HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 9, 2026.
-
Hackers breach TrueConf to trojanize client installers with backdoors
— Bleeping Computer
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client insta… -
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
— The Hacker News
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then … -
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
— The Hacker News
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains sp… -
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
— The Hacker News
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has be… -
Inside the Modern SOC: The Identity Front Door
— Unit 42
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The pos… -
Metabase SQLi zero-day exploited in customer data-theft attacks
— Bleeping Computer
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known … -
Unlimited Technology Systems breach impacts 3.8 million people
— Bleeping Computer
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident … -
AI-Generated Patches Fail Half the Time
— Dark Reading
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. -
Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
— SANS ISC
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they … -
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
ChainDrop: Inside a Self-Propagating npm Worm
— Unit 42
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. … -
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
— Dark Reading
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still op…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9934 in last 30 days).
Critical: 19 · High: 0 · Medium: 1 · Low: 0. View full dashboard →
-
CVE-2026-71993
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploi⦠-
CVE-2026-71992
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl⦠-
CVE-2026-71991
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affec⦠-
CVE-2026-71990
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected⦠-
CVE-2026-71989
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exp⦠-
CVE-2026-71988
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit⦠-
CVE-2026-71987
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit th⦠-
CVE-2026-71986
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit th⦠-
CVE-2026-71985
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can ⦠-
CVE-2026-71984
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl⦠-
CVE-2026-19323
— CVSS 5.3 (MEDIUM)
A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component ⦠-
CVE-2026-71983
— CVSS 9.8 (CRITICAL)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pi⦠-
CVE-2026-71958
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the ⦠-
CVE-2026-71957
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAc⦠-
CVE-2026-71956
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands in⦠-
CVE-2026-71955
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious com⦠-
CVE-2026-71954
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject ar⦠-
CVE-2026-71953
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malici⦠-
CVE-2026-71952
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbit⦠-
CVE-2026-71951
— CVSS 9.8 (CRITICAL)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary â¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 9, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment