📰 DAILY THREAT BRIEFING
Sunday, August 2, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 2, 2026.

  1. Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
    — The Hacker News

    An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Rese…
  2. Rails patches critical Active Storage flaw with RCE potential
    — Bleeping Computer

    A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails applicat…
  3. Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
    — The Hacker News

    Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryp…
  4. Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
    — SANS ISC

    Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, … Many brands have …
  5. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
    — The Hacker News

    Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing …
  6. Amgen says cloud data breach exposed patient health, proprietary info
    — Bleeping Computer

    Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multi…
  7. Arch Linux disables AUR package adoption to stop malware flood
    — Bleeping Computer

    The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of exis…
  8. CISA Issues Fresh SBOM Guidance. Did They Get It Right?
    — Dark Reading

    A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improv…
  9. The Morning After We Pull a Root of Trust, Nobody Owns It
    — Dark Reading

    The most valuable move any security team can make is building a certificate and key inventory.
  10. Interpol Leverages Global System to Curtail Fraud Payments
    — Dark Reading

    When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
  11. The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
    — Unit 42

    Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its l…
  12. zipdump.py: Metadata Encoding, (Fri, Jul 31st)
    — SANS ISC

    I was asked for help with a problem similar to the following.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9426 in last 30 days).
Critical: 4 · High: 6 · Medium: 9 · Low: 1. View full dashboard →

  1. CVE-2026-8457
    — CVSS 9.8 (CRITICAL)

    The WooCommerce – Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decod…
  2. CVE-2026-18352
    — CVSS 7.5 (HIGH)

    The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attacker…
  3. CVE-2026-13339
    — CVSS 7.5 (HIGH)

    The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers …
  4. CVE-2026-67355
    — CVSS 5.9 (MEDIUM)

    guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-o…
  5. CVE-2026-67354
    — CVSS 5.9 (MEDIUM)

    guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the po…
  6. CVE-2026-67353
    — CVSS 5.3 (MEDIUM)

    guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from …
  7. CVE-2026-67352
    — CVSS 7.6 (HIGH)

    luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status pa…
  8. CVE-2026-67344
    — CVSS 4.3 (MEDIUM)

    ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE … CUSTOM and ALTER TYPE … BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStra…
  9. CVE-2026-67343
    — CVSS 8.8 (HIGH)

    ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use th…
  10. CVE-2026-67342
    — CVSS 9.8 (CRITICAL)

    ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can ac…
  11. CVE-2026-67341
    — CVSS 9.8 (CRITICAL)

    ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEF…
  12. CVE-2026-67340
    — CVSS 9.8 (CRITICAL)

    ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UP…
  13. CVE-2026-67339
    — CVSS 5.3 (MEDIUM)

    guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests …
  14. CVE-2026-67338
    — CVSS 6.1 (MEDIUM)

    JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with java…
  15. CVE-2026-67337
    — CVSS 6.5 (MEDIUM)

    better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing …
  16. CVE-2026-67336
    — CVSS 8.7 (HIGH)

    better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiati…
  17. CVE-2026-67335
    — CVSS 5.3 (MEDIUM)

    better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-co…
  18. CVE-2026-67334
    — CVSS 3.8 (LOW)

    better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse d…
  19. CVE-2026-67333
    — CVSS 7.2 (HIGH)

    better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the sam…
  20. CVE-2026-67332
    — CVSS 6.4 (MEDIUM)

    @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain …

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 2, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com