HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 28, 2026.
-
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
— Bleeping Computer
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the co… -
Chinese Routers Sold Worldwide Contain Backdoors
— Dark Reading
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer. -
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
— The Hacker News
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last … -
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
— Dark Reading
This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effe… -
PaperCut warns of NG, MF flaw exploited in zero-day attacks
— Bleeping Computer
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print managemen… -
Manchester Airports Group says hackers stole travelers' data
— Bleeping Computer
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manch… -
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
— The Hacker News
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which… -
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
— The Hacker News
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a… -
Russian Hackers Phish EU Officials Over Messaging Apps
— Dark Reading
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and … -
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
— Krebs on Security
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for … -
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
— SANS ISC
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spa… -
ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12848 in last 30 days).
Critical: 3 · High: 9 · Medium: 6 · Low: 2. View full dashboard →
-
CVE-2026-81848
— CVSS 3.5 (LOW)
A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation c⦠-
CVE-2026-81847
— CVSS 5.5 (MEDIUM)
A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeline/load_pipeline of the file pipeline_tools.py. Performing a manipulation results in path traversal.⦠-
CVE-2026-81845
— CVSS 6.3 (MEDIUM)
A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session/export_session of the file mcp_sequential_thinking/server.py of the component Import Session/Export⦠-
CVE-2026-81837
— CVSS 6.3 (MEDIUM)
A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/core/tools/ApplyPatchTool.ts of the component ApplyPatchTool. This manipulation causes path traversa⦠-
CVE-2026-81836
— CVSS 3.7 (LOW)
A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cle⦠-
CVE-2026-81835
— CVSS 5.5 (MEDIUM)
A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulat⦠-
CVE-2026-80179
— CVSS 5.9 (MEDIUM)
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocat⦠-
CVE-2026-78239
— CVSS 9.8 (CRITICAL)
Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may pe⦠-
CVE-2026-78037
— CVSS 8.8 (HIGH)
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentia⦠-
CVE-2026-77977
— CVSS 8.1 (HIGH)
Ebyte gateway product's vendor configuration utility does not require authentication before
allowing certain disruptive administrative actions when default
credentials remain configured. An unauthenticated attacker on ⦠-
CVE-2026-76945
— CVSS 7.5 (HIGH)
The affected Ebyte device relies on client-managed authentication tokens
without sufficient server-side validation. An attacker may replay or
manipulate authentication tokens to gain unauthorized access to
administrat⦠-
CVE-2026-76943
— CVSS 9.8 (CRITICAL)
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation co⦠-
CVE-2026-76940
— CVSS 7.5 (HIGH)
The affected Ebyte device does not restrict repeated authentication
attempts through rate limiting or account lockout mechanisms. This could
allow an attacker to perform automated authentication attacks against
deploy⦠-
CVE-2026-76179
— CVSS 9.8 (CRITICAL)
An improper protection of authentication tokens vulnerability exists in
certain Ebyte gateway products. Authentication tokens used by the web
management interface are insufficiently protected during client-side
sessio⦠-
CVE-2026-76060
— CVSS 8.8 (HIGH)
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing ⦠-
CVE-2026-75814
— CVSS 8.8 (HIGH)
The Ebyte device does not adequately verify the origin or authenticity of
requests submitted to the web management interface. An unauthenticated
remote attacker could persuade an authenticated administrator to visit a
⦠-
CVE-2026-75813
— CVSS 7.5 (HIGH)
Certain configuration endpoints may lack proper server-side
authorization checks, allowing unauthorized users to access or modify
sensitive device settings. This could result in full compromise of
device functionality⦠-
CVE-2026-75548
— CVSS 5.4 (MEDIUM)
The affected Ebyte device web management interface does not restrict the
interface from being rendered within an external frame. An
unauthenticated remote attacker could use a crafted webpage to mislead
an authenticat⦠-
CVE-2026-75419
— CVSS 8.8 (HIGH)
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization⦠-
CVE-2026-75418
— CVSS 7.5 (HIGH)
A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 28, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment