HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 10, 2026.
-
Hackers breach TrueConf to trojanize client installers with backdoors
— Bleeping Computer
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client insta… -
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
— The Hacker News
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then … -
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
— The Hacker News
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains sp… -
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
— The Hacker News
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has be… -
Inside the Modern SOC: The Identity Front Door
— Unit 42
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The pos… -
Metabase SQLi zero-day exploited in customer data-theft attacks
— Bleeping Computer
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known … -
Unlimited Technology Systems breach impacts 3.8 million people
— Bleeping Computer
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident … -
AI-Generated Patches Fail Half the Time
— Dark Reading
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. -
Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
— SANS ISC
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they … -
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
ChainDrop: Inside a Self-Propagating npm Worm
— Unit 42
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. … -
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
— Dark Reading
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still op…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9656 in last 30 days).
Critical: 0 · High: 1 · Medium: 16 · Low: 3. View full dashboard →
-
CVE-2026-19374
— CVSS 7.3 (HIGH)
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. T⦠-
CVE-2026-19373
— CVSS 5.3 (MEDIUM)
A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the ⦠-
CVE-2026-19372
— CVSS 5.3 (MEDIUM)
A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performin⦠-
CVE-2026-19371
— CVSS 5.3 (MEDIUM)
A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_pa⦠-
CVE-2026-12372
— CVSS 3.7 (LOW)
A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal net⦠-
CVE-2026-19370
— CVSS 5.3 (MEDIUM)
A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the arg⦠-
CVE-2026-19369
— CVSS 5.3 (MEDIUM)
A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl result⦠-
CVE-2026-19368
— CVSS 3.3 (LOW)
A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_⦠-
CVE-2026-19367
— CVSS 6.3 (MEDIUM)
A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the⦠-
CVE-2026-19366
— CVSS 5.3 (MEDIUM)
A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a manipulation of the ar⦠-
CVE-2026-19365
— CVSS 5.3 (MEDIUM)
A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads ⦠-
CVE-2026-19364
— CVSS 6.3 (MEDIUM)
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql ⦠-
CVE-2026-19363
— CVSS 5.3 (MEDIUM)
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in ⦠-
CVE-2026-19362
— CVSS 5.3 (MEDIUM)
A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The mani⦠-
CVE-2026-19361
— CVSS 3.7 (LOW)
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The⦠-
CVE-2026-19360
— CVSS 4.7 (MEDIUM)
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege ⦠-
CVE-2026-19359
— CVSS 4.7 (MEDIUM)
A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper⦠-
CVE-2026-19358
— CVSS 6.3 (MEDIUM)
A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. Th⦠-
CVE-2026-19357
— CVSS 5.3 (MEDIUM)
A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to⦠-
CVE-2026-19356
— CVSS 5.3 (MEDIUM)
A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible toâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 10, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment