HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 24, 2026.
-
ToxicPanda Android malware uses VPN permissions to block Google Play
— Bleeping Computer
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support … -
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
— The Hacker News
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing… -
Hackers infect Android car head units with proxy botnet malware
— Bleeping Computer
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromi… -
Named Pipes Under Attack: Securing Windows Interprocess Communication
— Bleeping Computer
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes.… -
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
— Unit 42
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security… -
How an Emerging Industrial Protocol Family Could Put OT at Risk
— Dark Reading
New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes -
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
— The Hacker News
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are … -
OWASP Flags Top AI Skill Risks in New Security Blueprint
— Dark Reading
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal … -
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
— The Hacker News
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perfor… -
Calling on Cyber Pros to Help Defend City Hall
— Dark Reading
Government agencies with smaller budgets need support — and here's how you can help. -
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
— SANS ISC
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#… -
ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (11778 in last 30 days).
Critical: 4 · High: 5 · Medium: 11 · Low: 0. View full dashboard →
-
CVE-2026-78147
— CVSS 7.3 (HIGH)
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of⦠-
CVE-2026-78145
— CVSS 4.3 (MEDIUM)
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect. The atta⦠-
CVE-2026-78144
— CVSS 6.3 (MEDIUM)
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management ⦠-
CVE-2026-78143
— CVSS 7.3 (HIGH)
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulati⦠-
CVE-2026-78142
— CVSS 6.3 (MEDIUM)
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the ar⦠-
CVE-2026-78141
— CVSS 7.4 (HIGH)
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initi⦠-
CVE-2026-78140
— CVSS 4.7 (MEDIUM)
A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-templat⦠-
CVE-2026-9769
— CVSS 7.5 (HIGH)
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which⦠-
CVE-2026-8630
— CVSS 6.1 (MEDIUM)
justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_d⦠-
CVE-2026-8445
— CVSS 9.8 (CRITICAL)
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Ma⦠-
CVE-2026-7808
— CVSS 9.8 (CRITICAL)
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues pr⦠-
CVE-2026-77088
— CVSS 6.1 (MEDIUM)
justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code⦠-
CVE-2026-74793
— CVSS 6.1 (MEDIUM)
justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elements with event handl⦠-
CVE-2026-6827
— CVSS 6.1 (MEDIUM)
justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integr⦠-
CVE-2026-5751
— CVSS 6.1 (MEDIUM)
justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g., drop_foreign_namespa⦠-
CVE-2026-5389
— CVSS 6.1 (MEDIUM)
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to ⦠-
CVE-2026-5388
— CVSS 9.8 (CRITICAL)
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitiza⦠-
CVE-2026-4671
— CVSS 7.5 (HIGH)
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selec⦠-
CVE-2026-78155
— CVSS 9.9 (CRITICAL)
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges -
CVE-2026-78115
— CVSS 5.4 (MEDIUM)
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of â¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 24, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment