HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 29, 2026.
-
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
— Dark Reading -
McKesson discloses breach after ShinyHunters claims patient data theft
— Bleeping Computer
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-part… -
Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
— Unit 42
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered securit… -
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
— The Hacker News
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state ad… -
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
— The Hacker News
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchai… -
Hundreds of OpenAI Agents Invaded Hugging Face Servers
— Dark Reading
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, mult… -
PaperCut releases second emergency patch for exploited flaws
— Bleeping Computer
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print manageme… -
Offensive Security Investments Surge as AI Threats Increase
— Dark Reading
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration tes… -
GiveWP WordPress donation plugin flaw lets hackers execute server commands
— Bleeping Computer
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the … -
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
— The Hacker News
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as t… -
Some Malicious PE Stats, (Thu, Aug 27th)
— SANS ISC
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? … -
ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (13093 in last 30 days).
Critical: 0 · High: 10 · Medium: 9 · Low: 1. View full dashboard →
-
CVE-2026-55860
— CVSS 5.9 (MEDIUM)
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because t⦠-
CVE-2026-55859
— CVSS 5.9 (MEDIUM)
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character ⦠-
CVE-2026-55858
— CVSS 5.9 (MEDIUM)
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side esc⦠-
CVE-2026-55857
— CVSS 5.9 (MEDIUM)
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account passw⦠-
CVE-2026-55856
— CVSS 5.9 (MEDIUM)
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-⦠-
CVE-2026-55855
— CVSS 6.5 (MEDIUM)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-contro⦠-
CVE-2026-55854
— CVSS 5.9 (MEDIUM)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM ⦠-
CVE-2026-55848
— CVSS 8.6 (HIGH)
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api⦠-
CVE-2026-55841
— CVSS 7.5 (HIGH)
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/⦠-
CVE-2026-55785
— CVSS 3.7 (LOW)
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality ⦠-
CVE-2026-55784
— CVSS 7.5 (HIGH)
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/conte⦠-
CVE-2026-55779
— CVSS 5.4 (MEDIUM)
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts ⦠-
CVE-2026-82333
— CVSS 7.5 (HIGH)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array⦠-
CVE-2026-82018
— CVSS 6.1 (MEDIUM)
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing ⦠-
CVE-2026-82017
— CVSS 7.6 (HIGH)
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an ⦠-
CVE-2026-81533
— CVSS 7.1 (HIGH)
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on con⦠-
CVE-2026-81532
— CVSS 8.8 (HIGH)
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the ⦠-
CVE-2026-81520
— CVSS 7.5 (HIGH)
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because t⦠-
CVE-2026-81518
— CVSS 7.5 (HIGH)
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accep⦠-
CVE-2026-81517
— CVSS 7.5 (HIGH)
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log wrâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 29, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment