HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 7, 2026.
-
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
— Bleeping Computer
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text ch… -
ClickFix attack pushes macOS infostealer for crypto theft attacks
— Bleeping Computer
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Ke… -
ChainDrop: Inside a Self-Propagating npm Worm
— Unit 42
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. … -
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
— Dark Reading
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still op… -
Researcher Claims Control of ChatGPT Secure Sandbox
— Dark Reading
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session … -
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
— Bleeping Computer
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an… -
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
— Dark Reading
Former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support … -
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
— The Hacker News
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape… -
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
— The Hacker News
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of … -
Canadian Man Pleads Guilty in Snowflake Extortions
— Krebs on Security
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer f… -
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
— The Hacker News
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the k… -
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
— Unit 42
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cyberc…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (10285 in last 30 days).
Critical: 0 · High: 9 · Medium: 11 · Low: 0. View full dashboard →
-
CVE-2026-8325
— CVSS 7.8 (HIGH)
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute ar⦠-
CVE-2026-7867
— CVSS 7.8 (HIGH)
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This al⦠-
CVE-2026-7406
— CVSS 7.8 (HIGH)
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c⦠-
CVE-2026-7405
— CVSS 5.5 (MEDIUM)
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause⦠-
CVE-2026-71555
— CVSS 4.1 (MEDIUM)
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that o⦠-
CVE-2026-71554
— CVSS 5.3 (MEDIUM)
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming applicat⦠-
CVE-2026-71498
— CVSS 5.1 (MEDIUM)
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read pa⦠-
CVE-2026-71497
— CVSS 4.7 (MEDIUM)
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing ⦠-
CVE-2026-71488
— CVSS 7.5 (HIGH)
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because s⦠-
CVE-2026-71478
— CVSS 6.1 (MEDIUM)
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a ta⦠-
CVE-2026-71435
— CVSS 6.1 (MEDIUM)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenti⦠-
CVE-2026-71434
— CVSS 5.3 (MEDIUM)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated⦠-
CVE-2026-71433
— CVSS 5.3 (MEDIUM)
LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages ⦠-
CVE-2026-71430
— CVSS 6.2 (MEDIUM)
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empt⦠-
CVE-2026-70640
— CVSS 7.0 (HIGH)
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on f⦠-
CVE-2026-70639
— CVSS 5.5 (MEDIUM)
llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it⦠-
CVE-2026-70638
— CVSS 7.8 (HIGH)
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max paramete⦠-
CVE-2026-70636
— CVSS 7.5 (HIGH)
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentica⦠-
CVE-2026-70635
— CVSS 7.1 (HIGH)
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Sim⦠-
CVE-2026-70634
— CVSS 8.1 (HIGH)
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decodedâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 7, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment