HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 22, 2026.
-
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
— Unit 42
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security… -
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
— The Hacker News
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are … -
New SynkLoader malware pushed in Microsoft Teams phishing campaign
— Bleeping Computer
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a … -
OWASP Flags Top AI Skill Risks in New Security Blueprint
— Dark Reading
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal … -
Hundreds of leaked AWS keys give full control over corporate accounts
— Bleeping Computer
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. […] -
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
— The Hacker News
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perfor… -
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
— The Hacker News
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware … -
Microsoft blames Windows gaming issues on RGB lighting devices
— Bleeping Computer
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by per… -
Calling on Cyber Pros to Help Defend City Hall
— Dark Reading
Government agencies with smaller budgets need support — and here's how you can help. -
OpenAI Adds Controls That Should've Been There Already
— Dark Reading
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place p… -
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
— SANS ISC
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#… -
ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12060 in last 30 days).
Critical: 1 · High: 8 · Medium: 10 · Low: 1. View full dashboard →
-
CVE-2026-53541
— CVSS 4.3 (MEDIUM)
OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configurati⦠-
CVE-2026-53525
— CVSS 7.4 (HIGH)
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to v⦠-
CVE-2026-53524
— CVSS 6.5 (MEDIUM)
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bo⦠-
CVE-2026-34949
— CVSS 6.5 (MEDIUM)
Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from perfor⦠-
CVE-2026-34948
— CVSS 7.7 (HIGH)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3. -
CVE-2026-53528
— CVSS 8.8 (HIGH)
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are access⦠-
CVE-2026-53527
— CVSS 8.8 (HIGH)
LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a reg⦠-
CVE-2026-53509
— CVSS 5.7 (MEDIUM)
CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making H⦠-
CVE-2026-53497
— CVSS 5.3 (MEDIUM)
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — ⦠-
CVE-2026-53487
— CVSS 4.3 (MEDIUM)
Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`.⦠-
CVE-2026-53468
— CVSS 4.6 (MEDIUM)
Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in the page metadata fields ⦠-
CVE-2026-49849
— CVSS 9.1 (CRITICAL)
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially ⦠-
CVE-2026-43980
— CVSS 6.3 (MEDIUM)
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization⦠-
CVE-2026-34836
— CVSS 6.5 (MEDIUM)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has bee⦠-
CVE-2026-34741
— CVSS 8.6 (HIGH)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instanc⦠-
CVE-2026-33333
— CVSS 3.5 (LOW)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3. -
CVE-2026-33240
— CVSS 8.8 (HIGH)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3. -
CVE-2026-33047
— CVSS 4.3 (MEDIUM)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3. -
CVE-2026-31936
— CVSS 8.8 (HIGH)
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3. -
CVE-2026-77811
— CVSS 8.7 (HIGH)
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript iâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 22, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment