📰 DAILY THREAT BRIEFING
Monday, August 3, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 3, 2026.

  1. OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
    — Bleeping Computer

    OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten signif…
  2. COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
    — Bleeping Computer

    A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wall…
  3. Google Chrome may soon block New Tab hijacker extensions by default
    — Bleeping Computer

    Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing t…
  4. Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
    — SANS ISC

    Introduction
  5. Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
    — The Hacker News

    An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Rese…
  6. Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
    — The Hacker News

    Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryp…
  7. Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
    — SANS ISC

    Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, … Many brands have …
  8. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
    — The Hacker News

    Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing …
  9. CISA Issues Fresh SBOM Guidance. Did They Get It Right?
    — Dark Reading

    A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improv…
  10. The Morning After We Pull a Root of Trust, Nobody Owns It
    — Dark Reading

    The most valuable move any security team can make is building a certificate and key inventory.
  11. Interpol Leverages Global System to Curtail Fraud Payments
    — Dark Reading

    When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
  12. The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
    — Unit 42

    Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its l…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9294 in last 30 days).
Critical: 2 · High: 9 · Medium: 8 · Low: 1. View full dashboard →

  1. CVE-2026-10848
    — CVSS 7.0 (HIGH)

    The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fie…
  2. CVE-2026-9856
    — CVSS 7.1 (HIGH)

    A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` …
  3. CVE-2026-65321
    — CVSS 9.8 (CRITICAL)

    PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELE…
  4. CVE-2026-10774
    — CVSS 2.4 (LOW)

    Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONF…
  5. CVE-2026-68583
    — CVSS 5.4 (MEDIUM)

    luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast…
  6. CVE-2026-68582
    — CVSS 6.5 (MEDIUM)

    Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the request…
  7. CVE-2026-68581
    — CVSS 8.1 (HIGH)

    Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID()…
  8. CVE-2026-68580
    — CVSS 7.5 (HIGH)

    FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RD…
  9. CVE-2026-68579
    — CVSS 9.6 (CRITICAL)

    FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IS…
  10. CVE-2026-68578
    — CVSS 7.5 (HIGH)

    ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary databa…
  11. CVE-2026-67357
    — CVSS 7.5 (HIGH)

    ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster…
  12. CVE-2026-67356
    — CVSS 8.8 (HIGH)

    ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_…
  13. CVE-2025-71401
    — CVSS 5.9 (MEDIUM)

    better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startu…
  14. CVE-2025-71400
    — CVSS 7.1 (HIGH)

    better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with vali…
  15. CVE-2025-71399
    — CVSS 8.6 (HIGH)

    Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Aut…
  16. CVE-2026-12231
    — CVSS 6.4 (MEDIUM)

    The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input san…
  17. CVE-2026-18573
    — CVSS 6.5 (MEDIUM)

    A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specif…
  18. CVE-2026-18572
    — CVSS 6.5 (MEDIUM)

    Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can …
  19. CVE-2026-18571
    — CVSS 6.6 (MEDIUM)

    A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any gro…
  20. CVE-2026-18570
    — CVSS 5.4 (MEDIUM)

    A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 3, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com