HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 5, 2026.
-
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
— Bleeping Computer
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incide… -
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
— Bleeping Computer
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained wit… -
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
— Bleeping Computer
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-cod… -
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
— Dark Reading
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised … -
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
— The Hacker News
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device c… -
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
— The Hacker News
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages a… -
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
— The Hacker News
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe… -
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
— Unit 42
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source sof… -
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
— Dark Reading
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join … -
Almost Half of Malware Samples Communicate Direct to IP
— Unit 42
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these thre… -
Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
— SANS ISC
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven't noticed before. All of thes… -
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
— Dark Reading
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9719 in last 30 days).
Critical: 1 · High: 6 · Medium: 12 · Low: 1. View full dashboard →
-
CVE-2026-45705
— CVSS 5.3 (MEDIUM)
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp(⦠-
CVE-2026-18854
— CVSS 7.3 (HIGH)
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulat⦠-
CVE-2026-18853
— CVSS 5.3 (MEDIUM)
A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path travers⦠-
CVE-2026-18852
— CVSS 3.3 (LOW)
A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component F⦠-
CVE-2026-18103
— CVSS 4.9 (MEDIUM)
A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication⦠-
CVE-2026-45537
— CVSS 9.1 (CRITICAL)
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params⦠-
CVE-2026-18819
— CVSS 4.3 (MEDIUM)
A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is⦠-
CVE-2026-18818
— CVSS 6.3 (MEDIUM)
A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation c⦠-
CVE-2026-70620
— CVSS 6.8 (MEDIUM)
Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embed⦠-
CVE-2026-70619
— CVSS 8.8 (HIGH)
Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that ve⦠-
CVE-2026-70594
— CVSS 6.7 (MEDIUM)
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have r⦠-
CVE-2026-70593
— CVSS 6.6 (MEDIUM)
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of t⦠-
CVE-2026-70592
— CVSS 5.5 (MEDIUM)
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and ⦠-
CVE-2026-70591
— CVSS 4.1 (MEDIUM)
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts.⦠-
CVE-2026-70590
— CVSS 4.8 (MEDIUM)
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the ⦠-
CVE-2026-70589
— CVSS 4.8 (MEDIUM)
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1. -
CVE-2026-67861
— CVSS 7.5 (HIGH)
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component -
CVE-2026-67859
— CVSS 7.5 (HIGH)
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling. -
CVE-2026-67858
— CVSS 7.5 (HIGH)
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterSer⦠-
CVE-2026-67857
— CVSS 7.5 (HIGH)
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 5, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment