2026-08-13
2026-08-13 08:00Z
HIGH

Armored Likho expands its cyber-espionage toolkit

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed a new cyber-espionage campaign by Armored Likho (Eagle Werewolf) targeting Russian individuals and organizations using a fake donation app dropper written in Rust/Tauri. The campaign deploys two new malware components—Still Sync (Telegram session stealer and data exfiltrator) and Still Audio (covert audio surveillance implant)—both written in Rust with gRPC C2 communication and sophisticated anti-forensics techniques including SeBackupPrivilege abuse and Dead Drop Resolver fallback mechanisms.

SRFApplicationTACTA0005SRFMobileTACTA0001TACTA0002TACTA0007TACTA0003TACTA0009
82
Edit Score
2026-08-13
2026-08-13 06:17Z
HIGH

CVE-2026-18945 — Helper: The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18945

The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be e CVSSv3.1 8.2 (HIGH)

CWECWE 639VNDHelperTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 06:17Z
CRIT

CVE-2026-14182 — Customer: The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14182

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDCustomerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 03:16Z
HIGH

CVE-2026-0298 — Paloaltonetworks Globalprotect: An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0298

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected. CVSSv3.1 8.1 (HIGH) · EPSS 8th percentile

CWECWE 94VNDPaloaltonetworksTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 03:16Z
HIGH

CVE-2026-0297 — Paloaltonetworks Globalprotect: A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0297

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux). CVSSv3.1 8.1 (HIGH) · EPSS 6th percentile

CWECWE 787VNDPaloaltonetworksTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 00:17Z
CRIT

CVE-2026-49819 — UpSnap: Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser`

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49819

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers > 0` count check — a condition that is false on every fresh install — allowing an unauthenticated network-adj CVSSv3.1 9.8 (CRITICAL)

CWECWE 862CWECWE 269CWECWE 306CWECWE 78VNDUpsnapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 00:17Z
HIGH

CVE-2026-49473 — When an application defines separate actions for overlapping path prefixes with different authorization requirements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49473

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain circumstances, the middleware matches incoming requests against Cedar action mappings using req.originalUrl, which includes the query string, while Express rout CVSSv3.1 8.8 (HIGH)

CWECWE 863CWECWE 436TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 00:17Z
CRIT

CVE-2026-16770 — PDF: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16770

PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every <meta name="pdf-webkit-KEY" content="VALUE"> element in the document head through _pdf_webkit_meta_tags and turns each one into a wkhtmltopdf command line option. KEY is normalized to an option name matching --[a-z0-9-]+ but is not checked against an allow list, VALUE is passed through unch CVSSv3.1 9.8 (CRITICAL)

CWECWE 88VNDPdfTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 23:17Z
CRIT

CVE-2026-71193 — OpenStack: An authenticated user can bypass these checks by scheduling a zone to a different

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71193

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA resp CVSSv3.1 9.6 (CRITICAL)

CWECWE 863VNDOpenstackTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-12
2026-08-12 23:17Z
CRIT

CVE-2026-49481 — UpSnap: Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49481

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be inserted into the wake_cmd and shutdown_cmd templates and executed via /bin/sh -c (Linux) or cmd /C (Windows) without sanitization, resulting in an authenticated Remote Code Execution (RCE). A low-privi CVSSv3.1 9.6 (CRITICAL)

CWECWE 78VNDUpsnapTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-12
2026-08-12 22:17Z
CRIT

CVE-2026-73519 — WolfStack: before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73519

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node's management port to enumerate all Docker and LXC containers on the host and execute arbitrary CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDWolfstackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 22:17Z
CRIT

CVE-2026-73501 — kin-openapi is a Go project for handling OpenAPI files.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73501

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail- CVSSv3.1 9.1 (CRITICAL)

CWECWE 287TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-12
2026-08-12 22:17Z
HIGH

CVE-2026-71473 — A user with specific administrative permissions on a managed cluster can exploit a vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71473

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially compromising its integrity. CVSSv3.1 8.5 (HIGH)

CWECWE 915TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-12
2026-08-12 22:17Z
CRIT

CVE-2026-71471 — This allows the attacker to deploy an arbitrary container image across all managed clusters.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71471

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the CVSSv3.1 9.0 (CRITICAL)

CWECWE 829TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-12
2026-08-12 22:17Z
CRIT

CVE-2026-18749 — The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18749

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case. CVSSv3.1 9.8 (CRITICAL)

CWECWE 639TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 22:17Z
HIGH

CVE-2026-17485 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17485

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. CVSSv3.1 8.2 (HIGH)

CWECWE 125VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 22:17Z
HIGH

CVE-2026-10534 — IBM: Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10534

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-12
2026-08-12 22:17Z
CRIT

CVE-2024-27253 — IBM: DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-27253

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. CVSSv3.1 10.0 (CRITICAL)

CWECWE 287VNDIbmTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 22:00Z
INFO

From P-Code to GNN: extract binary code semantics

Quarkslab·blog.quarkslab.com

Quarkslab published pcode_graph, a Python library for extracting semantic graphs from binary code using P-Code intermediate representation and Graph Neural Networks (GNNs). The post demonstrates function similarity detection across architectures and compilers using the CISCO TALOS dataset, detailing the graph construction pipeline, GNN architecture (GINE), and supervised contrastive loss training methodology.

SRFApplicationSWGhidraSWPcode GraphSWPytorchTYPResearchTYPToolSTGDiscoveryTECT1027
72
Edit Score
2026-08-12
2026-08-12 21:47Z
INFO

v9.6.0-rc3

BloodHound releases·github.com

BloodHound v9.6.0-rc3 release candidate published with two bug fixes: explicit column handling in identity role/permission reads for deleted_at field (BED-9237) and a dependency bump to dawgs v0.7.0 (BED-8967). This is a pre-release candidate with 14 commits since the previous rc2 tag.

SWBloodhoundVNDSpecteropsTYPTool
25
Edit Score
2026-08-12
2026-08-12 21:17Z
CRIT

CVE-2026-66898 — LXD: A path traversal vulnerability in LXD allows an attacker to manipulate file system paths

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66898

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDLxdTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-19004 — MongoDB: This may result in process termination, disclosure of process memory, or, under certain conditions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19004

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDMongodbTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-19002 — A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19002

A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended CVSSv3.1 8.1 (HIGH)

CWECWE 120TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-12
2026-08-12 21:17Z
CRIT

CVE-2026-19001 — MongoDB: This may result in memory corruption within the calling application's process, leading to abnormal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19001

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDMongodbTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-12
2026-08-12 21:17Z
HIGH

CVE-2026-16033 — LXD: A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16033

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDLxdTYPVulnerability
8.5
CVSS v3.1
93
Edit Score