📰 DAILY THREAT BRIEFING
Tuesday, August 18, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 18, 2026.

  1. Video Call Exploit Chains Two Flaws in Unisoc Modems
    — Dark Reading

    Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the vict…
  2. Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
    — The Hacker News

    GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) so…
  3. Apple Patches iOS and macOS, (Mon, Aug 17th)
    — SANS ISC

    Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after …
  4. 'Turf War' Between Claude Agents Leads to Self-Replicating Malware
    — Dark Reading

    Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, ac…
  5. Hacker claims 3.6 million Azure account records stolen from major companies
    — Bleeping Computer

    A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies afte…
  6. Adam Shostack Talks Hugging Face & PHANTOM-B
    — Dark Reading

    World-class threat modeler Adam Shostack shared he was "blown away" by OpenAI's revelations about the Hugging Face attack, and explains why …
  7. Pokémon Center data breach exposes customer info, cancels some orders
    — Bleeping Computer

    Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole cust…
  8. Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
    — The Hacker News

    Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/sn…
  9. Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
    — The Hacker News

    A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could …
  10. Microsoft confirms GitHub is down worldwide
    — Bleeping Computer

    GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other se…
  11. Apple Screen Sharing Security, (Mon, Aug 17th)
    — SANS ISC

    About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Inst…
  12. ISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (11590 in last 30 days).
Critical: 2 · High: 4 · Medium: 6 · Low: 2. View full dashboard →

  1. CVE-2026-75082
    — CVSS 4.3 (MEDIUM)

    A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument…
  2. CVE-2026-75081
    — CVSS 4.3 (MEDIUM)

    A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enfor…
  3. CVE-2026-75080
    — CVSS 7.3 (HIGH)

    A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to …
  4. CVE-2026-75079
    — CVSS 7.3 (HIGH)

    A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql …
  5. CVE-2026-9693
    — CVSS 3.5 (LOW)

    Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited …
  6. CVE-2026-75587
    — CVSS 3.6 (LOW)

    Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the p…
  7. CVE-2026-75078
    — CVSS 4.3 (MEDIUM)

    A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site sc…
  8. CVE-2026-9859
    — CVSS 6.5 (MEDIUM)

    Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink an…
  9. CVE-2026-9816
    — CVSS 8.3 (HIGH)

    Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member …
  10. CVE-2026-75077
    — CVSS 4.3 (MEDIUM)

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross…
  11. CVE-2026-71424
    — CVSS 9.6 (CRITICAL)

    Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTok…
  12. CVE-2026-69148
    — CVSS 7.1 (HIGH)

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_…
  13. CVE-2026-69146
    — CVSS 6.5 (MEDIUM)

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth packag…
  14. CVE-2026-64849
    — CVSS 9.3 (CRITICAL)

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webho…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 18, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com