HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 10, 2026.
-
ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Hackers breach TrueConf to trojanize client installers with backdoors
— Bleeping Computer
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client insta… -
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
— The Hacker News
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then … -
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
— The Hacker News
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains sp… -
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
— The Hacker News
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has be… -
Inside the Modern SOC: The Identity Front Door
— Unit 42
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The pos… -
Metabase SQLi zero-day exploited in customer data-theft attacks
— Bleeping Computer
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known … -
Unlimited Technology Systems breach impacts 3.8 million people
— Bleeping Computer
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident … -
AI-Generated Patches Fail Half the Time
— Dark Reading
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. -
Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
— SANS ISC
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they … -
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
ChainDrop: Inside a Self-Propagating npm Worm
— Unit 42
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. …
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9665 in last 30 days).
Critical: 0 · High: 7 · Medium: 9 · Low: 4. View full dashboard →
-
CVE-2026-19389
— CVSS 7.1 (HIGH)
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of atta⦠-
CVE-2026-19387
— CVSS 7.6 (HIGH)
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allo⦠-
CVE-2026-19384
— CVSS 7.3 (HIGH)
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID⦠-
CVE-2026-19383
— CVSS 4.7 (MEDIUM)
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulat⦠-
CVE-2026-19382
— CVSS 2.3 (LOW)
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attac⦠-
CVE-2026-19381
— CVSS 7.8 (HIGH)
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation resu⦠-
CVE-2026-19380
— CVSS 2.3 (LOW)
A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local acces⦠-
CVE-2026-19379
— CVSS 7.3 (HIGH)
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The ⦠-
CVE-2026-19378
— CVSS 4.3 (MEDIUM)
A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/my⦠-
CVE-2026-19376
— CVSS 7.3 (HIGH)
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues⦠-
CVE-2026-19375
— CVSS 6.3 (MEDIUM)
A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-s⦠-
CVE-2026-19374
— CVSS 7.3 (HIGH)
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. T⦠-
CVE-2026-19373
— CVSS 5.3 (MEDIUM)
A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the ⦠-
CVE-2026-19372
— CVSS 5.3 (MEDIUM)
A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performin⦠-
CVE-2026-19371
— CVSS 5.3 (MEDIUM)
A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_pa⦠-
CVE-2026-12372
— CVSS 3.7 (LOW)
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal net⦠-
CVE-2026-19370
— CVSS 5.3 (MEDIUM)
A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the arg⦠-
CVE-2026-19369
— CVSS 5.3 (MEDIUM)
A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl result⦠-
CVE-2026-19368
— CVSS 3.3 (LOW)
A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_⦠-
CVE-2026-19367
— CVSS 6.3 (MEDIUM)
A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of theâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 10, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment