HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 26, 2026.
-
LACMA data breach last year exposed social security and medical data
— Bleeping Computer
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. […] -
Hackers abuse npm mirrors to host phishing redirect pages
— Bleeping Computer
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to atta… -
Hidden Prompts Trick AI Into False Email Summaries
— Dark Reading
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information. -
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
— Bleeping Computer
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple de… -
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
— Dark Reading
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, pavin… -
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
— The Hacker News
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole… -
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
— SANS ISC
It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname a… -
Is Cyber Facing an Affordability Crisis?
— Dark Reading
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply cha… -
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
— The Hacker News
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the… -
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
— The Hacker News
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help u… -
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
— Unit 42
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before … -
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12571 in last 30 days).
Critical: 2 · High: 6 · Medium: 2 · Low: 0. View full dashboard →
-
CVE-2026-80138
— CVSS 9.8 (CRITICAL)
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a ⦠-
CVE-2026-79912
— CVSS 8.3 (HIGH)
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in⦠-
CVE-2026-79911
— CVSS 10.0 (CRITICAL)
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation o⦠-
CVE-2026-70665
— CVSS 4.2 (MEDIUM)
Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes ⦠-
CVE-2026-54757
— CVSS 7.8 (HIGH)
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template inject⦠-
CVE-2026-41707
— CVSS 7.4 (HIGH)
Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by floodin⦠-
CVE-2026-80186
— CVSS 7.6 (HIGH)
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes ⦠-
CVE-2026-80185
— CVSS 5.7 (MEDIUM)
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointe⦠-
CVE-2026-79845
— CVSS 7.3 (HIGH)
A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. ⦠-
CVE-2026-79804
— CVSS 7.3 (HIGH)
A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation oâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 26, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment