HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 4, 2026.
-
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
— Bleeping Computer
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT… -
New Pass-ta-key attacks let malware hijack Google-synced passkeys
— Bleeping Computer
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manage… -
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
— Dark Reading
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. -
New Tool Traces AI Videos Back to Their Source
— Dark Reading
Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures. -
Anthropic: Claude Attacks Result of Security Gaps, Not Model Issues
— Dark Reading
Last month's incidents in which the AI model breached real-world systems derived from over-permissioning, especially with Internet access. -
New DOUBLECUP ClickFix service hides malware in browser cache images
— Bleeping Computer
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ul… -
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
— The Hacker News
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-plat… -
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
— The Hacker News
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, o… -
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
— The Hacker News
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure… -
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
— Unit 42
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a s… -
ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
— SANS ISC
Introduction
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9536 in last 30 days).
Critical: 3 · High: 8 · Medium: 9 · Low: 0. View full dashboard →
-
CVE-2026-66326
— CVSS 6.5 (MEDIUM)
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. -
CVE-2026-66325
— CVSS 6.1 (MEDIUM)
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. -
CVE-2026-66322
— CVSS 7.1 (HIGH)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. -
CVE-2026-66321
— CVSS 7.4 (HIGH)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. -
CVE-2026-66318
— CVSS 8.1 (HIGH)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. -
CVE-2026-66317
— CVSS 5.4 (MEDIUM)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. -
CVE-2026-66316
— CVSS 5.4 (MEDIUM)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. -
CVE-2026-66315
— CVSS 7.5 (HIGH)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. -
CVE-2026-66314
— CVSS 6.5 (MEDIUM)
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. -
CVE-2026-66313
— CVSS 6.8 (MEDIUM)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. -
CVE-2026-66312
— CVSS 6.5 (MEDIUM)
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. -
CVE-2026-66311
— CVSS 6.2 (MEDIUM)
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. -
CVE-2026-66310
— CVSS 7.7 (HIGH)
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. -
CVE-2026-65804
— CVSS 6.1 (MEDIUM)
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. -
CVE-2026-65802
— CVSS 7.4 (HIGH)
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. -
CVE-2026-62870
— CVSS 8.8 (HIGH)
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. -
CVE-2026-18686
— CVSS 9.8 (CRITICAL)
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in com⦠-
CVE-2026-18685
— CVSS 9.8 (CRITICAL)
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is po⦠-
CVE-2026-48399
— CVSS 7.5 (HIGH)
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures ⦠-
CVE-2026-48333
— CVSS 9.8 (CRITICAL)
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of thâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 4, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment