HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 23, 2026.
-
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
— The Hacker News
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing… -
Hackers infect Android car head units with proxy botnet malware
— Bleeping Computer
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromi… -
Named Pipes Under Attack: Securing Windows Interprocess Communication
— Bleeping Computer
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes.… -
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
— Unit 42
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security… -
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
— The Hacker News
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are … -
New SynkLoader malware pushed in Microsoft Teams phishing campaign
— Bleeping Computer
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a … -
OWASP Flags Top AI Skill Risks in New Security Blueprint
— Dark Reading
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal … -
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
— The Hacker News
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perfor… -
Calling on Cyber Pros to Help Defend City Hall
— Dark Reading
Government agencies with smaller budgets need support — and here's how you can help. -
OpenAI Adds Controls That Should've Been There Already
— Dark Reading
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place p… -
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
— SANS ISC
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#… -
ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (11934 in last 30 days).
Critical: 1 · High: 4 · Medium: 3 · Low: 1. View full dashboard →
-
CVE-2026-78051
— CVSS 5.3 (MEDIUM)
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes fil⦠-
CVE-2026-78050
— CVSS 9.9 (CRITICAL)
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component Web Management. The manipulation of ⦠-
CVE-2026-18027
— CVSS 6.5 (MEDIUM)
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base6⦠-
CVE-2026-16149
— CVSS 8.8 (HIGH)
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled b⦠-
CVE-2026-0551
— CVSS 8.8 (HIGH)
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerab⦠-
CVE-2026-78122
— CVSS 7.4 (HIGH)
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{⦠-
CVE-2026-78049
— CVSS 3.7 (LOW)
A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/address_space/internal/sopc_node_mgt_helper_interna⦠-
CVE-2026-47895
— CVSS 7.5 (HIGH)
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed⦠-
CVE-2026-12999
— CVSS 5.3 (MEDIUM)
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() râ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 23, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment