📰 DAILY THREAT BRIEFING
Sunday, August 9, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 9, 2026.

  1. Hackers breach TrueConf to trojanize client installers with backdoors
    — Bleeping Computer

    The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client insta…
  2. Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
    — The Hacker News

    Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then …
  3. New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
    — The Hacker News

    New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains sp…
  4. Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
    — The Hacker News

    Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has be…
  5. Inside the Modern SOC: The Identity Front Door
    — Unit 42

    Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The pos…
  6. Metabase SQLi zero-day exploited in customer data-theft attacks
    — Bleeping Computer

    A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known …
  7. Unlimited Technology Systems breach impacts 3.8 million people
    — Bleeping Computer

    Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident …
  8. AI-Generated Patches Fail Half the Time
    — Dark Reading

    A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
  9. Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
    — SANS ISC

    UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they …
  10. ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  11. ChainDrop: Inside a Self-Propagating npm Worm
    — Unit 42

    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. …
  12. The Coordination Gap: How Attackers Are Outpacing Law Enforcement
    — Dark Reading

    The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still op…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9934 in last 30 days).
Critical: 19 · High: 0 · Medium: 1 · Low: 0. View full dashboard →

  1. CVE-2026-71993
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploi…
  2. CVE-2026-71992
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl…
  3. CVE-2026-71991
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affec…
  4. CVE-2026-71990
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected…
  5. CVE-2026-71989
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exp…
  6. CVE-2026-71988
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit…
  7. CVE-2026-71987
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit th…
  8. CVE-2026-71986
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit th…
  9. CVE-2026-71985
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can …
  10. CVE-2026-71984
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl…
  11. CVE-2026-19323
    — CVSS 5.3 (MEDIUM)

    A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component …
  12. CVE-2026-71983
    — CVSS 9.8 (CRITICAL)

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pi…
  13. CVE-2026-71958
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the …
  14. CVE-2026-71957
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAc…
  15. CVE-2026-71956
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands in…
  16. CVE-2026-71955
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious com…
  17. CVE-2026-71954
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject ar…
  18. CVE-2026-71953
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malici…
  19. CVE-2026-71952
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbit…
  20. CVE-2026-71951
    — CVSS 9.8 (CRITICAL)

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary …

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 9, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com