HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 21, 2026.
-
Calling on Cyber Pros to Help Defend City Hall
— Dark Reading
Government agencies with smaller budgets need support — and here's how you can help. -
New CUSTODY Framework Constrains AI Agents Inside the Network
— Dark Reading
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI frame… -
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
— The Hacker News
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account publi… -
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
— The Hacker News
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out… -
What We Missed: Delta Flight Disrupted With Wi-Fi Hack
— Dark Reading
In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks… -
Hackers poison arrayref Rust crate to push infostealer malware
— Bleeping Computer
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' syst… -
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
— The Hacker News
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defe… -
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
— Bleeping Computer
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on… -
How MSPs can catch phishing attacks email filters miss
— Bleeping Computer
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs… -
Using Microsoft Graph and Powershell – Risk Detection Commands, (Thu, Aug 20th)
— SANS ISC
Building on the last diary on Using MS Graph and Powershell, let's look at "Risky" logins. -
Using Microsoft Graph and Powershell to Mine for Information – Stale Accounts and Licenses, (Thu, Aug 20th)
— SANS ISC
Microsoft Graph is a newer API that is meant to replace several others.  OK, it'… -
Identity Abuse Through Trusted Communication Channels
— Unit 42
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strate…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (11966 in last 30 days).
Critical: 7 · High: 9 · Medium: 3 · Low: 1. View full dashboard →
-
CVE-2026-77648
— CVSS 2.2 (LOW)
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// ⦠-
CVE-2026-77647
— CVSS 9.8 (CRITICAL)
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of ⦠-
CVE-2026-77643
— CVSS 4.4 (MEDIUM)
A cross-site scripting vulnerability in
queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exis⦠-
CVE-2026-77642
— CVSS 7.5 (HIGH)
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory au⦠-
CVE-2026-72860
— CVSS 8.5 (HIGH)
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That gu⦠-
CVE-2026-72848
— CVSS 8.6 (HIGH)
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, b⦠-
CVE-2026-72846
— CVSS 6.4 (MEDIUM)
Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams⦠-
CVE-2026-72843
— CVSS 9.8 (CRITICAL)
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without c⦠-
CVE-2026-72818
— CVSS 7.5 (HIGH)
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.-][a-z0-9]+)* i⦠-
CVE-2026-70105
— CVSS 6.5 (MEDIUM)
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. -
CVE-2026-69855
— CVSS 7.7 (HIGH)
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. -
CVE-2026-69851
— CVSS 9.9 (CRITICAL)
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. -
CVE-2026-69836
— CVSS 10.0 (CRITICAL)
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. -
CVE-2026-69558
— CVSS 8.6 (HIGH)
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. -
CVE-2026-69555
— CVSS 10.0 (CRITICAL)
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-69543
— CVSS 8.5 (HIGH)
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. -
CVE-2026-69519
— CVSS 8.6 (HIGH)
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. -
CVE-2026-69419
— CVSS 8.5 (HIGH)
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. -
CVE-2026-69400
— CVSS 9.6 (CRITICAL)
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. -
CVE-2026-68789
— CVSS 9.9 (CRITICAL)
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 21, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment