Critical vulnerabilities in Adobe products URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
NVD - CVE-2026-48323
nvd.nist.gov
Sami Laiho
@samilaiho.com
Keynote-speaker, Chief Research Officer, Microsoft MVP since 2011 More info: https://samilaiho.com/
Critical vulnerabilities in Adobe products URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
NVD - CVE-2026-48323
nvd.nist.gov
Cisco IOS XE Software Security Hardening Release: August 2026 URL: sec.cloudapps.cisco.com/security/cen... Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.8
Cisco Security Advisory: Cisco IOS XE Software Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted...
sec.cloudapps.cisco.com
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 URL: sec.cloudapps.cisco.com/security/cen... Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.9
Cisco Security Advisory: Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review...
sec.cloudapps.cisco.com
Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.4
NVD - CVE-2026-15587
nvd.nist.gov
Critical vulnerability in SUSE Rancher URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
NVD - CVE-2026-44945
nvd.nist.gov
Red Hat - Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Unavailable, CVSSv3.1: 9.9
NVD - CVE-2026-10090
nvd.nist.gov
Red Hat - Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
NVD - CVE-2026-10059
nvd.nist.gov
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls www.darkreading.com/application-...
AI Notetaker Exposes Government, Corporate Video Calls
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and join calls.
darkreading.com
Sophisticated Cyberattackers Boost Productivity Using AI www.databreachtoday.com/blogs/sophis...
Sophisticated Cyberattackers Boost Productivity Using AI
Everybody seems hellbent on applying artificial intelligence tools to boost productivity, and criminal hackers appear to be no exception. But as with non-illicit use of large language models, the most...
databreachtoday.com
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected therecord.media/swiss-bit-fo...
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers ...
therecord.media
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root thehackernews.com/2026/08/new-...
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel patches CVE-2026-58048, which could let authenticated customers run SQL as database root and, in some setups, compromise the OS.
thehackernews.com
New XCSSET variant targets macOS devs via compromised Xcode projects www.bleepingcomputer.com/news/securit...
New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
bleepingcomputer.com
77 Open VSX extensions found harvesting developer info www.bleepingcomputer.com/news/securit...
77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed.
bleepingcomputer.com
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant www.fortinet.com/blog/threat-...
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | FortiGuard Labs
The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant…
fortinet.com
Several vulnerability in NVIDIA Dynamo for Linux URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
NVD - CVE-2026-24254
nvd.nist.gov
Multiple Vulnerabilities in HPE Networking EdgeConnect Orchestrator 9.6 branch URL: support.hpe.com/hpesc/public...
support.hpe.com
Critical Vulnerabilities in Veeam ONE 13.1 and Veeam Service Provider Console 9.3 URL: www.veeam.com/kb4892 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
KB4892: Vulnerabilities Resolved in Veeam ONE 13.1
Vulnerabilities Resolved in Veeam ONE 13.1
veeam.com
August 2026 Security Bulletin of Qualcomm Technologies URL: docs.qualcomm.com/securitybull... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6
Qualcomm Documentation
docs.qualcomm.com
Vulnerability in Eclipse Milo URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
NVD - CVE-2026-60007
nvd.nist.gov
Vulnerability in GeoVision GV-AS1620 Controller Firmware (GV-ASManager), GV-AS1620 Controller Firmware (GV-Cloud) and GV-ASManager URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
NVD - CVE-2026-18754
nvd.nist.gov
Security update available for Adobe Campaign Classic URL: helpx.adobe.com/security/pro... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
helpx.adobe.com
Tenable Sensor Version 1.4.2 Fixes One Vulnerability URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6
NVD - CVE-2026-18667
nvd.nist.gov
Police National Legal Database confirms data theft after dark web leak www.theregister.com/cyber-crime/...
Police National Legal Database confirms data theft after dark web leak
ExfilSquad claims 135,000 contact records weeks after hitting the Department for Education
theregister.com
Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm www.darkreading.com/cyberattacks...
Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm
Researchers intercepted the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
darkreading.com
Fake Roblox Xeno script launcher pushes infostealer, RAT malware www.bleepingcomputer.com/news/securit...
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information.
bleepingcomputer.com
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws thehackernews.com/2026/08/inc-...
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
INC Ransomware is suspected of chaining CVE-2026-15409 and CVE-2026-15410 to steal credentials, TOTP seeds, and reach internal networks.
thehackernews.com
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication unit42.paloaltonetworks.com/passwordless...
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
unit42.paloaltonetworks.com
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete thehackernews.com/2026/08/n-ab...
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able says attackers exploited an N-central authentication bypass to take over servers, reach managed endpoints, and preserve access with Cloudflare
thehackernews.com
N‑central critical vulnerability Unauthenticated administrative account takeover URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: 8.2
NVD - CVE-2026-18577
nvd.nist.gov
@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
NVD - CVE-2026-18248
nvd.nist.gov