🚨 CISA KEV 2[−]
8 Aug KEVProgress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tra…THEHACKERNEWS.COM
8 Aug KEVU.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-80…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 9[−]
8 AugCVE-2026-63030 and CVE-2026-60137: 'wp2shell' Captured Exploit PayloadSensor Intel Series: August 2026 CVE TrendsF5.COM
8 AugCVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer AnnotationsInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injectionInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsiInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-44943 remote limited file-write as root via discovery in open-iscsiInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsiInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index PredicatesInformation published.MSRC.MICROSOFT.COM
8 AugCVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)Information published.MSRC.MICROSOFT.COM
8 AugCVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)Information published.MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 10[−]
8 AugNearly 800 Malicious npm Packages Deliver Cross-Platform RAT and InfostealerA cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting p…THEHACKERNEWS.COM
8 AugCoding for Veterans: Cybersecurity Today on the Weekend with David ShipleyCoding for Veterans: From Military Service to Cybersecurity & Generative AI Careers This episode is sponsored by Nordlayer. Contact them at Nordlayer.com/hashtagtrending and use discount code NLSummer26 for a discount during their summer sale. In this Weekend episode of Cybersecu…CYBERSECURITYTODAY.LIBSYN.COM
8 Aug KEVMetabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticat…THEHACKERNEWS.COM
8 AugN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistN-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitor…THEHACKERNEWS.COM
8 AugUnlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare PatientsHackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers be…SECURITYAFFAIRS.COM
8 AugCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataThe RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek .SECURITYWEEK.COM
8 AugCity of Coweta refuses to pay ransom after system-wide cyberattackAn update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who …DATABREACHES.NET
8 Aug KEVMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataAttackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against …SECURITYAFFAIRS.COM
8 AugHackers breach TrueConf to trojanize client installers with backdoorsThe Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]BLEEPINGCOMPUTER.COM
8 AugCity of Suisun declares local emergency after cyberattack downs 911 dispatch systemKatie Chavez reports: Suisun City officials declared a state of emergency Saturday, Aug. 8, after a cyberattack took out the city’s emergency dispatch line and other key systems. City officials said that “malicious software infected and compromised IT systems” at about 5:45 a.m. …DATABREACHES.NET
📢 SECURITY ADVISORIES 2[−]
8 AugResearchers report unauthorized AI behavior.Vishing attacks target hedge funds. CISA warns of cyberattacks targeting PLCs in the water sector.THECYBERWIRE.COM
8 AugPalo Alto Networks Faces China Cybersecurity Review Amid Rising Tech TensionsChina opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks…SECURITYAFFAIRS.COM
🔥 INCIDENT REPORTING 3[−]
8 AugA little help from your search engine.Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code in…THECYBERWIRE.COM
8 AugFlock’s Plans for Rideshare Dashcams and Coaching Police, RevealedPlus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years.WIRED.COM
8 AugBrinks Home - 732,162 breached accountsIn July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks …HAVEIBEENPWNED.COM
🕵️ THREAT INTELLIGENCE 2[−]
8 AugNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensNew research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts…THEHACKERNEWS.COM
8 AugThe End of SMS LoginsMicrosoft has announced that native SMS and voice authentication delivery for Entra will be retired beginning February 1, 2027. Organizations that continue using those methods will need to integrate a third-party provider. The change aligns with Microsoft's broader push toward ph…YOUTUBE.COM
📡 INFOSEC NEWS 3[−]
8 AugAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersAttacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirm…THEHACKERNEWS.COM
8 AugSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllTwo security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets.WIRED.COM
8 AugGoogle’s top hacker hunter explains why hacking groups get codenamesGoogle recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.TECHCRUNCH.COM