<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Cyber Threat Digest — Cyber Attacks</title>
    <link>https://example.github.io/cyber-rss</link>
    <description>Breaches, ransomware, intrusions, compromises, supply-chain attacks, DDoS, and extortion.</description>
    <atom:link href="https://example.github.io/cyber-rss/feeds/cyber-attacks.xml" rel="self"/>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>cyber-rss-aggregator</generator>
    <language>en</language>
    <lastBuildDate>Tue, 11 Aug 2026 02:30:42 +0000</lastBuildDate>
    <item>
      <title>Hackers breached a small Polish energy plant via private APN last year</title>
      <link>https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/</link>
      <description>&lt;p&gt;Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.80)&lt;/p&gt;</description>
      <guid isPermaLink="false">3cb7fb7fad5010a89bccac8cc0b422ba</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 23:07:21 +0000</pubDate>
    </item>
    <item>
      <title>My Homelab Got Hacked – A Postmortem</title>
      <link>https://phunky.cafe/my-homelab-got-hacked/</link>
      <description>&lt;p&gt;Article URL: https://phunky.cafe/my-homelab-got-hacked/ Comments URL: https://news.ycombinator.com/item?id=49251087 Points: 6 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.42; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">a39a746dfd2a2100e593690f22ba0d05</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 23:04:18 +0000</pubDate>
    </item>
    <item>
      <title>BdThemes plugins supply-chain hack creates rogue WordPress admins</title>
      <link>https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/</link>
      <description>&lt;p&gt;A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators&amp;#x27; browsers to create rogue admin accounts. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.37; also threat_intel 0.59)&lt;/p&gt;</description>
      <guid isPermaLink="false">31b66be99af3207f459f1edc9c11e6a3</guid>
      <category>Security</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 21:12:10 +0000</pubDate>
    </item>
    <item>
      <title>OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users</title>
      <link>https://www.bleepingcomputer.com/news/security/openai-releases-chatgpt-56-cyber-but-its-only-for-approved-users/</link>
      <description>&lt;p&gt;OpenAI has developed a new model called &amp;quot;GPT 5.6 Cyber,&amp;quot; designed for vulnerability research, penetration testing, incident response, and remediation. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security, Artificial Intelligence&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.70; also vulnerabilities 0.52)&lt;/p&gt;</description>
      <guid isPermaLink="false">87366ebf9d600daf308a592246e7548b</guid>
      <category>Security</category>
      <category>Artificial Intelligence</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:vulnerabilities</category>
      <pubDate>Mon, 10 Aug 2026 19:24:40 +0000</pubDate>
    </item>
    <item>
      <title>CISA Advisory: #StopRansomware: Gunra Ransomware</title>
      <link>https://databreaches.net/2026/08/10/cisa-advisory-stopransomware-gunra-ransomware/</link>
      <description>&lt;p&gt;Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.99; also threat_intel 0.91)&lt;/p&gt;</description>
      <guid isPermaLink="false">7d46ce02c02169b334db9de93f3758d6</guid>
      <category>Malware</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 19:02:46 +0000</pubDate>
    </item>
    <item>
      <title>New StormEncryptor ransomware used by former Medusa affiliate</title>
      <link>https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/</link>
      <description>&lt;p&gt;A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.98; also threat_intel 0.59)&lt;/p&gt;</description>
      <guid isPermaLink="false">f8cb8b670a1ef85ff5ba80c72828ee3c</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 17:42:00 +0000</pubDate>
    </item>
    <item>
      <title>China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw</title>
      <link>https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html</link>
      <description>&lt;p&gt;Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary&amp;#x27;s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. &amp;quot;StormEncryptor is written in C++ and appends the file name extension .encrypted&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.98; also threat_intel 0.88, vulnerabilities 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">4c624f6c9bd5a27e21068cdbd69f5eda</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <category>bucket:vulnerabilities</category>
      <pubDate>Mon, 10 Aug 2026 16:38:37 +0000</pubDate>
    </item>
    <item>
      <title>⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors</title>
      <link>https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html</link>
      <description>&lt;p&gt;A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.93; also vulnerabilities 0.87, threat_intel 0.56)&lt;/p&gt;</description>
      <guid isPermaLink="false">ab9fcef0eed7ce972e79363eeeffbc9c</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 15:00:29 +0000</pubDate>
    </item>
    <item>
      <title>Someone hacked the X algorithm with fable and shows how it works</title>
      <link>https://thomasunise.com/x-algorithm</link>
      <description>&lt;p&gt;Article URL: https://thomasunise.com/x-algorithm Comments URL: https://news.ycombinator.com/item?id=49244428 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.42; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">c847c345d3ce4a08439a9d6d897f37b4</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 14:47:54 +0000</pubDate>
    </item>
    <item>
      <title>CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs</title>
      <link>https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/</link>
      <description>&lt;p&gt;CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.90; also vulnerabilities 0.91)&lt;/p&gt;</description>
      <guid isPermaLink="false">0ae2ad26aa145b0d1ac8b654f9205f9b</guid>
      <category>Security</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 14:34:32 +0000</pubDate>
    </item>
    <item>
      <title>OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns</title>
      <link>https://www.securityweek.com/openais-upcoming-astra-model-raises-autonomous-cyberattack-concerns/</link>
      <description>&lt;p&gt;The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Artificial Intelligence, AI, Astra, cybersecurity AI, OpenAI, OpenAI Astra&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.79)&lt;/p&gt;</description>
      <guid isPermaLink="false">f6707319419b6ceffa2a0672592fcf49</guid>
      <category>Artificial Intelligence</category>
      <category>AI</category>
      <category>Astra</category>
      <category>cybersecurity AI</category>
      <category>OpenAI</category>
      <category>OpenAI Astra</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 14:33:36 +0000</pubDate>
    </item>
    <item>
      <title>Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds</title>
      <link>https://www.securityweek.com/stealthium-targets-security-blind-spots-in-ai-accelerators-and-neo-clouds/</link>
      <description>&lt;p&gt;The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Application Security, Supply Chain Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35)&lt;/p&gt;</description>
      <guid isPermaLink="false">78008530804e6bf8ab8c4fde5b48ffd4</guid>
      <category>Application Security</category>
      <category>Supply Chain Security</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 14:19:36 +0000</pubDate>
    </item>
    <item>
      <title>Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC</title>
      <link>https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/</link>
      <description>&lt;p&gt;Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Vulnerabilities, Cisco, ClamAV, DoS, Patch, PoC, public PoC, vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">6d33e550407f92125e9575937f539db4</guid>
      <category>Vulnerabilities</category>
      <category>Cisco</category>
      <category>ClamAV</category>
      <category>DoS</category>
      <category>Patch</category>
      <category>PoC</category>
      <category>public PoC</category>
      <category>vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 14:07:48 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68130: In the Linux kernel, the following vulnerability has been resolved:

ksmbd: defer destroy_previous_session() until</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68130</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

ksmbd: defer destroy_previous_session() until after NTLM authentication

In ntlm_authenticate(), destroy_previous_session() is called using a
user pointer resolved from the client-supplied NTLM blob username field
before the NTLMv2 response is validated. An authenticated attacker can
set the NTLM blob username to match a victim account and set
PreviousSessionId to the victim&amp;#x27;s session ID; destroy_previous_session()
destroys the victim&amp;#x27;s session while ksmbd_decode_ntlmssp_auth_blob()
subsequently rejects the request with -EPERM.

