📰 DAILY THREAT BRIEFING
Saturday, August 1, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 1, 2026.

  1. Amgen says cloud data breach exposed patient health, proprietary info
    — Bleeping Computer

    Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multi…
  2. Arch Linux disables AUR package adoption to stop malware flood
    — Bleeping Computer

    The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of exis…
  3. Online ad firm Adform’s script compromised to steal cryptocurrency
    — Bleeping Computer

    Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platfo…
  4. Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
    — The Hacker News

    A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in…
  5. CISA Issues Fresh SBOM Guidance. Did They Get It Right?
    — Dark Reading

    A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improv…
  6. HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
    — The Hacker News

    Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware…
  7. Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
    — The Hacker News

    Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or V…
  8. The Morning After We Pull a Root of Trust, Nobody Owns It
    — Dark Reading

    The most valuable move any security team can make is building a certificate and key inventory.
  9. Interpol Leverages Global System to Curtail Fraud Payments
    — Dark Reading

    When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
  10. The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
    — Unit 42

    Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its l…
  11. zipdump.py: Metadata Encoding, (Fri, Jul 31st)
    — SANS ISC

    I was asked for help with a problem similar to the following.
  12. ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9542 in last 30 days).
Critical: 2 · High: 7 · Medium: 7 · Low: 4. View full dashboard →

  1. CVE-2026-54909
    — CVSS 5.3 (MEDIUM)

    pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote d…
  2. CVE-2026-54787
    — CVSS 3.1 (LOW)

    sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived si…
  3. CVE-2026-54785
    — CVSS 6.2 (MEDIUM)

    gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument …
  4. CVE-2026-45377
    — CVSS 6.5 (MEDIUM)

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export own…
  5. CVE-2026-45376
    — CVSS 5.5 (MEDIUM)

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER…
  6. CVE-2026-45330
    — CVSS 4.9 (MEDIUM)

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by …
  7. CVE-2026-34641
    — CVSS 7.8 (HIGH)

    Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mus…
  8. CVE-2026-68771
    — CVSS 9.8 (CRITICAL)

    ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and trigge…
  9. CVE-2026-45086
    — CVSS 5.4 (MEDIUM)

    Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics quest…
  10. CVE-2026-68770
    — CVSS 9.8 (CRITICAL)

    sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/u…
  11. CVE-2026-65981
    — CVSS 7.1 (HIGH)

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using –mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identi…
  12. CVE-2026-62999
    — CVSS 7.5 (HIGH)

    Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository…
  13. CVE-2026-62324
    — CVSS 5.4 (MEDIUM)

    Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the sche…
  14. CVE-2026-55825
    — CVSS 3.1 (LOW)

    Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoi…
  15. CVE-2026-53599
    — CVSS 7.5 (HIGH)

    REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permissi…
  16. CVE-2026-53510
    — CVSS 8.1 (HIGH)

    Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the applica…
  17. CVE-2026-18394
    — CVSS 7.4 (HIGH)

    Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests t…
  18. CVE-2026-57232
    — CVSS 3.1 (LOW)

    Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() witho…
  19. CVE-2026-55824
    — CVSS 2.6 (LOW)

    Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from …
  20. CVE-2026-53505
    — CVSS 7.5 (HIGH)

    Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker ca…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 1, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com