HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 11, 2026.
-
Hackers breached a small Polish energy plant via private APN last year
— Bleeping Computer
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point… -
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
— Unit 42
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and paylo… -
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
— Dark Reading
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. -
Multistate Water System Attacks Widen, Iran Suspected
— Dark Reading
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs. -
BdThemes plugins supply-chain hack creates rogue WordPress admins
— Bleeping Computer
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote… -
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
— Dark Reading
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform… -
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
— Bleeping Computer
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and re… -
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
— The Hacker News
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependenc… -
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
— The Hacker News
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransom… -
Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)
— SANS ISC
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To inte… -
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
— The Hacker News
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed… -
ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (10305 in last 30 days).
Critical: 1 · High: 6 · Medium: 11 · Low: 2. View full dashboard →
-
CVE-2026-8718
— CVSS 8.4 (HIGH)
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() wi⦠-
CVE-2026-11812
— CVSS 2.5 (LOW)
The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a⦠-
CVE-2026-11811
— CVSS 3.7 (LOW)
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket clos⦠-
CVE-2026-72919
— CVSS 4.3 (MEDIUM)
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated r⦠-
CVE-2026-72918
— CVSS 5.4 (MEDIUM)
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an ⦠-
CVE-2026-72917
— CVSS 5.9 (MEDIUM)
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/Passwo⦠-
CVE-2026-72915
— CVSS 7.5 (HIGH)
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controll⦠-
CVE-2026-72914
— CVSS 7.5 (HIGH)
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api:⦠-
CVE-2026-6426
— CVSS 4.4 (MEDIUM)
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian⦠-
CVE-2026-73035
— CVSS 4.3 (MEDIUM)
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json⦠-
CVE-2026-73033
— CVSS 6.5 (MEDIUM)
Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary⦠-
CVE-2026-73030
— CVSS 8.1 (HIGH)
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory con⦠-
CVE-2026-72912
— CVSS 4.3 (MEDIUM)
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment ⦠-
CVE-2026-72911
— CVSS 9.9 (CRITICAL)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statem⦠-
CVE-2026-72910
— CVSS 7.1 (HIGH)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across ⦠-
CVE-2026-72908
— CVSS 6.5 (MEDIUM)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from reque⦠-
CVE-2026-72907
— CVSS 6.5 (MEDIUM)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account creat⦠-
CVE-2026-72906
— CVSS 4.3 (MEDIUM)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py ⦠-
CVE-2026-72903
— CVSS 8.1 (HIGH)
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.⦠-
CVE-2026-72743
— CVSS 5.4 (MEDIUM)
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modifyâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 11, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment