<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Cyber Threat Digest — Threat Intelligence</title>
    <link>https://example.github.io/cyber-rss</link>
    <description>APT activity, campaigns, nation-state operations, malware families, actor TTPs, and government advisories.</description>
    <atom:link href="https://example.github.io/cyber-rss/feeds/threat-intel.xml" rel="self"/>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>cyber-rss-aggregator</generator>
    <language>en</language>
    <lastBuildDate>Tue, 11 Aug 2026 02:30:42 +0000</lastBuildDate>
    <item>
      <title>ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)</title>
      <link>https://isc.sans.edu/diary/rss/33232</link>
      <description>&lt;p&gt;ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SANS Internet Storm Center&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.80)&lt;/p&gt;</description>
      <guid isPermaLink="false">87b46cd8b021597160327e4a6b0fe342</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Tue, 11 Aug 2026 02:00:03 +0000</pubDate>
    </item>
    <item>
      <title>The Field Is Optional. The Death Threats Were Not</title>
      <link>https://canartuc.medium.com/the-field-is-optional-the-death-threats-were-not-1e2f1f0ce772</link>
      <description>&lt;p&gt;Article URL: https://canartuc.medium.com/the-field-is-optional-the-death-threats-were-not-1e2f1f0ce772 Comments URL: https://news.ycombinator.com/item?id=49251320 Points: 2 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">f5dbc2dbbdb8d74556e4a89ecabc414d</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 23:33:25 +0000</pubDate>
    </item>
    <item>
      <title>My Homelab Got Hacked – A Postmortem</title>
      <link>https://phunky.cafe/my-homelab-got-hacked/</link>
      <description>&lt;p&gt;Article URL: https://phunky.cafe/my-homelab-got-hacked/ Comments URL: https://news.ycombinator.com/item?id=49251087 Points: 6 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also cyber_attacks 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">a39a746dfd2a2100e593690f22ba0d05</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 23:04:18 +0000</pubDate>
    </item>
    <item>
      <title>The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications</title>
      <link>https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/</link>
      <description>&lt;p&gt;Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42 .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Palo Alto Unit 42&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware, Threat Research, Aeternum, infection chain, JSON, Python, RPC, Telegram, XMRig, XOR&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">f54cb05742c7171e9a7cbabebed19bc2</guid>
      <category>Malware</category>
      <category>Threat Research</category>
      <category>Aeternum</category>
      <category>infection chain</category>
      <category>JSON</category>
      <category>Python</category>
      <category>RPC</category>
      <category>Telegram</category>
      <category>XMRig</category>
      <category>XOR</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 22:00:02 +0000</pubDate>
    </item>
    <item>
      <title>We cut a 40-day financial integration down to 5 days using Google Anti</title>
      <link>https://discuss.google.dev/t/trusted-automation-with-google-antigravity-scaling-secure-finance-integrations-from-40-days-to-5/383313</link>
      <description>&lt;p&gt;Article URL: https://discuss.google.dev/t/trusted-automation-with-google-antigravity-scaling-secure-finance-integrations-from-40-days-to-5/383313 Comments URL: https://news.ycombinator.com/item?id=49249986 Points: 9 # Comments: 4&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also vulnerabilities 0.63)&lt;/p&gt;</description>
      <guid isPermaLink="false">a20fef11884db4d317455aea046e6907</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 21:27:02 +0000</pubDate>
    </item>
    <item>
      <title>Vulnerability Prioritization with Broadsheet.sh</title>
      <link>https://broadsheet.sh</link>
      <description>&lt;p&gt;Article URL: https://broadsheet.sh Comments URL: https://news.ycombinator.com/item?id=49249895 Points: 2 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also vulnerabilities 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">a68d9fe5ca6a1bbac9ac237df90dfd82</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 21:18:51 +0000</pubDate>
    </item>
    <item>
      <title>BdThemes plugins supply-chain hack creates rogue WordPress admins</title>
      <link>https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/</link>
      <description>&lt;p&gt;A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators&amp;#x27; browsers to create rogue admin accounts. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also cyber_attacks 0.37)&lt;/p&gt;</description>
      <guid isPermaLink="false">31b66be99af3207f459f1edc9c11e6a3</guid>
      <category>Security</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 21:12:10 +0000</pubDate>
    </item>
    <item>
      <title>Temperature Zero for Culture: Why Everything Is Starting to Look the Same</title>
      <link>https://laurenleek.substack.com/p/temperature-zero-for-culture-why</link>
      <description>&lt;p&gt;Article URL: https://laurenleek.substack.com/p/temperature-zero-for-culture-why Comments URL: https://news.ycombinator.com/item?id=49249341 Points: 6 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">25e26df482a33b0f70dcc31afd8ada48</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 20:35:59 +0000</pubDate>
    </item>
    <item>
      <title>CISA Advisory: #StopRansomware: Gunra Ransomware</title>
      <link>https://databreaches.net/2026/08/10/cisa-advisory-stopransomware-gunra-ransomware/</link>
      <description>&lt;p&gt;Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.91; also cyber_attacks 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">7d46ce02c02169b334db9de93f3758d6</guid>
      <category>Malware</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 19:02:46 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-65400: Apple macOS Screen Sharing authentication bypass</title>
      <link>https://support.apple.com/en-us/148170</link>
      <description>&lt;p&gt;Article URL: https://support.apple.com/en-us/148170 Comments URL: https://news.ycombinator.com/item?id=49247537 Points: 2 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also vulnerabilities 0.85)&lt;/p&gt;</description>
      <guid isPermaLink="false">0a8429560ff4db32cbe9bf3f364d6010</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 18:16:54 +0000</pubDate>
    </item>
    <item>
      <title>Security Vulnerability in Pioneer Rekordbox</title>
      <link>https://alphatheta.com/en/information/important-notice-security-vulnerability-in-pro-dj-link/</link>
      <description>&lt;p&gt;Article URL: https://alphatheta.com/en/information/important-notice-security-vulnerability-in-pro-dj-link/ Comments URL: https://news.ycombinator.com/item?id=49247461 Points: 15 # Comments: 10&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also vulnerabilities 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">9b7bf62fcaeb950a240c52160d1ec679</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 18:11:52 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52968 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52968.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52968. Severity: important. Addresses CVE-2026-13149, CVE-2026-15927, CVE-2026-39822, CVE-2026-42504, CVE-2026-54058, CVE-2026-54060, CVE-2026-55379, CVE-2026-55380, CVE-2026-57231, CVE-2026-59197.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">2e3d4d710709f9fbb5876ba01b6dbcf2</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 17:58:19 +0000</pubDate>
    </item>
    <item>
      <title>New StormEncryptor ransomware used by former Medusa affiliate</title>
      <link>https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/</link>
      <description>&lt;p&gt;A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also cyber_attacks 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">f8cb8b670a1ef85ff5ba80c72828ee3c</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 17:42:00 +0000</pubDate>
    </item>
    <item>
      <title>Show HN: EnclaveOps – Zero-trust control plane for self-hosted AI</title>
      <link>https://www.enclaveops.dev/</link>
      <description>&lt;p&gt;Article URL: https://www.enclaveops.dev/ Comments URL: https://news.ycombinator.com/item?id=49246624 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">9c877ddca5356ce29b282ce827f1e3b7</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 17:09:19 +0000</pubDate>
    </item>
    <item>
      <title>Show HN: Bombay Bhaag – a Three.js endless runner with zero art assets</title>
      <link>https://bombaybhaag.com/</link>
      <description>&lt;p&gt;Article URL: https://bombaybhaag.com/ Comments URL: https://news.ycombinator.com/item?id=49246545 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">5e5cd9ab4e0d348cc08b8bdd419967cd</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 17:04:47 +0000</pubDate>
    </item>
    <item>
      <title>China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw</title>
      <link>https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html</link>
      <description>&lt;p&gt;Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary&amp;#x27;s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. &amp;quot;StormEncryptor is written in C++ and appends the file name extension .encrypted&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.88; also cyber_attacks 0.98, vulnerabilities 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">4c624f6c9bd5a27e21068cdbd69f5eda</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <category>bucket:vulnerabilities</category>
      <pubDate>Mon, 10 Aug 2026 16:38:37 +0000</pubDate>
    </item>
    <item>
      <title>The Day the AI Act Grew Teeth: GPAI Enforcement Goes Live</title>
      <link>https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/</link>
      <description>&lt;p&gt;Article URL: https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/ Comments URL: https://news.ycombinator.com/item?id=49246042 Points: 2 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">a846ecf3478f8eb0e97a4540c2231957</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 16:34:51 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52946 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52946.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52946. Severity: critical. Addresses CVE-2026-27145, CVE-2026-33376, CVE-2026-33377, CVE-2026-53492, CVE-2026-55677, CVE-2026-55969, CVE-2026-66801.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, critical, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">42efdc775ae0ba3de1ebdbd9fb3793ee</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>critical</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 16:32:57 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52930 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52930.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52930. Severity: important. Addresses CVE-2026-42198.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">e8c6128c018a1ef7493f1a556f433318</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 16:19:48 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52929 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52929.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52929. Severity: important. Addresses CVE-2026-42198.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">dc0b01408b91f58a1871520a6721beb4</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 16:09:23 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52928 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52928.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52928. Severity: important. Addresses CVE-2026-42198.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">f724dd6db84caa27d18174e8bd7cd02f</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 15:40:43 +0000</pubDate>
    </item>
    <item>
      <title>Ben Jones, 'Dukes of Hazzard' Actor and Congressman, Dies at 84</title>
      <link>https://www.nytimes.com/2026/08/10/obituaries/ben-jones-dead.html</link>
      <description>&lt;p&gt;Article URL: https://www.nytimes.com/2026/08/10/obituaries/ben-jones-dead.html Comments URL: https://news.ycombinator.com/item?id=49244734 Points: 4 # Comments: 2&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.51)&lt;/p&gt;</description>
      <guid isPermaLink="false">d3932949a4666e1664c2fe83857b6511</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 15:09:07 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52912 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52912.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52912. Severity: important. Addresses CVE-2026-56852.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">c3c3d39c5892d3eb345e2744675fa15e</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 15:02:29 +0000</pubDate>
    </item>
    <item>
      <title>⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors</title>
      <link>https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html</link>
      <description>&lt;p&gt;A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.56; also cyber_attacks 0.93, vulnerabilities 0.87)&lt;/p&gt;</description>
      <guid isPermaLink="false">ab9fcef0eed7ce972e79363eeeffbc9c</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 15:00:29 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52910 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52910.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52910. Severity: important. Addresses CVE-2026-25681, CVE-2026-27136, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39835, CVE-2026-42508.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">494083bb362462ea9cfaa5fd4347a745</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 14:51:20 +0000</pubDate>
    </item>
    <item>
      <title>Someone hacked the X algorithm with fable and shows how it works</title>
      <link>https://thomasunise.com/x-algorithm</link>
      <description>&lt;p&gt;Article URL: https://thomasunise.com/x-algorithm Comments URL: https://news.ycombinator.com/item?id=49244428 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also cyber_attacks 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">c847c345d3ce4a08439a9d6d897f37b4</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 14:47:54 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52848 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52848.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52848. Severity: important. Addresses CVE-2026-49261.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">86b97b6d6163a01ebf79fde51c89a87a</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 14:06:03 +0000</pubDate>
    </item>
    <item>
      <title>When Credentials Are No Longer Enough: Device Trust in the AI Era</title>
      <link>https://www.bleepingcomputer.com/news/security/when-credentials-are-no-longer-enough-device-trust-in-the-ai-era/</link>
      <description>&lt;p&gt;AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.31 ; routed by best-effort floor)&lt;/p&gt;</description>
      <guid isPermaLink="false">3208fc872be056ac0cd1100c747f7b67</guid>
      <category>Security</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 14:01:11 +0000</pubDate>
    </item>
    <item>
      <title>A Growing Threat: The Anti-Rights Movement in the UK (By Amnesty International)</title>
      <link>https://archive.org/details/report-a-growing-threat-the-anti-rights-movement-in-the-uk-july</link>
      <description>&lt;p&gt;Article URL: https://archive.org/details/report-a-growing-threat-the-anti-rights-movement-in-the-uk-july Comments URL: https://news.ycombinator.com/item?id=49243597 Points: 7 # Comments: 2&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.47)&lt;/p&gt;</description>
      <guid isPermaLink="false">642ea3bb381c508db0eaaf688b2dadb8</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:46:31 +0000</pubDate>
    </item>
    <item>
      <title>Fedi Thread to Blog Post</title>
      <link>https://shom.dev/posts/20260809_fedi-thread-to-blog-post/</link>
      <description>&lt;p&gt;Article URL: https://shom.dev/posts/20260809_fedi-thread-to-blog-post/ Comments URL: https://news.ycombinator.com/item?id=49243282 Points: 4 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">a290dcbe2bf5445c658c5d1b3bb30baf</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:21:48 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68275: In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: check amdgpu_vm_bo_find() result in</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68275</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO

The AMDGPU_GEM_OP_GET_MAPPING_INFO path of amdgpu_gem_op_ioctl() looks
up the bo_va for the buffer object in the caller&amp;#x27;s VM via
amdgpu_vm_bo_find(), but uses the returned pointer without checking it.

amdgpu_vm_bo_find() returns NULL when the BO has no bo_va in that VM,
which is the normal case for a BO that has never been mapped. The result
is fed straight into amdgpu_vm_bo_va_for_each_valid_mapping(), which
expands to list_for_each_entry(mapping, &amp;amp;(bo_va)-&amp;gt;valids, list) and
dereferences bo_va, causing a NULL pointer dereference.

This is reachable by any process able to issue the ioctl (render group)
simply by requesting mapping info for an unmapped BO.

Return -ENOENT when no bo_va is found, jumping to out_exec so the
drm_exec context and GEM object reference are released.

(cherry picked from commit 528b19377affc1cc7362a70a254c1dda793595f9)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">64bd04a75c9bd650aa1b7bd7562ed480</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:16 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68261: In the Linux kernel, the following vulnerability has been resolved:

drm/imagination: fix error checking of</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68261</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

drm/imagination: fix error checking of pvr_vm_context_lookup()

Since pvr_vm_context_lookup() returns either NULL or a pointer, then stop
using IS_ERR() for checking the return value.

Using IS_ERR() leads to the kernel oops reported below. It can be
reproduced by passing an invalid VM context handle from userspace to the
DRM_IOCTL_PVR_CREATE_CONTEXT ioctl.

[   92.733119] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000148
[   92.742042] Mem abort info:
[   92.744890]   ESR = 0x0000000096000004
[   92.748686]   EC = 0x25: DABT (current EL), IL = 32 bits
[   92.754020]   SET = 0, FnV = 0
[   92.757154]   EA = 0, S1PTW = 0
[   92.760337]   FSC = 0x04: level 0 translation fault
[   92.765243] Data abort info:
[   92.768129]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000
[   92.773626]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[   92.778763]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[   92.784098] user pgtable: 4k pages, 48-bit VAs, pgdp=000000088ed23000
[   92.790550] [0000000000000148] pgd=0000000000000000, p4d=0000000000000000
[   92.797381] Internal error: Oops: 000000009600000&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">a0cbada829eb809a20a434e3a314dc55</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:14 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68260: In the Linux kernel, the following vulnerability has been resolved:

drm/imagination: acquire vm_ctx-&gt;lock before</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68260</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

drm/imagination: acquire vm_ctx-&amp;gt;lock before mapping memory to GPU VM

The drm gpuvm code doesn&amp;#x27;t protect find operation against map operation,
and the driver needs to ensure a map operation shouldn&amp;#x27;t happen when a
find operation is in progress.

In some cases a find operation will be in progress when doing map/unmap
operations, and the find operation will do a NULL pointer dereference.

An example of the stack trace of such NULL dereference is shown below:

```
Unable to handle kernel access to user memory without uaccess routines at
virtual address 0000000000000010

[&amp;lt;ffffffff01e989d4&amp;gt;] drm_gpuva_find+0x28/0x6c [drm_gpuvm]
[&amp;lt;ffffffff01ed3a40&amp;gt;] pvr_vm_unmap+0x34/0x68 [powervr]
[&amp;lt;ffffffff01ec69da&amp;gt;] pvr_ioctl_vm_unmap+0x2e/0x50 [powervr]
[&amp;lt;ffffffff8080ce0a&amp;gt;] drm_ioctl_kernel+0x8e/0xdc
[&amp;lt;ffffffff8080d016&amp;gt;] drm_ioctl+0x1be/0x3e0
[&amp;lt;ffffffff802bec3e&amp;gt;] __riscv_sys_ioctl+0xba/0xc4
[&amp;lt;ffffffff80d858b2&amp;gt;] do_trap_ecall_u+0x23e/0x3f4
[&amp;lt;ffffffff80d92288&amp;gt;] handle_exception+0x168/0x174
```

As all occurences of drm_gpuva_find*() are already guarded by
vm_ctx-&amp;gt;lock, make pvr_vm_map() to acquire this lock to prevent
disturbing any&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">4a4a2447dd4e8d1d5e91abfe1c86d97f</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:14 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68242: In the Linux kernel, the following vulnerability has been resolved:

drm/i915/gt: Fix NULL deref on sched_engine alloc</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68242</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

drm/i915/gt: Fix NULL deref on sched_engine alloc failure

Avoid using intel_context_put() before intel_context_init() in
execlists_create_virtual() as the kref_put() inside would lead
to NULL deref on the IOCTL path when sched_engine allocation fails.

Discovered using AI-assisted static analysis confirmed by
Intel Product Security.

(cherry picked from commit 4f2a12f2d50e9f48227656e4dcbd6423506be31d)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">eeb7bf375bfd8bbce2b0c8a236018e2a</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:12 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68204: In the Linux kernel, the following vulnerability has been resolved:

media: vivid: check for vb2_is_busy() when</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68204</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

media: vivid: check for vb2_is_busy() when toggling caps

The vivid_update_format_cap/out() functions must only be called if the
capture/output queue are not busy. But for the controls that select
the CROP/COMPOSE/SCALE capability that is not checked.

Only when streaming starts will they be set to &amp;#x27;grabbed&amp;#x27; and it is
impossible to change the control, but between REQBUFS and STREAMON you
are still allowed to set these controls. Since vivid_update_format_cap/out
will change the format, this can cause unexpected results.

Besides adding these checks, also add a WARN_ON in
vivid_update_format_cap/out() if the queue is busy.

I&amp;#x27;m 90% certain that this is the cause of this syzbot bug:

https://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89

But since we never have reproducers, it is hard to be certain. In any case,
these checks are needed regardless.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">18d0f80245bac8e90bdccd85bceb1e94</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:08 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68200: In the Linux kernel, the following vulnerability has been resolved:

ALSA: timer: don't re-enter an instance callback</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68200</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

ALSA: timer: don&amp;#x27;t re-enter an instance callback that is still running

The userspace-driven timer (utimer) TRIGGER ioctl calls
snd_timer_interrupt() directly with no serialization, so two threads
triggering the same utimer can run snd_timer_interrupt() on one
snd_timer concurrently.

snd_timer_process_callbacks() drops timer-&amp;gt;lock around each instance
callback and marks the in-flight callback with the single
SNDRV_TIMER_IFLG_CALLBACK bit; snd_timer_close_locked() waits on that
bit to drain an in-flight callback before freeing the instance. The bit
cannot represent two concurrent callbacks: when a second interrupt
re-queues an instance whose callback is still running, both run at once,
the first to finish clears the bit, and the close-path drain then frees
the instance (and its callback_data) while the other callback is still
live - a use-after-free reachable by any user able to open
/dev/snd/timer, both via a user timer instance and via a sequencer queue
timer bound to the utimer.

snd_timer_interrupt() sets IFLG_CALLBACK before dropping timer-&amp;gt;lock, so
a concurrent interrupt already observes it under the lock. S&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">0074ea5793ab24df477ab05c2d58f18b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:07 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68197: In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: fix NULL dereference when the AP</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68197</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper

mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc-&amp;gt;bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc-&amp;gt;bcn_ht_oper:

	if (ISSUPP_CHANWIDTH40(priv-&amp;gt;adapter-&amp;gt;hw_dot_11n_dev_cap) &amp;amp;&amp;amp;
	    bss_desc-&amp;gt;bcn_ht_cap &amp;amp;&amp;amp;
	    ISALLOWED_CHANWIDTH40(bss_desc-&amp;gt;bcn_ht_oper-&amp;gt;ht_param))

bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP&amp;#x27;s beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.

Guard on the pointer that is actually dereferenced.

Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">8d9f535c84bd0710e3670c12085fd83c</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:07 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68188: In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: Fix session UAF in</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68188</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: RFCOMM: Fix session UAF in set_termios

rfcomm_tty_set_termios() tests dlc-&amp;gt;session without rfcomm_mutex and
later passes the pointer to rfcomm_send_rpn(). The latter dereferences
both session-&amp;gt;initiator and session-&amp;gt;sock. Meanwhile, krfcommd can
unlink the DLC and free the session while holding rfcomm_mutex.

The race can proceed as follows:

  TTY ioctl task                 krfcommd
  --------------                 --------
  load dlc-&amp;gt;session
  enter rfcomm_send_rpn()
                                 lock rfcomm_mutex
                                 clear dlc-&amp;gt;session
                                 free session
                                 unlock rfcomm_mutex
  read session-&amp;gt;initiator

KASAN reported:

  BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0
  Read of size 4 at addr ffff88810012a850 by task poc/92

  Call Trace:
   rfcomm_send_rpn+0x297/0x2a0
   rfcomm_tty_set_termios+0x50d/0x850
   tty_set_termios+0x596/0x950
   set_termios+0x46a/0x6e0
   tty_mode_ioctl+0x152/0xbd0
   tty_ioctl+0x915/0x1240
   __x64_sys_ioctl+0x134/0x1c0

  Allocated by task 92:
   rfcomm_session_add+&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">b6bd5325c09ae11d0b2064056d6e3e32</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:06 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68184: In the Linux kernel, the following vulnerability has been resolved:

cdrom: fix stack out-of-bounds read in</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68184</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

cdrom: fix stack out-of-bounds read in CDROMVOLCTRL

mmc_ioctl_cdrom_volume() first reads the audio control mode page into a
32-byte stack buffer with cgc-&amp;gt;buflen set to 24.  If the device reports a
block descriptor, the function increases cgc-&amp;gt;buflen to include that
descriptor and reads the page again.

For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list
by moving cgc-&amp;gt;buffer forward by offset - 8 bytes.  This drops the block
descriptor from the outgoing payload and leaves a new 8-byte mode
parameter header in front of the audio control page.  However, cgc-&amp;gt;buflen
is left unchanged.

With a standard 8-byte block descriptor, cgc-&amp;gt;buffer points at buffer + 8
but cgc-&amp;gt;buflen remains 32.  cdrom_mode_select() therefore asks the low
level packet path to write 32 bytes from that adjusted pointer, reading 8
bytes past the end of the 32-byte stack buffer.

This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on
drives that return a non-zero block descriptor length, which helps explain
why it has gone unnoticed.  The overread is also sent to the device as
extra MODE SELECT payload, so it m&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">44bf79f96bbc75b7eeba4d86b44e08e0</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:05 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68179: In the Linux kernel, the following vulnerability has been resolved:

misc: nsm: only unlock nsm_dev on post-lock error</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68179</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

misc: nsm: only unlock nsm_dev on post-lock error paths

nsm_dev_ioctl() jumps to the common out label even when the initial
copy_from_user() fails before nsm-&amp;gt;lock has been taken.  The error path
then blindly unlocks a mutex that was never acquired.

This issue was found by our static analysis tool and then manually
reviewed against the current tree.

The grounded PoC kept the miscdevice ioctl entry and the pre-lock
copy_from_user(&amp;amp;raw, argp, _IOC_SIZE(cmd)) failure path by issuing
NSM_IOCTL_RAW with an invalid user pointer.  That failure reaches the
shared out label before mutex_lock(&amp;amp;nsm-&amp;gt;lock).  Lockdep reported:

  WARNING: bad unlock balance detected!
  exploit/193 is trying to release lock (&amp;amp;global_nsm.lock) at:
  nsm_dev_ioctl+0x5f/0xcf [vuln_msv]
  but there are no more locks to release!
  no locks held by exploit/193.

Return immediately on the pre-lock copy_from_user() failure and keep the
common unlock label for the post-lock paths only.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.65; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">a288733941eff4f59d69c8c92ea9bc7b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:04 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68178: In the Linux kernel, the following vulnerability has been resolved:

misc: nsm: pin the module while the device is</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68178</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

misc: nsm: pin the module while the device is open

misc_open() installs a misc driver&amp;#x27;s file operations with fops_get(),
which pins file_operations::owner before replacing the file&amp;#x27;s f_op.  The
NSM misc device leaves nsm_dev_fops.owner unset, so opening /dev/nsm does
not take a module reference on the nsm driver.

If the driver is built as a module, an open file descriptor can therefore
survive rmmod of the module that provides its ioctl callbacks.  A later
ioctl through that descriptor can call into unloaded module text.

Set nsm_dev_fops.owner to THIS_MODULE so the misc core holds the module
while any /dev/nsm file descriptor is open, matching the lifetime
expectation for the installed file operations.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">2c9287a5677c6fbe6070bf9dcf79a188</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:20:04 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-68142: In the Linux kernel, the following vulnerability has been resolved:

geneve: require CAP_NET_ADMIN in the device netns</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-68142</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:

geneve: require CAP_NET_ADMIN in the device netns for changelink

A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns geneve-&amp;gt;net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in geneve-&amp;gt;net can rewrite a geneve
device whose underlay lives in geneve-&amp;gt;net.

geneve_changelink() applies the new configuration against geneve-&amp;gt;net:
geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair
reopen the underlay sockets in that netns (geneve_sock_add() uses
geneve-&amp;gt;net), so the same reasoning as the tunnel changelink series
applies here.

Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the &amp;quot;require CAP_NET_ADMIN in the device netns for
changelink&amp;quot; series.

Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.59; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">2456877c1937db659335b000ccdd63e7</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:19:59 +0000</pubDate>
    </item>
    <item>
      <title>Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development</title>
      <link>https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html</link>
      <description>&lt;p&gt;North Korea&amp;#x27;s state hackers are no longer content to type prompts into public chatbots. One of the country&amp;#x27;s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.98; also cyber_attacks 0.35)&lt;/p&gt;</description>
      <guid isPermaLink="false">e4cbe4f1c2f955e0940f09e86e40faa8</guid>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 13:19:58 +0000</pubDate>
    </item>
    <item>
      <title>Asynchronous I/O in DuckDB: Work, Thread, Work</title>
      <link>https://duckdb.org/2026/07/31/asynchronous-io</link>
      <description>&lt;p&gt;Article URL: https://duckdb.org/2026/07/31/asynchronous-io Comments URL: https://news.ycombinator.com/item?id=49243061 Points: 4 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">3916cf166b258d4c62844a332dc22b28</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 13:01:18 +0000</pubDate>
    </item>
    <item>
      <title>Show HN: Synchrium, a synchronized timer where remote peers meet at zero</title>
      <link>https://synchrium.com/</link>
      <description>&lt;p&gt;Article URL: https://synchrium.com/ Comments URL: https://news.ycombinator.com/item?id=49242803 Points: 2 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">1ce232e28ed83f5cdf5b8b7fa84b0df4</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:33:13 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52832 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52832.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52832. Severity: important. Addresses CVE-2026-58049, CVE-2026-64835.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">ec0eaa593555dbd8f89b1832b5713476</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:28:47 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52833 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52833.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52833. Severity: important. Addresses CVE-2026-58049, CVE-2026-64835.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">87cd157a711da8f196275cae4eb63ead</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:28:27 +0000</pubDate>
    </item>
    <item>
      <title>New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA</title>
      <link>https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html</link>
      <description>&lt;p&gt;Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim&amp;#x27;s machine, and used a&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.74; also cyber_attacks 0.79)&lt;/p&gt;</description>
      <guid isPermaLink="false">cdcb04f053b50d7b593de00f643c86b8</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:25:04 +0000</pubDate>
    </item>
    <item>
      <title>DeepSeek costs OpenCode Go user $1.14/day; dual DGX breaks even in 24 years</title>
      <link>https://twitter.com/thdxr/status/2086599224674681242</link>
      <description>&lt;p&gt;Article URL: https://twitter.com/thdxr/status/2086599224674681242 Comments URL: https://news.ycombinator.com/item?id=49242728 Points: 64 # Comments: 58&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">13046e0834aac7e109a0850d383074f5</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:24:48 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52834 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52834.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52834. Severity: important. Addresses CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">45bc0ceb211bd3290ce5f983ec965d46</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:23:42 +0000</pubDate>
    </item>
    <item>
      <title>LexisNexis shuts down services after suspicious activity on servers</title>
      <link>https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/</link>
      <description>&lt;p&gt;LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.26 ; routed by best-effort floor)&lt;/p&gt;</description>
      <guid isPermaLink="false">950b09a3f598f2017855e3ea7d193f66</guid>
      <category>Security</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 12:11:52 +0000</pubDate>
    </item>
    <item>
      <title>Pioneer DJ Warns of Major Security Threat to Rekordbox and Every CDJ</title>
      <link>https://5mag.net/news/pioneer-dj-rekordbox-cdj-exploit-security-vulnerability/</link>
      <description>&lt;p&gt;Article URL: https://5mag.net/news/pioneer-dj-rekordbox-cdj-exploit-security-vulnerability/ Comments URL: https://news.ycombinator.com/item?id=49242559 Points: 5 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42; also vulnerabilities 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">c414b77c3075da2346db38046b393a4b</guid>
      <category>bucket:threat_intel</category>
      <category>bucket:vulnerabilities</category>
      <pubDate>Mon, 10 Aug 2026 12:02:31 +0000</pubDate>
    </item>
    <item>
      <title>TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore</title>
      <link>https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html</link>
      <description>&lt;p&gt;The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.82; also vulnerabilities 0.89, cyber_attacks 0.35)&lt;/p&gt;</description>
      <guid isPermaLink="false">8cd19c7c9cd43bd13e6088bc5d9db256</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:33:41 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72591 (CVSS 7.7 HIGH): A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72591</link>
      <description>&lt;p&gt;CVSS 7.7 HIGH. A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supplying a crafted image_url value in the PATCH /apis/web/v1/album/{id}/image endpoint.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">4c6faad2a0b0313aae7a3806c7439b58</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 11:17:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72588 (CVSS 5.3 MEDIUM): A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72588</link>
      <description>&lt;p&gt;CVSS 5.3 MEDIUM. A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered ones, enabling attackers to enumerate valid user accounts.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99, cyber_attacks 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">0578f4ae67910144ca6b53bc2c82a9f3</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72582 (CVSS 7.5 HIGH): A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72582</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in pkg/auth/local.go dereferences a pointer obtained from an unchecked error path without validating it is non-nil, causing a fatal panic that terminates the entire server when a recovery request is sent to the /api/auth/local/recover endpoint.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99, cyber_attacks 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">0004127ec218ce0f3bdbbeeb00e06234</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72581 (CVSS 8.6 HIGH): A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72581</link>
      <description>&lt;p&gt;CVSS 8.6 HIGH. A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home Assistant instance without validating the destination URL, enabling internal network scanning and access to internal services.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">e8ecef58a070e09cade5cc483042b3cd</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 11:17:31 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-72566 (CVSS 7.7 HIGH): A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-72566</link>
      <description>&lt;p&gt;CVSS 7.7 HIGH. A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with &amp;#x27;manage Flow&amp;#x27; permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app&amp;#x27;s Custom Request action.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">aa67b91a29f42813dca860308958da60</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 11:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-59087 (CVSS 7.8 HIGH): A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-59087</link>
      <description>&lt;p&gt;CVSS 7.8 HIGH. A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">a72c10a43290e280e39b25b37fbe777b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 11:17:26 +0000</pubDate>
    </item>
    <item>
      <title>The OpenAI and Hugging Face breach story told from the perspective of the AI</title>
      <link>https://www.youtube.com/watch?v=RE4IDWjfOZc</link>
      <description>&lt;p&gt;Article URL: https://www.youtube.com/watch?v=RE4IDWjfOZc Comments URL: https://news.ycombinator.com/item?id=49242015 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also cyber_attacks 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">46d7c133970e93bd0624cb102eda4431</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 10:52:23 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52772 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52772.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52772. Severity: important. Addresses CVE-2026-14380, CVE-2026-14739.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">8cc7dc30a2b1ad9ea7495e4e1cc1c6fe</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 10:48:57 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52765 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52765.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52765. Severity: moderate. Addresses CVE-2026-64496.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, moderate, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">110131f1648e1e91f083b64d660b8508</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>moderate</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 10:43:52 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52764 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52764.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52764. Severity: important. Addresses CVE-2025-71116, CVE-2026-22990, CVE-2026-31613, CVE-2026-31787, CVE-2026-43112, CVE-2026-46054, CVE-2026-52923, CVE-2026-52976.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">a437d83b3540b1c1213a76e86924d8d4</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 10:40:37 +0000</pubDate>
    </item>
    <item>
      <title>The dumbest ransomware I've ever seen</title>
      <link>https://mrunix.me/posts/ransomware/</link>
      <description>&lt;p&gt;Article URL: https://mrunix.me/posts/ransomware/ Comments URL: https://news.ycombinator.com/item?id=49241642 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also cyber_attacks 0.76)&lt;/p&gt;</description>
      <guid isPermaLink="false">5b1f0209a7d2dc9a650aea1699fdbf06</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 10:04:59 +0000</pubDate>
    </item>
    <item>
      <title>Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility</title>
      <link>https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/</link>
      <description>&lt;p&gt;CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; ICS/OT, Malware &amp;amp; Threats, energy, Featured, ICS, OT, PLC, Poland, power grid, SCADA&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.69; also cyber_attacks 0.69)&lt;/p&gt;</description>
      <guid isPermaLink="false">f5669cdaa1090acfb66ef1a684ccbe16</guid>
      <category>ICS/OT</category>
      <category>Malware &amp; Threats</category>
      <category>energy</category>
      <category>Featured</category>
      <category>ICS</category>
      <category>OT</category>
      <category>PLC</category>
      <category>Poland</category>
      <category>power grid</category>
      <category>SCADA</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:01:52 +0000</pubDate>
    </item>
    <item>
      <title>IT threat evolution in Q2 2026. Non-mobile statistics</title>
      <link>https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/</link>
      <description>&lt;p&gt;The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Securelist (Kaspersky GReAT)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware reports, Linux, Microsoft Windows, Malware Statistics, Apple MacOS, Antivirus Technologies, Trojan, Internet of Things, Mirai, RaaS, Honeypot, Miner&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.94; also cyber_attacks 0.89)&lt;/p&gt;</description>
      <guid isPermaLink="false">f66385591c5ec4a1450f9ae67f50fe79</guid>
      <category>Malware reports</category>
      <category>Linux</category>
      <category>Microsoft Windows</category>
      <category>Malware Statistics</category>
      <category>Apple MacOS</category>
      <category>Antivirus Technologies</category>
      <category>Trojan</category>
      <category>Internet of Things</category>
      <category>Mirai</category>
      <category>RaaS</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:00:37 +0000</pubDate>
    </item>
    <item>
      <title>IT threat evolution in Q2 2026. Mobile statistics</title>
      <link>https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/</link>
      <description>&lt;p&gt;This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Securelist (Kaspersky GReAT)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Malware reports, Google Android, Adware, Mobile Malware, Malware Statistics, Trojan Banker, Trojan, Trojan Clicker, Trojan-Dropper, Google Play, Mamont, Triada&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.88; also cyber_attacks 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">b4e568d2833e6db68407d79c1b303820</guid>
      <category>Malware reports</category>
      <category>Google Android</category>
      <category>Adware</category>
      <category>Mobile Malware</category>
      <category>Malware Statistics</category>
      <category>Trojan Banker</category>
      <category>Trojan</category>
      <category>Trojan Clicker</category>
      <category>Trojan-Dropper</category>
      <category>Google Play</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Mon, 10 Aug 2026 10:00:09 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52674 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52674.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52674. Severity: moderate. Addresses CVE-2026-14164.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, moderate, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">d371441d78b8d959d09c913791b8b57d</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>moderate</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 09:44:57 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52768 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52768.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52768. Severity: important. Addresses CVE-2026-5038, CVE-2026-5079, CVE-2026-13149, CVE-2026-46625, CVE-2026-48068, CVE-2026-48712, CVE-2026-49978, CVE-2026-59869, CVE-2026-59877, CVE-2026-59892.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">e2f50c02be221282e2118e523d6b6fd1</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 09:41:59 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52761 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52761.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52761. Severity: moderate. Addresses CVE-2026-64496.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, moderate, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">e1410d3189760e81aaf126106e9961ff</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>moderate</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 09:21:37 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52675 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52675.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52675. Severity: moderate. Addresses CVE-2026-14164.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, moderate, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">8e305268184963cd3e8c5410601cd731</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>moderate</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 09:10:02 +0000</pubDate>
    </item>
    <item>
      <title>Corporate Data Stolen in Levi Strauss Cyberattack</title>
      <link>https://www.securityweek.com/corporate-data-stolen-in-levi-strauss-cyberattack/</link>
      <description>&lt;p&gt;Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SecurityWeek&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Data Breaches, data breach, Levi Strauss&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.62; also cyber_attacks 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">84e6e5aca5bb70a6f1edabb22725a621</guid>
      <category>Data Breaches</category>
      <category>data breach</category>
      <category>Levi Strauss</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 08:55:44 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52667 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52667.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52667. Severity: important. Addresses CVE-2025-71131, CVE-2026-46054, CVE-2026-52976.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">cec7f678a5aca6a46c41f0b36e75e3c8</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 07:59:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-13600: The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-13600</link>
      <description>&lt;p&gt;The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator&amp;#x27;s session cookie and gain administrator access without credentials.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.97)&lt;/p&gt;</description>
      <guid isPermaLink="false">db053c345fbc307f012c83ddb34ce3d4</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 07:16:46 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52649 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52649.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52649. Severity: important. Addresses CVE-2025-10263, CVE-2026-31787, CVE-2026-43112, CVE-2026-46054, CVE-2026-52923, CVE-2026-53059.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">c888f13283e68e320e3b1b6fabee4ed6</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 05:43:12 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52551 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52551.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52551. Severity: important. Addresses CVE-2026-54058, CVE-2026-54059, CVE-2026-54060, CVE-2026-55379, CVE-2026-55380, CVE-2026-59197.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">dea130eb7bbd0243510599fbffb45a87</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 04:01:12 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52395 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52395.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52395. Severity: important. Addresses CVE-2026-6479.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">2ecca025431681627b4b800addbcb9b7</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 03:35:32 +0000</pubDate>
    </item>
    <item>
      <title>Reflex: Demonstrate a GUI workflow once, replay it with zero LLM calls</title>
      <link>https://github.com/MARCCHERGGI/reflex</link>
      <description>&lt;p&gt;Article URL: https://github.com/MARCCHERGGI/reflex Comments URL: https://news.ycombinator.com/item?id=49238903 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">0a84d968b2e2642b7ee40115e171522c</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 03:30:26 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52396 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52396.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52396. Severity: important. Addresses CVE-2026-6479.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">52d5a58b8618681f9fe84d7fc3e5cfe0</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:59:03 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52399 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52399.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52399. Severity: important. Addresses CVE-2026-12151, CVE-2026-13149, CVE-2026-42338, CVE-2026-48615, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">e32abd2222284875fc1c2287c895c2c6</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:56:38 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52400 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52400.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52400. Severity: important. Addresses CVE-2026-6100.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">a9dbeb85dfe7f66b27477c7e687367de</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:33:57 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52398 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52398.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52398. Severity: important. Addresses CVE-2026-55999, CVE-2026-56000.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">8468c18b2add24571650e68475f5191f</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:07:38 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52389 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52389.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52389. Severity: important. Addresses CVE-2026-25679.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">9435edb14cd0439156d901d6facaf480</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:03:02 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52397 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52397.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52397. Severity: important. Addresses CVE-2026-55999.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">696590a2eef14849c228b38a9c44804a</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:01:47 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52392 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52392.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52392. Severity: important. Addresses CVE-2026-55999.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">ce13beba2910b0c863b9b38d4c12412e</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:00:57 +0000</pubDate>
    </item>
    <item>
      <title>ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)</title>
      <link>https://isc.sans.edu/diary/rss/33228</link>
      <description>&lt;p&gt;ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; SANS Internet Storm Center&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.80)&lt;/p&gt;</description>
      <guid isPermaLink="false">44d185566182fa933ed83bb97288426c</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 02:00:03 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52391 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52391.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52391. Severity: important. Addresses CVE-2026-25679.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">0aad31031fd9c36b717333d5af64d23f</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 01:56:57 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52390 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52390.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52390. Severity: important. Addresses CVE-2026-25679.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">85120ef80e3b6cc46d3240ba7aa02ffe</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 01:52:27 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52393 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52393.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52393. Severity: moderate. Addresses CVE-2026-29168.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, moderate, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">11d7751ab4e9d9dde3f38ab86ba74ca5</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>moderate</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 01:46:27 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52394 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52394.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52394. Severity: important. Addresses CVE-2026-13149.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">79b320ecb8cdf2dd169143172b572894</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 01:38:27 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-19380 (CVSS 2.3 LOW): A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-19380</link>
      <description>&lt;p&gt;CVSS 2.3 LOW. A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, LOW&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">e67f0f904988dcbe23c461eddccfaf78</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>LOW</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 01:16:48 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:52414 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:52414.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:52414. Severity: moderate. Addresses CVE-2026-58055.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, moderate, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">c71891d40943b0316aaee0cc2123153c</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>moderate</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 01:09:10 +0000</pubDate>
    </item>
    <item>
      <title>Blender MCP maintainer GitHub account hacked</title>
      <link>https://twitter.com/sidahuj/status/2086445625147793503</link>
      <description>&lt;p&gt;Article URL: https://twitter.com/sidahuj/status/2086445625147793503 Comments URL: https://news.ycombinator.com/item?id=49238028 Points: 24 # Comments: 4&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also cyber_attacks 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">3e00bfe87160d9b4f963aa6e5b8f5c23</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 00:58:29 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6428-1 libyaml-syck-perl - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00339.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6428-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">043628fab06c0c567034c86f9e28c610</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6427-1 wordpress - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00338.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6427-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">f7650ab9d616bcd25aa3086ce7b8d081</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6426-1 icinga2 - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00337.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6426-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">2190756a507b442759467b6051be9e1e</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6425-1 openjdk-21 - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00336.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6425-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">1d24d31f3549131624a8dc5f3a9019af</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>A zero-dependency, ultra-lightweight database time machine for SQLite</title>
      <link>https://github.com/nsrht/time-travel-sqlite-debugger</link>
      <description>&lt;p&gt;Article URL: https://github.com/nsrht/time-travel-sqlite-debugger Comments URL: https://news.ycombinator.com/item?id=49234506 Points: 36 # Comments: 5&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">2246448508797e0529a662193f62322a</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 18:59:53 +0000</pubDate>
    </item>
    <item>
      <title>DeepMind AI gives an extra day of warning ahead of deadly cyclones</title>
      <link>https://www.newscientist.com/article/2583547-deepmind-ai-gives-an-extra-day-of-warning-ahead-of-deadly-cyclones/</link>
      <description>&lt;p&gt;Article URL: https://www.newscientist.com/article/2583547-deepmind-ai-gives-an-extra-day-of-warning-ahead-of-deadly-cyclones/ Comments URL: https://news.ycombinator.com/item?id=49233162 Points: 2 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">0b704a962b57200bbf4fbede0d5358fb</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 16:56:47 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-19352 (CVSS 3.1 LOW): A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-19352</link>
      <description>&lt;p&gt;CVSS 3.1 LOW. A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: &amp;quot;I&amp;#x27;m not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn&amp;#x27;t really a LosslessCut bug.&amp;quot; The CVSS vector reflects the high level of pre-requisites.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, LOW&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">52e0b32af172fd52d844545ead68be8b</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>LOW</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 13:16:50 +0000</pubDate>
    </item>
    <item>
      <title>KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts</title>
      <link>https://databreaches.net/2026/08/09/kr-3pro-tv-data-breach-exposes-460000-records-including-2979-bank-accounts/</link>
      <description>&lt;p&gt;Park Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s website saying it had confirmed that “an external actor illegally accessed the... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Business Sector, Hack, Non-U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.58; also cyber_attacks 0.95)&lt;/p&gt;</description>
      <guid isPermaLink="false">5dc108f1ab738ec2155c7950ba1396e7</guid>
      <category>Business Sector</category>
      <category>Hack</category>
      <category>Non-U.S.</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 12:58:02 +0000</pubDate>
    </item>
    <item>
      <title>Ransomware gangs skip the CEO, head straight for the 40-something IT manager</title>
      <link>https://databreaches.net/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/</link>
      <description>&lt;p&gt;Carly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Commentaries and Analyses, Malware&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.89; also cyber_attacks 0.95)&lt;/p&gt;</description>
      <guid isPermaLink="false">7614cdd6c3207238c649ab6d8f154f90</guid>
      <category>Commentaries and Analyses</category>
      <category>Malware</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 12:24:57 +0000</pubDate>
    </item>
    <item>
      <title>Show HN: Find. Fix. Verify. Zero Guesswork</title>
      <link>https://kinetixseo.com</link>
      <description>&lt;p&gt;Article URL: https://kinetixseo.com Comments URL: https://news.ycombinator.com/item?id=49229739 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">868bbd253a5f4364f20866f236679e35</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 09:10:39 +0000</pubDate>
    </item>
    <item>
      <title>I asked 4 AI companions what they were. They lied, then texted me the next day</title>
      <link>https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7244220</link>
      <description>&lt;p&gt;Article URL: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7244220 Comments URL: https://news.ycombinator.com/item?id=49228137 Points: 11 # Comments: 2&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">ff5d77dbbcf0438946b9cd3b73b5f2f0</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 03:21:10 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6424-1 xen - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00335.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6424-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">bb48705e596283e696c1c3fc7bb0f4b5</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6423-1 kitty - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00334.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6423-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">f20f2fe37b95ef8149bab6a368350f71</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>Lisp doesn't have just one syntax (or zero syntax); it has infinite syntax</title>
      <link>https://www.reddit.com/r/ProgrammingLanguages/comments/1ejaowf/making_my_own_lisp_made_me_realize_lisp_doesnt/</link>
      <description>&lt;p&gt;Article URL: https://www.reddit.com/r/ProgrammingLanguages/comments/1ejaowf/making_my_own_lisp_made_me_realize_lisp_doesnt/ Comments URL: https://news.ycombinator.com/item?id=49227013 Points: 6 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">b4c949f4910c41a89cc4637a9059444c</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 23:53:31 +0000</pubDate>
    </item>
    <item>
      <title>City of Suisun declares local emergency after cyberattack downs 911 dispatch system</title>
      <link>https://databreaches.net/2026/08/08/city-of-suisun-declares-local-emergency-after-cyberattack-downs-911-dispatch-system/</link>
      <description>&lt;p&gt;Katie Chavez reports: Suisun City officials declared a state of emergency Saturday, Aug. 8, after a cyberattack took out the city’s emergency dispatch line and other key systems. City officials said that “malicious software infected and compromised IT systems” at about 5:45 a.m. on Friday. The cybersecurity issue forced the city to shut down its... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Government Sector&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.51; also cyber_attacks 0.89)&lt;/p&gt;</description>
      <guid isPermaLink="false">81cab50014dfe45b74b52e022a4125ea</guid>
      <category>Government Sector</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 23:05:28 +0000</pubDate>
    </item>
    <item>
      <title>Show HN: Zero-bloat, client-side utility suite with zero telemetry</title>
      <link>https://summit-side-utilities.pages.dev/</link>
      <description>&lt;p&gt;I built an simple unbloated utility suite of 51 actually useful tools that runs client-side on static html. Access is a $2/month subscription for everything on the website, now or in the future, and the tools unlock with a 12 digit key. I built these tools to buy back my time by providing value to workers who need to buy back theirs. Comments URL: https://news.ycombinator.com/item?id=49225010 Points: 1 # Comments: 1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">3995b1be36ca353d43a1a2fee431106b</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 19:25:23 +0000</pubDate>
    </item>
    <item>
      <title>Thomas Wolf thread on the AISI incident</title>
      <link>https://twitter.com/Thom_Wolf/status/2085084718320464230</link>
      <description>&lt;p&gt;Article URL: https://twitter.com/Thom_Wolf/status/2085084718320464230 Comments URL: https://news.ycombinator.com/item?id=49224910 Points: 3 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42; also cyber_attacks 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">5b95f0e92868a1b7fdd0faeac643d056</guid>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 19:13:51 +0000</pubDate>
    </item>
    <item>
      <title>macOS vulnerability: authenticate Screen Sharing without valid credentials</title>
      <link>https://twitter.com/calif_io/status/2086022794840793454</link>
      <description>&lt;p&gt;Article URL: https://twitter.com/calif_io/status/2086022794840793454 Comments URL: https://news.ycombinator.com/item?id=49224782 Points: 2 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also vulnerabilities 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">a180eb794ec7cb7c0be905e58b5f501c</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 18:58:51 +0000</pubDate>
    </item>
    <item>
      <title>Show HN: Happy 808 Day</title>
      <link>https://raygum.com/instruments/roland-tr-808-drum-machine</link>
      <description>&lt;p&gt;Article URL: https://raygum.com/instruments/roland-tr-808-drum-machine Comments URL: https://news.ycombinator.com/item?id=49224603 Points: 4 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">da7b1fc616e162947b43b1d7aba2e218</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 18:41:21 +0000</pubDate>
    </item>
    <item>
      <title>The New Spy Race: For Agentic AI and Quantum Computing Threats</title>
      <link>https://www.quantumhorizon.it/inside-the-new-spy-race-how-the-us-china-russia-israel-and-italy-are-gearing-up-for-agentic-ai-and-quantum-computing-threats/</link>
      <description>&lt;p&gt;Article URL: https://www.quantumhorizon.it/inside-the-new-spy-race-how-the-us-china-russia-israel-and-italy-are-gearing-up-for-agentic-ai-and-quantum-computing-threats/ Comments URL: https://news.ycombinator.com/item?id=49224043 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">d28191eaf8f7f2ebd2db876de9559e9e</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 17:44:27 +0000</pubDate>
    </item>
    <item>
      <title>HTML Day 2026</title>
      <link>https://2026.html.energy/</link>
      <description>&lt;p&gt;Article URL: https://2026.html.energy/ Comments URL: https://news.ycombinator.com/item?id=49223191 Points: 5 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">8974aab031274597b73c704ace5e28ec</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 16:17:07 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-67620 (CVSS 7.7 HIGH): Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-67620</link>
      <description>&lt;p&gt;CVSS 7.7 HIGH. Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. Attackers can send requests to the fetch-links API endpoint with a crafted URL parameter, bypassing deny-list validation including redirect-based bypasses, to reach instance metadata services and expose instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments, with unauthenticated access possible when URL-fetching nodes exist in public chatflows.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">87d82a2d807f649ed680814be308c17f</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 16:16:49 +0000</pubDate>
    </item>
    <item>
      <title>Hackers breach TrueConf to trojanize client installers with backdoors</title>
      <link>https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/</link>
      <description>&lt;p&gt;The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also cyber_attacks 0.80, vulnerabilities 0.69)&lt;/p&gt;</description>
      <guid isPermaLink="false">c230c50ef5b75be94db815ec83273a39</guid>
      <category>Security</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 14:16:23 +0000</pubDate>
    </item>
    <item>
      <title>City of Coweta refuses to pay ransom after system-wide cyberattack</title>
      <link>https://databreaches.net/2026/08/08/city-of-coweta-refuses-to-pay-ransom-after-system-wide-cyberattack/</link>
      <description>&lt;p&gt;An update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who don’t keep their word do spoil it for... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Government Sector, Malware, U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.94; also cyber_attacks 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">e3d0c45575751ade0932187bd20b208c</guid>
      <category>Government Sector</category>
      <category>Malware</category>
      <category>U.S.</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 12:40:22 +0000</pubDate>
    </item>
    <item>
      <title>Happy 808 day: The TR-808 Monograph</title>
      <link>https://raygum.com/research/roland-tr-808-monograph</link>
      <description>&lt;p&gt;Article URL: https://raygum.com/research/roland-tr-808-monograph Comments URL: https://news.ycombinator.com/item?id=49221000 Points: 3 # Comments: 1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">95ca6620ba97dd7dc130d3a45ee41050</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 12:01:16 +0000</pubDate>
    </item>
    <item>
      <title>AI is not your biggest cyber threat. Your shitty patching process is</title>
      <link>https://0ut3r.space/2026/08/08/ai-is-not-your-biggest-cyber-threat/</link>
      <description>&lt;p&gt;Article URL: https://0ut3r.space/2026/08/08/ai-is-not-your-biggest-cyber-threat/ Comments URL: https://news.ycombinator.com/item?id=49220370 Points: 1 # Comments: 1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42; also vulnerabilities 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">6e692e35cc4e4da67c297ded9e8abb4a</guid>
      <category>bucket:threat_intel</category>
      <category>bucket:vulnerabilities</category>
      <pubDate>Sat, 08 Aug 2026 10:11:31 +0000</pubDate>
    </item>
    <item>
      <title>FlowChartCharter – A Zero-Hallucination, Fear-Driven GraphRAG Alternative</title>
      <link>https://github.com/CharleSpectre13/flowchartcharter</link>
      <description>&lt;p&gt;Article URL: https://github.com/CharleSpectre13/flowchartcharter Comments URL: https://news.ycombinator.com/item?id=49220311 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">61bb5780c6f3981a1e23869c05da55b8</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 09:58:34 +0000</pubDate>
    </item>
    <item>
      <title>N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist</title>
      <link>https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html</link>
      <description>&lt;p&gt;N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. &amp;quot;We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,&amp;quot; the company said. &amp;quot;This is not a duplicate of our&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.62; also vulnerabilities 0.81, cyber_attacks 0.62)&lt;/p&gt;</description>
      <guid isPermaLink="false">62e6df9d879f730cdaa0ccc24d00864a</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Sat, 08 Aug 2026 06:57:43 +0000</pubDate>
    </item>
    <item>
      <title>The biggest threat to air-passenger safety may be our own government</title>
      <link>https://nymag.com/intelligencer/article/marine-ones-near-miss-incident-was-scarier-than-it-looks.html</link>
      <description>&lt;p&gt;Article URL: https://nymag.com/intelligencer/article/marine-ones-near-miss-incident-was-scarier-than-it-looks.html Comments URL: https://news.ycombinator.com/item?id=49219225 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (threat intel filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">1f1852eff09bef389295e103c4483a53</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 05:56:49 +0000</pubDate>
    </item>
    <item>
      <title>Show HN: Zero-token memory retrieval for Pi</title>
      <link>https://github.com/skorotkiewicz/zero-mem</link>
      <description>&lt;p&gt;Article URL: https://github.com/skorotkiewicz/zero-mem Comments URL: https://news.ycombinator.com/item?id=49218337 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">b16d7ad75e3601941a79a796bdb5c573</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 02:17:33 +0000</pubDate>
    </item>
    <item>
      <title>Hacked Amazon Echo Dot 2 and can run LLMs locally</title>
      <link>https://www.reddit.com/r/homeassistant/s/X13006g0tS</link>
      <description>&lt;p&gt;Article URL: https://www.reddit.com/r/homeassistant/s/X13006g0tS Comments URL: https://news.ycombinator.com/item?id=49217748 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also cyber_attacks 0.42)&lt;/p&gt;</description>
      <guid isPermaLink="false">7908f468bc9fccc83328435196257493</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 00:28:37 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6422-1 chromium - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00333.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6422-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">8435d9a79d5780c8ca54bd9ea9cd6616</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6421-1 pdns-recursor - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00332.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6421-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">9cb5a158cf951bf80a1bdbded1c676e5</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6420-1 pdns - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00331.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6420-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">ff23e8dd8015f953da87cc4e8a0088b0</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6419-1 dnsdist - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00330.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6419-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">21556e9fb4ce4132837d4966c50cf928</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>DSA-6417-1 libheif - security update</title>
      <link>https://lists.debian.org/debian-security-announce/2026/msg00328.html</link>
      <description>&lt;p&gt;https://security-tracker.debian.org/tracker/DSA-6417-1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Debian Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.94)&lt;/p&gt;</description>
      <guid isPermaLink="false">2ee316ff8739c52afe3c97847a3b41cb</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>A quick look at zero-knowledge proofs</title>
      <link>https://bernsteinbear.com/blog/zkp/</link>
      <description>&lt;p&gt;Article URL: https://bernsteinbear.com/blog/zkp/ Comments URL: https://news.ycombinator.com/item?id=49217367 Points: 4 # Comments: 1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">cbc6f05ee2faa7939ddfd73850809b8d</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 23:18:26 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-52880 (CVSS 7.5 HIGH): Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-52880</link>
      <description>&lt;p&gt;CVSS 7.5 HIGH. Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go&amp;#x27;s default HTTP server with no ReadHeaderTimeout, ReadTimeout, or MaxHeaderBytes configured. As a result, incoming connections that never complete their request headers are held open indefinitely. When a REST listener is reachable beyond localhost through the documented all-interface bind or a Docker port-publish deployment, a single unauthenticated client can open many slow-header connections and hold them open until server file descriptors are exhausted, preventing the API from accepting new connections. This renders the REST API unavailable to legitimate clients. This issue is fixed in version 1.7.18.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, HIGH&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">32d260ed270d6cac0e6a4608371770fc</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>HIGH</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 23:17:04 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-46409 (CVSS 9.6 CRITICAL): OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46409</link>
      <description>&lt;p&gt;CVSS 9.6 CRITICAL. OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:&amp;lt;random port&amp;gt;` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a wildcard CORS policy. Any webpage a user visits while OpenYak is running can issue cross-origin requests to this local server — the browser acts as a proxy into loopback, bypassing OS-level network isolation. Chained, this lets a malicious page execute arbitrary shell commands on the host (RCE) via the build agent with `permission_presets.bash=true`, shut down the service, and exfiltrate chat history and account PII — with no user interaction beyond opening the page. Version 1.1.3 patches the issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 1.00, cyber_attacks 0.53)&lt;/p&gt;</description>
      <guid isPermaLink="false">8492f72b18c1f8a796072007f9451d2e</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <category>bucket:cyber_attacks</category>
      <pubDate>Fri, 07 Aug 2026 23:17:03 +0000</pubDate>
    </item>
    <item>
      <title>Inside the Modern SOC: The Identity Front Door</title>
      <link>https://unit42.paloaltonetworks.com/soc-identity-front-door/</link>
      <description>&lt;p&gt;Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42 .&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Palo Alto Unit 42&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Inside the Modern SOC, Insights, AI, identity, social engineering, Unit 42 Incident Response Report&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.37; also cyber_attacks 0.93)&lt;/p&gt;</description>
      <guid isPermaLink="false">3226262867fdd25354ea97093d18f43e</guid>
      <category>Inside the Modern SOC</category>
      <category>Insights</category>
      <category>AI</category>
      <category>identity</category>
      <category>social engineering</category>
      <category>Unit 42 Incident Response Report</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 23:00:01 +0000</pubDate>
    </item>
    <item>
      <title>The Zero-Click Economy: Why 60% of Searches End Without a Click</title>
      <link>https://www.forbes.com/councils/forbesbusinesscouncil/2026/03/02/the-zero-click-economy-why-60-of-searches-end-without-a-click-and-what-ceos-should-do-about-it/</link>
      <description>&lt;p&gt;Article URL: https://www.forbes.com/councils/forbesbusinesscouncil/2026/03/02/the-zero-click-economy-why-60-of-searches-end-without-a-click-and-what-ceos-should-do-about-it/ Comments URL: https://news.ycombinator.com/item?id=49216830 Points: 4 # Comments: 1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36)&lt;/p&gt;</description>
      <guid isPermaLink="false">d58d83d71e68ad3f06f46297917cdd38</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 22:11:08 +0000</pubDate>
    </item>
    <item>
      <title>New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc.</title>
      <link>https://databreaches.net/2026/08/07/new-york-state-department-of-financial-services-secures-cybersecurity-settlement-with-order-express-inc/</link>
      <description>&lt;p&gt;A press release from the NYS DFS: August 5, 2026 New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulation (23 NYCRR Part 500). DFS investigators identified deficiencies in the company’s cybersecurity program... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Financial Sector, Legislation, U.S.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.43)&lt;/p&gt;</description>
      <guid isPermaLink="false">4bc37beee586a9dbe81fdb2997918fbf</guid>
      <category>Financial Sector</category>
      <category>Legislation</category>
      <category>U.S.</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 21:50:11 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-9031: An input validation
vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation
of user-supplied</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9031</link>
      <description>&lt;p&gt;An input validation
vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation
of user-supplied data before it is processed by internal flash-write handling
logic.









Successful
exploitation may cause httpd process or device to crash, resulting in loss of access
to the web interface and a denial-of-service condition.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.78; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">fed97ff9bb04e2e3e5732cce65555ec8</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 21:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-9030: A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool
instruction</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9030</link>
      <description>&lt;p&gt;A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool
instruction handlng path in httpd does not properly synchronize or safely manage
concurrent systool operations.  





By sending
crafted systool instructions through the asynchronous request path, successful
exploitation may cause the httpd process or device management service to crash
and may result in temporary loss of access to the web management interface or
device reboot.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.78; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">8831dde3245371ad57e895ddd035b936</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 21:17:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-69207 (CVSS 5.3 MEDIUM): Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69207</link>
      <description>&lt;p&gt;CVSS 5.3 MEDIUM. Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker-controlled Access-Control-Request-Headers header using a whitespace-tolerant regular expression whose backtracking makes its running time quadratic in the input length. Because the header value is bounded only by the deployment&amp;#x27;s maximum HTTP header size, a single preflight carrying a long run of whitespace can consume seconds of CPU and block request processing. On runtimes that share one execution thread across requests, this stalls concurrent requests as well, and repeated requests can render the service unresponsive. This affects the default configuration, since the vulnerable path is reached whenever cors() is used with an unset or empty allowHeaders. Applications that set a non-empty allowHeaders are not affected. This issue is fixed in version 4.12.34.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">a749252b229383dc73e4acd3e5a6ec15</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 21:17:29 +0000</pubDate>
    </item>
    <item>
      <title>CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX</title>
      <link>https://www.crowdstrike.com/en-us/blog/crowdstrike-hunts-for-shell-command-obfuscation-vmware-esx/</link>
      <description>&lt;p&gt;CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; CrowdStrike Blog&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Next-Gen SIEM &amp;amp; Log Management&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.62)&lt;/p&gt;</description>
      <guid isPermaLink="false">9f0f5338f9153c50b77fd37c21a356e6</guid>
      <category>Next-Gen SIEM &amp; Log Management</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:59:20 +0000</pubDate>
    </item>
    <item>
      <title>City of Coweta hit with system-wide ransomware attack, has backup</title>
      <link>https://databreaches.net/2026/08/07/city-of-coweta-hit-with-system-wide-ransomware-attack-has-backup/</link>
      <description>&lt;p&gt;KTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity professionals to secure their systems to prevent any further intrusion and to begin a recovery... Source&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; DataBreaches.net&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Government Sector, Malware&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.84; also cyber_attacks 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">51bbcb0529c8c7ed2eb475f6275ec001</guid>
      <category>Government Sector</category>
      <category>Malware</category>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:26:50 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-48039 (CVSS 9.1 CRITICAL): Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109,</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48039</link>
      <description>&lt;p&gt;CVSS 9.1 CRITICAL. Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authentication. When no per-request credential is present, tool handlers fall back to the `META_ACCESS_TOKEN` environment variable, and when the downstream Meta Graph API call fails, `api.py:263–269` serialises the raw `httpx` request URL—including the operator&amp;#x27;s `access_token` as a query parameter—into the JSON-RPC response body, delivering the credential to the unauthenticated caller. Version 1.0.109 fixes the issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, CRITICAL&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">8d7a4ebc726689606f4cbb24d6cc06ea</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>CRITICAL</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:16:51 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-48007: Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48007</link>
      <description>&lt;p&gt;Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey` URL parameters. Several fields of this data (`$initial_person_info`, `$session_entry_url`, and `$current_url`) were found to contain the full URL of the user&amp;#x27;s visited page, including the fragment. Users of a standalone Element Call ‘SPA’ instance such as https://call.element.io may therefore have reported the full URLs of certain calls, including encryption passwords, to the configured PostHog server, potentially compromising the confidentiality of the calls to actors who could access both the PostHog analytics data and the encrypted media streams. The same issue is present in Element Call&amp;#x27;s embedded package, but in practice it does not impact applications using this package (including Element Web, Element Desktop, Element X iOS, and Element X Android) because they distribute encryption keys over Matrix rather than encoding a password in the URL. The issue is patched in Element Call 0.19.4. Some workarounds are available. Users may opt out of anal&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.70; also vulnerabilities 0.98)&lt;/p&gt;</description>
      <guid isPermaLink="false">890a4f92b1b248b157d5bf84c64df69f</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:16:51 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-19113 (CVSS 5.3 MEDIUM): Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-19113</link>
      <description>&lt;p&gt;CVSS 5.3 MEDIUM. Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability, CVE-2026-19113, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">71f3ce57dc12d3b74f312777f63c16e6</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:16:50 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-15970 (CVSS 4.2 MEDIUM): Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-15970</link>
      <description>&lt;p&gt;CVSS 4.2 MEDIUM. Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; NIST NVD Recent CVEs&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; CVE, Vulnerability, MEDIUM&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.53; also vulnerabilities 0.99)&lt;/p&gt;</description>
      <guid isPermaLink="false">433f3865ce5677ff48d6d75be6079b60</guid>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>MEDIUM</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:16:49 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:51861 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:51861.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:51861. Severity: moderate. Addresses CVE-2026-19079.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, moderate, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">ccd17d38f350a3d98ff246fff4d7a15b</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>moderate</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:16:32 +0000</pubDate>
    </item>
    <item>
      <title>Computer maker Framework notifies 'all customers' of a data breach</title>
      <link>https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/</link>
      <description>&lt;p&gt;Article URL: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/ Comments URL: https://news.ycombinator.com/item?id=49215565 Points: 2 # Comments: 1&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (attack filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also cyber_attacks 0.76)&lt;/p&gt;</description>
      <guid isPermaLink="false">29ab2e09c7b21ad546937298c9160d6a</guid>
      <category>bucket:cyber_attacks</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 20:04:04 +0000</pubDate>
    </item>
    <item>
      <title>WordPress CVE-2026-64638 Pre-Auth XSS to RCE</title>
      <link>https://pwn.ai/blog/xss2shell</link>
      <description>&lt;p&gt;Article URL: https://pwn.ai/blog/xss2shell Comments URL: https://news.ycombinator.com/item?id=49215218 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also vulnerabilities 0.85)&lt;/p&gt;</description>
      <guid isPermaLink="false">a834c1e53f3e7b6b0719ceda6096d3aa</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 19:30:43 +0000</pubDate>
    </item>
    <item>
      <title>SLOs from Mesh Metrics: A 30-Day Implementation Playbook</title>
      <link>https://www.buoyant.io/blog/slos-from-mesh-metrics-a-30-day-implementation-playbook</link>
      <description>&lt;p&gt;Article URL: https://www.buoyant.io/blog/slos-from-mesh-metrics-a-30-day-implementation-playbook Comments URL: https://news.ycombinator.com/item?id=49215181 Points: 1 # Comments: 0&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Hacker News (vulnerability filter)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.36; also vulnerabilities 0.63)&lt;/p&gt;</description>
      <guid isPermaLink="false">150610774cdcb24933457c22489403a8</guid>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 19:27:44 +0000</pubDate>
    </item>
    <item>
      <title>RHSA-2026:51746 security update</title>
      <link>https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:51746.json</link>
      <description>&lt;p&gt;Red Hat security advisory RHSA-2026:51746. Severity: important. Addresses CVE-2025-10263, CVE-2026-46054, CVE-2026-64531.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; Red Hat Security Advisories&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; Security Advisory, Vulnerability, Red Hat, important, CVE&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.68; also vulnerabilities 1.00)&lt;/p&gt;</description>
      <guid isPermaLink="false">54234ef4787ba3b1084fe964765ee1fa</guid>
      <category>Security Advisory</category>
      <category>Vulnerability</category>
      <category>Red Hat</category>
      <category>important</category>
      <category>CVE</category>
      <category>bucket:vulnerabilities</category>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 18:53:06 +0000</pubDate>
    </item>
    <item>
      <title>Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer</title>
      <link>https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html</link>
      <description>&lt;p&gt;A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. &amp;quot;These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,&amp;quot; OpenSourceMalware researcher Paul&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; The Hacker News&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; threat_intel (confidence 0.88)&lt;/p&gt;</description>
      <guid isPermaLink="false">7f2f0040ed3dddf4bac57591c644c822</guid>
      <category>bucket:threat_intel</category>
      <pubDate>Fri, 07 Aug 2026 18:48:17 +0000</pubDate>
    </item>
  </channel>
</rss>
