2026-08-04
2026-08-04 12:00Z
HIGH

How legitimate cloud platforms enable phishers to bypass MFA

Kaspersky Securelist·securelist.com

Kaspersky researchers document a sophisticated multi-stage adversary-in-the-middle (AitM) phishing campaign that exploits legitimate cloud platforms (Cloudflare Workers, Vercel, GitHub Pages, Netlify) to bypass MFA and hijack user sessions. The attack chains a fake CAPTCHA landing page, service worker-based transparent proxy (using Ultraviolet), and browser-in-browser (BitB) UI spoofing to intercept credentials and session tokens. Telemetry from August 2025–July 2026 shows 224,984 unique phishing domains across cloud platforms, with Cloudflare Pages (24.9%), Vercel (13.8%), and GitHub Pages (13.7%) dominating the abuse landscape.

TACTA0001SRFWebSRFCloudTACTA0009SWUltravioletVNDMicrosoftVNDCloudflareVNDVercel
78
Edit Score
2026-08-04
2026-08-04 11:22Z
CRIT

CVE-2026-10050 — Eclipse Jetty: Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10050

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example CVSSv3.1 9.1 (CRITICAL)

CWECWE 303CWECWE 173VNDEclipseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-04
2026-08-04 11:11Z
CRIT

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Rapid7 Research·rapid7.comCVE-2026-18577CVE-2026-18556in the wild0day

CVE-2026-18577 is a critical authentication bypass in N-able N-central RMM platform affecting all versions up to 2026.3.1, allowing unauthenticated remote attackers to gain administrative control. Active exploitation in the wild since August 1, 2026 has been observed using the platform's Take Control feature to pivot to managed endpoints and establish persistence via Cloudflare Tunnel. The vulnerability is a regression from an incomplete fix to CVE-2026-18556 and has been added to CISA's KEV catalog.

SRFApplicationTACTA0001SRFNetworkTACTA0003TACTA0008SWN CentralVNDN AbleTYPVulnerability
92
Edit Score
2026-08-04
2026-08-04 10:19Z
CRIT

CVE-2026-15721 — Cleartext: HUMANIST Digital Human Resources allows SQL Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15721

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 312VNDCleartextTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 10:19Z
CRIT

CVE-2026-14804 — Use: of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14804

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 321TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-04
2026-08-04 10:19Z
CRIT

CVE-2026-14175 — HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14175

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 08:16Z
CRIT

CVE-2026-18754 — Exposure of this private key allows malicious actors to breach the confidentiality and integrity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18754

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. CVSSv3.1 9.1 (CRITICAL)

CWECWE 321TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-04
2026-08-04 08:16Z
CRIT

CVE-2026-18753 — Exposure of this private key allows malicious actors to breach the confidentiality and integrity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18753

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. CVSSv3.1 9.1 (CRITICAL)

CWECWE 321TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-04
2026-08-04 07:16Z
CRIT

CVE-2026-64564 — Linux: In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64564

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_ CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 07:16Z
HIGH

CVE-2026-64562 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64562

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still points to it. But because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU might migrate before the pointer is cleared and __loaded_vmcs_clear() may then execute VMCLEAR. The VMCS needs to stay attached until its explicit VMCLEAR completes, but then it can be hidden and the page safely fre CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 07:16Z
HIGH

CVE-2026-64561 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64561

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 07:16Z
HIGH

CVE-2026-16623 — Create: The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16623

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server. CVSSv3.1 8.0 (HIGH)

CWECWE 94VNDCreateTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-04
2026-08-04 07:16Z
CRIT

CVE-2026-16618 — Improve: The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16618

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDImproveTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 07:16Z
CRIT

CVE-2026-15958 — Easy: The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15958

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses. CVSSv3.1 9.3 (CRITICAL)

CWECWE 862VNDEasyTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-04
2026-08-04 00:17Z
HIGH

CVE-2026-66318 — Origin: validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66318

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 346VNDOriginTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 00:17Z
HIGH

CVE-2026-62870 — Use: after free in Microsoft Office Excel allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62870

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 00:16Z
CRIT

CVE-2026-18686 — Performing a manipulation results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18686

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 00:16Z
CRIT

CVE-2026-18685 — Such manipulation leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18685

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 74CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 00:00Z
INFO

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Elastic Security Labs·elastic.co

Elastic Security Labs published a technical deep-dive on building an AI-powered vulnerability triage agent that processes HackerOne bug bounty submissions at ~$2 per report with 85% agreement to human analyst decisions. The system uses a two-phase architecture (analysis on isolated VM + optional reproduction in sandboxed environment), an eight-stage assessment pipeline with adversarial review, and Elastic-specific triage rules calibrated against 3,300+ historical reports. The post covers threat modeling, defense-in-depth controls against prompt injection and sandbox escape, and lessons learned from iterative calibration.

SRFApplicationTACTA0001TACTA0002SRFCloudSWElasticsearchSWKibanaVNDElasticTYPResearch
72
Edit Score
2026-08-04
2026-08-04 00:00Z
CRIT

2608-volatility-interlock

Sophos X-Ops·news.sophos.comCVE-2026-20131in the wild0day

Sophos EIR investigated an Interlock ransomware attack (tracked as GOLD EMBRACE) where the threat actor abused legitimate DFIR tools—Volatility3 and WinPmem—to dump credentials and conduct memory forensics on a compromised Windows 10 endpoint. The attack chain spanned 26 hours across three days, leveraging ClickFix social engineering, a custom NodeSnake RAT, Kerberoasting, NTLM downgrade attacks, and exploitation of CVE-2026-20131 (Cisco Secure Firewall zero-day) to achieve domain compromise, data exfiltration, and hypervisor lockout.

SRFOsTACTA0004TACTA0005TACTA0001SRFNetworkTACTA0006TACTA0007TACTA0003
82
Edit Score
2026-08-04
2026-08-04 00:00Z
CRIT

N-able N-central exploitation results in RMM tool deployment

Sophos X-Ops·news.sophos.comCVE-2026-18577CVE-2026-18556in the wild0day

N-able N-central RMM platform suffered active zero-day exploitation (CVE-2026-18577), an authentication bypass affecting both hosted and on-premises deployments, beginning July 31, 2026. Threat actors leveraged the vulnerability to deploy multiple RMM tools (AnyDesk, TacticalRMM, TeamViewer, RustDesk, SimpleHelp, HopToDesk, Cloudflare Tunnel) for persistent access, evaded EDR using PhantomKiller, and targeted high-value assets including domain controllers and backup servers. N-able released a hotfix on August 2 after the vulnerability was disclosed on August 1; Sophos CTU identified one compromised customer with no evidence of widespread compromise at time of publication.

SRFApplicationTACTA0004TACTA0001SRFNetworkTACTA0007TACTA0003SWN CentralVNDN Able
88
Edit Score
2026-08-04
2026-08-04 00:00Z
INFO

Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human

Elastic Security Labs·elastic.co

Elastic Security Labs published a technical deep-dive on building an AI-powered vulnerability triage agent for HackerOne bug bounty reports. The system processes reports through an eight-stage analysis pipeline with adversarial review, achieves 85% agreement with human analysts on 764 validation reports, and costs approximately $2 per triage using ephemeral GCP VMs with sandboxed reproduction environments. The architecture separates analysis and reproduction phases for security isolation and includes comprehensive defenses against prompt injection, credential exfiltration, sandbox escape, and data poisoning.

SRFApplicationTACTA0001SRFCloudSWElasticsearchSWKibanaVNDElasticTYPResearchTECT1566
68
Edit Score
2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-48333 — Adobe: Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48333

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-48331 — Adobe: Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-03
2026-08-03 23:16Z
CRIT

CVE-2026-48330 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48330

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 89VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score