📰 DAILY THREAT BRIEFING
Wednesday, August 26, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 26, 2026.

  1. LACMA data breach last year exposed social security and medical data
    — Bleeping Computer

    The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. […]
  2. Hackers abuse npm mirrors to host phishing redirect pages
    — Bleeping Computer

    Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to atta…
  3. Hidden Prompts Trick AI Into False Email Summaries
    — Dark Reading

    With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
  4. AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
    — Bleeping Computer

    A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple de…
  5. Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
    — Dark Reading

    Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, pavin…
  6. U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
    — The Hacker News

    The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole…
  7. Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
    — SANS ISC

    It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname a…
  8. Is Cyber Facing an Affordability Crisis?
    — Dark Reading

    As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply cha…
  9. A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
    — The Hacker News

    Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the…
  10. WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
    — The Hacker News

    Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help u…
  11. The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
    — Unit 42

    Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before …
  12. ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (12571 in last 30 days).
Critical: 2 · High: 6 · Medium: 2 · Low: 0. View full dashboard →

  1. CVE-2026-80138
    — CVSS 9.8 (CRITICAL)

    ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a …
  2. CVE-2026-79912
    — CVSS 8.3 (HIGH)

    A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in…
  3. CVE-2026-79911
    — CVSS 10.0 (CRITICAL)

    A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation o…
  4. CVE-2026-70665
    — CVSS 4.2 (MEDIUM)

    Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes …
  5. CVE-2026-54757
    — CVSS 7.8 (HIGH)

    Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template inject…
  6. CVE-2026-41707
    — CVSS 7.4 (HIGH)

    Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by floodin…
  7. CVE-2026-80186
    — CVSS 7.6 (HIGH)

    A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes …
  8. CVE-2026-80185
    — CVSS 5.7 (MEDIUM)

    BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointe…
  9. CVE-2026-79845
    — CVSS 7.3 (HIGH)

    A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. …
  10. CVE-2026-79804
    — CVSS 7.3 (HIGH)

    A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation o…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 26, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com