HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 19, 2026.
-
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
— Dark Reading
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CV… -
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
— Dark Reading
Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses. -
Comcast turns your Xfinity WiFi into a home motion detector
— Bleeping Computer
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless… -
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
— Unit 42
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provi… -
CISOs Break Their Silence in 'Declassified' Docuseries
— Dark Reading
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look a… -
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
— The Hacker News
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted l… -
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
— The Hacker News
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCA… -
Clop created custom web shell for Windchill data theft attacks
— Bleeping Computer
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with buil… -
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
— The Hacker News
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delet… -
Your Controls Block Known Attacks. What About the Behavior?
— Bleeping Computer
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report … -
ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Apple Patches iOS and macOS, (Mon, Aug 17th)
— SANS ISC
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after …
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12552 in last 30 days).
Critical: 1 · High: 6 · Medium: 13 · Low: 0. View full dashboard →
-
CVE-2026-75978
— CVSS 6.3 (MEDIUM)
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFact⦠-
CVE-2026-75976
— CVSS 9.9 (CRITICAL)
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based⦠-
CVE-2025-11729
— CVSS 4.3 (MEDIUM)
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and⦠-
CVE-2026-66591
— CVSS 6.5 (MEDIUM)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a throughâ¦
-
CVE-2026-66589
— CVSS 5.4 (MEDIUM)
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B2BKing: from n/a through 5.2.30.
-
CVE-2026-27365
— CVSS 5.9 (MEDIUM)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS.This issue affects PublishPress Series: from n/a through 2.17.0.
-
CVE-2026-73974
— CVSS 5.5 (MEDIUM)
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-li⦠-
CVE-2026-73973
— CVSS 5.5 (MEDIUM)
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form –filename path and opened it as root when in⦠-
CVE-2026-66603
— CVSS 6.5 (MEDIUM)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS.This issue affects Draft List: from n/a through 2.6.4.
-
CVE-2026-66602
— CVSS 8.8 (HIGH)
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
-
CVE-2026-62377
— CVSS 4.3 (MEDIUM)
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash wh⦠-
CVE-2026-62291
— CVSS 5.3 (MEDIUM)
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2×2 primary plane and a 256×256 auxiliary alpha plane can cause attacker-controlled heap corruption durin⦠-
CVE-2026-62289
— CVSS 4.3 (MEDIUM)
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results whe⦠-
CVE-2026-53959
— CVSS 6.5 (MEDIUM)
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts⦠-
CVE-2026-53958
— CVSS 7.6 (HIGH)
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ⦠-
CVE-2026-52877
— CVSS 8.3 (HIGH)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron'⦠-
CVE-2026-52876
— CVSS 8.8 (HIGH)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without vali⦠-
CVE-2026-52873
— CVSS 6.9 (MEDIUM)
Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron ⦠-
CVE-2026-52872
— CVSS 8.8 (HIGH)
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a ⦠-
CVE-2026-52854
— CVSS 8.6 (HIGH)
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML â¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 19, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment