📰 DAILY THREAT BRIEFING
Thursday, August 13, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 13, 2026.

  1. "City-Forum" data-theft attacks target Salesforce, ServiceNow portals
    — Bleeping Computer

    An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNo…
  2. Android malware combo takes out loans and relays victims' credit cards
    — Bleeping Computer

    A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card dat…
  3. Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
    — Dark Reading

    The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooli…
  4. Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
    — Bleeping Computer

    Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, poten…
  5. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
    — The Hacker News

    The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impac…
  6. Walmart's "Trusted Agent" Approach to Purple Teaming
    — Dark Reading

    Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
  7. Linux Kernel Process Accounting, (Wed, Aug 12th)
    — SANS ISC

    A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing w…
  8. 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
    — The Hacker News

    A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked service…
  9. Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
    — Dark Reading

    Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity ac…
  10. OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
    — The Hacker News

    A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover intern…
  11. ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. Microsoft Plugs Nearly 400 Security Holes
    — Krebs on Security

    Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, in…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (11304 in last 30 days).
Critical: 6 · High: 9 · Medium: 5 · Low: 0. View full dashboard →

  1. CVE-2026-71194
    — CVSS 6.8 (MEDIUM)

    In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with …
  2. CVE-2026-71193
    — CVSS 9.6 (CRITICAL)

    In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by schedulin…
  3. CVE-2026-49481
    — CVSS 9.6 (CRITICAL)

    UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation usi…
  4. CVE-2026-47717
    — CVSS 7.5 (HIGH)

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secur…
  5. CVE-2026-7366
    — CVSS 4.2 (MEDIUM)

    IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of reque…
  6. CVE-2026-73519
    — CVSS 9.8 (CRITICAL)

    WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by …
  7. CVE-2026-73501
    — CVSS 9.1 (CRITICAL)

    kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which ret…
  8. CVE-2026-73498
    — CVSS 7.7 (HIGH)

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in…
  9. CVE-2026-73495
    — CVSS 7.4 (HIGH)

    blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer …
  10. CVE-2026-73493
    — CVSS 7.5 (HIGH)

    Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total siz…
  11. CVE-2026-71846
    — CVSS 6.5 (MEDIUM)

    A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secre…
  12. CVE-2026-71473
    — CVSS 8.5 (HIGH)

    A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manip…
  13. CVE-2026-71471
    — CVSS 9.0 (CRITICAL)

    A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.I…
  14. CVE-2026-71469
    — CVSS 7.5 (HIGH)

    A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which…
  15. CVE-2026-19003
    — CVSS 7.8 (HIGH)

    A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffe…
  16. CVE-2026-18727
    — CVSS 6.5 (MEDIUM)

    A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, craf…
  17. CVE-2026-18726
    — CVSS 6.5 (MEDIUM)

    A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Mes…
  18. CVE-2026-17485
    — CVSS 8.2 (HIGH)

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
  19. CVE-2026-10534
    — CVSS 8.4 (HIGH)

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
  20. CVE-2024-27253
    — CVSS 10.0 (CRITICAL)

    IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 13, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com