📰 DAILY THREAT BRIEFING
Friday, August 21, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 21, 2026.

  1. Calling on Cyber Pros to Help Defend City Hall
    — Dark Reading

    Government agencies with smaller budgets need support — and here's how you can help.
  2. New CUSTODY Framework Constrains AI Agents Inside the Network
    — Dark Reading

    Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI frame…
  3. Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
    — The Hacker News

    The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account publi…
  4. Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
    — The Hacker News

    Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out…
  5. What We Missed: Delta Flight Disrupted With Wi-Fi Hack
    — Dark Reading

    In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks…
  6. Hackers poison arrayref Rust crate to push infostealer malware
    — Bleeping Computer

    Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' syst…
  7. ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
    — The Hacker News

    A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defe…
  8. Critical Elementor Pro bug exposes WordPress sites to RCE attacks
    — Bleeping Computer

    A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on…
  9. How MSPs can catch phishing attacks email filters miss
    — Bleeping Computer

    AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs…
  10. Using Microsoft Graph and Powershell – Risk Detection Commands, (Thu, Aug 20th)
    — SANS ISC

    Building on the last diary on Using MS Graph and Powershell, let's look at "Risky" logins.
  11. Using Microsoft Graph and Powershell to Mine for Information – Stale Accounts and Licenses, (Thu, Aug 20th)
    — SANS ISC

    Microsoft Graph is a newer API that is meant to replace several others.  OK, it'…
  12. Identity Abuse Through Trusted Communication Channels
    — Unit 42

    Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strate…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (11966 in last 30 days).
Critical: 7 · High: 9 · Medium: 3 · Low: 1. View full dashboard →

  1. CVE-2026-77648
    — CVSS 2.2 (LOW)

    In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
    bypass import_filtering_opts, allowing an admin to fetch internal
    URLs from the Glance service network (aka SSRF), as long as https:// …
  2. CVE-2026-77647
    — CVSS 9.8 (CRITICAL)

    SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of …
  3. CVE-2026-77643
    — CVSS 4.4 (MEDIUM)

    A cross-site scripting vulnerability in
    queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exis…
  4. CVE-2026-77642
    — CVSS 7.5 (HIGH)

    tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory au…
  5. CVE-2026-72860
    — CVSS 8.5 (HIGH)

    The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That gu…
  6. CVE-2026-72848
    — CVSS 8.6 (HIGH)

    SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, b…
  7. CVE-2026-72846
    — CVSS 6.4 (MEDIUM)

    Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams…
  8. CVE-2026-72843
    — CVSS 9.8 (CRITICAL)

    The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without c…
  9. CVE-2026-72818
    — CVSS 7.5 (HIGH)

    The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.-][a-z0-9]+)* i…
  10. CVE-2026-70105
    — CVSS 6.5 (MEDIUM)

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
  11. CVE-2026-69855
    — CVSS 7.7 (HIGH)

    Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
  12. CVE-2026-69851
    — CVSS 9.9 (CRITICAL)

    Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
  13. CVE-2026-69836
    — CVSS 10.0 (CRITICAL)

    Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
  14. CVE-2026-69558
    — CVSS 8.6 (HIGH)

    Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
  15. CVE-2026-69555
    — CVSS 10.0 (CRITICAL)

    Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
  16. CVE-2026-69543
    — CVSS 8.5 (HIGH)

    Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
  17. CVE-2026-69519
    — CVSS 8.6 (HIGH)

    Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
  18. CVE-2026-69419
    — CVSS 8.5 (HIGH)

    Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
  19. CVE-2026-69400
    — CVSS 9.6 (CRITICAL)

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
  20. CVE-2026-68789
    — CVSS 9.9 (CRITICAL)

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 21, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com