📰 DAILY THREAT BRIEFING
Tuesday, August 25, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 25, 2026.

  1. Exploited Zimbra Flaw Highlights Shrinking Window to Patch
    — Dark Reading

    CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a …
  2. Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
    — Bleeping Computer

    An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthen…
  3. Foul Language: WordlistLoader Disguises Malware as Ordinary Text
    — Dark Reading

    ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
  4. Hackers target WordPress sites in miniOrange auth bypass attacks
    — Bleeping Computer

    Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for Wo…
  5. TikTok reaches $400M settlement with US over COPPA violations
    — Bleeping Computer

    The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that th…
  6. Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
    — The Hacker News

    If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent…
  7. Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
    — The Hacker News

    Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by m…
  8. Tricky 'SynkLoader' Multitool May Herald Ransomware
    — Dark Reading

    An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along wi…
  9. ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
    — The Hacker News

    A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood thi…
  10. DOUBLECUP's PNG Payload, (Mon, Aug 24th)
    — SANS ISC

    New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It does…
  11. ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
    — Unit 42

    Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (11813 in last 30 days).
Critical: 6 · High: 10 · Medium: 3 · Low: 1. View full dashboard →

  1. CVE-2026-78435
    — CVSS 3.8 (LOW)

    A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the…
  2. CVE-2026-78434
    — CVSS 6.5 (MEDIUM)

    A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endp…
  3. CVE-2026-78284
    — CVSS 8.6 (HIGH)

    Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
  4. CVE-2026-78282
    — CVSS 7.1 (HIGH)

    Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
  5. CVE-2026-78268
    — CVSS 7.5 (HIGH)

    Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
  6. CVE-2026-78267
    — CVSS 9.8 (CRITICAL)

    Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
  7. CVE-2026-78266
    — CVSS 6.5 (MEDIUM)

    Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
  8. CVE-2026-78265
    — CVSS 9.8 (CRITICAL)

    Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
  9. CVE-2026-78264
    — CVSS 7.1 (HIGH)

    Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
  10. CVE-2026-78263
    — CVSS 7.1 (HIGH)

    Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
  11. CVE-2026-78262
    — CVSS 9.8 (CRITICAL)

    Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
  12. CVE-2026-78259
    — CVSS 7.3 (HIGH)

    Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
  13. CVE-2026-77384
    — CVSS 7.5 (HIGH)

    libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another ab…
  14. CVE-2026-68516
    — CVSS 6.5 (MEDIUM)

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during n…
  15. CVE-2026-32563
    — CVSS 9.8 (CRITICAL)

    Subscriber PHP Object Injection in ACPT (Pro) – Custom Post Types Plugin for WordPress <= 2.0.63 versions.
  16. CVE-2026-32561
    — CVSS 8.8 (HIGH)

    Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
  17. CVE-2026-32560
    — CVSS 8.8 (HIGH)

    Subscriber Local File Inclusion in MagicAI for WordPress – AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
  18. CVE-2026-32559
    — CVSS 9.9 (CRITICAL)

    Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
  19. CVE-2026-32556
    — CVSS 7.1 (HIGH)

    Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
  20. CVE-2026-32555
    — CVSS 9.3 (CRITICAL)

    Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 25, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com