📰 DAILY THREAT BRIEFING
Monday, August 31, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 31, 2026.

  1. [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
    — Dark Reading
  2. FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
    — Bleeping Computer

    FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples re…
  3. Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
    — Bleeping Computer

    Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to …
  4. Chrome Web Store extensions caught stealing crypto, browser data
    — Bleeping Computer

    Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensit…
  5. TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
    — The Hacker News

    Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in …
  6. YARA-X 1.20.0 Release, (Sun, Aug 30th)
    — SANS ISC

    YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes.
  7. Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
    — The Hacker News

    Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, P…
  8. Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
    — Unit 42

    New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered securit…
  9. Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
    — The Hacker News

    Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state ad…
  10. Hundreds of OpenAI Agents Invaded Hugging Face Servers
    — Dark Reading

    The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, mult…
  11. Offensive Security Investments Surge as AI Threats Increase
    — Dark Reading

    Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration tes…
  12. Some Malicious PE Stats, (Thu, Aug 27th)
    — SANS ISC

    During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? …

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (12360 in last 30 days).
Critical: 2 · High: 3 · Medium: 13 · Low: 2. View full dashboard →

  1. CVE-2026-82596
    — CVSS 3.3 (LOW)

    A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetec…
  2. CVE-2026-82595
    — CVSS 7.4 (HIGH)

    A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the arg…
  3. CVE-2026-82594
    — CVSS 5.0 (MEDIUM)

    A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be …
  4. CVE-2026-82593
    — CVSS 9.9 (CRITICAL)

    A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url …
  5. CVE-2026-82592
    — CVSS 9.9 (CRITICAL)

    A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition…
  6. CVE-2026-82591
    — CVSS 5.3 (MEDIUM)

    A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation o…
  7. CVE-2026-82590
    — CVSS 4.3 (MEDIUM)

    A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemp…
  8. CVE-2026-82589
    — CVSS 4.3 (MEDIUM)

    A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_transfer of the file src/amf/namf-handler.c of the component N1-N2 Message Handler. Performing a man…
  9. CVE-2026-82588
    — CVSS 4.3 (MEDIUM)

    A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference…
  10. CVE-2026-56718
    — CVSS 7.5 (HIGH)

    AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by su…
  11. CVE-2026-82587
    — CVSS 4.3 (MEDIUM)

    A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_context_list of the file src/amf/namf-handler.c of the component AMF. This manipulation of the arg…
  12. CVE-2026-82556
    — CVSS 6.3 (MEDIUM)

    A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a …
  13. CVE-2026-82555
    — CVSS 3.7 (LOW)

    A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulat…
  14. CVE-2026-82554
    — CVSS 4.3 (MEDIUM)

    A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to i…
  15. CVE-2026-82553
    — CVSS 6.3 (MEDIUM)

    A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of the component S…
  16. CVE-2026-82552
    — CVSS 4.3 (MEDIUM)

    A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manip…
  17. CVE-2026-82551
    — CVSS 5.3 (MEDIUM)

    A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The atta…
  18. CVE-2026-82550
    — CVSS 5.3 (MEDIUM)

    A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in …
  19. CVE-2026-82549
    — CVSS 8.3 (HIGH)

    A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The…
  20. CVE-2026-82658
    — CVSS 4.3 (MEDIUM)

    Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass prof…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · August 31, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com