📰 DAILY THREAT BRIEFING
Thursday, August 20, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 20, 2026.

  1. OpenAI confirms ChatGPT is down as logins and signups fail
    — Bleeping Computer

    ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. […
  2. Rogue ransomware affiliate poses as recovery firm to steal payments
    — Bleeping Computer

    A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the atta…
  3. Sakura Internet hack exposes data of up to 1.36 million accounts
    — Bleeping Computer

    Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer …
  4. No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
    — Dark Reading

    The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to…
  5. Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
    — The Hacker News

    Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) …
  6. OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
    — The Hacker News

    OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two we…
  7. SilkParasite Threatens Central Asian Orgs With Flurry of RATs
    — Dark Reading

    A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic glob…
  8. Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)
    — SANS ISC

    Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific dat…
  9. SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
    — The Hacker News

    A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The int…
  10. ISC Stormcast For Wednesday, August 19th, 2026 https://isc.sans.edu/podcastdetail/10058, (Wed, Aug 19th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  11. China-Linked Hacker Shows AI Capabilities in APAC Attack
    — Dark Reading

    In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and com…
  12. Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
    — Unit 42

    In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provi…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (12960 in last 30 days).
Critical: 0 · High: 3 · Medium: 12 · Low: 5. View full dashboard →

  1. CVE-2026-76764
    — CVSS 7.3 (HIGH)

    A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argumen…
  2. CVE-2026-76762
    — CVSS 7.3 (HIGH)

    A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack …
  3. CVE-2022-4996
    — CVSS 5.3 (MEDIUM)

    A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remote…
  4. CVE-2026-76929
    — CVSS 4.7 (MEDIUM)

    Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  5. CVE-2026-76928
    — CVSS 7.5 (HIGH)

    X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  6. CVE-2026-76927
    — CVSS 4.7 (MEDIUM)

    H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  7. CVE-2026-76926
    — CVSS 3.1 (LOW)

    BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  8. CVE-2026-76924
    — CVSS 5.5 (MEDIUM)

    Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  9. CVE-2026-76923
    — CVSS 5.5 (MEDIUM)

    Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  10. CVE-2026-76922
    — CVSS 5.5 (MEDIUM)

    Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  11. CVE-2026-76921
    — CVSS 5.5 (MEDIUM)

    CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  12. CVE-2026-76920
    — CVSS 4.7 (MEDIUM)

    3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  13. CVE-2026-76919
    — CVSS 5.3 (MEDIUM)

    ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  14. CVE-2026-76918
    — CVSS 5.5 (MEDIUM)

    SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  15. CVE-2026-76917
    — CVSS 5.5 (MEDIUM)

    Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  16. CVE-2026-76891
    — CVSS 3.1 (LOW)

    Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  17. CVE-2026-76890
    — CVSS 3.1 (LOW)

    Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  18. CVE-2026-76889
    — CVSS 4.7 (MEDIUM)

    UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  19. CVE-2026-76888
    — CVSS 3.1 (LOW)

    RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
  20. CVE-2026-76887
    — CVSS 3.1 (LOW)

    Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 20, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com