vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and req… The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
threat-intel A Tale of Two SOCs: Insights From Two Red Team Assessments Two separate red team assessments at a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector organization (Organization B) revealed significant vulnerabilities… CISA Advisories · 5d ago High credential abuseactive directorymicrosoft
vulnerability Ebyte NE2-D11 A CISA advisory highlights critical vulnerabilities in Ebyte NE2-D11 devices, primarily due to a lack of consistent authentication enforcement and cleartext transmission of sensitive information. The vendor, Ebyte, has n… CISA Advisories · 5d ago High CVE-2026-73125CVE-2026-73809CVE-2026-73839CHvulnerabilityauthenticationencryption
vulnerability PayRange API A critical vulnerability in the PayRange API allows unauthorized access to sensitive device information and potential denial-of-service attacks. The vulnerability stems from a lack of proper authorization on management e… CISA Advisories · 5d ago Critical CVE-2026-18965USCAvulnerabilityicscontrol systems
vulnerability FURUNO FA-50 Class B AIS Transponder A vulnerability in FURUNO FA-50 Class B AIS Transponders allows an attacker with credentials to alter device settings. Production of this product has ended, and software updates are no longer provided. Mitigation involve… CISA Advisories · 5d ago Medium CVE-2026-59769CVE-2026-67578vulnerabilityaiscontrol systems
vulnerability Siemens SIMATIC IoT2050 Advanced A vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed allows unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying ser… CISA Advisories · 5d ago Critical CVE-2026-58115vulnerabilityindustrial control systemsnode-red
vulnerability Bendix EC80 Brake ECU A critical vulnerability exists in Bendix EC80 Brake ECU firmware, potentially allowing an attacker to disable ABS, steering assist, speedometer, and shifting capabilities, or inject malicious CAN bus traffic. Multiple f… CISA Advisories · 5d ago Critical CVE-2026-67560CVE-2026-68967CVE-2026-71396UNCAfirmwarebuffer overflowcan bus
vulnerability Zoneminder A critical Remote Code Execution (RCE) vulnerability exists in Zoneminder versions 1.37.48 and 1.38.3, allowing authenticated users to execute arbitrary operating system commands. The vulnerability stems from an Improper… CISA Advisories · 5d ago Critical CVE-2026-76060vulnerabilityrceos command injection
vulnerability Rently Smart Home Rently Smart Home versions 20.1.0 and earlier are vulnerable to an insufficient credentials issue, potentially allowing an attacker to access sensitive information and override user permissions. Rently has released a pat… CISA Advisories · 5d ago Medium CVE-2026-75960USINvulnerabilitycwe-522industrial control systems
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
ddos Large DDoS attack knocks Norwegian public services offline A massive DDoS attack has severely disrupted several Norwegian public services for over 30 hours, impacting digital identity verification and government data exchange. The attack, the third of its kind since June, is sig… The Record · 5d ago Medium NOddosdhscyberattack
threat-intel E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net… The Hacker News · 5d ago High UNdvrftpremote access trojan
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel Frontier AI: Vulnerability Management's Systemic Revolution This article discusses how the rapid advancements in Frontier AI models, like those developed by Anthropic, are forcing vulnerability management programs to undergo a significant transformation. Traditional vulnerability… The Hacker News · 5d ago High vulnerability managementfrontier aicybersecurity
threat-intel Black Hat State of Security Vendors Black Hat 2023 showcased a significant shift in the security vendor landscape, driven by the increasing influence of AI. Vendors are now heavily emphasizing AI-powered solutions, though a notable number continue to focus… Schneier on Security · 5d ago Medium aisecurityvendors
vulnerability CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw CISA has issued a critical three-day patch deadline for a vulnerability in the Perfect 10 plugin for Joomla, which is being actively exploited by attackers. This plugin flaw allows attackers to gain unauthorized access t… The Register · 5d ago Critical CVE-2026-21962joomlavulnerabilityplugin
threat-intel The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution A recent analysis by Palo Alto Unit 42 found that while a significant number of AI-enabled malware samples exist in research and testing environments, only a small fraction (around 12) reached production endpoints across… Palo Alto Unit 42 · 5d ago Medium USCNGBaimalwarethreat intelligence
threat-intel The safety penalty: Reclaiming operational sovereignty in the age of AI As AI models become more powerful, their built-in safety mechanisms are increasingly causing friction for security teams, leading to a "safety penalty" where analysts are forced to redo work that a model refuses to compl… Cisco Talos · 5d ago High aifrontier-modelsguardrails
threat-intel Silent Patches Don’t Stop Attackers—They Blind Defenders Broadcom’s new program offering early access to CVE-only patches for Spring Framework users is exacerbating the problem of silent patching. While Broadcom continues to issue CVEs, the program effectively provides pre-ale… SecurityWeek · 5d ago High silent patchingvulnerability disclosureai-driven vulnerability