📰 DAILY THREAT BRIEFING
Monday, August 24, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 24, 2026.

  1. ToxicPanda Android malware uses VPN permissions to block Google Play
    — Bleeping Computer

    The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support …
  2. TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
    — The Hacker News

    The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing…
  3. Hackers infect Android car head units with proxy botnet malware
    — Bleeping Computer

    A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromi…
  4. Named Pipes Under Attack: Securing Windows Interprocess Communication
    — Bleeping Computer

    Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes.…
  5. Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
    — Unit 42

    Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security…
  6. How an Emerging Industrial Protocol Family Could Put OT at Risk
    — Dark Reading

    New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes
  7. 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
    — The Hacker News

    Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are …
  8. OWASP Flags Top AI Skill Risks in New Security Blueprint
    — Dark Reading

    The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal …
  9. Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
    — The Hacker News

    Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perfor…
  10. Calling on Cyber Pros to Help Defend City Hall
    — Dark Reading

    Government agencies with smaller budgets need support — and here's how you can help.
  11. Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
    — SANS ISC

    In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#…
  12. ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (11778 in last 30 days).
Critical: 4 · High: 5 · Medium: 11 · Low: 0. View full dashboard →

  1. CVE-2026-78147
    — CVSS 7.3 (HIGH)

    A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of…
  2. CVE-2026-78145
    — CVSS 4.3 (MEDIUM)

    A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect. The atta…
  3. CVE-2026-78144
    — CVSS 6.3 (MEDIUM)

    A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management …
  4. CVE-2026-78143
    — CVSS 7.3 (HIGH)

    A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulati…
  5. CVE-2026-78142
    — CVSS 6.3 (MEDIUM)

    A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the ar…
  6. CVE-2026-78141
    — CVSS 7.4 (HIGH)

    A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initi…
  7. CVE-2026-78140
    — CVSS 4.7 (MEDIUM)

    A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-templat…
  8. CVE-2026-9769
    — CVSS 7.5 (HIGH)

    justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which…
  9. CVE-2026-8630
    — CVSS 6.1 (MEDIUM)

    justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_d…
  10. CVE-2026-8445
    — CVSS 9.8 (CRITICAL)

    justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Ma…
  11. CVE-2026-7808
    — CVSS 9.8 (CRITICAL)

    justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues pr…
  12. CVE-2026-77088
    — CVSS 6.1 (MEDIUM)

    justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code…
  13. CVE-2026-74793
    — CVSS 6.1 (MEDIUM)

    justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elements with event handl…
  14. CVE-2026-6827
    — CVSS 6.1 (MEDIUM)

    justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integr…
  15. CVE-2026-5751
    — CVSS 6.1 (MEDIUM)

    justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g., drop_foreign_namespa…
  16. CVE-2026-5389
    — CVSS 6.1 (MEDIUM)

    justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to …
  17. CVE-2026-5388
    — CVSS 9.8 (CRITICAL)

    justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitiza…
  18. CVE-2026-4671
    — CVSS 7.5 (HIGH)

    justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selec…
  19. CVE-2026-78155
    — CVSS 9.9 (CRITICAL)

    privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
  20. CVE-2026-78115
    — CVSS 5.4 (MEDIUM)

    A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of …

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 24, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com