"critical_count":0},{"vendor":"Unknown","count":17,"critical_count":1},{"vendor":"NVIDIA","count":16,"critical_count":1},{"vendor":"HashiCorp","count":14,"critical_count":3},{"vendor":"open-webui","count":12,"critical_count":0},{"vendor":"Qualcomm","count":11,"critical_count":1},{"vendor":"Veeam","count":10,"critical_count":0},{"vendor":"H3C","count":8,"critical_count":0},{"vendor":"Apache","count":8,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":285,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-08-04","date_human":"Tuesday, August 4, 2026","generated_utc":"2026-08-04 21:15 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Google dev kit spurs first-ever agent-on-agent violence","link":"https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496","reason":"Google","category":"News","sources":["Bleeping Computer","Dark Reading","Malwarebytes Labs","Proofpoint Threat Insight","SecurityWeek","The Hacker News","The Register Security"],"coverage":7,"cve_ids":[],"summary":"In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could\u2026","source":"The Register Security","date_rel":"23h ago","thumbnail":"https://image.theregister.com/?imageId=5282519&width=800","description":"In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in google/adk-python, an open source Python toolkit with more than 90 million downloads used to build and deploy AI agents. Google has since fixed the underlying issue in the repository\u2026","related":[{"title":"AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls","link":"https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls","source":"Dark Reading","date_rel":"7h ago"},{"title":"Online backlash ends in Google rolling back Google Earth AI tool after a day","link":"https://www.malwarebytes.com/blog/news/2026/08/online-backlash-ends-in-google-rolling-back-google-earth-ai-tool-after-a-day","source":"Malwarebytes Labs","date_rel":"8h ago"},{"title":"Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering","link":"https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/","source":"SecurityWeek","date_rel":"9h ago"},{"title":"Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today\u2019s Most Sophisticated Threats","link":"https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-joins-google-unified-security-recommended-program-help","source":"Proofpoint Threat Insight","date_rel":"9h ago"},{"title":"New Pass-ta-key attacks let malware hijack Google-synced passkeys","link":"https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts","link":"https://thehackernews.com/2026/08/google-password-manager-attacks-could.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/n-able-n-central-auth-bypass-exploited/","reason":"CVE-2026-18577","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Cyber Security News","Dark Reading","Rapid7 Blog","The Hacker News"],"coverage":6,"cve_ids":["CVE-2026-18577"],"summary":"CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577 , the flaw affects N-central servers running versions earlier than\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CISA-Warns-of-N-able-N-central-Authentication-Bypass-Vulnerability-Exploited-in-Attacks.webp","description":"CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577 , the flaw affects N-central servers running versions earlier than 2026.3.1.7. N-central is a remote monitoring and management platform widely used by managed service providers to administer customer systems. Because the platform provides centralized access to many endpoint devices, a compromise could enable attackers to move across managed environments. CVE-2026-18577 is classified as an authentication bypass vulnerability via an alternate path\u2026","related":[{"title":"CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild","source":"Rapid7 Blog","date_rel":"9h ago"},{"title":"Attackers Exploit N-able Patch Bypass Flaw on RMM Servers","link":"https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw","source":"Dark Reading","date_rel":"23h ago"},{"title":"N-able warns of N-central auth bypass flaw exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"3 Aug"},{"title":"N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete","link":"https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers","link":"https://cybersecuritynews.com/hackers-weaponize-microsoft-copilot/","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Cyber Security News","Malwarebytes Labs","The Record","The Register Security"],"coverage":6,"cve_ids":[],"summary":"A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for business email compromise (BEC) and large-scale wire fraud. The\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Weaponize-Microsoft-Copilot.webp","description":"A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for business email compromise (BEC) and large-scale wire fraud. The demonstration shows that a single compromised employee account can escalate, with alarming speed, into full CEO account takeover and the theft of a quarter of a million dollars, with minimal technical effort from the attacker. The attack begins the moment threat actors gain access to a regular employee\u2019s inbox. Rather than relying on traditional \u201cliving off the land\u201d techniques like\u2026","related":[{"title":"Microsoft Tells Engineers \u2018Tokenmaxxing Is Not What We Are Optimizing For\u2019","link":"https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/","source":"404 Media","date_rel":"4h ago"},{"title":"Microsoft Strengthens NuGet Supply Chain Security By Reducing API Key Lifetime","link":"https://cybersecuritynews.com/microsoft-strengthens-nuget-supply-chain-security/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"AI helps Microsoft bug hunters chase a record $20M payday","link":"https://www.theregister.com/security/2026/08/04/ai-helps-microsoft-bug-hunters-chase-a-record-20m-payday/5282821","source":"The Register Security","date_rel":"5h ago"},{"title":"Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected","link":"https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities","source":"The Record","date_rel":"7h ago"},{"title":"Travelers targeted when logging into hotel Wi-Fi networks","link":"https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks","source":"Malwarebytes Labs","date_rel":"8h ago"},{"title":"Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts","link":"https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/","source":"Bleeping Computer","date_rel":"20h ago"}]},{"title":"Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams","link":"https://cybersecuritynews.com/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/","reason":"Teams","category":"News","sources":["Cyber Security News","Elastic Security Labs","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://i3.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilQYFaXQzJutaH7hl-0b-fZNl9Pj2QFfhn8y0WC8tl8petfT-OsvUOQBOGQqs-J5TihxgGHU0eLHls9Pq6UQHMGfCs10CqW7G_A93fDrInS8ydHhPGYfbK5Pts0WxUvLKUW6swCn2i9Z00hQZTZH7yiqEoz_K80W2Oy7GaElclO45TC0rgZhGEwFhjI1c/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20project,%20one%20team,%20o%20(81).webp?ssl=1","description":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the tools security teams already run Mallory , the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams. The architecture has three parts: a context graph that correlates attack surface, threat, and vulnerability data; an intelligent reasoning layer that determines what matters and why; and a policy and\u2026","related":[{"title":"Wiz at Black Hat 2026: Driving AI Threat Readiness","link":"https://www.wiz.io/blog/wiz-at-black-hat-2026","source":"Wiz Research","date_rel":"7h ago"},{"title":"When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted","link":"https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html","source":"The Hacker News","date_rel":"8h ago"},{"title":"FOMO in the SOC: Where AI Platforms like Claude Actually Fit","link":"https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html","source":"The Hacker News","date_rel":"3 Aug"},{"title":"SOC case management and detection rule history in Elastic Security","link":"https://www.elastic.co/security-labs/soc-case-management-detection-rule-history","source":"Elastic Security Labs","date_rel":"3 Aug"}]},{"title":"Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access","link":"https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi35nnI5-o_HtA0Eunk4tOFM1lg12NrqY7HrDNBbee-kPWR-BHHxXQtd-Tj3b7FrMlTOcWNC63XgVV9n0FEoD-G4ydCpmBv2g1PjvS-lzopLbMnODHbNL2bGMJ6nOYXST9M83vc9IYZaUOjkUqaa4Xo-LaAOtXu3bRhYAcVIUwxgDNMifc6xWI27VVca_B4/s1600/screenconnect.jpg","description":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat","related":[{"title":"Adobe security advisory (AV26-776)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-776","source":"CCCS Alerts & Advisories","date_rel":"43m ago"}]},{"title":"Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent","link":"https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html","reason":"Github","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLUUlqxE9AYL9PyFAlWMsG9czDcrU9p2kMUsumVIYx5SnlMAO0z-n_weUWeX-CiMHQBbkGK1lV-78vp003-bAeRP4gQRyGXlq5blzx5dJdd9zFttd2tjhGlNUFLNk-6ro9GfXMkRCFVLs-ex3gWHoJh-87sZifOeTKohLNoypvvqLUUPLkGUsjKXfAj7A/s1600/google.gif","description":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied","related":[{"title":"New XCSSET variant targets macOS devs via compromised Xcode projects","link":"https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/","source":"Bleeping Computer","date_rel":"1h ago"}]},{"title":"Bypassing AI guardrails is so easy a script kiddie can do it","link":"https://www.theregister.com/security/2026/08/04/bypassing-ai-guardrails-is-so-easy-a-script-kiddie-can-do-it/5282973","reason":"Talos","category":"News","sources":["Infosecurity Magazine","The Register Security"],"coverage":2,"cve_ids":[],"summary":"If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to researchers from Cisco Talos. Simply claiming you own the servers\u2026","source":"The Register Security","date_rel":"3h ago","thumbnail":"https://image.theregister.com/?imageId=5283021&width=800","description":"If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to researchers from Cisco Talos. Simply claiming you own the servers you're targeting or that you're taking part in a capture-the-flag or bug bounty exercise was often enough to persuade models to cooperate. Talos researchers have been poring over prompt logs and artifacts recovered from threat-actor endpoints running tools such as Claude Code, Codex, Cursor, and Gemini to learn how suspected threat actors are abusing LLMs. The big takeaway from\u2026","related":[{"title":"Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions","link":"https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/","source":"Infosecurity Magazine","date_rel":"7h ago"}]},{"title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog","reason":"Ibm","category":"Advisory","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories"],"coverage":2,"cve_ids":["CVE-2026-18556","CVE-2026-9198"],"summary":"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able\u2026","source":"CISA Alerts & Advisories","date_rel":"8h ago","thumbnail":"","description":"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on\u2026","related":[{"title":"IBM security advisory (AV26-770)","link":"https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-770","source":"CCCS Alerts & Advisories","date_rel":"5h ago"}]},{"title":"Apple launches new legal challenge against UK over iCloud access","link":"https://therecord.media/apple-uk-tcn-icloud-new-legal-challenge","reason":"Apple","category":"News","sources":["The Hacker News","The Record"],"coverage":2,"cve_ids":[],"summary":"Seeking to protect users' iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company's Advanced Data Protection feature.","source":"The Record","date_rel":"7h ago","thumbnail":"http://cms.therecord.media/uploads/apple_logo_pexels_tim_gouw_be4c718ff6.jpg","description":"","related":[{"title":"Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS","link":"https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"New DOUBLECUP ClickFix service hides malware in browser cache images","link":"https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/","reason":"Macos","category":"News","sources":["Bleeping Computer","SANS Internet Storm Center"],"coverage":2,"cve_ids":[],"summary":"A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote\u2026","source":"Bleeping Computer","date_rel":"3 Aug","thumbnail":"","description":"A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.","related":[{"title":"Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)","link":"https://isc.sans.edu/diary/rss/33208","source":"SANS Internet Storm Center","date_rel":"2 Aug"}]}],"worth_reading":[{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","reason":"Android","category":"Media","sources":["Bleeping Computer","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.","source":"Wired Security","date_rel":"2 Aug","thumbnail":"https://media.wired.com/photos/690270685216e0070a31d8d0/master/pass/The%20Best%20Password%20Managers%20to%20Secure%20Your%20Digital%20Life.png","description":"","related":[{"title":"Inside the Underground Business of the Android BTMOB RAT malware","link":"https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/","source":"Bleeping Computer","date_rel":"3 Aug"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-48323","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit t\u2026","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","epss":0.0062,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48323"},{"id":"CVE-2026-48330","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker \u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0068,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48330"},{"id":"CVE-2026-48331","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":0.0047,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48331"},{"id":"CVE-2026-48326","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":9.9,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privil\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0048,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48326"},{"id":"CVE-2026-18602","vendor":"GL.iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Host\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0199,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18602"},{"id":"CVE-2026-41452","vendor":"krayin","product":"laravel-crm","severity":"CRITICAL","score":9.8,"description":"Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Reque\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0066,"url":"https://cve.blackmesa.ca/?q=CVE-2026-41452"},{"id":"CVE-2026-18612","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes comm\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0216,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18612"},{"id":"CVE-2026-18613","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be \u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0055,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18613"},{"id":"CVE-2026-18614","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command in\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0201,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18614"},{"id":"CVE-2026-18615","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argumen\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0199,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18615"}],"vendor_spikes":[{"vendor":"WordPress","count":22,"critical_count":0},{"vendor":"Microsoft","count":21,"critical_count":1},{"vendor":"Unknown","count":19,"critical_count":1},{"vendor":"HashiCorp","count":12,"critical_count":3},{"vendor":"Red Hat","count":10,"critical_count":0},{"vendor":"TP-Link Systems Inc.","count":7,"critical_count":0},{"vendor":"Adobe","count":7,"critical_count":6},{"vendor":"Eclipse Foundation","count":7,"critical_count":0},{"vendor":"Apache","count":5,"critical_count":0},{"vendor":"GL-iNet","count":5,"critical_count":5}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":231,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-08-03","date_human":"Monday, August 3, 2026","generated_utc":"2026-08-03 13:55 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says","link":"https://therecord.media/russian-wifi-hackers-hotels","reason":"Microsoft","category":"News","sources":["Malwarebytes Labs","SecurityWeek","The Hacker News","The Record"],"coverage":4,"cve_ids":[],"summary":"Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, Microsoft said.","source":"The Record","date_rel":"1h ago","thumbnail":"http://cms.therecord.media/uploads/Hotel_room_5c31b73771.jpg","description":"","related":[{"title":"Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking","link":"https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"A week in security (July 27 \u2013 August 2)","link":"https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-july-27-august-2","source":"Malwarebytes Labs","date_rel":"5h ago"},{"title":"Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware","link":"https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html","source":"The Hacker News","date_rel":"1 Aug"}]},{"title":"Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft","link":"https://cybersecuritynews.com/coldcard-hardware-wallet-rng-flaw-bitcoin-theft/","reason":"Coldcard Bitcoin Million","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing them to reconstruct victims\u2019\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Coldcard-Hardware-Wallet-RNG-Flaw-Linked-to-88.6-Million-Bitcoin-Theft-1-1.webp","description":"A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing them to reconstruct victims\u2019 private keys without ever accessing their devices. Digital asset research firm Galaxy Research first noted unusual activity on July 30, when an attacker drained about 1,082.65 BTC, valued at around $70.2 million, from 1,196 addresses in a rapid sweep lasting just 41 minutes. By August 1, Galaxy detected additional waves of transactions, bringing the total theft to 1,367.05 BTC\u2026","related":[{"title":"COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft","link":"https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/","source":"Bleeping Computer","date_rel":"15h ago"},{"title":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes","link":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html","source":"The Hacker News","date_rel":"1 Aug"}]},{"title":"MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets","link":"https://cybersecuritynews.com/macsync-uses-fake-claude-guide/","reason":"Macos","category":"News","sources":["Cyber Security News","SANS Internet Storm Center"],"coverage":2,"cve_ids":[],"summary":"Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on a legitimate Claude sharing page to persuade victims to paste a\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/MacSync-macOS-Stealer-Uses-Fake-Claude-Guide-to-Steal-Passwords-and-Crypto-Wallets.webp","description":"Mac users searching for Claude installation help have been led into a dangerous trap. A malicious campaign used a paid search result and a fake guide on a legitimate Claude sharing page to persuade victims to paste a command into Terminal. That action started the MacSync information-stealing malware. The campaign shows how software searches can become an entry point for account theft. Rather than exploiting a flaw, the operators relied on trust in a familiar domain, a convincing guide, and a command that looked like an installation step. The result can be stolen browser sessions, passwords\u2026","related":[{"title":"Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)","link":"https://isc.sans.edu/diary/rss/33208","source":"SANS Internet Storm Center","date_rel":"2 Aug"}]},{"title":"N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete","link":"https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html","reason":"CVE-2026-18577","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-18577"],"summary":"N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjs1H8Wx5_ZrUFksG2Tgb_6qho5XHULdP13qVeYXx1xWPPt8B2rH68XC6IhzBk-dczgsdWvpZ_dVTI7AIMsgK1EeU3B89WVUJu2N5B71FQ4GnlZDRlvNiD4pGO2hBCJGVowjUVDMSHAO_0CPlYthpa8jx-Af5OwB6ZMDr-PKTYDJKjP4pGCZZolbjbGi44/s1600/n-able.jpg","description":"N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform","related":[{"title":"N\u2011able Patches Vulnerability Exploited to Hack N-central Servers","link":"https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/","source":"SecurityWeek","date_rel":"26m ago"}]},{"title":"XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands","link":"https://cybersecuritynews.com/xcsset-v40-abuses-chrome-devtools/","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once activated, it can spread through\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/XCSSET-v40-Abuses-Chrome-DevTools-Protocol-to-Steal-Cookies-and-Run-Commands.webp","description":"XCSSET has returned with a way to target macOS developers. The latest version, v40, hides inside poisoned Xcode projects and can turn a local build into a supply-chain compromise. Once activated, it can spread through other projects, raising risk for developers and the organizations that use their code. The malware family was first documented in 2020, but its campaign shows a move toward stealth and scale. It uses memory-based execution, changing payloads, and short-lived files to reduce visible traces. Developers across South Asia have seen heightened targeting, while infected projects have\u2026","related":[{"title":"Google Chrome may soon block New Tab hijacker extensions by default","link":"https://www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/","source":"Bleeping Computer","date_rel":"22h ago"}]},{"title":"AI is 'both the weapon and the target' in latest wave of cyberattacks","link":"https://www.theregister.com/cyber-crime/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks/5281534","reason":"Crowdstrike","category":"News","sources":["CyberScoop","The Register Security"],"coverage":2,"cve_ids":[],"summary":"AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal\u2026","source":"The Register Security","date_rel":"5h ago","thumbnail":"https://image.theregister.com/?imageId=258436&width=800","description":"AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal gangs and nation states using AI throughout the attack chain. Attackers are also targeting organizations' AI infrastructure and poisoning popular software packages to compromise their users. \"AI is both the weapon and the target,\" CrowdStrike counter adversary division senior VP Adam Meyers told reporters. \"AI is a high-value attack surface, and it's being used by more and more\u2026","related":[{"title":"CrowdStrike: AI is now both the weapon and the target in cyberattacks","link":"https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/","source":"CyberScoop","date_rel":"5h ago"}]},{"title":"Cheap Android TV Boxes Pose as Phones and Turn Owners\u2019 Broadband Into Proxies","link":"https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html","reason":"Android","category":"News","sources":["The Hacker News","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers\u2026","source":"The Hacker News","date_rel":"31 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhxfc7_NuArKSujgjgzPzENagYVTlBxcvnFBXSbptnFs_TI1o-Zt5SINHtPEO5MNkJ3vwkKUTX68vwmCzVxRQVFcgnb9eXwAsLKayCtzMLVRuqwV3RDaWTgQNOm0CVXcV_jX1v4x4mgEthTDjAsZdF4BSPSuTTRqKnM6qbIhPVjZP38dHmpptNurSmXRM/s1600/android-tv.jpg","description":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box","related":[{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","source":"Wired Security","date_rel":"2 Aug"}]},{"title":"Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction","link":"https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html","reason":"Adobe","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The\u2026","source":"The Hacker News","date_rel":"1 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW/s1600/adobe-flaw.jpg","description":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in","related":[{"title":"In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research","link":"https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/","source":"SecurityWeek","date_rel":"31 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"31 Jul","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. \ud83d\udca1 Do you work at Google? I would love to hear\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"31 Jul"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-65321","vendor":"laughingman7743","product":"PyAthena","severity":"CRITICAL","score":9.8,"description":"PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statemen\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65321"},{"id":"CVE-2026-68579","vendor":"Microsoft","product":"FreeRDP","severity":"CRITICAL","score":9.6,"description":"FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a f\u2026","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68579"},{"id":"CVE-2026-67356","vendor":"ArcadeData","product":"arcadedb","severity":"HIGH","score":8.8,"description":"ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission ca\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67356"},{"id":"CVE-2025-71399","vendor":"better-auth","product":"better-auth","severity":"HIGH","score":8.6,"description":"Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to \u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-71399"},{"id":"CVE-2026-68581","vendor":"go-vikunja","product":"vikunja","severity":"HIGH","score":8.1,"description":"Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-s\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68581"},{"id":"CVE-2026-67357","vendor":"ArcadeData","product":"arcadedb","severity":"HIGH","score":7.5,"description":"ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it wi\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67357"},{"id":"CVE-2026-68578","vendor":"ArcadeData","product":"arcadedb","severity":"HIGH","score":7.5,"description":"ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, sche\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68578"},{"id":"CVE-2026-68580","vendor":"FreeRDP","product":"FreeRDP","severity":"HIGH","score":7.5,"description":"FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers\u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68580"},{"id":"CVE-2026-3245","vendor":"Palo Alto","product":"PRISMAproduction","severity":"HIGH","score":7.5,"description":"A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-3245"},{"id":"CVE-2025-71400","vendor":"better-auth","product":"passkey","severity":"HIGH","score":7.1,"description":"better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submi\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-71400"}],"vendor_spikes":[{"vendor":"MediaTek, Inc.","count":34,"critical_count":0},{"vendor":"Legion of the Bouncy Castle Inc.","count":31,"critical_count":0},{"vendor":"better-auth","count":3,"critical_count":0},{"vendor":"ArcadeData","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":9,"new_cve_count":92,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-08-02","date_human":"Sunday, August 2, 2026","generated_utc":"2026-08-02 13:34 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware","link":"https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html","reason":"Macos","category":"News","sources":["Palo Alto Unit 42","SANS Internet Storm Center","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCHbm6QCC9jjGwa-7P1N2PwhDjRvpC2hlS2hl09-DUZa5xdDeHt9qH1zISepl2ERqDzmDbdQ_zfE2vkHDsvE7G8QsetJHjzC45DpPr5-83lc1BGaLHfEwMfdYEA04d5xc7GL02_qkz1HjhIenSKBWF0FZqHnICaLn9agLEoEGnnN2n-smXxYFuQQaYNd8A/s1600/all-secure.jpg","description":"Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily","related":[{"title":"Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)","link":"https://isc.sans.edu/diary/rss/33208","source":"SANS Internet Storm Center","date_rel":"8h ago"},{"title":"The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version","link":"https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/","source":"Palo Alto Unit 42","date_rel":"31 Jul"}]},{"title":"Cheap Android TV Boxes Pose as Phones and Turn Owners\u2019 Broadband Into Proxies","link":"https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html","reason":"Android","category":"News","sources":["The Hacker News","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers\u2026","source":"The Hacker News","date_rel":"31 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhxfc7_NuArKSujgjgzPzENagYVTlBxcvnFBXSbptnFs_TI1o-Zt5SINHtPEO5MNkJ3vwkKUTX68vwmCzVxRQVFcgnb9eXwAsLKayCtzMLVRuqwV3RDaWTgQNOm0CVXcV_jX1v4x4mgEthTDjAsZdF4BSPSuTTRqKnM6qbIhPVjZP38dHmpptNurSmXRM/s1600/android-tv.jpg","description":"Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box","related":[{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","source":"Wired Security","date_rel":"50m ago"}]},{"title":"Windows 11 Gets More Taskbar Control and AI Integration as Microsoft Details Quality Progress","link":"https://cybersecuritynews.com/windows-11-quality-initiative/","reason":"Microsoft","category":"News","sources":["Cyber Security News","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Microsoft has released a detailed update on its Windows quality initiative, four months after committing in March to improve performance, reliability, and everyday user experiences across Windows 11 . The company says\u2026","source":"Cyber Security News","date_rel":"23h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Windows-11-Quality-Initiative.webp","description":"Microsoft has released a detailed update on its Windows quality initiative, four months after committing in March to improve performance, reliability, and everyday user experiences across Windows 11 . The company says early improvements are already reaching Windows Insiders and will begin rolling out more broadly to Windows 11 PCs this fall, while stressing that work is far from finished. In March, Microsoft outlined immediate priorities that included greater taskbar customization, more intentional AI integration, less disruptive Windows Updates, a faster and more dependable File Explorer\u2026","related":[{"title":"Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware","link":"https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html","source":"The Hacker News","date_rel":"1 Aug"},{"title":"Malwarebytes for Windows, now available on the Microsoft Store","link":"https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"30 Jul"}]},{"title":"Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction","link":"https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The\u2026","source":"The Hacker News","date_rel":"1 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW/s1600/adobe-flaw.jpg","description":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in","related":[{"title":"In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research","link":"https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"Adobe security advisory (AV26-760)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-760","source":"CCCS Alerts & Advisories","date_rel":"30 Jul"}]},{"title":"Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined","link":"https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","SecurityWeek","The Hacker News","Wired Security"],"coverage":4,"cve_ids":[],"summary":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions\u2026","source":"The Hacker News","date_rel":"31 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx/s1600/chrome.jpg","description":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the","related":[{"title":"Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace","link":"https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"Google says AI helped Chrome fix 1,072 security bugs in two releases","link":"https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting","link":"https://www.wired.com/story/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now/","source":"Wired Security","date_rel":"30 Jul"},{"title":"ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories","link":"https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html","source":"The Hacker News","date_rel":"30 Jul"}]},{"title":"Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits","link":"https://cybersecuritynews.com/arch-linux-disables-aur-package/","reason":"Linux","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine"],"coverage":3,"cve_ids":[],"summary":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The\u2026","source":"Cyber Security News","date_rel":"1 Aug","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Arch-Linux-Disables-AUR-Package.webp","description":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The move, announced by Robin Candau (known online as Antiz) on behalf of the Arch Linux DevOps team, comes as attackers increasingly exploit an abandoned or unmaintained package as an entry point for supply-chain attacks. Last month, a massive supply chain attack targeting the Arch User Repository (AUR) compromised more than 400 community-maintained packages , with attackers injecting\u2026","related":[{"title":"Arch Linux disables AUR package adoption to stop malware flood","link":"https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/","source":"Bleeping Computer","date_rel":"31 Jul"},{"title":"Cryptominer Abuses Linux PAM to Hide From SOC Analysts","link":"https://www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/","source":"Infosecurity Magazine","date_rel":"30 Jul"}]},{"title":"Top 10 Best DNS Security Solutions in 2026","link":"https://cybersecuritynews.com/best-dns-security-solutions/","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the\u2026","source":"Cyber Security News","date_rel":"21h ago","thumbnail":"https://i2.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQMZ593YhBRfEXBcbxtVpDeFa2CXQ1OWGPnssevXefPGPeHzFHPjIEtCGj-IkW6XWsQe-1F0-ZzNidBdB480KYYUkASAKxo5bRC1NSlW-YIteiIeBcTq4xkBlhKwOxR4SL60jvNHVDSjAMeCzyIfQ26ZLJ9S1t6xm9zLV7iXAd8aY2BH2zmGkp0KdL4d4/s1600/Best%20DNS%20Security%20Solutions%20(3).webp?ssl=1","description":"Nearly every attack touches DNS the phishing click, the malware callback, the exfiltration tunnel which makes the DNS layer the cheapest place to break kill chains. Cisco Umbrella is our top pick for 2026 on the strength of Talos-fed intelligence and proven scale, with Infoblox leading DDI-integrated security and Akamai delivering edge-scale protection. DNS security protects and exploits the DNS layer blocking resolution of malicious domains, detecting tunneling and DGA activity, and hardening DNS infrastructure. Below, the ten best DNS security solutions ranked. Quick Verdict \u2022 Best overall\u2026","related":[{"title":"Cisco security advisory (AV26-757)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-757","source":"CCCS Alerts & Advisories","date_rel":"30 Jul"}]},{"title":"Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database","link":"https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html","reason":"Azure","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-24304","CVE-2026-66803"],"summary":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_dFT-y76kGOf4rFOAu6NYNsE2s57G-7dl0a03tULY-f2ZGTbpPeEvu-NUCLVh-bgEdBvecIt28BJLQXUHclBc_IfGP9tBSZyMIm971Myrp2_zhSPyXhCJkhYmSfvLWNRewSsCip2YJfBEWocEEKdXPUL-y_mK8ZcHbBAaTWt8SzXmDJeQoYc6r5ceC6A/s1600/wiz-cosmodb.jpg","description":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a","related":[{"title":"Critical Flaw Allowed to Azure Cosmos DB Pwnage","link":"https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"31 Jul","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. \ud83d\udca1 Do you work at Google? I would love to hear\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"31 Jul"}]},{"title":"Anthropic says its AI hacked real-world companies in three incidents","link":"https://therecord.media/anthropic-ai-hacked-three-real-companies","reason":"Companies Anthropic Hacked","category":"News","sources":["CyberScoop","The Record"],"coverage":2,"cve_ids":[],"summary":"Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.","source":"The Record","date_rel":"31 Jul","thumbnail":"http://cms.therecord.media/uploads/anthropic_logo_daaf076757.jpg","description":"","related":[{"title":"Anthropic says its AI accidentally hacked three companies during safety tests","link":"https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/","source":"CyberScoop","date_rel":"31 Jul"}]}],"worth_reading":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/","reason":"Exchange","category":"Media","sources":["Ars Technica Security","Proofpoint Threat Insight"],"coverage":2,"cve_ids":[],"summary":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security\u2026","source":"Ars Technica Security","date_rel":"30 Jul","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2023/07/exploit-vulnerability-security-500x500.jpg","description":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday . Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email\u2026","related":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://www.proofpoint.com/us/newsroom/news/max-severity-exchange-server-flaw-under-active-exploitation-kremlin-hackers","source":"Proofpoint Threat Insight","date_rel":"30 Jul"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-67308","vendor":"wazuh","product":"wazuh","severity":"CRITICAL","score":10.0,"description":"Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharact\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67308"},{"id":"CVE-2026-67330","vendor":"better-auth","product":"scim","severity":"CRITICAL","score":9.9,"description":"@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, \u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67330"},{"id":"CVE-2026-15964","vendor":"WordPress","product":"Single Sign On For TNG","severity":"CRITICAL","score":9.8,"description":"The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function \u2014 registered on `wp_ajax_\u2026","cwe":"CWE-620","kev":false,"kev_action":"","kev_due":"","epss":0.0049,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15964"},{"id":"CVE-2026-66402","vendor":"Apple","product":"FreeRDP","severity":"CRITICAL","score":9.8,"description":"FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common N\u2026","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66402"},{"id":"CVE-2026-67289","vendor":"FreeRDP","product":"FreeRDP","severity":"CRITICAL","score":9.8,"description":"FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client co\u2026","cwe":"CWE-113","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67289"},{"id":"CVE-2026-67324","vendor":"gitpython-developers","product":"GitPython","severity":"CRITICAL","score":9.8,"description":"GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67324"},{"id":"CVE-2026-67340","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.8,"description":"ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permissi\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67340"},{"id":"CVE-2026-67341","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.8,"description":"ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION stateme\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67341"},{"id":"CVE-2026-67342","vendor":"ArcadeData","product":"arcadedb","severity":"CRITICAL","score":9.8,"description":"ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify data\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67342"},{"id":"CVE-2026-8457","vendor":"Apple","product":"WooCommerce - Social Login","severity":"CRITICAL","score":9.8,"description":"The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 \u2026","cwe":"CWE-289","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-8457"}],"vendor_spikes":[{"vendor":"WordPress","count":92,"critical_count":1},{"vendor":"FreeRDP","count":17,"critical_count":1},{"vendor":"better-auth","count":14,"critical_count":1},{"vendor":"Apple","count":12,"critical_count":2},{"vendor":"gitpython-developers","count":5,"critical_count":1},{"vendor":"guzzle","count":4,"critical_count":0},{"vendor":"ArcadeData","count":4,"critical_count":3},{"vendor":"ueberauth","count":4,"critical_count":0},{"vendor":"Red Hat","count":4,"critical_count":0},{"vendor":"Unknown","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":176,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-08-01","date_human":"Saturday, August 1, 2026","generated_utc":"2026-08-01 13:34 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware","link":"https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Infosecurity Magazine","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglJ30Q0_3tS3R4yrNdyR3sDdvBam1plVfmenBAFVPGmaVMErJ_oq_zXoIpeAjrFrkkFkudKUSHI-h82FGoiIJlkT2JghjQKrO2p7VmzpduPGv26gGgJ8I04b-U7eY1sihmIer0bGTtIof3CwH1vKmQOYLDvhNsYICoALOLhehhaLC65fPmAH_fpT0BrKk/s1600/hotel-wifi.jpg","description":"A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as","related":[{"title":"Malwarebytes for Windows, now available on the Microsoft Store","link":"https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages","link":"https://www.infosecurity-magazine.com/news/teams-phishing-abused-legit/","source":"Infosecurity Magazine","date_rel":"30 Jul"},{"title":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","link":"https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Russian spies take their half-click email attack from Zimbra to Outlook","link":"https://www.theregister.com/security/2026/07/30/russian-spies-take-their-half-click-email-attack-from-zimbra-to-outlook/5281033","source":"The Register Security","date_rel":"30 Jul"}]},{"title":"Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined","link":"https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News","Wired Security"],"coverage":6,"cve_ids":[],"summary":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx/s1600/chrome.jpg","description":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the","related":[{"title":"Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities","link":"https://cybersecuritynews.com/google-ai-fixes-chrome-vulnerabilities/","source":"Cyber Security News","date_rel":"23h ago"},{"title":"Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace","link":"https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"Google says AI helped Chrome fix 1,072 security bugs in two releases","link":"https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting","link":"https://www.wired.com/story/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now/","source":"Wired Security","date_rel":"30 Jul"},{"title":"ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories","link":"https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Google Releases Patches for 370 Vulnerabilities in Chrome 151","link":"https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/","source":"Infosecurity Magazine","date_rel":"30 Jul"}]},{"title":"Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits","link":"https://cybersecuritynews.com/arch-linux-disables-aur-package/","reason":"Linux","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Arch-Linux-Disables-AUR-Package.webp","description":"Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The move, announced by Robin Candau (known online as Antiz) on behalf of the Arch Linux DevOps team, comes as attackers increasingly exploit an abandoned or unmaintained package as an entry point for supply-chain attacks. Last month, a massive supply chain attack targeting the Arch User Repository (AUR) compromised more than 400 community-maintained packages , with attackers injecting\u2026","related":[{"title":"Arch Linux disables AUR package adoption to stop malware flood","link":"https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/","source":"Bleeping Computer","date_rel":"14h ago"},{"title":"BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations","link":"https://cybersecuritynews.com/blacktech-apt-deploys-blueshell-linux-backdoor/","source":"Cyber Security News","date_rel":"31 Jul"},{"title":"Cryptominer Abuses Linux PAM to Hide From SOC Analysts","link":"https://www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/","source":"Infosecurity Magazine","date_rel":"30 Jul"},{"title":"Closed models refuse to help researcher swat Linux bug","link":"https://www.theregister.com/ai-and-ml/2026/07/29/closed-models-refuse-to-help-researcher-swat-linux-bug/5280647","source":"The Register Security","date_rel":"29 Jul"}]},{"title":"Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction","link":"https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW/s1600/adobe-flaw.jpg","description":"Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in","related":[{"title":"In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research","link":"https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/","source":"SecurityWeek","date_rel":"20h ago"},{"title":"Adobe security advisory (AV26-760)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-760","source":"CCCS Alerts & Advisories","date_rel":"30 Jul"},{"title":"Adobe security advisory (AV26-756)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-756","source":"CCCS Alerts & Advisories","date_rel":"29 Jul"}]},{"title":"Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database","link":"https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html","reason":"Azure","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":["CVE-2026-24304","CVE-2026-66803"],"summary":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_dFT-y76kGOf4rFOAu6NYNsE2s57G-7dl0a03tULY-f2ZGTbpPeEvu-NUCLVh-bgEdBvecIt28BJLQXUHclBc_IfGP9tBSZyMIm971Myrp2_zhSPyXhCJkhYmSfvLWNRewSsCip2YJfBEWocEEKdXPUL-y_mK8ZcHbBAaTWt8SzXmDJeQoYc6r5ceC6A/s1600/wiz-cosmodb.jpg","description":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a","related":[{"title":"Critical Flaw Allowed to Azure Cosmos DB Pwnage","link":"https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CosmosEscape: Taking Over Every Database in Azure Cosmos DB","link":"https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db","source":"Wiz Research","date_rel":"30 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"20h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. \ud83d\udca1 Do you work at Google? I would love to hear\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"Wiz\u2019s First 6 Months as Part of Google","link":"https://www.wiz.io/blog/6-months-google","source":"Wiz Research","date_rel":"29 Jul"}]},{"title":"Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely \u2013 Update Now","link":"https://cybersecuritynews.com/jetbrains-vulnerability-execute-malicious-code/","reason":"CVE-2026-63077","category":"News","sources":["Cyber Security News","Rapid7 Blog","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2026-63077"],"summary":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects\u2026","source":"Cyber Security News","date_rel":"22h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/Critical-JetBrains-Vulnerability-Allow-Attackers-to-Execute-Malicious-Code-Remotely-Update-Now-.webp","description":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects all versions of TeamCity On-Premises. An attacker only requires HTTP or HTTPS access to a vulnerable TeamCity server to exploit this issue, with no need for a valid account, password, or prior access. According to JetBrains, the flaw resides in the TeamCity agent polling protocol. A remote attacker can use this protocol to bypass authentication checks and execute operating\u2026","related":[{"title":"Critical Code Execution Vulnerability Patched in TeamCity","link":"https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/","source":"SecurityWeek","date_rel":"31 Jul"},{"title":"CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity","link":"https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity","source":"Rapid7 Blog","date_rel":"29 Jul"}]},{"title":"USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports","link":"https://www.darkreading.com/identity-access-management-security/usa-fencing-hidden-identity-challenge-amateur-sports","reason":"Teams","category":"News","sources":["Dark Reading","Recorded Future Intelligence","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.","source":"Dark Reading","date_rel":"23h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt66a2e6a794ec3f06/6a6b70a2c08842d09cba7462/USA_Fencing-Jumio_Bala_Kumar.png?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Claude Mythos \u2014 Hype vs. Reality: What Security Teams Need to Know","link":"https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality","source":"Dark Reading","date_rel":"30 Jul"},{"title":"The Network Has Become the Control Plane for AI Security","link":"https://thehackernews.com/2026/07/the-network-has-become-control-plane.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Dealing with AI-Generated Extortion","link":"https://www.recordedfuture.com/blog/ai-generated-extortion","source":"Recorded Future Intelligence","date_rel":"30 Jul"},{"title":"Hugging Face Hack: Lessons for Cyber Defenders","link":"https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders","source":"Dark Reading","date_rel":"29 Jul"}]},{"title":"North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials","link":"https://cybersecuritynews.com/north-korean-etherhiding-campaign/","reason":"Macos","category":"News","sources":["Cyber Security News","Palo Alto Unit 42","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine\u2026","source":"Cyber Security News","date_rel":"31 Jul","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/North-Korean-EtherHiding-Campaign-Targets-Crypto-Wallets-and-Developer-Credentials.webp","description":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine web search into a possible entry point for a serious compromise. The attack begins with a ClickFix-style lure that makes a browser page look like a frozen or rebooting Mac. Victims are told to open Terminal and paste a command that the malicious page has already copied to their clipboard, allowing the infection chain to start. AllSecure analysts identified the activity while\u2026","related":[{"title":"The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version","link":"https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/","source":"Palo Alto Unit 42","date_rel":"31 Jul"},{"title":"DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware","link":"https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html","source":"The Hacker News","date_rel":"30 Jul"}]},{"title":"Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)","link":"https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310","reason":"Broadcom","category":"Research","sources":["Bleeping Computer","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-59309","CVE-2026-59310"],"summary":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable\u2026","source":"Rapid7 Blog","date_rel":"30 Jul","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical) An authentication bypass vulnerability in the VMware Directory Service of vCenter that\u2026","related":[{"title":"VMware fixes three critical flaws allowing auth bypass, VM escapes","link":"https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape","link":"https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html","source":"The Hacker News","date_rel":"29 Jul"}]}],"worth_reading":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/","reason":"Exchange","category":"Media","sources":["Ars Technica Security","Proofpoint Threat Insight"],"coverage":2,"cve_ids":[],"summary":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security\u2026","source":"Ars Technica Security","date_rel":"30 Jul","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2023/07/exploit-vulnerability-security-500x500.jpg","description":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday . Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email\u2026","related":[{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://www.proofpoint.com/us/newsroom/news/max-severity-exchange-server-flaw-under-active-exploitation-kremlin-hackers","source":"Proofpoint Threat Insight","date_rel":"30 Jul"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-18452","vendor":"Rich Source","product":"DMS+ (Non-Mobile)","severity":"CRITICAL","score":10.0,"description":"DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.0043,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18452"},{"id":"CVE-2026-17566","vendor":"pgadmin.org","product":"pgAdmin 4","severity":"CRITICAL","score":9.9,"description":"pgAdmin 4's Import/Export Data tool builds a psql \\copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (.\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17566"},{"id":"CVE-2026-52855","vendor":"pterodactyl","product":"wings","severity":"CRITICAL","score":9.9,"description":"Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{confi\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-52855"},{"id":"CVE-2026-14483","vendor":"WordPress","product":"Realtyna Organic IDX plugin + WPL Real Estate","severity":"CRITICAL","score":9.8,"description":"The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload fun\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.0061,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14483"},{"id":"CVE-2026-14919","vendor":"WordPress","product":"ShopMonitor.io","severity":"CRITICAL","score":9.8,"description":"The ShopMonitor.io  WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0014,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14919"},{"id":"CVE-2026-17561","vendor":"HashiCorp","product":"Logsign SIEM","severity":"CRITICAL","score":9.8,"description":"Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.\n\nThis issue affects Logsign SIEM: before 6.4.108.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17561"},{"id":"CVE-2026-67822","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer witho\u2026","cwe":"CWE-121","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67822"},{"id":"CVE-2026-68770","vendor":"Hugging Face","product":"sentence-transformers","severity":"CRITICAL","score":9.8,"description":"sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where t\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68770"},{"id":"CVE-2026-68771","vendor":"Comfy-Org","product":"ComfyUI","severity":"CRITICAL","score":9.8,"description":"ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserializa\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68771"},{"id":"CVE-2026-17349","vendor":"pgadmin.org","product":"pgAdmin 4","severity":"CRITICAL","score":9.6,"description":"/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user\u2026","cwe":"CWE-522","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17349"}],"vendor_spikes":[{"vendor":"HashiCorp","count":48,"critical_count":1},{"vendor":"WordPress","count":43,"critical_count":3},{"vendor":"Unknown","count":20,"critical_count":1},{"vendor":"Red Hat","count":15,"critical_count":0},{"vendor":"pgadmin.org","count":6,"critical_count":3},{"vendor":"PHP Jabbers","count":5,"critical_count":0},{"vendor":"HCL Software","count":5,"critical_count":0},{"vendor":"thumbor","count":5,"critical_count":0},{"vendor":"ANDRITZ","count":4,"critical_count":0},{"vendor":"decidim","count":4,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":213,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-07-31","date_human":"Friday, July 31, 2026","generated_utc":"2026-07-31 16:24 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined","link":"https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News","Wired Security"],"coverage":6,"cve_ids":[],"summary":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx/s1600/chrome.jpg","description":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the","related":[{"title":"Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities","link":"https://cybersecuritynews.com/google-ai-fixes-chrome-vulnerabilities/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace","link":"https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"Google says AI helped Chrome fix 1,072 security bugs in two releases","link":"https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/","source":"Bleeping Computer","date_rel":"23h ago"},{"title":"Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting","link":"https://www.wired.com/story/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now/","source":"Wired Security","date_rel":"23h ago"},{"title":"ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories","link":"https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Google Releases Patches for 370 Vulnerabilities in Chrome 151","link":"https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/","source":"Infosecurity Magazine","date_rel":"30 Jul"}]},{"title":"Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database","link":"https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html","reason":"Azure","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":["CVE-2026-24304","CVE-2026-66803"],"summary":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_dFT-y76kGOf4rFOAu6NYNsE2s57G-7dl0a03tULY-f2ZGTbpPeEvu-NUCLVh-bgEdBvecIt28BJLQXUHclBc_IfGP9tBSZyMIm971Myrp2_zhSPyXhCJkhYmSfvLWNRewSsCip2YJfBEWocEEKdXPUL-y_mK8ZcHbBAaTWt8SzXmDJeQoYc6r5ceC6A/s1600/wiz-cosmodb.jpg","description":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a","related":[{"title":"Critical Flaw Allowed to Azure Cosmos DB Pwnage","link":"https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CosmosEscape: Taking Over Every Database in Azure Cosmos DB","link":"https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db","source":"Wiz Research","date_rel":"30 Jul"}]},{"title":"USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports","link":"https://www.darkreading.com/identity-access-management-security/usa-fencing-hidden-identity-challenge-amateur-sports","reason":"Teams","category":"News","sources":["CrowdStrike Blog","Dark Reading","Recorded Future Intelligence","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.","source":"Dark Reading","date_rel":"3h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt66a2e6a794ec3f06/6a6b70a2c08842d09cba7462/USA_Fencing-Jumio_Bala_Kumar.png?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Claude Mythos \u2014 Hype vs. Reality: What Security Teams Need to Know","link":"https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality","source":"Dark Reading","date_rel":"30 Jul"},{"title":"The Network Has Become the Control Plane for AI Security","link":"https://thehackernews.com/2026/07/the-network-has-become-control-plane.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Dealing with AI-Generated Extortion","link":"https://www.recordedfuture.com/blog/ai-generated-extortion","source":"Recorded Future Intelligence","date_rel":"30 Jul"},{"title":"Hugging Face Hack: Lessons for Cyber Defenders","link":"https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders","source":"Dark Reading","date_rel":"29 Jul"},{"title":"73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack","link":"https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html","source":"The Hacker News","date_rel":"29 Jul"},{"title":"Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud","link":"https://www.crowdstrike.com/en-us/blog/new-in-falcon-cloud-security-helping-security-teams-move-faster/","source":"CrowdStrike Blog","date_rel":"29 Jul"}]},{"title":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","link":"https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Dark Reading","Elastic Security Labs","Malwarebytes Labs","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-BgxoTGLqXYzQh4HW0TUm-hbX0ApFizzFtFkKe5mb3fKS_yn6Zzpj_Uvivxi7VCwEUOuJx3Bg1XHpHWq9tbZh5xBrAHT4gBG2DYyqvFkVKmWIRiF_zCpXIG5bTs7HfsV1pjM2EsTm-e7WttN-iB57p0n4ki2Vs7vXyB6rTF9mSqlwPu3h7KHocg0mWcI/s1600/copilot-word.jpg","description":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. M\u00e5l\u00f8y's","related":[{"title":"Malwarebytes for Windows, now available on the Microsoft Store","link":"https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation","link":"https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here","link":"https://www.elastic.co/security-labs/sentinel-detection-rules-migration","source":"Elastic Security Labs","date_rel":"29 Jul"},{"title":"'Certighost' Flaw Haunts Microsoft Active Directory Certificates","link":"https://www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates","source":"Dark Reading","date_rel":"28 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"4m ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. In 404 Media\u2019s tests, we were able to add\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"Wiz\u2019s First 6 Months as Part of Google","link":"https://www.wiz.io/blog/6-months-google","source":"Wiz Research","date_rel":"29 Jul"}]},{"title":"Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely \u2013 Update Now","link":"https://cybersecuritynews.com/jetbrains-vulnerability-execute-malicious-code/","reason":"CVE-2026-63077","category":"News","sources":["Cyber Security News","Rapid7 Blog","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2026-63077"],"summary":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/Critical-JetBrains-Vulnerability-Allow-Attackers-to-Execute-Malicious-Code-Remotely-Update-Now-.webp","description":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects all versions of TeamCity On-Premises. An attacker only requires HTTP or HTTPS access to a vulnerable TeamCity server to exploit this issue, with no need for a valid account, password, or prior access. According to JetBrains, the flaw resides in the TeamCity agent polling protocol. A remote attacker can use this protocol to bypass authentication checks and execute operating\u2026","related":[{"title":"Critical Code Execution Vulnerability Patched in TeamCity","link":"https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/","source":"SecurityWeek","date_rel":"9h ago"},{"title":"CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity","link":"https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity","source":"Rapid7 Blog","date_rel":"29 Jul"}]},{"title":"North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials","link":"https://cybersecuritynews.com/north-korean-etherhiding-campaign/","reason":"Macos","category":"News","sources":["Cyber Security News","Palo Alto Unit 42","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/North-Korean-EtherHiding-Campaign-Targets-Crypto-Wallets-and-Developer-Credentials.webp","description":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine web search into a possible entry point for a serious compromise. The attack begins with a ClickFix-style lure that makes a browser page look like a frozen or rebooting Mac. Victims are told to open Terminal and paste a command that the malicious page has already copied to their clipboard, allowing the infection chain to start. AllSecure analysts identified the activity while\u2026","related":[{"title":"The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version","link":"https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/","source":"Palo Alto Unit 42","date_rel":"6h ago"},{"title":"DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware","link":"https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html","source":"The Hacker News","date_rel":"21h ago"}]},{"title":"BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations","link":"https://cybersecuritynews.com/blacktech-apt-deploys-blueshell-linux-backdoor/","reason":"Linux","category":"News","sources":["Cyber Security News","Infosecurity Magazine","Schneier on Security"],"coverage":3,"cve_ids":[],"summary":"BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/BlackTech-APT-Deploys-BlueShell-Linux-Backdoor-Against-Japanese-Organizations.webp","description":"BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to run commands, move files, and route traffic after they have already entered a network, raising the risk to internal systems and sensitive data. The attack begins after the attackers gain access and move laterally through the victim environment using SSH. From there, they deploy a loader that launches the backdoor, a method that reflects the group\u2019s established interest in\u2026","related":[{"title":"SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner","link":"https://cybersecuritynews.com/ssh-bot-profiles-linux-cpu/","source":"Cyber Security News","date_rel":"6h ago"},{"title":"Cryptominer Abuses Linux PAM to Hide From SOC Analysts","link":"https://www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/","source":"Infosecurity Magazine","date_rel":"30 Jul"},{"title":"Long-Lived Vulnerability in Microsoft Secure Boot","link":"https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html","source":"Schneier on Security","date_rel":"29 Jul"}]},{"title":"ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans","link":"https://cybersecuritynews.com/shuttergap-exposes-millions-of-aws-resources/","reason":"Aws","category":"News","sources":["Cyber Security News","Infosecurity Magazine","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify risky configurations. However, new research from Aryon Security\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/ShutterGap-Exposes-Millions-of-AWS-Resources-Between-Cloud-Security-Scans.webp","description":"Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify risky configurations. However, new research from Aryon Security reveals that this approach may overlook a significant class of threats: temporary AWS resources that are publicly exposed but removed before the next scan occurs. Aryon refers to this visibility gap as \u201cShutterGap.\u201d It happens when a cloud resource is made public for a brief period, sometimes lasting only a few minutes. Attackers can continuously monitor public AWS resources\u2026","related":[{"title":"AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks","link":"https://www.infosecurity-magazine.com/news/aws-north-korea-axios-npm-supply/","source":"Infosecurity Magazine","date_rel":"6h ago"},{"title":"CareCloud Data Breach Impacts Over 350,000","link":"https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/","source":"SecurityWeek","date_rel":"8h ago"}]},{"title":"North Korean hackers behind major open-source supply chain attacks, Amazon says","link":"https://therecord.media/north-korea-hackers-amazon-malware","reason":"Amazon","category":"News","sources":["Bleeping Computer","CyberScoop","The Hacker News","The Record"],"coverage":4,"cve_ids":[],"summary":"A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.","source":"The Record","date_rel":"30 Jul","thumbnail":"http://cms.therecord.media/uploads/Javascript_ebfda374da.jpg","description":"","related":[{"title":"Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers","link":"https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Amazon Links Debug and Chalk npm Hijack to North Korea\u2019s Sapphire Sleet","link":"https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"A little-known npm package was North Korea\u2019s warm-up act for the axios hack","link":"https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/","source":"CyberScoop","date_rel":"29 Jul"}]}],"worth_reading":[{"title":"Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)","link":"https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310","reason":"Broadcom","category":"Research","sources":["Bleeping Computer","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-59309","CVE-2026-59310"],"summary":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable\u2026","source":"Rapid7 Blog","date_rel":"30 Jul","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical) An authentication bypass vulnerability in the VMware Directory Service of vCenter that\u2026","related":[{"title":"VMware fixes three critical flaws allowing auth bypass, VM escapes","link":"https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape","link":"https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html","source":"The Hacker News","date_rel":"29 Jul"}]},{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/","reason":"Exchange","category":"Media","sources":["Ars Technica Security","Bleeping Computer"],"coverage":2,"cve_ids":[],"summary":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security\u2026","source":"Ars Technica Security","date_rel":"19h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2023/07/exploit-vulnerability-security-500x500.jpg","description":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday . Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email\u2026","related":[{"title":"Russian hackers exploit Exchange OWA zero-day for long-term mailbox access","link":"https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/","source":"Bleeping Computer","date_rel":"29 Jul"}]},{"title":"ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-495/","reason":"Vmware","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to\u2026","source":"Zero Day Initiative","date_rel":"29 Jul","thumbnail":"","description":"This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-47876.","related":[{"title":"VMware security advisory (AV26-763)","link":"https://cyber.gc.ca/en/alerts-advisories/vmware-security-advisory-av26-763","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-66803","vendor":"Microsoft","product":"Azure Cosmos DB","severity":"CRITICAL","score":10.0,"description":"Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":0.0049,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66803"},{"id":"CVE-2026-18452","vendor":"Rich Source","product":"DMS+ (Non-Mobile)","severity":"CRITICAL","score":10.0,"description":"DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.0043,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18452"},{"id":"CVE-2026-13435","vendor":"IBM","product":"Langflow OSS","severity":"CRITICAL","score":9.9,"description":"IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13435"},{"id":"CVE-2026-12946","vendor":"IBM","product":"Langflow OSS","severity":"CRITICAL","score":9.9,"description":"IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":0.0034,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12946"},{"id":"CVE-2026-28323","vendor":"SolarWinds","product":"Web Help Desk","severity":"CRITICAL","score":9.8,"description":"SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0064,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28323"},{"id":"CVE-2026-4978","vendor":"UMAI Vision","product":"Traffic Analysis System","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection.\n\nThis issue affects Traffic Analysis System: from 30 before 34.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0026,"url":"https://cve.blackmesa.ca/?q=CVE-2026-4978"},{"id":"CVE-2026-12940","vendor":"IBM","product":"Langflow OSS","severity":"CRITICAL","score":9.8,"description":"IBM Langflow OSS 1.0.0 through 1.10.1\u00a0 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.0048,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12940"},{"id":"CVE-2026-12118","vendor":"IBM","product":"webMethods Integration (on prem)","severity":"CRITICAL","score":9.8,"description":"IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.005,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12118"},{"id":"CVE-2026-12943","vendor":"IBM","product":"HMC V10.3.1050.0","severity":"CRITICAL","score":9.8,"description":"IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.0092,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12943"},{"id":"CVE-2026-67208","vendor":"somta","product":"Juggle","severity":"CRITICAL","score":9.8,"description":"Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attack\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.011,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67208"}],"vendor_spikes":[{"vendor":"HashiCorp","count":56,"critical_count":1},{"vendor":"WordPress","count":37,"critical_count":1},{"vendor":"Unknown","count":25,"critical_count":3},{"vendor":"IBM","count":23,"critical_count":5},{"vendor":"Red Hat","count":19,"critical_count":0},{"vendor":"Apache","count":16,"critical_count":0},{"vendor":"Microsoft","count":6,"critical_count":1},{"vendor":"SGLang","count":6,"critical_count":0},{"vendor":"cloudreve","count":6,"critical_count":0},{"vendor":"MZ Automation GmbH","count":5,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":293,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-07-30","date_human":"Thursday, July 30, 2026","generated_utc":"2026-07-30 13:00 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","link":"https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html","reason":"Microsoft","category":"News","sources":["Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-BgxoTGLqXYzQh4HW0TUm-hbX0ApFizzFtFkKe5mb3fKS_yn6Zzpj_Uvivxi7VCwEUOuJx3Bg1XHpHWq9tbZh5xBrAHT4gBG2DYyqvFkVKmWIRiF_zCpXIG5bTs7HfsV1pjM2EsTm-e7WttN-iB57p0n4ki2Vs7vXyB6rTF9mSqlwPu3h7KHocg0mWcI/s1600/copilot-word.jpg","description":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. M\u00e5l\u00f8y's","related":[{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"1m ago"},{"title":"Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages","link":"https://www.infosecurity-magazine.com/news/teams-phishing-abused-legit/","source":"Infosecurity Magazine","date_rel":"1h ago"},{"title":"Russian spies take their half-click email attack from Zimbra to Outlook","link":"https://www.theregister.com/security/2026/07/30/russian-spies-take-their-half-click-email-attack-from-zimbra-to-outlook/5281033","source":"The Register Security","date_rel":"2h ago"},{"title":"Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT","link":"https://cybersecuritynews.com/fake-flash-player-installer/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"A Two-Minute Microsoft Teams Call Could End With Your Network Encrypted With Ransomware","link":"https://cybersecuritynews.com/a-two-minute-microsoft-teams-call/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation","link":"https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html","source":"The Hacker News","date_rel":"5h ago"}]},{"title":"Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data","link":"https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html","reason":"Cisco","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-20316"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFSDmsE6q7010reBwpOwS1ESkJSxlBlgRBbtjEVAdeClQFAkRfpriRQWUpL0Br8xnFdF1mctv4Ttj1Nv77MMIKm9qlNehPtTLYzOQwcZAWR4Vw1HzjAvItevYjwQkUo_2JNRluc2_OeJ3vOZ-P8meai9NLLWBvothfh7GDqoOpMPmKpOO-hjAeY-Pxa-BV/s1600/cisco.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log","related":[{"title":"Cisco security advisory (AV26-757)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-757","source":"CCCS Alerts & Advisories","date_rel":"14m ago"},{"title":"Cisco warns of FMC static credential flaw exploited in zero-day attacks","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/","source":"Bleeping Computer","date_rel":"15h ago"}]},{"title":"The Network Has Become the Control Plane for AI Security","link":"https://thehackernews.com/2026/07/the-network-has-become-control-plane.html","reason":"Teams","category":"News","sources":["Dark Reading","Recorded Future Intelligence","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCMiEYFcCrvL7s-o_ZApEbF6gP4J5FpWseBSQN2iP5bBIXP51mVR8QDnUmxDHBrMr0ta6ucsouVsVnWg8mGPeRvwkx09PCddi0pWLYzOpeA7NnrKUaeVhypXKK9rBJSfminUSBH9cz4YTelqUFMU-VZU2G-mkKFhb1pMQsGcAqtuT4btXzbbgb4pD1Mdfi/s1600/checkpoint-main.jpg","description":"Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls","related":[{"title":"Dealing with AI-Generated Extortion","link":"https://www.recordedfuture.com/blog/ai-generated-extortion","source":"Recorded Future Intelligence","date_rel":"13h ago"},{"title":"Hugging Face Hack: Lessons for Cyber Defenders","link":"https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders","source":"Dark Reading","date_rel":"19h ago"}]},{"title":"North Korean hackers behind major open-source supply chain attacks, Amazon says","link":"https://therecord.media/north-korea-hackers-amazon-malware","reason":"Amazon","category":"News","sources":["CyberScoop","The Hacker News","The Record"],"coverage":3,"cve_ids":[],"summary":"A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.","source":"The Record","date_rel":"just now","thumbnail":"http://cms.therecord.media/uploads/Javascript_ebfda374da.jpg","description":"","related":[{"title":"Amazon Links Debug and Chalk npm Hijack to North Korea\u2019s Sapphire Sleet","link":"https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html","source":"The Hacker News","date_rel":"6h ago"},{"title":"A little-known npm package was North Korea\u2019s warm-up act for the axios hack","link":"https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/","source":"CyberScoop","date_rel":"15h ago"}]},{"title":"Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)","link":"https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310","reason":"Broadcom","category":"Research","sources":["Rapid7 Blog","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-59309","CVE-2026-59310"],"summary":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable\u2026","source":"Rapid7 Blog","date_rel":"2h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical) An authentication bypass vulnerability in the VMware Directory Service of vCenter that\u2026","related":[{"title":"Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape","link":"https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html","source":"The Hacker News","date_rel":"21h ago"}]},{"title":"Wiz\u2019s First 6 Months as Part of Google","link":"https://www.wiz.io/blog/6-months-google","reason":"Google","category":"Research","sources":["Infosecurity Magazine","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"Fast gets even faster: redefining security for the AI era and doubling down on our multicloud commit","source":"Wiz Research","date_rel":"22h ago","thumbnail":"https://www.datocms-assets.com/75231/1742297622-wiz-google.png","description":"","related":[{"title":"Google Releases Patches for 370 Vulnerabilities in Chrome 151","link":"https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/","source":"Infosecurity Magazine","date_rel":"3h ago"}]},{"title":"MZ Automation lib60870","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11","reason":"CVE-2026-61893","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":["CVE-2026-61893","CVE-2026-63033"],"summary":"View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033) CVSS Vendor Equipment Vulnerabilities v3 6.5 MZ Automation GmbH MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-61893 A crafted IEC 60870-5-104 I-frame with TypeID 104\u2026","related":[{"title":"MZ Automation lib60870","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05","reason":"Rockwell","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 /\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected: ControlLogix 5580 >=V36|<=V37 (CVE-2026-9636) CompactLogix 5380 >=V36|<=V37 (CVE-2026-9636) GuardLogix 5580 >=V36|<=V37 (CVE-2026-9636) Compact GuardLogix 5380 >=V36|<=V37 (CVE-2026-9636) 1756-EN4TR V6.001 (CVE-2026-9636) 1756-EN4TR V7.001 (CVE-2026-9636) CVSS Vendor Equipment Vulnerabilities v3 5.9 Rockwell Automation Rockwell Automation\u2026","related":[{"title":"Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Schneider Electric IGSS","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04","reason":"Scada","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could\u2026","related":[{"title":"Schneider Electric IGSS","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"NASA Core Flight System (cFS) Health & Safety (HS) Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06","reason":"Application Safety Health","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0.1 (CVE-2026-18064) CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United\u2026","related":[{"title":"NASA Core Flight System (cFS) Health & Safety (HS) Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06","source":"CISA ICS Advisories","date_rel":"1h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-54735","vendor":"prebid","product":"prebid-server","severity":"CRITICAL","score":10.0,"description":"Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without prope\u2026","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":0.0035,"url":"https://cve.blackmesa.ca/?q=CVE-2026-54735"},{"id":"CVE-2026-16326","vendor":"HashiCorp","product":"Tooling","severity":"CRITICAL","score":10.0,"description":"In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (C\u2026","cwe":"CWE-488","kev":false,"kev_action":"","kev_due":"","epss":0.003,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16326"},{"id":"CVE-2026-67429","vendor":"flytohub","product":"flyto-core","severity":"CRITICAL","score":10.0,"description":"Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR c\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":0.0049,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67429"},{"id":"CVE-2026-48449","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is ch\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":0.0054,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48449"},{"id":"CVE-2026-54680","vendor":"Kubernetes","product":"logging-operator","severity":"CRITICAL","score":9.9,"description":"Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_tr\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0043,"url":"https://cve.blackmesa.ca/?q=CVE-2026-54680"},{"id":"CVE-2026-58046","vendor":"WebPros","product":"Plesk","severity":"CRITICAL","score":9.9,"description":"Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0031,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58046"},{"id":"CVE-2026-60112","vendor":"NASA-AMMOS","product":"AIT-GUI","severity":"CRITICAL","score":9.8,"description":"AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() \u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0041,"url":"https://cve.blackmesa.ca/?q=CVE-2026-60112"},{"id":"CVE-2026-60113","vendor":"NASA-AMMOS","product":"AIT-DSN","severity":"CRITICAL","score":9.8,"description":"AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0041,"url":"https://cve.blackmesa.ca/?q=CVE-2026-60113"},{"id":"CVE-2026-67191","vendor":"Xlight","product":"Xlight FTP Server","severity":"CRITICAL","score":9.8,"description":"Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A l\u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":0.0058,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67191"},{"id":"CVE-2026-41939","vendor":"Microsoft","product":"Care Everywhere Gateway","severity":"CRITICAL","score":9.8,"description":"Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials \u2026","cwe":"CWE-1392","kev":false,"kev_action":"","kev_due":"","epss":0.008,"url":"https://cve.blackmesa.ca/?q=CVE-2026-41939"}],"vendor_spikes":[{"vendor":"Google","count":370,"critical_count":42},{"vendor":"WordPress","count":43,"critical_count":2},{"vendor":"Unknown","count":21,"critical_count":6},{"vendor":"Phoenix Contact","count":20,"critical_count":8},{"vendor":"Apple","count":13,"critical_count":0},{"vendor":"GitLab","count":13,"critical_count":0},{"vendor":"balbooa.com","count":11,"critical_count":0},{"vendor":"Red Hat","count":11,"critical_count":0},{"vendor":"ASUSTOR Inc.","count":8,"critical_count":0},{"vendor":"netty","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":662,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-07-29","date_human":"Wednesday, July 29, 2026","generated_utc":"2026-07-29 13:00 UTC","read_minutes":4,"patch_tuesday":false,"top_stories":[{"title":"Apple\u2019s iMessage Scanning Flagged a Video of My Friend's Dog as Nudity","link":"https://www.404media.co/apples-imessage-scanning-flagged-a-video-of-my-friends-dog-as-nudity/","reason":"Apple","category":"News","sources":["404 Media","CCCS Alerts & Advisories","SANS Internet Storm Center","Zero Day Initiative"],"coverage":4,"cve_ids":[],"summary":"In a video my friend\u2019s dog is laying on her back, her little paws in the air, while my friend rubs the dog\u2019s chest. You can see most of the dog \u2014 who I\u2019m not naming for very important privacy reasons \u2014 from her head to\u2026","source":"404 Media","date_rel":"22h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/dog-redact.png","description":"In a video my friend\u2019s dog is laying on her back, her little paws in the air, while my friend rubs the dog\u2019s chest. You can see most of the dog \u2014 who I\u2019m not naming for very important privacy reasons \u2014 from her head to her belly. On closer inspection, you\u2019ll notice the picture includes some dog nipples. Apple\u2019s iMessage thought this video was so inappropriate that it flagged the video as potentially containing nudity and blurred it. When someone else received the video over iMessage, the app displayed the message \u201cThis may be sensitive.\u201d They had to purposefully tap to reveal the video of a\u2026","related":[{"title":"Apple Patches Everything (July 2026), (Wed, Jul 29th)","link":"https://isc.sans.edu/diary/rss/33196","source":"SANS Internet Storm Center","date_rel":"5h ago"},{"title":"ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-494/","source":"Zero Day Initiative","date_rel":"8h ago"},{"title":"ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-493/","source":"Zero Day Initiative","date_rel":"8h ago"},{"title":"ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-492/","source":"Zero Day Initiative","date_rel":"8h ago"},{"title":"Apple security advisory (AV26-753)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-753","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"MCP gets an enterprise makeover","link":"https://www.theregister.com/ai-and-ml/2026/07/29/mcp-gets-an-enterprise-makeover/5280027","reason":"Linux","category":"News","sources":["Infosecurity Magazine","Schneier on Security","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024\u2026","source":"The Register Security","date_rel":"13h ago","thumbnail":"https://image.theregister.com/?imageId=5239946&width=800","description":"The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024, MCP provides a way for AI applications (agents) based on models like GPT-5.6 Sol or Claude Opus 5 to connect to existing data sources, tools, or other applications. It defines how content is exchanged in a client-server architecture. \"The new release is MCP\u2019s most important since remote MCP first launched over a year ago,\" wrote David Soria Parra, a member of technical staff at\u2026","related":[{"title":"Long-Lived Vulnerability in Microsoft Secure Boot","link":"https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html","source":"Schneier on Security","date_rel":"1h ago"},{"title":"Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process","link":"https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html","source":"The Hacker News","date_rel":"21h ago"},{"title":"AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched","link":"https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/","source":"Infosecurity Magazine","date_rel":"22h ago"}]},{"title":"Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here","link":"https://www.elastic.co/security-labs/sentinel-detection-rules-migration","reason":"Microsoft","category":"Research","sources":["Dark Reading","Elastic Security Labs","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping\u2026","source":"Elastic Security Labs","date_rel":"13h ago","thumbnail":"https://www.elastic.co/security-labs/assets/images/sentinel-detection-rules-migration/image4.jpg","description":"Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping and translation from there using an LLM you choose. Watchlists and severity mappings carry over. This is the first automatic migration path off a modern SIEM, available now in Tech Preview in 9.5, and it works across multiple cloud providers and regions so you can deploy closer to where your data lives. Which Microsoft Sentinel rule types can be migrated automatically?\u2026","related":[{"title":"Microsoft and Wiz mind-meld agents catch more than 90% of bugs","link":"https://www.theregister.com/security/2026/07/28/microsoft-and-wiz-mind-meld-agents-catch-more-than-90-of-bugs/5279914","source":"The Register Security","date_rel":"17h ago"},{"title":"'Certighost' Flaw Haunts Microsoft Active Directory Certificates","link":"https://www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates","source":"Dark Reading","date_rel":"20h ago"}]},{"title":"73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack","link":"https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html","reason":"Teams","category":"News","sources":["CrowdStrike Blog","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixbolkSzPCa__qy94Mm27YfEsvVeyY94SOG5BrCQCGtAe-QenE0qDM5Tkbb7eOy0PwSCECFGMrZ7IG7lVePoMWjqMn8s_7-5_r8JUSQ7WVHsHAo-zZIhyphenhyphenyNW5aGTbFkpgtu99ucSeEgcJK75UdxkAsWKjXf_x8zEGpcDURPf9UJjcDz8JSHFD0uahDcOI5/s1600/ss.jpg","description":"Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January","related":[{"title":"Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud","link":"https://www.crowdstrike.com/en-us/blog/new-in-falcon-cloud-security-helping-security-teams-move-faster/","source":"CrowdStrike Blog","date_rel":"8h ago"}]},{"title":"Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass","link":"https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html","reason":"Check Point","category":"News","sources":["Rapid7 Blog","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-16232"],"summary":"Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIxq_zUC231fexQTfY9VPvqP7FWVRurT9fbUUS3YMpMX2SRmJu9eXIlH7v6fnvqJGtirQwXJVjs1h-hbUM7j-R6DlfpW7M4kt28q9EoxMt7jJFjUjaAoVsuTWSsBZOFcDj99U8ApvFR4B4sDQ37QHYeWXjJsowFBP3n8-TBfzcKB2Rl-de-OluIkzbJIYb/s1600/cp-poc.jpg","description":"Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that","related":[{"title":"Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)","link":"https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232","source":"Rapid7 Blog","date_rel":"18h ago"}]}],"worth_reading":[],"kev_watch":[{"id":"CVE-2026-20316","vendor":"Cisco","product":"Secure Firewall Management Center","severity":"MEDIUM","score":5.3,"description":"A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within th\u2026","cwe":"CWE-259","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-08-01","epss":0.0079,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20316"}],"vuln_watch":[{"id":"CVE-2026-16498","vendor":"HashiCorp","product":"Tooling","severity":"CRITICAL","score":10.0,"description":"The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of sub\u2026","cwe":"CWE-488","kev":false,"kev_action":"","kev_due":"","epss":0.0033,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16498"},{"id":"CVE-2026-33267","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"Improper Input Validation vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes t\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-33267"},{"id":"CVE-2026-57834","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"Apache Traffic Server allows request smuggling if chunked messages are malformed.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade \u2026","cwe":"CWE-444","kev":false,"kev_action":"","kev_due":"","epss":0.0026,"url":"https://cve.blackmesa.ca/?q=CVE-2026-57834"},{"id":"CVE-2026-58150","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nU\u2026","cwe":"CWE-444","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58150"},{"id":"CVE-2026-58162","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers ar\u2026","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58162"},{"id":"CVE-2026-63227","vendor":"An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"An unrestricted SCORM file upload vulnerability\nin Koollab LMS allowed\nan authenticated module designer to upload a SCORM package containing a PHP\nwebshell to a publicly accessible directory and execute arbitrary code on the\nserver.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.0033,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63227"},{"id":"CVE-2026-63232","vendor":"Three Learning","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"A SQL injection and unsafe deserialisation\nvulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment\nreinforcement endpoint, control data passed to unserialize(), write a webshell\nto a publicly accessib\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63232"},{"id":"CVE-2026-63233","vendor":"Three Learning","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"A SQL injection and unsafe deserialisation\nvulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment\noverall answer endpoint, control data passed to unserialize(), write a webshell\nto a publicly accessi\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63233"},{"id":"CVE-2026-63234","vendor":"Three Learning","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"A SQL injection and unsafe deserialisation\nvulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark\nassessment endpoint, control data passed to unserialize(), write a webshell to\na publicly accessible\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63234"},{"id":"CVE-2026-51252","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata.","cwe":"CWE-120","kev":false,"kev_action":"","kev_due":"","epss":0.0034,"url":"https://cve.blackmesa.ca/?q=CVE-2026-51252"}],"vendor_spikes":[{"vendor":"Apache","count":45,"critical_count":8},{"vendor":"WordPress","count":39,"critical_count":5},{"vendor":"IBM","count":31,"critical_count":5},{"vendor":"Xen","count":18,"critical_count":0},{"vendor":"Three Learning","count":15,"critical_count":5},{"vendor":"Unknown","count":12,"critical_count":6},{"vendor":"koxudaxi","count":12,"critical_count":0},{"vendor":"HashiCorp","count":11,"critical_count":4},{"vendor":"Adobe","count":10,"critical_count":0},{"vendor":"Red Hat","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":5,"new_cve_count":300,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-07-28","date_human":"Tuesday, July 28, 2026","generated_utc":"2026-07-28 13:00 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost","link":"https://thehackernews.com/2026/07/microsoft-says-new-cybersecurity-ai.html","reason":"Microsoft","category":"News","sources":["Ars Technica Security","CCCS Alerts & Advisories","Infosecurity Magazine","Sophos Threat Research","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwmG858LYHQA-u4cQupdhqsi5oUcvLaQdoorupsW3tzPZvDg7kwgRIewOBPVNvp3Szfqb4VFJ_j6caul2NTIlm69_-vskp4gYQwVkQA59LbsMhOEO3yr4C48nhrO177ORbi9uFc_oIOrcXnCBs_dmPhVDZVZx9F3Cyp4RQKi71EhvfZQqmUKat36cbqEE/s1600/MAI-Cyber-1-Flash.jpg","description":"Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved","related":[{"title":"Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats","link":"https://www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/","source":"Infosecurity Magazine","date_rel":"15m ago"},{"title":"Chaos in Teams vishing","link":"https://www.sophos.com/en-us/blog/chaos-in-teams-vishing","source":"Sophos Threat Research","date_rel":"13h ago"},{"title":"Microsoft unveils AI security tools it says outperform competing platforms","link":"https://arstechnica.com/security/2026/07/microsoft-unveils-ai-security-tools-it-says-outperform-competing-platforms/","source":"Ars Technica Security","date_rel":"15h ago"},{"title":"Microsoft's solution to AI security: more AI and more acronyms","link":"https://www.theregister.com/security/2026/07/27/microsofts-solution-to-ai-security-more-ai-and-more-acronyms/5279140","source":"The Register Security","date_rel":"17h ago"},{"title":"Microsoft security advisory (AV26-747)","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-av26-747","source":"CCCS Alerts & Advisories","date_rel":"19h ago"}]},{"title":"Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit","link":"https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html","reason":"Linux","category":"News","sources":["CISA Alerts & Advisories","CISA ICS Advisories","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-53264"],"summary":"STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgBRFXQr7hvRBIkSC-vqaka7UlRsU8Y380TbDC3jFpFlSlCK1RuVthJDLKt5KaNzAn82kMBNUWPp5s1Voug8ptjn0DiHoxbzw9QdoKXhFfR9SR9zCm1uYeE43tZUba0H7F-mlLogft-qyvtdggSASBR8qAxrRK3U3uPzvf_bkRmJPNzcWX-vfb7qW0VD8/s1600/linux.jpg","description":"STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local","related":[{"title":"Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04","source":"CISA Alerts & Advisories","date_rel":"1h ago"},{"title":"Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04","source":"CISA ICS Advisories","date_rel":"1h ago"},{"title":"Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update","link":"https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpoint-leaves-some-linux-boxes-defenseless-after-update/5278914","source":"The Register Security","date_rel":"23h ago"}]},{"title":"Tons of Peoples\u2019 Claude Chats and Creations are Exposed on Google","link":"https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are-exposed-on-google/","reason":"Google","category":"News","sources":["404 Media","Dark Reading","Malwarebytes Labs"],"coverage":3,"cve_ids":[],"summary":"Claude is exposing a wealth of users\u2019 chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly\u2026","source":"404 Media","date_rel":"23h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/brett-wharton-YmSiFKOecCU-unsplash.jpg","description":"Claude is exposing a wealth of users\u2019 chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly available for strangers to see.","related":[{"title":"Shared Claude chats were searchable on Google","link":"https://www.malwarebytes.com/blog/privacy/2026/07/shared-claude-chats-were-searchable-on-google","source":"Malwarebytes Labs","date_rel":"26m ago"},{"title":"'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure","link":"https://www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure","source":"Dark Reading","date_rel":"16h ago"},{"title":"Aftercall ads are driving Android users crazy","link":"https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy","source":"Malwarebytes Labs","date_rel":"17h ago"}]},{"title":"ABB KNX Update Tool","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07","reason":"Abb","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX\u2026","related":[{"title":"ABB KNX Update Tool","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Siemens Desigo CC","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01","reason":"Openssl","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Desigo CC are affected: Desigo CC family V7 vers:all/* (CVE-2025-15467) Desigo CC family V8 vers:all/* (CVE-2025-15467) Desigo\u2026","related":[{"title":"Siemens Desigo CC","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Siemens SIMATIC S7-PLCSIM Advanced","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03","reason":"Siemens","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected: SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429) CVSS Vendor Equipment Vulnerabilities v3 7.4 Siemens Siemens SIMATIC S7-PLCSIM Advanced Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical\u2026","related":[{"title":"Siemens Mendix Runtime","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02","source":"CISA Alerts & Advisories","date_rel":"1h ago"},{"title":"Siemens SIMATIC S7-PLCSIM Advanced","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03","source":"CISA ICS Advisories","date_rel":"1h ago"},{"title":"Siemens Mendix Runtime","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"igloohome Smart Lock Mobile Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06","reason":"Application Igloohome Mobile","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected: Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581) CVSS Vendor Equipment Vulnerabilities v3 5.3 igloohome igloohome Smart Lock Mobile Application Inclusion of Sensitive Information in Source Code Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Singapore Vulnerabilities Expand All +\u2026","related":[{"title":"igloohome Smart Lock Mobile Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"MikroTik RouterOS and Cloud Hosted Router","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05","reason":"Routeros Mikrotik Hosted","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router are affected: RouterOS vers:all/* (CVE-2026-16347) Cloud Hosted Router vers:all/* (CVE-2026-16347) CVSS Vendor Equipment Vulnerabilities v3 8.8 MikroTik MikroTik RouterOS and Cloud Hosted Router Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Information Technology, Commercial Facilities Countries/Areas Deployed: Worldwide\u2026","related":[{"title":"MikroTik RouterOS and Cloud Hosted Router","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock","link":"https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414","reason":"CVE-2026-16812","category":"News","sources":["The Hacker News","The Register Security"],"coverage":2,"cve_ids":["CVE-2026-16812"],"summary":"A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812\u2026","source":"The Register Security","date_rel":"3h ago","thumbnail":"https://image.theregister.com/?imageId=5279434&width=800","description":"A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch offices, datacenters, and clouds environments. According to Arista's security advisory, the flaw is an OS command injection vulnerability that allows\u2026","related":[{"title":"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw","link":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html","source":"The Hacker News","date_rel":"8h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-16812","vendor":"Arista Networks","product":"Velocloud Orchestrator","severity":"CRITICAL","score":10.0,"description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit\u2026","cwe":"CWE-78","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-07-30","epss":0.0088,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16812"},{"id":"CVE-2026-11756","vendor":"Dassault Syst\u00e8mes","product":"Station Launcher App in 3DEXPERIENCE platform","severity":"CRITICAL","score":10.0,"description":"A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0045,"url":"https://cve.blackmesa.ca/?q=CVE-2026-11756"},{"id":"CVE-2026-48030","vendor":"pheditor","product":"pheditor","severity":"CRITICAL","score":9.9,"description":"Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS command\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.0155,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48030"},{"id":"CVE-2026-61511","vendor":"vBulletin","product":"vBulletin","severity":"CRITICAL","score":9.8,"description":"vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code\u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":0.0127,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61511"},{"id":"CVE-2026-65879","vendor":"joomshaper.com","product":"SP Page Builder extension for Joomla","severity":"CRITICAL","score":9.8,"description":"Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.0028,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65879"},{"id":"CVE-2026-51303","vendor":"Apple","product":"","severity":"CRITICAL","score":9.8,"description":"A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDelete and then subsequently accesses the dangling pointer of \u2026","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","epss":0.0037,"url":"https://cve.blackmesa.ca/?q=CVE-2026-51303"},{"id":"CVE-2026-63077","vendor":"JetBrains","product":"TeamCity","severity":"CRITICAL","score":9.8,"description":"In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0065,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63077"},{"id":"CVE-2026-55579","vendor":"pheditor","product":"pheditor","severity":"CRITICAL","score":9.8,"description":"Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a \u2026","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.006,"url":"https://cve.blackmesa.ca/?q=CVE-2026-55579"},{"id":"CVE-2026-28911","vendor":"Apple","product":"Macos","severity":"CRITICAL","score":9.8,"description":"The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28911"},{"id":"CVE-2026-28928","vendor":"Apple","product":"Ipados","severity":"CRITICAL","score":9.8,"description":"A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","epss":0.0042,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28928"}],"vendor_spikes":[{"vendor":"Apple","count":167,"critical_count":56},{"vendor":"WordPress","count":45,"critical_count":3},{"vendor":"Linux","count":19,"critical_count":2},{"vendor":"Unknown","count":13,"critical_count":3},{"vendor":"jfrog","count":11,"critical_count":0},{"vendor":"Red Hat","count":8,"critical_count":0},{"vendor":"vercel","count":8,"critical_count":0},{"vendor":"Progress","count":5,"critical_count":0},{"vendor":"joomshaper.com","count":5,"critical_count":1},{"vendor":"Microsoft","count":5,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":9,"new_cve_count":452,"has_news_data":true,"has_cve_data":true},{"date_iso":"2026-07-27","date_human":"Monday, July 27, 2026","generated_utc":"2026-07-27 13:00 UTC","read_minutes":3,"patch_tuesday":false,"top_stories":[{"title":"Google goes it alone with a new cybercrime crew taxonomy","link":"https://www.theregister.com/security/2026/07/27/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy/5278749","reason":"Google","category":"News","sources":["Malwarebytes Labs","The Register Security"],"coverage":2,"cve_ids":[],"summary":"Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022\u2026","source":"The Register Security","date_rel":"5h ago","thumbnail":"https://image.theregister.com/?imageId=255057&width=800","description":"Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022 acquisition of Mandiant and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG). Now that two have become one, Google reckons they need consistent naming conventions to describe cybercrime crews. The result is a two-word schema in which the first word \u201cis a unique and memorable term chosen to represent the specific actor.\u201d If security\u2026","related":[{"title":"A week in security (July 20 \u2013 July 26)","link":"https://www.malwarebytes.com/blog/news/2026/07/a-week-in-security-july-20-july-26","source":"Malwarebytes Labs","date_rel":"5h ago"}]}],"worth_reading":[],"kev_watch":[{"id":"CVE-2026-16812","vendor":"Arista Networks","product":"Velocloud Orchestrator","severity":"CRITICAL","score":10.0,"description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit\u2026","cwe":"CWE-78","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-07-30","epss":0.0088,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16812"}],"vuln_watch":[{"id":"CVE-2026-12394","vendor":"WordPress","product":"MemberGlut","severity":"CRITICAL","score":9.8,"description":"The MemberGlut  WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compr\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":0.0028,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12394"},{"id":"CVE-2026-13714","vendor":"WordPress","product":"Realtyna Organic IDX plugin + WPL Real Estate","severity":"CRITICAL","score":9.8,"description":"The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardco\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.0046,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13714"},{"id":"CVE-2026-64534","vendor":"Linux","product":"Linux","severity":"CRITICAL","score":9.8,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path\n\nIn nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,\nnvmet_req_uninit() is ca\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":0.0038,"url":"https://cve.blackmesa.ca/?q=CVE-2026-64534"},{"id":"CVE-2026-64535","vendor":"Linux","product":"Linux","severity":"CRITICAL","score":9.8,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Fix potential UAF when ddgst mismatch\n\nShivam Kumar found via vulnerability testing:\nWhen data digest is enabled on an NVMe/TCP connection and a digest\nmismatch\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":0.0047,"url":"https://cve.blackmesa.ca/?q=CVE-2026-64535"},{"id":"CVE-2026-55971","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.8,"description":"Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":0.0104,"url":"https://cve.blackmesa.ca/?q=CVE-2026-55971"},{"id":"CVE-2026-13332","vendor":"WordPress","product":"Masteriyo LMS","severity":"CRITICAL","score":9.1,"description":"The Masteriyo LMS  WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of an\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13332"},{"id":"CVE-2026-13597","vendor":"WordPress","product":"\u5fae\u4fe1\u4e8c\u7ef4\u7801\u767b\u9646","severity":"CRITICAL","score":9.1,"description":"The \u5fae\u4fe1\u4e8c\u7ef4\u7801\u767b\u9646 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0026,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13597"},{"id":"CVE-2026-48144","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.1,"description":"Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.","cwe":"CWE-297","kev":false,"kev_action":"","kev_due":"","epss":0.0042,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48144"},{"id":"CVE-2026-58023","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.1,"description":"Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.","cwe":"CWE-125","kev":false,"kev_action":"","kev_due":"","epss":0.0108,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58023"},{"id":"CVE-2026-58662","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.1,"description":"Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue\u2026","cwe":"CWE-125","kev":false,"kev_action":"","kev_due":"","epss":0.0115,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58662"}],"vendor_spikes":[{"vendor":"WordPress","count":23,"critical_count":5},{"vendor":"Apache","count":15,"critical_count":4},{"vendor":"Linux","count":6,"critical_count":2},{"vendor":"Microsoft","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":1,"new_cve_count":68,"has_news_data":true,"has_cve_data":true}]