2026-08-30 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-16061 Unknown - Rest Routes ...
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-16061 Unknown - Rest Routes ...
Protect Your WhatsApp Account with New Passkey and 2FA Upgrades 🚀 WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app. The announcement inclu...
Multiple Vulnerabilities in SOY Series 🚨 Multiple vulnerabilities have been identified in the SOY series provided by Tsuyoshi Saito. These vulnerabilities affect: SOY Calendar ver 2.4.0 and ea...
CVE-2026-82343 - Gimp Vulnerability Details A flaw, tracked as CVE-2026-82343, was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not pro...
CVE-2026-82306 - StarRocks Query Detail Endpoint Vulnerability CVE-2026-82306: The StarRocks Query Detail Endpoint is vulnerable and returns every user’s query history. This is a MEDIUM severity v...
CVE-2026-82291 - HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials HeyForm, prior to version 3.0.0-rc.8, reflects the request Origin header in CORS responses while allowing ...
JavaScript Obfuscation: From Party Trick to Phishing Kit We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, an...
Vulnerability Alert 🚨 Title: Installer for Rakuten Kobo Desktop Application (Windows version) may insecurely load Dynamic Link Libraries Source: Japan Vulnerability Network Date Published: Augus...
Major Data Breach at UK Airports 🚨 Three major UK airports have been affected by a cyber security incident where criminal hackers accessed the data of almost nine million people and demanded a ran...
ATF Responds to Major Cybersecurity Incident 🚨 The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is currently addressing a major cybersecurity incident following claims made by the Qil...
AI Girlfriend Review Site’s Secrets Exposed for Three Weeks 🚨 Our story comes courtesy of Mia Morin, Editor & AI Quality Analyst at Intimeros, a site that rates, reviews, and evaluates AI comp...
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia 🚨 Authorities in Australia have arrested two men believed to be members of TeamPCP, a notorious cybercrime and data extortion group responsible ...
Threat Intelligence Report - University Leak Exposes Russia’s Military Cyber Training Pipeline Recently leaked records have revealed that Bauman Moscow State Technical University’s Department No. ...
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption A misconfigured open directory on 86.53.111[.]212:8080 exposed critical details of an active cy...
Caught in 4K: The Aurora Files An exposed open directory revealed months of activity belonging to a Russian-speaking Aurora ransomware affiliate, active against more than twenty organizations betw...
Carry-On Compromise: TA4922 Packs PackClient Date Published: August 27, 2026 Source: Proofpoint 🚨 Proofpoint researchers have recently uncovered a new RAT framework named PackClient. This malware...
A Polymorphic Phishing Page That Occasionally Breaks Itself Source: SANS ISC Date Published: August 27, 2026 But even something that seems to be “run-of-the-mill” at first glance can sometimes tu...
Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments 🚨 Attention all Visa cardholders! Did you know that your expired Visa card could potentially be used for contactless paymen...
New GPUThor Attack Defeats NVIDIA ECC Protection for Root Access A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denia...
Major Cybersecurity Action 🚨 The Justice Department and FBI have announced significant court-authorized domain seizures aimed at disrupting malicious cyber activities. Today, they targeted two hac...