HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 30, 2026.
-
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
— Dark Reading -
Anthropic is cutting Claude Code's current weekly limits by 17%
— Bleeping Computer
Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, b… -
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
— The Hacker News
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, P… -
Brave browser adds email aliases to help users evade tracking
— Bleeping Computer
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email a… -
McKesson discloses breach after ShinyHunters claims patient data theft
— Bleeping Computer
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-part… -
Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
— Unit 42
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered securit… -
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
— The Hacker News
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state ad… -
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
— The Hacker News
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchai… -
Hundreds of OpenAI Agents Invaded Hugging Face Servers
— Dark Reading
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, mult… -
Offensive Security Investments Surge as AI Threats Increase
— Dark Reading
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration tes… -
Some Malicious PE Stats, (Thu, Aug 27th)
— SANS ISC
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? … -
ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12492 in last 30 days).
Critical: 1 · High: 7 · Medium: 12 · Low: 0. View full dashboard →
-
CVE-2026-82417
— CVSS 5.3 (MEDIUM)
### Summary`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructâ¦
-
CVE-2026-82424
— CVSS 6.3 (MEDIUM)
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead⦠-
CVE-2026-82423
— CVSS 5.4 (MEDIUM)
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId ⦠-
CVE-2026-82422
— CVSS 6.3 (MEDIUM)
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack⦠-
CVE-2026-82421
— CVSS 6.3 (MEDIUM)
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The a⦠-
CVE-2026-15369
— CVSS 9.8 (CRITICAL)
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_sel⦠-
CVE-2026-75807
— CVSS 7.5 (HIGH)
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 cert⦠-
CVE-2026-82476
— CVSS 5.3 (MEDIUM)
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server re⦠-
CVE-2026-82475
— CVSS 8.1 (HIGH)
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwri⦠-
CVE-2026-82474
— CVSS 7.8 (HIGH)
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly o⦠-
CVE-2026-82473
— CVSS 8.2 (HIGH)
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceivi⦠-
CVE-2026-82472
— CVSS 7.5 (HIGH)
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefi⦠-
CVE-2026-82470
— CVSS 5.4 (MEDIUM)
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the ⦠-
CVE-2026-82469
— CVSS 5.4 (MEDIUM)
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh rou⦠-
CVE-2026-82468
— CVSS 4.7 (MEDIUM)
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing applicati⦠-
CVE-2026-82467
— CVSS 4.7 (MEDIUM)
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with⦠-
CVE-2026-82466
— CVSS 8.7 (HIGH)
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic ⦠-
CVE-2026-82465
— CVSS 5.3 (MEDIUM)
pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on ⦠-
CVE-2026-82464
— CVSS 6.1 (MEDIUM)
pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with bac⦠-
CVE-2026-82463
— CVSS 8.1 (HIGH)
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resourcâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 30, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment