📰 DAILY THREAT BRIEFING
Thursday, July 16, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 16, 2026.

  1. The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
    — Unit 42

    Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The…
  2. Dutch police bust investment fraud ring stealing over €100 million
    — Bleeping Computer

    The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated …
  3. Forgotten Bootloaders Expose Secure Boot Blind Spot
    — Dark Reading

    Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.
  4. Identity Attacks Overtake Exploits as Top Ransomware Cause
    — Dark Reading

    Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credenti…
  5. Zoom warns of critical account takeover vulnerability
    — Bleeping Computer

    Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an una…
  6. TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
    — The Hacker News

    Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolu…
  7. Google Gemini CLI abused as a hacking agent, malware botnet operator
    — Bleeping Computer

    A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small…
  8. Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
    — Dark Reading

    We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity in…
  9. OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
    — The Hacker News

    A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wal…
  10. Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
    — The Hacker News

    Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerab…
  11. TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
    — Unit 42

    TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. Th…
  12. ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (8316 in last 30 days).
Critical: 4 · High: 6 · Medium: 9 · Low: 1. View full dashboard →

  1. CVE-2026-15907
    — CVSS 7.3 (HIGH)

    A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection…
  2. CVE-2026-62314
    — CVSS 5.8 (MEDIUM)

    Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client…
  3. CVE-2026-55652
    — CVSS 9.8 (CRITICAL)

    Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the…
  4. CVE-2026-55234
    — CVSS 8.5 (HIGH)

    Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored sou…
  5. CVE-2026-54458
    — CVSS 9.6 (CRITICAL)

    WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript i…
  6. CVE-2026-53447
    — CVSS 6.5 (MEDIUM)

    Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking …
  7. CVE-2026-52892
    — CVSS 6.5 (MEDIUM)

    Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAcces…
  8. CVE-2026-52891
    — CVSS 9.9 (CRITICAL)

    Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avata…
  9. CVE-2026-52890
    — CVSS 7.1 (HIGH)

    Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.p…
  10. CVE-2026-50183
    — CVSS 4.7 (MEDIUM)

    WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data …
  11. CVE-2026-50182
    — CVSS 6.1 (MEDIUM)

    WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenate…
  12. CVE-2026-48795
    — CVSS 8.6 (HIGH)

    AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted a…
  13. CVE-2026-45313
    — CVSS 7.7 (HIGH)

    Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a…
  14. CVE-2026-15921
    — CVSS 3.1 (LOW)

    Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm …
  15. CVE-2026-62361
    — CVSS 5.5 (MEDIUM)

    listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled query parameter into QuerySubscribersForExport in …
  16. CVE-2026-62312
    — CVSS 8.8 (HIGH)

    9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by combining a Host header bypass of localhost-only r…
  17. CVE-2026-56678
    — CVSS 6.4 (MEDIUM)

    9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled region value, allowing an authenticated attacker to …
  18. CVE-2026-55608
    — CVSS 4.2 (MEDIUM)

    n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant…
  19. CVE-2026-55410
    — CVSS 6.7 (MEDIUM)

    NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the databas…
  20. CVE-2026-54052
    — CVSS 9.9 (CRITICAL)

    n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's loca…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 16, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com