Move destroy_previous_session() and the prev_id assignment to after
ksmbd_decode_ntlmssp_auth_blob() returns success and use sess-&amp;gt;user
rather than the pre-authentication lookup result. This matches the
ordering already used by krb5_authenticate(), where
destroy_previous_session() is called only after
ksmbd_krb5_authenticate() returns success.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">5f5cb3cd6ded97225d86756be4020bab</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 13:19:58 +0000</pubDate>
    </item>
    <item>
      <title>Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development</title>
      <link>https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html</link>
      <description>&lt;p&gt;North Korea&amp;#x27;s state hackers are no longer content to type prompts into public chatbots. One of the country&amp;#x27;s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also threat_intel 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">e4cbe4f1c2f955e0940f09e86e40faa8</guid>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 13:19:58 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-59090 (CVSS 8.4 HIGH): A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem`</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-59090</link>
      <description>&lt;p&gt;CVSS 8.4 HIGH. A flaw was found in GIMP&amp;#x27;s PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim&amp;#x27;s system.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">7267394206123191ae51690f5b528b1e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 13:19:51 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-19278 (CVSS 6.8 MEDIUM): A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-19278</link>
      <description>&lt;p&gt;CVSS 6.8 MEDIUM. A flaw was found in StackRox/RHACS Central&amp;#x27;s Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">6a9d9256eda5f819a8b7bd23abd9a08d</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 13:17:58 +0000</pubDate>
    </item>
    <item>
      <title>‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad</title>
      <link>https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/</link>
      <description>&lt;p&gt;An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Artificial Intelligence, AI, Ghostjacking&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.56)&lt;/p&gt;</description>
      <guid isPermaLink="false">fce87c1281fb1a527560dcc26566fd67</guid>
      <category>Artificial Intelligence</category>
      <category>AI</category>
      <category>Ghostjacking</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 12:59:34 +0000</pubDate>
    </item>
    <item>
      <title>Member of The Com sent to prison for blackmail, sextortion</title>
      <link>https://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/</link>
      <description>&lt;p&gt;A member of &amp;quot;The Com,&amp;quot; a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.37)&lt;/p&gt;</description>
      <guid isPermaLink="false">904037e4e9dbce8bb75bb31a4dfbefbc</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 12:56:28 +0000</pubDate>
    </item>
    <item>
      <title>New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA</title>
      <link>https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html</link>
      <description>&lt;p&gt;Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim&amp;#x27;s machine, and used a&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.79; also threat_intel 0.74)&lt;/p&gt;</description>
      <guid isPermaLink="false">cdcb04f053b50d7b593de00f643c86b8</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:25:04 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-64941: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-64941</link>
      <description>&lt;p&gt;URL Redirection to Untrusted Site (&amp;#x27;Open Redirect&amp;#x27;) vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim&amp;#x27;s browser to an origin of the attacker&amp;#x27;s choosing via a :to value containing ASCII tab, LF or CR.

redirect/2 validates :to through the private validate_local_url!/2 in lib/phoenix_live_view.ex, which is intended to guarantee the target is a path within the application. It rejects a leading // and any backslash, but not ASCII tab, LF or CR. Browsers strip those three characters before parsing a URL, so a value such as /&amp;lt;TAB&amp;gt;/example.com passes validation as a path and is then resolved as the scheme-relative URL //example.com. The live navigation functions share the guard but are not affected, because the client expands their target against the current origin. push_patch/2 is also affected before 0.7.0, which is when that expansion was added.

This issue affects phoenix_live_view: from 0.5.0 before 1.0.19, from 1.1.0-rc.0 before 1.1.33, and from 1.2.0-rc.0 before 1.2.9.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">28d8b0944896dce0e8a087552f240b9b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 12:17:19 +0000</pubDate>
    </item>
    <item>
      <title>Valve notifies Steam hardware customers of a data breach</title>
      <link>https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/</link>
      <description>&lt;p&gt;Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.93)&lt;/p&gt;</description>
      <guid isPermaLink="false">4a7027d536527b273337a7c5fe94c7f2</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:47:55 +0000</pubDate>
    </item>
    <item>
      <title>New Jersey, Alabama Join States Targeted in Water Cyberattacks</title>
      <link>https://www.securityweek.com/new-jersey-alabama-join-states-targeted-in-water-cyberattacks/</link>
      <description>&lt;p&gt;Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; ICS/OT, ICS, OT, Water&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.86)&lt;/p&gt;</description>
      <guid isPermaLink="false">96de0fce908dc4f4ec87f01c0e8ab00c</guid>
      <category>ICS/OT</category>
      <category>ICS</category>
      <category>OT</category>
      <category>Water</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:44:26 +0000</pubDate>
    </item>
    <item>
      <title>TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore</title>
      <link>https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html</link>
      <description>&lt;p&gt;The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also vulnerabilities 0.89, threat_intel 0.82)&lt;/p&gt;</description>
      <guid isPermaLink="false">8cd19c7c9cd43bd13e6088bc5d9db256</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:33:41 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72593 (CVSS 9.8 CRITICAL): A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72593</link>
      <description>&lt;p&gt;CVSS 9.8 CRITICAL. A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the server filesystem.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">acfd2093142f553f5e3822ae00226a71</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72592 (CVSS 9.8 CRITICAL): An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72592</link>
      <description>&lt;p&gt;CVSS 9.8 CRITICAL. An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and no authentication enabled by default (auth_pass is empty string), allowing an unauthenticated attacker to upload a PHP webshell and execute it by browsing to the uploaded path.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">64c5357fcb896e59bfbdcee717d49390</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72588 (CVSS 5.3 MEDIUM): A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72588</link>
      <description>&lt;p&gt;CVSS 5.3 MEDIUM. A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered ones, enabling attackers to enumerate valid user accounts.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99, threat_intel 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">0578f4ae67910144ca6b53bc2c82a9f3</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72587 (CVSS 6.1 MEDIUM): A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72587</link>
      <description>&lt;p&gt;CVSS 6.1 MEDIUM. A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/&amp;lt;nodeId&amp;gt; server island endpoint.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">319e51bddf16ce718d86a41c66c3db4e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72586 (CVSS 7.5 HIGH): A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72586</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES, DEVICE_TAGS_REQUEST, etc.) call isSocketAdminAuthorized to verify the connection token, but the DAQ_QUERY handler in server/runtime/index.js lacks this check entirely.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">9b45ddca06ea6f3dd259f6968c63fa5e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72582 (CVSS 7.5 HIGH): A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72582</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in pkg/auth/local.go dereferences a pointer obtained from an unchecked error path without validating it is non-nil, causing a fatal panic that terminates the entire server when a recovery request is sent to the /api/auth/local/recover endpoint.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99, threat_intel 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">0004127ec218ce0f3bdbbeeb00e06234</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72580 (CVSS 9.8 CRITICAL): An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72580</link>
      <description>&lt;p&gt;CVSS 9.8 CRITICAL. An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute and /unmute endpoint handlers in api/main.py pass the user-supplied silent query parameter directly to os.system() without sanitization, enabling command injection via shell metacharacters.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">a9deb774ee65d69d5157e15e973a151c</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72579 (CVSS 7.5 HIGH): An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72579</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary system commands on the researcher&amp;#x27;s workstation.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">75d36a3bca70b037e50a348c8ee1d71e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72578 (CVSS 8.8 HIGH): A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72578</link>
      <description>&lt;p&gt;CVSS 8.8 HIGH. A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">008c85e124e05aca4ce8d01f01dc8a10</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72577 (CVSS 9.8 CRITICAL): Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72577</link>
      <description>&lt;p&gt;CVSS 9.8 CRITICAL. Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">fdc3f9e6a6005c8129f62d749a06cc50</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72575 (CVSS 9.1 CRITICAL): An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read,</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72575</link>
      <description>&lt;p&gt;CVSS 9.1 CRITICAL. An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergroup records. The permission check functions (CanRead, CanPeek, CanCreate, CanUpdate, CanDelete, CanRefer) in server/permission/permission.go return true whenever p.UserId equals the requesting userId, but fail to reject the null/zero reference — unlike CanExecute, which explicitly guards it.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">e9b0194b49058c1167195f5be6500583</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72574 (CVSS 6.1 MEDIUM): A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72574</link>
      <description>&lt;p&gt;CVSS 6.1 MEDIUM. A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control the origin of JavaScript and CSS assets loaded by the default theme. When base_url is unset (the default), Pico::getBaseUrl in lib/Pico.php builds the base URL from unvalidated Host, X-Forwarded-Host, X-Forwarded-Proto, and X-Forwarded-Port request headers.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">17f10a23783af4375f72fdf91b9b937c</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72573 (CVSS 8.8 HIGH): An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72573</link>
      <description>&lt;p&gt;CVSS 8.8 HIGH. An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on the host. The pm2panel.js handler at line 188 passes the unsanitized req.query.id parameter directly to exec(&amp;#x27;pm2 restart &amp;#x27; + id) without input validation or shell escaping, enabling command chaining via semicolons or other shell metacharacters.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">4193fa5cbc440ebc4e4cf1fe9942fe9f</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72572 (CVSS 7.5 HIGH): A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72572</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the server. The lib/xapi.js file at lines 338 and 424 uses the user-controlled req.query.name parameter in path.join(cwd, name) without sanitization before passing it to res.download, enabling directory traversal via ../ sequences to access sensitive system files.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">c647774a2e7b3d93b39aeace44f585da</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72571 (CVSS 7.5 HIGH): A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72571</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without sanitization, enabling directory traversal via absolute paths or ../ sequences to read sensitive system files.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">babec6ad92da675a86ae244963fb541c</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72570 (CVSS 5.4 MEDIUM): A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72570</link>
      <description>&lt;p&gt;CVSS 5.4 MEDIUM. A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">86daa53edbc5c4ed0527cca5da185346</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72569 (CVSS 9.1 CRITICAL): A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72569</link>
      <description>&lt;p&gt;CVSS 9.1 CRITICAL. A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">1f6fcb9a73eb80ac7fd36bac0ddcd9a7</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72568 (CVSS 7.1 HIGH): An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72568</link>
      <description>&lt;p&gt;CVSS 7.1 HIGH. An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">f66a39f337ede5e5e8487ac064536445</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72565 (CVSS 9.8 CRITICAL): A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72565</link>
      <description>&lt;p&gt;CVSS 9.8 CRITICAL. A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">7bba19e3f7ed2229dd300395e881c1d7</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:28 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72564 (CVSS 9.6 CRITICAL): An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72564</link>
      <description>&lt;p&gt;CVSS 9.6 CRITICAL. An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">86095ddd49f4fee96bb13b5deda7f0e6</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:28 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-66485: GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-66485</link>
      <description>&lt;p&gt;GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service.

This issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">b098dae4e15d28ed33c8d8627dc0f43c</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:27 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-61899: Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-61899</link>
      <description>&lt;p&gt;Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs.
Users are recommended to upgrade to version 5.9.1, which fixes this issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">a9671a4328e3a31ca5aca14464a69721</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:27 +0000</pubDate>
    </item>
    <item>
      <title>Metabase Patches Vulnerability Exploited as Zero-Day</title>
      <link>https://www.securityweek.com/metabase-patches-vulnerability-exploited-as-zero-day/</link>
      <description>&lt;p&gt;The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Vulnerabilities, exploited, Metabase, Zero-Day&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">85776505eb23cd8b33186515928cd2c6</guid>
      <category>Vulnerabilities</category>
      <category>exploited</category>
      <category>Metabase</category>
      <category>Zero-Day</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:03:55 +0000</pubDate>
    </item>
    <item>
      <title>The OpenAI and Hugging Face breach story told from the perspective of the AI</title>
      <link>https://www.youtube.com/watch?v=RE4IDWjfOZc</link>
      <description>&lt;p&gt;Article URL: https://www.youtube.com/watch?v=RE4IDWjfOZc Comments URL: https://news.ycombinator.com/item?id=49242015 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.42; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">46d7c133970e93bd0624cb102eda4431</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 10:52:23 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-66915: Joomla Extension - fabrikar.com - Remote code execution in Fabrik &lt; 4.6.7 - An unauthenticated attacker could execute</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-66915</link>
      <description>&lt;p&gt;Joomla Extension - fabrikar.com - Remote code execution in Fabrik &amp;lt; 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">d847c5b14281867c76eee58bea3cdb1d</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:17:33 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-44630: Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44630</link>
      <description>&lt;p&gt;Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError.


This issue affects Apache IoTDB: before 1.3.8, from 2.0.0 before 2.0.9.

Users are recommended to upgrade to version 2.0.10, which fixes the issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">c526f824f0f2cd4a863b4a25d7b9cf4f</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:17:32 +0000</pubDate>
    </item>
    <item>
      <title>The dumbest ransomware I've ever seen</title>
      <link>https://mrunix.me/posts/ransomware/</link>
      <description>&lt;p&gt;Article URL: https://mrunix.me/posts/ransomware/ Comments URL: https://news.ycombinator.com/item?id=49241642 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.76; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">5b1f0209a7d2dc9a650aea1699fdbf06</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 10:04:59 +0000</pubDate>
    </item>
    <item>
      <title>Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility</title>
      <link>https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/</link>
      <description>&lt;p&gt;CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; ICS/OT, Malware &amp;amp; Threats, energy, Featured, ICS, OT, PLC, Poland, power grid, SCADA&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.69; also threat_intel 0.69)&lt;/p&gt;</description>
      <guid isPermaLink="false">f5669cdaa1090acfb66ef1a684ccbe16</guid>
      <category>ICS/OT</category>
      <category>Malware &amp; Threats</category>
      <category>energy</category>
      <category>Featured</category>
      <category>ICS</category>
      <category>OT</category>
      <category>PLC</category>
      <category>Poland</category>
      <category>power grid</category>
      <category>SCADA</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:01:52 +0000</pubDate>
    </item>
    <item>
      <title>IT threat evolution in Q2 2026. Non-mobile statistics</title>
      <link>https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/</link>
      <description>&lt;p&gt;The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Securelist (Kaspersky GReAT)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware reports, Linux, Microsoft Windows, Malware Statistics, Apple MacOS, Antivirus Technologies, Trojan, Internet of Things, Mirai, RaaS, Honeypot, Miner&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.89; also threat_intel 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">f66385591c5ec4a1450f9ae67f50fe79</guid>
      <category>Malware reports</category>
      <category>Linux</category>
      <category>Microsoft Windows</category>
      <category>Malware Statistics</category>
      <category>Apple MacOS</category>
      <category>Antivirus Technologies</category>
      <category>Trojan</category>
      <category>Internet of Things</category>
      <category>Mirai</category>
      <category>RaaS</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:00:37 +0000</pubDate>
    </item>
    <item>
      <title>IT threat evolution in Q2 2026. Mobile statistics</title>
      <link>https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/</link>
      <description>&lt;p&gt;This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Securelist (Kaspersky GReAT)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware reports, Google Android, Adware, Mobile Malware, Malware Statistics, Trojan Banker, Trojan, Trojan Clicker, Trojan-Dropper, Google Play, Mamont, Triada&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also threat_intel 0.88)&lt;/p&gt;</description>
      <guid isPermaLink="false">b4e568d2833e6db68407d79c1b303820</guid>
      <category>Malware reports</category>
      <category>Google Android</category>
      <category>Adware</category>
      <category>Mobile Malware</category>
      <category>Malware Statistics</category>
      <category>Trojan Banker</category>
      <category>Trojan</category>
      <category>Trojan Clicker</category>
      <category>Trojan-Dropper</category>
      <category>Google Play</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:00:09 +0000</pubDate>
    </item>
    <item>
      <title>Critical Progress LoadMaster flaw now actively exploited in attacks</title>
      <link>https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/</link>
      <description>&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.70; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">7b67d6b745de8786b0fdd2eb62b52ea1</guid>
      <category>Security</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:49:37 +0000</pubDate>
    </item>
    <item>
      <title>CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability</title>
      <link>https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-progress-loadmaster-vulnerability/</link>
      <description>&lt;p&gt;The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Vulnerabilities, CISA KEV, exploited, Kemp LoadMaster, Progress Software&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">6e47382dcf51e8ad933f22a2f1985203</guid>
      <category>Vulnerabilities</category>
      <category>CISA KEV</category>
      <category>exploited</category>
      <category>Kemp LoadMaster</category>
      <category>Progress Software</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:31:51 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21084: Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21084</link>
      <description>&lt;p&gt;Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">2f7faf2e6df67834ed06883c8b3cf88d</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:22 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21083: Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21083</link>
      <description>&lt;p&gt;Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">8764eee7a0d2afe8df391ae45c8db5ab</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:22 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21082: Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21082</link>
      <description>&lt;p&gt;Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">d83eebc719b8adeb7112c61f2f98b64f</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21080: Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21080</link>
      <description>&lt;p&gt;Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">ffc125570b1b69241fb78c63f078bde6</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21079: Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21079</link>
      <description>&lt;p&gt;Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">5da0b8e79055d2396de77e629e01303b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21077: Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21077</link>
      <description>&lt;p&gt;Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">511a95dab21a73b568150f58a8e94624</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21076: Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21076</link>
      <description>&lt;p&gt;Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">d28b8204b00c1b5e6b802b3e2d74579a</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21075: Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21075</link>
      <description>&lt;p&gt;Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">6b3edf29271f36615a6a8e447bad7d6e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21074: Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21074</link>
      <description>&lt;p&gt;Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">69b4cab18028ac7555225aa94e249349</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21073: Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21073</link>
      <description>&lt;p&gt;Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">f03ec8358b8b2e13a551f5cbab0f14cf</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21072: Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21072</link>
      <description>&lt;p&gt;Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">b8c391542d7638d5c0ac478e9f74923e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21071: Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21071</link>
      <description>&lt;p&gt;Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">12b86702418791762bc6bc67134b6bb2</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21070: Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21070</link>
      <description>&lt;p&gt;Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">b145a87f06fe187bb6f12bf47bccc9fb</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21068: Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21068</link>
      <description>&lt;p&gt;Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">30798288fab7cfcac27fb470051b8c91</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21067: Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21067</link>
      <description>&lt;p&gt;Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">591ede6f1b7e509658107295e87dbc00</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:19 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21066: Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21066</link>
      <description>&lt;p&gt;Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">03ec7a33739dcafa0d5dbc4bfd20db42</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:19 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21065: Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21065</link>
      <description>&lt;p&gt;Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">40bd5e78df7ea5a38d990d8e288759f2</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:19 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21064: Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21064</link>
      <description>&lt;p&gt;Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">0ba703a3a61b3cf5340b383d89ae5221</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:19 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21063: Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21063</link>
      <description>&lt;p&gt;Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">abd3f2ab7dc5c277e077e9a0e6ef1d8a</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 09:17:19 +0000</pubDate>
    </item>
    <item>
      <title>Corporate Data Stolen in Levi Strauss Cyberattack</title>
      <link>https://www.securityweek.com/corporate-data-stolen-in-levi-strauss-cyberattack/</link>
      <description>&lt;p&gt;Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Data Breaches, data breach, Levi Strauss&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 1.00; also threat_intel 0.62)&lt;/p&gt;</description>
      <guid isPermaLink="false">84e6e5aca5bb70a6f1edabb22725a621</guid>
      <category>Data Breaches</category>
      <category>data breach</category>
      <category>Levi Strauss</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 08:55:44 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21062: Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21062</link>
      <description>&lt;p&gt;Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">dddeb59d1cfce1b7881f103349b71d64</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 08:16:48 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21061: Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21061</link>
      <description>&lt;p&gt;Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">70b414150735447c51cc9098521d6d15</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 08:16:48 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21060: Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21060</link>
      <description>&lt;p&gt;Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">4618c1a672d0fc3b21bc88b482e37b67</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 08:16:48 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-21058: Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21058</link>
      <description>&lt;p&gt;Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts&amp;#x27; privilege.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">af3598618af444737afda04e4190cea6</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 08:16:47 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-12570 (CVSS 5.5 MEDIUM): A vulnerability in keras-team/keras versions &lt;= 3.15.0 allows for a denial of service (DoS) attack when loading</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-12570</link>
      <description>&lt;p&gt;CVSS 5.5 MEDIUM. A vulnerability in keras-team/keras versions &amp;lt;= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">3b023496f092fc1b6d892147f8915d18</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 07:16:44 +0000</pubDate>
    </item>
    <item>
      <title>Blender MCP maintainer GitHub account hacked</title>
      <link>https://twitter.com/sidahuj/status/2086445625147793503</link>
      <description>&lt;p&gt;Article URL: https://twitter.com/sidahuj/status/2086445625147793503 Comments URL: https://news.ycombinator.com/item?id=49238028 Points: 24 # Comments: 4&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.42; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">3e00bfe87160d9b4f963aa6e5b8f5c23</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 00:58:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-70395: Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-70395</link>
      <description>&lt;p&gt;Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up.

When manage_relationship is used with on_lookup: :relate on a belongs_to relationship, the client-supplied lookup value is passed to Ash.Query.filter/2 without being cast to the attribute type. A nested map submitted where a scalar is expected is therefore interpreted as a filter predicate rather than a literal, so a lookup for a specific record becomes a query for any record matching a condition. The same path omits Ash.Query.limit(1), leaving Ash.read_one/2 able to distinguish no match from one match from several, which turns comparison predicates into an oracle for the lookup value. Authorization is unaffected; the destination read policy still applies.

This issue affects ash: from 1.52.0-rc.11 before 3.31.1.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">adc2b58b648e215e212b5cdae2c85b60</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sun, 09 Aug 2026 19:17:02 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-69659: Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69659</link>
      <description>&lt;p&gt;Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor.

Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary_to_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node.

This issue affects ash: from 1.17.0 before 3.31.1.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">fb538a7e6aa4f6263fcde6b7599d9d09</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sun, 09 Aug 2026 18:16:43 +0000</pubDate>
    </item>
    <item>
      <title>KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts</title>
      <link>https://databreaches.net/2026/08/09/kr-3pro-tv-data-breach-exposes-460000-records-including-2979-bank-accounts/</link>
      <description>&lt;p&gt;Park Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s website saying it had confirmed that “an external actor illegally accessed the... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Business Sector, Hack, Non-U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.95; also threat_intel 0.58)&lt;/p&gt;</description>
      <guid isPermaLink="false">5dc108f1ab738ec2155c7950ba1396e7</guid>
      <category>Business Sector</category>
      <category>Hack</category>
      <category>Non-U.S.</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 12:58:02 +0000</pubDate>
    </item>
    <item>
      <title>Ransomware gangs skip the CEO, head straight for the 40-something IT manager</title>
      <link>https://databreaches.net/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/</link>
      <description>&lt;p&gt;Carly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Commentaries and Analyses, Malware&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.95; also threat_intel 0.89)&lt;/p&gt;</description>
      <guid isPermaLink="false">7614cdd6c3207238c649ab6d8f154f90</guid>
      <category>Commentaries and Analyses</category>
      <category>Malware</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 12:24:57 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack</title>
      <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49506</link>
      <description>&lt;p&gt;Information published.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Microsoft Security Update Guide&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.90)&lt;/p&gt;</description>
      <guid isPermaLink="false">ec43dea9e8d6b96dc282348423666dfe</guid>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sun, 09 Aug 2026 08:02:14 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-17011: The Nexter Blocks  WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-17011</link>
      <description>&lt;p&gt;The Nexter Blocks  WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">73a819c227a2d02cd1d3dd1bfa17db96</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sun, 09 Aug 2026 06:18:10 +0000</pubDate>
    </item>
    <item>
      <title>City of Suisun declares local emergency after cyberattack downs 911 dispatch system</title>
      <link>https://databreaches.net/2026/08/08/city-of-suisun-declares-local-emergency-after-cyberattack-downs-911-dispatch-system/</link>
      <description>&lt;p&gt;Katie Chavez reports: Suisun City officials declared a state of emergency Saturday, Aug. 8, after a cyberattack took out the city’s emergency dispatch line and other key systems. City officials said that “malicious software infected and compromised IT systems” at about 5:45 a.m. on Friday. The cybersecurity issue forced the city to shut down its... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Government Sector&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.89; also threat_intel 0.51)&lt;/p&gt;</description>
      <guid isPermaLink="false">81cab50014dfe45b74b52e022a4125ea</guid>
      <category>Government Sector</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 23:05:28 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-71502: CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-71502</link>
      <description>&lt;p&gt;CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data.

An unauthenticated attacker can create a public conversion whose name or description contains a malicious Vue expression using the application&amp;#x27;s configured [[ ... ]] delimiters. User profile names may provide an additional injection vector. Although Jinja HTML escaping is applied, the resulting value is subsequently included in a DOM region compiled by Vue.

Vue interprets the attacker-controlled value as a template expression rather than ordinary text. By accessing the JavaScript Function constructor from within the expression, an attacker can execute arbitrary JavaScript in the security context of the CTI-Transmute origin. The application&amp;#x27;s nonce-based Content Security Policy does not prevent exploitation because the Vue runtime compiler requires the unsafe-eval policy exception.

The malicious payload is stored by the application and executed whenever another user opens an affected page, such as the public conversion detail page. The victim may be a normal user or an administrator. Successful expl&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">7c0d67e4251067658399ecd7845ecb98</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 22:16:34 +0000</pubDate>
    </item>
    <item>
      <title>Thomas Wolf thread on the AISI incident</title>
      <link>https://twitter.com/Thom_Wolf/status/2085084718320464230</link>
      <description>&lt;p&gt;Article URL: https://twitter.com/Thom_Wolf/status/2085084718320464230 Comments URL: https://news.ycombinator.com/item?id=49224910 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.36; also threat_intel 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">5b95f0e92868a1b7fdd0faeac643d056</guid>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 19:13:51 +0000</pubDate>
    </item>
    <item>
      <title>Hackers breach TrueConf to trojanize client installers with backdoors</title>
      <link>https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/</link>
      <description>&lt;p&gt;The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.80; also vulnerabilities 0.69, threat_intel 0.68)&lt;/p&gt;</description>
      <guid isPermaLink="false">c230c50ef5b75be94db815ec83273a39</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 14:16:23 +0000</pubDate>
    </item>
    <item>
      <title>City of Coweta refuses to pay ransom after system-wide cyberattack</title>
      <link>https://databreaches.net/2026/08/08/city-of-coweta-refuses-to-pay-ransom-after-system-wide-cyberattack/</link>
      <description>&lt;p&gt;An update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who don’t keep their word do spoil it for... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Government Sector, Malware, U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.99; also threat_intel 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">e3d0c45575751ade0932187bd20b208c</guid>
      <category>Government Sector</category>
      <category>Malware</category>
      <category>U.S.</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 12:40:22 +0000</pubDate>
    </item>
    <item>
      <title>Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data</title>
      <link>https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/</link>
      <description>&lt;p&gt;The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Artificial Intelligence, Vulnerabilities, AI, Atlassian, data theft, Featured, Rovo&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.83; also vulnerabilities 0.83)&lt;/p&gt;</description>
      <guid isPermaLink="false">a553bc68eaf0de24f3b2713f4be86ae1</guid>
      <category>Artificial Intelligence</category>
      <category>Vulnerabilities</category>
      <category>AI</category>
      <category>Atlassian</category>
      <category>data theft</category>
      <category>Featured</category>
      <category>Rovo</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 11:30:00 +0000</pubDate>
    </item>
    <item>
      <title>Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers</title>
      <link>https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html</link>
      <description>&lt;p&gt;Attacker-controlled instructions can make Atlassian&amp;#x27;s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.56)&lt;/p&gt;</description>
      <guid isPermaLink="false">ab2cf02445d4050eb2a042ccfbda3d29</guid>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 08:54:50 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)</title>
      <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48524</link>
      <description>&lt;p&gt;Information published.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Microsoft Security Update Guide&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.90)&lt;/p&gt;</description>
      <guid isPermaLink="false">9c44784ed1afa860621661409e8dc638</guid>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 08:40:45 +0000</pubDate>
    </item>
    <item>
      <title>New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens</title>
      <link>https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html</link>
      <description>&lt;p&gt;New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.56)&lt;/p&gt;</description>
      <guid isPermaLink="false">92a77f3ffeabd187872485bbaa3fcc2f</guid>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 08:03:57 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-16955: The AI Engine  WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-16955</link>
      <description>&lt;p&gt;The AI Engine  WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">b48ff4a65cdaf75110e93e0f521b5957</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 07:17:11 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-16953: The AI Engine  WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-16953</link>
      <description>&lt;p&gt;The AI Engine  WordPress plugin before 3.6.4 does not verify ownership of a guest&amp;#x27;s uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim&amp;#x27;s session identifier and file reference can delete that victim&amp;#x27;s uploaded files.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">bb01b1d1ffad9b1be662a8ed2265902d</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 07:17:11 +0000</pubDate>
    </item>
    <item>
      <title>Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication</title>
      <link>https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html</link>
      <description>&lt;p&gt;Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">ecc4777c9ae87466f333c26238c4e461</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 06:58:31 +0000</pubDate>
    </item>
    <item>
      <title>N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist</title>
      <link>https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html</link>
      <description>&lt;p&gt;N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. &amp;quot;We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,&amp;quot; the company said. &amp;quot;This is not a duplicate of our&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.62; also vulnerabilities 0.81, threat_intel 0.62)&lt;/p&gt;</description>
      <guid isPermaLink="false">62e6df9d879f730cdaa0ccc24d00864a</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 06:57:43 +0000</pubDate>
    </item>
    <item>
      <title>Hacked Amazon Echo Dot 2 and can run LLMs locally</title>
      <link>https://www.reddit.com/r/homeassistant/s/X13006g0tS</link>
      <description>&lt;p&gt;Article URL: https://www.reddit.com/r/homeassistant/s/X13006g0tS Comments URL: https://news.ycombinator.com/item?id=49217748 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.42; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">7908f468bc9fccc83328435196257493</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 00:28:37 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-46409 (CVSS 9.6 CRITICAL): OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46409</link>
      <description>&lt;p&gt;CVSS 9.6 CRITICAL. OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:&amp;lt;random port&amp;gt;` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a wildcard CORS policy. Any webpage a user visits while OpenYak is running can issue cross-origin requests to this local server — the browser acts as a proxy into loopback, bypassing OS-level network isolation. Chained, this lets a malicious page execute arbitrary shell commands on the host (RCE) via the build agent with `permission_presets.bash=true`, shut down the service, and exfiltrate chat history and account PII — with no user interaction beyond opening the page. Version 1.1.3 patches the issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00, threat_intel 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">8492f72b18c1f8a796072007f9451d2e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 23:17:03 +0000</pubDate>
    </item>
    <item>
      <title>US cloud ‘kill switch’ is as dangerous as ransomware, European businesses fear</title>
      <link>https://databreaches.net/2026/08/07/us-cloud-kill-switch-is-as-dangerous-as-ransomware-european-businesses-fear/</link>
      <description>&lt;p&gt;Emma Woollacott reports: European firms are more concerned about a potential US government-imposed ‘kill switch’ for cloud services than almost anything else. In a survey of 1,500 businesses in the UK, France, and Germany, Proton found that with many having built their operations around a small number of US-based providers, they’re worried that access to those platforms could be... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Non-U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.92)&lt;/p&gt;</description>
      <guid isPermaLink="false">0e1159915c2102beff731cae7fe98741</guid>
      <category>Non-U.S.</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 23:08:16 +0000</pubDate>
    </item>
    <item>
      <title>Inside the Modern SOC: The Identity Front Door</title>
      <link>https://unit42.paloaltonetworks.com/soc-identity-front-door/</link>
      <description>&lt;p&gt;Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42 .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Palo Alto Unit 42&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Inside the Modern SOC, Insights, AI, identity, social engineering, Unit 42 Incident Response Report&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.93; also threat_intel 0.37)&lt;/p&gt;</description>
      <guid isPermaLink="false">3226262867fdd25354ea97093d18f43e</guid>
      <category>Inside the Modern SOC</category>
      <category>Insights</category>
      <category>AI</category>
      <category>identity</category>
      <category>social engineering</category>
      <category>Unit 42 Incident Response Report</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 23:00:01 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-59717 (CVSS 4.3 MEDIUM): Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-59717</link>
      <description>&lt;p&gt;CVSS 4.3 MEDIUM. Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without ever displaying the destination hostname. Because no screen in the invitation or onboarding flow shows the parsed server URL before onboarding commits to it, a victim has no way to distinguish a legitimate invite from a malicious one. An attacker can craft an invite so that a single tap on the legitimate-looking &amp;quot;Connect to my Home Assistant server&amp;quot; button opens their /auth/authorize endpoint in the URL-less onboarding WebView, presenting a look-alike login page that captures the victim&amp;#x27;s credentials. Since invitations are intended to onboard brand-new users, targets are especially unlikely to notice the substitution. This issue is fixed in version 2026.6.1.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">efd867304a7bba8609b41a9df2af6711</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 21:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-46358: OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46358</link>
      <description>&lt;p&gt;OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao&amp;#x27;s inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate. This is fixed in OpenBao v2.5.4.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.68; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">083bc24ec0888d15a245024105cd6675</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 21:17:28 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-11425 (CVSS 4.4 MEDIUM): Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-11425</link>
      <description>&lt;p&gt;CVSS 4.4 MEDIUM. Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via ng-bind-html with only an nl2br() transform that performs no HTML escaping, allowing attackers to store malicious payloads that execute in any administrator&amp;#x27;s browser upon viewing the mobile dashboard, enabling session cookie theft and account takeover.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.68; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">abcf000e3e01431362e3b5c95ba7e80e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 21:17:27 +0000</pubDate>
    </item>
    <item>
      <title>City of Coweta hit with system-wide ransomware attack, has backup</title>
      <link>https://databreaches.net/2026/08/07/city-of-coweta-hit-with-system-wide-ransomware-attack-has-backup/</link>
      <description>&lt;p&gt;KTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity professionals to secure their systems to prevent any further intrusion and to begin a recovery... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Government Sector, Malware&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.98; also threat_intel 0.84)&lt;/p&gt;</description>
      <guid isPermaLink="false">51bbcb0529c8c7ed2eb475f6275ec001</guid>
      <category>Government Sector</category>
      <category>Malware</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:26:50 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-19017 (CVSS 6.8 MEDIUM): Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-19017</link>
      <description>&lt;p&gt;CVSS 6.8 MEDIUM. Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.68; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">b3af83c940513aa7778fa3e233294026</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 20:16:50 +0000</pubDate>
    </item>
    <item>
      <title>Metabase SQLi zero-day exploited in customer data-theft attacks</title>
      <link>https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/</link>
      <description>&lt;p&gt;A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security, Software&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.80; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">842c057e79fd89b7bdf8377ee1a97a6f</guid>
      <category>Security</category>
      <category>Software</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 20:14:46 +0000</pubDate>
    </item>
    <item>
      <title>Computer maker Framework notifies 'all customers' of a data breach</title>
      <link>https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/</link>
      <description>&lt;p&gt;Article URL: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/ Comments URL: https://news.ycombinator.com/item?id=49215565 Points: 2 # Comments: 1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.76; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">29ab2e09c7b21ad546937298c9160d6a</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:04:04 +0000</pubDate>
    </item>
    <item>
      <title>Unlimited Technology Systems breach impacts 3.8 million people</title>
      <link>https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/</link>
      <description>&lt;p&gt;Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security, Healthcare&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.86)&lt;/p&gt;</description>
      <guid isPermaLink="false">15d43f09382a985b105c98d3db7933c0</guid>
      <category>Security</category>
      <category>Healthcare</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 19:30:41 +0000</pubDate>
    </item>
    <item>
      <title>ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets</title>
      <link>https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html</link>
      <description>&lt;p&gt;ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that&amp;#x27;s compatible with the computer&amp;#x27;s CPU architecture. &amp;quot;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.56; also threat_intel 0.35)&lt;/p&gt;</description>
      <guid isPermaLink="false">e7092c00880a133b4c483269d2c6cdf4</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 18:29:08 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.&#13;
&#13;
Via a specially crafted</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-64638</link>
      <description>&lt;p&gt;WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.&#13;
&#13;
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.&#13;
&#13;
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.&#13;
&#13;
Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99, threat_intel 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">1a3af6df0b206c0d0c5eb8d90bd18471</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 18:17:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-47363 (CVSS 6.3 MEDIUM): In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47363</link>
      <description>&lt;p&gt;CVSS 6.3 MEDIUM. In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend.&#13;
This requires a malicious application co-installed on a device with the Datadog app installed, and an OAuth token the attacker is willing to load into the victim&amp;#x27;s app.&#13;
Impact: A co-installed application can switch the victim&amp;#x27;s Datadog app to a session the attacker controls. This is an account-confusion issue; it does not by itself expose the victim&amp;#x27;s existing session or data.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">345292b5bf888e1cd93f14f51ca20959</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 18:17:16 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-47361 (CVSS 6.4 MEDIUM): In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47361</link>
      <description>&lt;p&gt;CVSS 6.4 MEDIUM. In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI chat notification), with no check on the caller&amp;#x27;s identity or ownership of the conversation.&#13;
This requires a malicious application co-installed on the victim&amp;#x27;s device.&#13;
Impact: A co-installed application can silently dismiss the victim&amp;#x27;s Bits AI chat notification. No chat content is exposed; conversation data remains server-authentication gated and is never returned to the caller.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">13a0ddda34a9e97f5cadbbe76f8a1d07</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 18:17:15 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-44965 (CVSS 5.5 MEDIUM): In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44965</link>
      <description>&lt;p&gt;CVSS 5.5 MEDIUM. In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a caller-supplied AppWidgetManager.EXTRA_APPWIDGET_ID and, when no deep-link destination is resolved, uses it to load the matching widget&amp;#x27;s stored session and automatically log in as that user. Because Android widget IDs are small sequential integers, a co-installed application can brute-force this value to find one that matches a widget configured on the victim&amp;#x27;s device.&#13;
This requires:&#13;
A malicious application co-installed on the victim&amp;#x27;s device.&#13;
At least one of the six widgets configured on the victim&amp;#x27;s home screen.&#13;
An active Datadog session cached locally.&#13;
Impact: The matching configuration activity opens in the foreground under the victim&amp;#x27;s session and renders live infrastructure data. Exposure is limited to a visual side channel (e.g., screen recording or accessibility services); the calling application cannot programmatically read the rendered d&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">aa1128fd740301ecea42d6f91fdd5144</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 18:17:14 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-44964 (CVSS 6.5 MEDIUM): In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44964</link>
      <description>&lt;p&gt;CVSS 6.5 MEDIUM. In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an arbitrary on-call page ID, and an arbitrary Intent to run inside the Datadog process.&#13;
This requires:&#13;
A malicious application co-installed on the victim&amp;#x27;s device.&#13;
An active Datadog session in the Android app.&#13;
Impact: After a single tap on the Acknowledge button, the app sends a forged on-call acknowledgement to the backend under the victim&amp;#x27;s session, launches the attacker-supplied Intent from within the Datadog process (reaching otherwise non-exported components), and turns on the screen while dismissing the keyguard.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">c33cab207fa8e8990ce8872533987053</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 18:17:14 +0000</pubDate>
    </item>
    <item>
      <title>UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data</title>
      <link>https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html</link>
      <description>&lt;p&gt;A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. &amp;quot;UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.90; also threat_intel 0.82)&lt;/p&gt;</description>
      <guid isPermaLink="false">37859bd4cd5d193a3cfb35faecf9029d</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 18:16:13 +0000</pubDate>
    </item>
    <item>
      <title>Boston Children’s Hospital named in North Korean hacking operation</title>
      <link>https://databreaches.net/2026/08/07/boston-childrens-hospital-named-in-north-korean-hacking-operation/</link>
      <description>&lt;p&gt;Naomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached, saying the issue traced to a former contractor’s personal device. Mr. Stykas, chief technology officer at... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Commentaries and Analyses, cyberwar, Health Data, U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.49)&lt;/p&gt;</description>
      <guid isPermaLink="false">6b497962a09ee9054e732eadd0771c16</guid>
      <category>Commentaries and Analyses</category>
      <category>cyberwar</category>
      <category>Health Data</category>
      <category>U.S.</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:37:17 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20348 (CVSS 7.5 HIGH): A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20348</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&amp;amp;nbsp;memory corruption on an affected device.&#13;
&#13;
This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that contains XAR content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">ee1bbddd7beee1f45f805e64b05a6a3b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:17:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20347 (CVSS 7.5 HIGH): A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20347</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&amp;amp;nbsp;memory corruption on an affected device.&#13;
&#13;
This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted Mach-O file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">54c75854cc1765cab8807aade00d7904</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:17:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20346 (CVSS 7.5 HIGH): A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20346</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&amp;amp;nbsp;memory corruption on an affected device.&#13;
&#13;
This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">a7662389a71dc967a8b869fa5ad88367</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:17:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20345 (CVSS 7.5 HIGH): A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20345</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&amp;amp;nbsp;memory corruption on an affected device.&#13;
&#13;
This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">3086099fd917a1718e96fdc8e804bf67</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:17:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20339 (CVSS 7.5 HIGH): A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20339</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&amp;amp;nbsp;memory corruption on an affected device.&#13;
&#13;
This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">eaeecf7573ba6ce45296401b4b2d6620</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:17:02 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20338 (CVSS 7.5 HIGH): A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20338</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.&#13;
&#13;
This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">68126b22111fc68c76f9176d3e917c34</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:17:02 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20337 (CVSS 7.5 HIGH): A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20337</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.&#13;
&#13;
This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">bd620790e80c0278bfd27df25da7375e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 17:17:02 +0000</pubDate>
    </item>
    <item>
      <title>Tell HN: Tally Data Breach</title>
      <link>https://news.ycombinator.com/item?id=49213500</link>
      <description>&lt;p&gt;Received a notice from tally.so notifying that someone accessed their user database. I asked which “hash” they used and whether passwords were salted. I have not heard back yet. — On August 3, an attacker gained unauthorized access to Metabase, the analytics service we use to see how Tally is used. Through that they reached your email address, and your password as a cryptographic hash. A hash is one-way, so it can&amp;#x27;t be turned back into your password. They didn&amp;#x27;t reach your forms, or the answers people submitted to them. Those are stored separately. Comments URL: https://news.ycombinator.com/item?id=49213500 Points: 7 # Comments: 3&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.85; also threat_intel 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">662f59e21ad4acc5296a09533656f5b2</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 17:16:45 +0000</pubDate>
    </item>
    <item>
      <title>Levi Strauss &amp; Co. says hackers stole corporate data in cyberattack</title>
      <link>https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/</link>
      <description>&lt;p&gt;Levi Strauss &amp;amp; Co. (Levi&amp;#x27;s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.90)&lt;/p&gt;</description>
      <guid isPermaLink="false">fc5c53dd4b92c899f21e6ff8f1e86b4d</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 15:48:20 +0000</pubDate>
    </item>
    <item>
      <title>In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street</title>
      <link>https://www.securityweek.com/in-other-news-ai-slop-limits-apple-bounties-north-carolina-port-attacks-hackers-target-wall-street/</link>
      <description>&lt;p&gt;Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Artificial Intelligence, Malware &amp;amp; Threats, In Other News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.93; also threat_intel 0.79)&lt;/p&gt;</description>
      <guid isPermaLink="false">38c1794d7c0129e6a4a76891da5cca73</guid>
      <category>Artificial Intelligence</category>
      <category>Malware &amp; Threats</category>
      <category>In Other News</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 14:26:42 +0000</pubDate>
    </item>
    <item>
      <title>Real emails, hijacked payments: Two H1 2026 attack chains</title>
      <link>https://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/</link>
      <description>&lt;p&gt;Gen&amp;#x27;s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.70; also threat_intel 0.72)&lt;/p&gt;</description>
      <guid isPermaLink="false">5b36178ea48d518a06bdc65808519ade</guid>
      <category>Security</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 14:00:10 +0000</pubDate>
    </item>
    <item>
      <title>AU: Hackers leak sensitive Victorian court data to dark web</title>
      <link>https://databreaches.net/2026/08/07/au-hackers-leak-sensitive-victorian-court-data-to-dark-web/</link>
      <description>&lt;p&gt;Kristian Silva and Danny The personal information of Victorian court users has been posted on the dark web, sparking a police investigation. Names, emails and job titles of people who attended online hearings in regional courts were posted on an underground hacking forum in July. A user has claimed responsibility in a post. […] Court... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Government Sector, Hack, Non-U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.70; also threat_intel 0.73)&lt;/p&gt;</description>
      <guid isPermaLink="false">3d2c1b2a2db93bbde11a7893ca350a98</guid>
      <category>Government Sector</category>
      <category>Hack</category>
      <category>Non-U.S.</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 13:39:06 +0000</pubDate>
    </item>
    <item>
      <title>What Canvas learned from a massive cyberattack</title>
      <link>https://databreaches.net/2026/08/07/what-canvas-learned-from-a-massive-cyberattack/</link>
      <description>&lt;p&gt;Alcino Donadel reports: …. Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher ed. Higher education’s more meditative, governed approach to technological change is useful for reviewing rigor and long-term quality assurance, Pendleton... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Artificial Intelligence, Commentaries and Analyses, Education Sector, Subcontractor, U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.95; also threat_intel 0.51)&lt;/p&gt;</description>
      <guid isPermaLink="false">ce21f52270bdade9a891b97f66443e43</guid>
      <category>Artificial Intelligence</category>
      <category>Commentaries and Analyses</category>
      <category>Education Sector</category>
      <category>Subcontractor</category>
      <category>U.S.</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 13:39:00 +0000</pubDate>
    </item>
    <item>
      <title>Unlimited Technology Systems Data Breach Affects 3.8 Million Patients</title>
      <link>https://databreaches.net/2026/08/07/unlimited-technology-systems-data-breach-affects-3-8-million-patients/</link>
      <description>&lt;p&gt;HIPAA Journal reports an update to the Unlimited Technology Systems breach that occurred between October 10 – 15, 2025, and was discovered on October 19, 2025: On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-based provider of revenue cycle management services. At the time, the... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Hack, Health Data, Subcontractor, U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.92)&lt;/p&gt;</description>
      <guid isPermaLink="false">1e153e843746e6272d55fcfcebf6c085</guid>
      <category>Hack</category>
      <category>Health Data</category>
      <category>Subcontractor</category>
      <category>U.S.</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 13:38:52 +0000</pubDate>
    </item>
    <item>
      <title>North Carolina Ports confirms cyberattack disrupting operations</title>
      <link>https://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberattack-disrupting-operations/</link>
      <description>&lt;p&gt;The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.80)&lt;/p&gt;</description>
      <guid isPermaLink="false">58611e89fb9edda76420aba5ecd876d0</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 13:34:40 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-56793 (CVSS 7.7 HIGH): Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-56793</link>
      <description>&lt;p&gt;CVSS 7.7 HIGH. Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">32964fc0d2826fd8345ab7d43ddaa610</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 13:16:52 +0000</pubDate>
    </item>
    <item>
      <title>New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP</title>
      <link>https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html</link>
      <description>&lt;p&gt;WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also vulnerabilities 0.95)&lt;/p&gt;</description>
      <guid isPermaLink="false">38709a9cedbfb5509fca40c75a40839b</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 12:56:23 +0000</pubDate>
    </item>
    <item>
      <title>Vishing Extortion Group UNC6671 Rebrands After Making Millions</title>
      <link>https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/</link>
      <description>&lt;p&gt;Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware &amp;amp; Threats, cybercrime, UNC6671, vishing&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.79; also threat_intel 0.90)&lt;/p&gt;</description>
      <guid isPermaLink="false">cf71eea5d13b74032868d19ab06d67fd</guid>
      <category>Malware &amp; Threats</category>
      <category>cybercrime</category>
      <category>UNC6671</category>
      <category>vishing</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 11:06:01 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-71559 (CVSS 7.5 HIGH): Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-71559</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.

This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected.

Users are recommended to upgrade to version 1.5.0, which fixes the issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">cca4c2860bb3a4c52213e795a25bbe4b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 10:16:59 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-54217: Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An 
attacker can send</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-54217</link>
      <description>&lt;p&gt;Tobit Laboratories AG TeamDavid&amp;#x27;s Webbox application is vulnerable to a stored XSS vulnerability. An 
attacker can send an email containing malicious JavaScript code. When a 
user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">54cfdcb53927f64c4a716e056132c6a6</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 10:16:59 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-54216: Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) 
vulnerability. By</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-54216</link>
      <description>&lt;p&gt;Tobit Laboratories AG TeamDavid&amp;#x27;s Webbox application contains a reflected cross-site scripting (XSS) 
vulnerability. By sending a specially crafted link including an 
arbitrary path, an XSS payload or the parameter “EntryInfo”, and the 
parameter “!templateName=entryMail”, an attacker can cause the payload 
to execute in the victim’s browser when they click the link. This issue affects TeamDavid through Rollout 524.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">61adcc6d32374acddfc6c96401fabf2a</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 10:16:58 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-54212: Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a 
buffer</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-54212</link>
      <description>&lt;p&gt;Tobit Laboratories AG TeamDavid&amp;#x27;s Webbox application implements an API endpoint that is vulnerable to a 
buffer overflow condition. By submitting a specially crafted JSON body, 
such as one that is at least 8 characters long and begins with a number,
 an unauthenticated attacker can cause the server to crash, resulting in
 denial of service. Depending on the stack state or if a stack canary 
can be disclosed through another vulnerability, this buffer overflow 
could potentially lead to remote code execution and full compromise of 
the server. This issue affects TeamDavid through Rollout 524.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">3b91889a9e35df7d633e197c71b80b04</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 10:16:58 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-54211: Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a
 buffer</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-54211</link>
      <description>&lt;p&gt;Tobit Laboratories AG TeamDavid&amp;#x27;s Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a
 buffer overflow vulnerability in multiple form data parameters. By 
submitting excessively long values in these parameters, an authenticated
 attacker can trigger a server crash, resulting in denial of service. 
Depending on the stack state or if a stack canary can be disclosed 
through another vulnerability, this buffer overflow could potentially be
 exploited for remote code execution, leading to full compromise of the 
server. This issue affects TeamDavid through Rollout 524.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">439ac8d3176790b9a8dc88fe829828f4</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 10:16:58 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-54210: Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-54210</link>
      <description>&lt;p&gt;Tobit Laboratories AG TeamDavid&amp;#x27;s Webbox application implements various file upload functionalities that are 
vulnerable to a buffer overflow condition. By specifying an excessively 
long filename in a file upload request, an unauthenticated attacker can 
trigger a crash of the server, resulting in a denial of service. 
Depending on the stack state or if a stack canary can be disclosed 
through another vulnerability, this buffer overflow could potentially be
 exploited for remote code execution, leading to full compromise of the 
server. This issue affects TeamDavid through Rollout 524.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">607bb354134609cea980d6853b86f841</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 10:16:58 +0000</pubDate>
    </item>
    <item>
      <title>AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day</title>
      <link>https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html</link>
      <description>&lt;p&gt;PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.35; also threat_intel 0.82, vulnerabilities 0.78)&lt;/p&gt;</description>
      <guid isPermaLink="false">862642bee841f0265480a7c64a273d53</guid>
      <category>bucket:threat_intel</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 10:09:54 +0000</pubDate>
    </item>
    <item>
      <title>New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables</title>
      <link>https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html</link>
      <description>&lt;p&gt;Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.56)&lt;/p&gt;</description>
      <guid isPermaLink="false">db7fd783f4de3ba0565565c4711cd7e3</guid>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 09:32:57 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-9169 (CVSS 8.8 HIGH): DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9169</link>
      <description>&lt;p&gt;CVSS 8.8 HIGH. DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">7430aa19d0ea7af283bb8cb1f175cc41</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 09:16:59 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-49008 (CVSS 6.5 MEDIUM): By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49008</link>
      <description>&lt;p&gt;CVSS 6.5 MEDIUM. By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the device.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">95ebbbd0393a596dab175f2609079d2d</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 09:16:58 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-18938 (CVSS 6.2 MEDIUM): A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-18938</link>
      <description>&lt;p&gt;CVSS 6.2 MEDIUM. A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; cyber_attacks (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">308723e84483a0bec0772c11d727d931</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 09:16:58 +0000</pubDate>
    </item>
  </channel>
</rss>
