Rosetta Daily · Aug 10, 2026
Scanned 33 sources, selected 20 items from 379 raw records.
Critical Vulnerabilities (CVSS ≥ 8.0)
Fabrik (Joomla extension) unauthenticated RCE — CVE-2026-66915 (CVSS 10.0)
The ajax_calc feature of Fabrik's calc plugin (< 4.6.7) allows an unauthenticated attacker to execute arbitrary code — a maximum-severity flaw.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-66915
Tencent APIJSON SQL injection — CVE-2026-72565 (CVSS 9.8)
Improper handling of the Map-form @having operator in APIJSON ≤ 8.1.8 lets unauthenticated remote attackers bypass per-table access control and read arbitrary database tables.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-72565
deepwiki-open path traversal enables arbitrary file read/write/delete — CVE-2026-72567 (CVSS 9.8)
The api/api.py wiki-cache endpoint builds file paths from unsanitized owner/repo/repo_type fields, letting unauthenticated remote attackers write or delete arbitrary files with root privileges via path traversal.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-72567
fosrl/pangolin cross-organization auth bypass — CVE-2026-72564 (CVSS 9.6)
An improper authorization flaw in pangolin ≤ v1.20.0 lets an authenticated remote attacker reuse an access token issued for a different resource to authenticate to any resource in any organization.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-72564
cube-root/directory-serve path traversal arbitrary file deletion — CVE-2026-72569 (CVSS 9.1)
When run with the --delete option, directory-serve ≤ 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the served directory via path traversal.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-72569
Shenzhen Aitemi M300 Wi-Fi Repeater command injection, public PoC — CVE-2026-19348 (CVSS 8.9)
Flawed sprintf handling in the protocol.csp endpoint allows remote command injection via the enable/name/mac parameters; exploit code is already public.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-19348
Samsung libril_sem.so stack overflow — local privilege escalation — CVE-2026-21068 (CVSS 8.4)
Versions prior to the SMR August 2026 Release 1 contain a stack-based buffer overflow in libril_sem.so, allowing privileged local attackers to execute arbitrary code.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21068
LINE for Windows installer DLL hijacking — CVE-2026-13133 (CVSS 8.4)
LineInst.exe (LINE for Windows, prior to 26.4.0) loads Msftedit.dll via a relative path without a secure DLL search path, letting a malicious DLL in the installer directory load ahead of the legitimate System32 copy.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-13133
Ecovacs DEEBOT PRO M1 / K1VAC leave debug interfaces exposed — CVE-2026-66403 / CVE-2026-66405 (both CVSS 8.7)
Both robot vacuum models leave a debug web server and a telnet service enabled, exposing stored floor-map/log data or allowing direct device login.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-66403
Actively Exploited / CISA KEV
SonicWall SMA1000 flaws now exploited by ransomware gangs — CVE-2026-15409, CVE-2026-15410
CISA confirmed attackers are exploiting recently patched SMA1000 SSRF (maximum severity) and code injection flaws; both are KEV-listed with confirmed ransomware use.
Source: https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/
Progress (Kemp) LoadMaster command injection under active attack — CVE-2026-8037
CISA warns attackers are exploiting this critical-severity command injection flaw; it is KEV-listed — patch internet-facing LoadMaster instances immediately.
Source: https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/
CISA issues #StopRansomware advisory on Gunra ransomware
Gunra, first seen in 2025 and expanded to a ransomware-as-a-service model in 2026, primarily targets government and critical infrastructure with a double-extortion model. CISA recommends prioritizing patching of internet-facing systems, offline immutable backups, and network segmentation.
Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
Notable Emerging Threats
Kimsuky builds an offline AI stack for phishing and malware automation
South Korean firm Genians reports North Korea's Kimsuky group now runs AI offline on its own servers, connects document-search tools to stolen files, and is assembling the software components needed to build AI into its malware.
Source: https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html
New passkey attacks can recover synced private keys or bypass phishing-resistant MFA
Three independent research efforts defeated passkey protections without breaking the underlying cryptography — reusing signed authentication material exposed by Windows and abusing a cloud-synced passkey system via existing malware on the victim's machine.
Source: https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html
Head Mare exploits TrueConf server flaws to deploy PhantomCore malware
Kaspersky reports the threat actor targeted unpatched TrueConf servers at Russian instrumentation, electronics, and energy firms in July 2026, chaining vulnerabilities to replace legitimate client installers with PhantomCore.
Source: https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html
Malicious "Solidity Pro" VS Code extensions steal crypto wallets and credentials
Two extensions (helper-beeps.solidity-pro, web3devtoolsx.solidity-pro) were found delivering a browser wallet and credential stealer; both are gone from Open VSX, but the associated GitHub repo remains a risk.
Source: https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html
AI Security
OpenAI pauses some internal activities on Astra after strong cyber capability evaluation
An internal OpenAI evaluation found the upcoming Astra model showed significant advances in agentic coding and cybersecurity, prompting a pause on related internal activities and new security controls, including isolated environments, for higher-capability models.
Source: https://thehackernews.com/2026/08/openais-next-ai-model-astra-shows-cyber.html
Other Notable Items
LexisNexis takes services offline after suspicious server activity
LexisNexis pulled its Diligence, Metabase API, and Newsdesk services offline in response to unusual activity on servers hosted by an unnamed third-party vendor.
Source: https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/
Valve notifies Steam hardware customers of a data breach
Valve is notifying European Steam hardware customers that their data was stolen after attackers hacked its shipping partner, CEVA Logistics.
Source: https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
1,755 BTC (~$110M) lost overnight due to non-random key generation
Chinese outlet Anquanke reports a "cold storage" wallet compromise traced back to a random-number generator that wasn't truly random — underscoring the importance of auditing key-generation processes.
Source: https://www.anquanke.com/post/id/315945