📰 DAILY THREAT BRIEFING
Monday, August 10, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 10, 2026.

  1. ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  2. Hackers breach TrueConf to trojanize client installers with backdoors
    — Bleeping Computer

    The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client insta…
  3. Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
    — The Hacker News

    Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then …
  4. New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
    — The Hacker News

    New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains sp…
  5. Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
    — The Hacker News

    Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has be…
  6. Inside the Modern SOC: The Identity Front Door
    — Unit 42

    Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The pos…
  7. Metabase SQLi zero-day exploited in customer data-theft attacks
    — Bleeping Computer

    A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known …
  8. Unlimited Technology Systems breach impacts 3.8 million people
    — Bleeping Computer

    Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident …
  9. AI-Generated Patches Fail Half the Time
    — Dark Reading

    A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
  10. Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
    — SANS ISC

    UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they …
  11. ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. ChainDrop: Inside a Self-Propagating npm Worm
    — Unit 42

    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. …

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9665 in last 30 days).
Critical: 0 · High: 7 · Medium: 9 · Low: 4. View full dashboard →

  1. CVE-2026-19389
    — CVSS 7.1 (HIGH)

    Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of atta…
  2. CVE-2026-19387
    — CVSS 7.6 (HIGH)

    A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allo…
  3. CVE-2026-19384
    — CVSS 7.3 (HIGH)

    A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID…
  4. CVE-2026-19383
    — CVSS 4.7 (MEDIUM)

    A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulat…
  5. CVE-2026-19382
    — CVSS 2.3 (LOW)

    A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attac…
  6. CVE-2026-19381
    — CVSS 7.8 (HIGH)

    A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation resu…
  7. CVE-2026-19380
    — CVSS 2.3 (LOW)

    A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local acces…
  8. CVE-2026-19379
    — CVSS 7.3 (HIGH)

    A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The …
  9. CVE-2026-19378
    — CVSS 4.3 (MEDIUM)

    A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/my…
  10. CVE-2026-19376
    — CVSS 7.3 (HIGH)

    A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues…
  11. CVE-2026-19375
    — CVSS 6.3 (MEDIUM)

    A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-s…
  12. CVE-2026-19374
    — CVSS 7.3 (HIGH)

    A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. T…
  13. CVE-2026-19373
    — CVSS 5.3 (MEDIUM)

    A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the …
  14. CVE-2026-19372
    — CVSS 5.3 (MEDIUM)

    A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performin…
  15. CVE-2026-19371
    — CVSS 5.3 (MEDIUM)

    A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_pa…
  16. CVE-2026-12372
    — CVSS 3.7 (LOW)

    A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal net…
  17. CVE-2026-19370
    — CVSS 5.3 (MEDIUM)

    A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the arg…
  18. CVE-2026-19369
    — CVSS 5.3 (MEDIUM)

    A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl result…
  19. CVE-2026-19368
    — CVSS 3.3 (LOW)

    A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_…
  20. CVE-2026-19367
    — CVSS 6.3 (MEDIUM)

    A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 10, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com