HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 18, 2026.
-
Video Call Exploit Chains Two Flaws in Unisoc Modems
— Dark Reading
Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the vict… -
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
— The Hacker News
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) so… -
Apple Patches iOS and macOS, (Mon, Aug 17th)
— SANS ISC
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after … -
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
— Dark Reading
Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, ac… -
Hacker claims 3.6 million Azure account records stolen from major companies
— Bleeping Computer
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies afte… -
Adam Shostack Talks Hugging Face & PHANTOM-B
— Dark Reading
World-class threat modeler Adam Shostack shared he was "blown away" by OpenAI's revelations about the Hugging Face attack, and explains why … -
Pokémon Center data breach exposes customer info, cancels some orders
— Bleeping Computer
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole cust… -
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
— The Hacker News
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/sn… -
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
— The Hacker News
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could … -
Microsoft confirms GitHub is down worldwide
— Bleeping Computer
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other se… -
Apple Screen Sharing Security, (Mon, Aug 17th)
— SANS ISC
About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Inst… -
ISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (11590 in last 30 days).
Critical: 2 · High: 4 · Medium: 6 · Low: 2. View full dashboard →
-
CVE-2026-75082
— CVSS 4.3 (MEDIUM)
A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument⦠-
CVE-2026-75081
— CVSS 4.3 (MEDIUM)
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enfor⦠-
CVE-2026-75080
— CVSS 7.3 (HIGH)
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to ⦠-
CVE-2026-75079
— CVSS 7.3 (HIGH)
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql ⦠-
CVE-2026-9693
— CVSS 3.5 (LOW)
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited ⦠-
CVE-2026-75587
— CVSS 3.6 (LOW)
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the p⦠-
CVE-2026-75078
— CVSS 4.3 (MEDIUM)
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site sc⦠-
CVE-2026-9859
— CVSS 6.5 (MEDIUM)
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink an⦠-
CVE-2026-9816
— CVSS 8.3 (HIGH)
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member ⦠-
CVE-2026-75077
— CVSS 4.3 (MEDIUM)
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross⦠-
CVE-2026-71424
— CVSS 9.6 (CRITICAL)
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTok⦠-
CVE-2026-69148
— CVSS 7.1 (HIGH)
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_⦠-
CVE-2026-69146
— CVSS 6.5 (MEDIUM)
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth packag⦠-
CVE-2026-64849
— CVSS 9.3 (CRITICAL)
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhoâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 18, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment