HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 8, 2026.
-
Inside the Modern SOC: The Identity Front Door
— Unit 42
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The pos… -
Metabase SQLi zero-day exploited in customer data-theft attacks
— Bleeping Computer
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known … -
Unlimited Technology Systems breach impacts 3.8 million people
— Bleeping Computer
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident … -
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
— The Hacker News
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platfo… -
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
— The Hacker News
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored pas… -
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
— The Hacker News
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion gro… -
AI-Generated Patches Fail Half the Time
— Dark Reading
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. -
Levi Strauss & Co. says hackers stole corporate data in cyberattack
— Bleeping Computer
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data s… -
Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
— SANS ISC
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they … -
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
ChainDrop: Inside a Self-Propagating npm Worm
— Unit 42
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. … -
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
— Dark Reading
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still op…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (10149 in last 30 days).
Critical: 2 · High: 9 · Medium: 8 · Low: 1. View full dashboard →
-
CVE-2026-52880
— CVSS 7.5 (HIGH)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run con⦠-
CVE-2026-52879
— CVSS 7.5 (HIGH)
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-le⦠-
CVE-2026-52878
— CVSS 7.5 (HIGH)
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted⦠-
CVE-2026-49343
— CVSS 5.9 (MEDIUM)
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded throttler slots on error pa⦠-
CVE-2026-48120
— CVSS 8.6 (HIGH)
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed b⦠-
CVE-2026-48026
— CVSS 8.7 (HIGH)
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files fro⦠-
CVE-2026-47249
— CVSS 7.5 (HIGH)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestData⦠-
CVE-2026-47127
— CVSS 6.5 (MEDIUM)
Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id>` retrieves the Stripe ⦠-
CVE-2026-46409
— CVSS 9.6 (CRITICAL)
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 1⦠-
CVE-2026-64676
— CVSS 5.7 (MEDIUM)
Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-gue⦠-
CVE-2026-48170
— CVSS 9.1 (CRITICAL)
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patc⦠-
CVE-2026-48169
— CVSS 8.8 (HIGH)
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs g⦠-
CVE-2026-46405
— CVSS 5.3 (MEDIUM)
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response i⦠-
CVE-2026-11743
— CVSS 6.6 (MEDIUM)
The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths with the test (offset + size) > data->size. Because offset is a signed of⦠-
CVE-2026-11742
— CVSS 3.6 (LOW)
The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued via k_queue_alloc_append/alloc_prepend, the data po⦠-
CVE-2026-71381
— CVSS 4.0 (MEDIUM)
Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged this vulnerability to bypass security mea⦠-
CVE-2026-69207
— CVSS 5.3 (MEDIUM)
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a p⦠-
CVE-2026-66061
— CVSS 7.1 (HIGH)
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as ⦠-
CVE-2026-66060
— CVSS 7.1 (HIGH)
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they ⦠-
CVE-2026-59717
— CVSS 4.3 (MEDIUM)
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassiâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 8, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment