📰 DAILY THREAT BRIEFING
Sunday, August 23, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 23, 2026.

  1. TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
    — The Hacker News

    The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing…
  2. Hackers infect Android car head units with proxy botnet malware
    — Bleeping Computer

    A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromi…
  3. Named Pipes Under Attack: Securing Windows Interprocess Communication
    — Bleeping Computer

    Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes.…
  4. Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
    — Unit 42

    Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security…
  5. 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
    — The Hacker News

    Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are …
  6. New SynkLoader malware pushed in Microsoft Teams phishing campaign
    — Bleeping Computer

    A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a …
  7. OWASP Flags Top AI Skill Risks in New Security Blueprint
    — Dark Reading

    The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal …
  8. Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
    — The Hacker News

    Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perfor…
  9. Calling on Cyber Pros to Help Defend City Hall
    — Dark Reading

    Government agencies with smaller budgets need support — and here's how you can help.
  10. OpenAI Adds Controls That Should've Been There Already
    — Dark Reading

    The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place p…
  11. Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
    — SANS ISC

    In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#…
  12. ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (11934 in last 30 days).
Critical: 1 · High: 4 · Medium: 3 · Low: 1. View full dashboard →

  1. CVE-2026-78051
    — CVSS 5.3 (MEDIUM)

    A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes fil…
  2. CVE-2026-78050
    — CVSS 9.9 (CRITICAL)

    A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of …
  3. CVE-2026-18027
    — CVSS 6.5 (MEDIUM)

    The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base6…
  4. CVE-2026-16149
    — CVSS 8.8 (HIGH)

    The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled b…
  5. CVE-2026-0551
    — CVSS 8.8 (HIGH)

    The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerab…
  6. CVE-2026-78122
    — CVSS 7.4 (HIGH)

    docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{…
  7. CVE-2026-78049
    — CVSS 3.7 (LOW)

    A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/address_space/internal/sopc_node_mgt_helper_interna…
  8. CVE-2026-47895
    — CVSS 7.5 (HIGH)

    In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed…
  9. CVE-2026-12999
    — CVSS 5.3 (MEDIUM)

    The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() r…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 23, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com