August 2026 (30)
Critical RCE and Information Disclosure Vulnerability in Gitea
1 TTPGitea contains a critical vulnerability allowing remote, unauthenticated attackers to execute arbitrary code and gain unauthorized access to sensitive information.
Multiple Vulnerabilities in pgAdmin
2 TTPsMultiple vulnerabilities in pgAdmin enable unauthenticated or authenticated remote attackers to execute arbitrary code, conduct SQL injection, bypass security controls, and perform unauthorized data access.
Detection of Background Utility Usage for Process Execution on Linux
1 rule 2 TTPsAdversaries leverage Linux background utilities such as setsid, nohup, and disown to execute processes in new sessions, enabling them to ignore termination signals and decouple malicious tasks from parent process trees.
Detection of External IP Discovery via Curl on macOS
1 rule 1 TTP 1 IOCThreat actors utilize curl or nscurl on macOS to query public IP geolocation services for reconnaissance, enabling them to assess network context and stage follow-on malicious activity.
Apple Security Updates — August 2026
Roundup of Apple security advisories published in August 2026.
Suspicious Cross-User Process Spawning Behavior
1 rule 2 TTPsDetection of common user-space applications being spawned under different user contexts, which often indicates privilege escalation testing or sacrificial process execution.
Detection of Suspicious Offline Registry Library Usage
1 rule 1 TTPDetection of unauthorized processes loading offreg.dll to perform direct registry hive modification, potentially bypassing standard Windows Registry auditing.
Suspicious Staging of Windows Registry Hive Files
1 rule 2 TTPsDetection of registry hive files created outside of standard user profile directories, a common indicator of unauthorized hive manipulation for credential access or persistence.
Detection of Suspicious Explicit Credential Local Logon
1 rule 1 TTPDetection logic for monitoring Windows Event ID 4648 to identify potential privilege escalation through unauthorized explicit credential usage.
Suspicious Microsoft Office Child Process Activity
1 rule 3 TTPs 1 CVEMicrosoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.
Incorrect Default Permissions in Synology Assistant
1 CVESynology Assistant versions prior to 7.0.7-50095 contain a vulnerability allowing local users to perform arbitrary file operations and trigger denial-of-service during the installation process.
Stack-based Buffer Overflow in Wavlink WL-NU516U1 nas.cgi
4 TTPs 1 CVEA stack-based buffer overflow vulnerability in the nas.cgi file of Wavlink WL-NU516U1 routers allows remote, unauthenticated attackers to execute arbitrary code via a malicious CONTENT_LENGTH argument.
Diffusers TOCTOU Vulnerability Leads to Remote Code Execution
2 rules 1 TTP 3 CVEsA Time-of-Check Time-of-Use (TOCTOU) vulnerability in the `diffusers` package allows arbitrary code execution via a race condition when loading pipelines from the Hugging Face Hub, bypassing trust checks.
WordPress Redsys Payment Gateway Plugin Vulnerable to Payment Forgery (CVE-2026-5050)
2 rules 1 TTP 1 CVE 1 IOCThe Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to cryptographic signature forgery, allowing unauthenticated attackers to mark pending orders as paid by forging payment callback data in versions up to 7.0.0.
Critical Unauthenticated RCE in Realtyna WPL Real Estate Plugin
1 rule 2 TTPs 1 CVE 1 IOCA critical unauthenticated remote code execution vulnerability, CVE-2026-13714, in Realtyna WPL Real Estate and Organic IDX plugins allows attackers to upload arbitrary PHP shells via the I/O API.
SQL Injection in PyAthena DefaultParameterFormatter
1 TTP 1 CVEUnauthenticated attackers can achieve arbitrary SQL execution in PyAthena versions prior to 3.35.4 by exploiting improper quote-escaping within the DefaultParameterFormatter.format() function.
Authentication Bypass and Privilege Escalation in Vikunja API
1 TTP 1 CVEVikunja versions 0.22.0 through 2.3.0 contain an authentication bypass vulnerability allowing attackers to impersonate users and manage their API tokens via manipulated link-share JWTs.
Heap-based Buffer Overflow in FreeRDP Windows Clipboard Client
1 CVEA heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows a malicious RDP server to execute an out-of-bounds write in the memory of a paste consumer process when handling clipboard file transfers.
ArcadeDB Privilege Escalation via JavaScript Triggers
1 rule 3 TTPs 1 CVEArcadeDB versions before 26.7.3 insecurely expose the LocalDatabase object to JavaScript triggers, allowing attackers with schema update permissions to perform unauthorized administrative actions.
Insecure Direct Object Reference in better-auth passkey
1 rule 1 TTP 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability (CVE-2025-71400) in better-auth passkey versions before 1.4.0 allows authenticated users to delete arbitrary passkeys by enumerating IDs.
Better Auth Path Normalization Vulnerability (CVE-2025-71399)
1 CVEBetter Auth versions prior to 1.4.5 contain a path normalization vulnerability in the rou3 library that allows attackers to bypass disabledPaths configurations and rate limits via URL path manipulation.
Local Privilege Escalation in PackageKit via TOCTOU Race Condition
1 TTP 1 CVECVE-2026-41651 is a local privilege escalation vulnerability in PackageKit that allows unprivileged users to execute arbitrary packages as root by bypassing PolKit via a TOCTOU race condition.
Gitea Actions Fork Pull Request Approval Gate Bypass
4 TTPs 1 CVE 1 IOCA vulnerability in Gitea Actions (versions v1.20.0 and later) allows an unprivileged attacker to permanently bypass the fork pull request approval gate for a repository after a single, initial workflow approval, enabling arbitrary shell command execution on the Gitea Actions runner without further maintainer interaction, leading to source code disclosure and potential system compromise.
Directory Traversal Vulnerability in User Access Manager for WordPress
1 rule 2 TTPs 1 CVEAn unauthenticated directory traversal vulnerability in the User Access Manager WordPress plugin (CVE-2026-18352) allows attackers to read arbitrary files by bypassing access controls via the uamgetfile parameter.
Arbitrary File Read Vulnerability in CubeWP Framework
2 TTPs 1 CVEAn unauthenticated directory traversal vulnerability in the CubeWP Framework plugin allows attackers to read arbitrary files by leveraging exposed AJAX nonces.
Authentication Bypass Vulnerability in WooCommerce Social Login Plugin
2 TTPs 1 CVEThe WooCommerce - Social Login plugin for WordPress contains an authentication bypass vulnerability (CVE-2026-8457) that allows unauthenticated attackers to log in as any user, including administrators, via forged Apple ID tokens.
Autonomous AI Agents Pose New Supply Chain and Data Exfiltration Risks
4 TTPs 16 IOCsThis content introduces AI Detection and Response (AIDR) as a new cybersecurity category to address emerging threats from autonomous AI agents, including supply chain attacks and unintended data sharing, highlighting their ability to execute with inherited privileges across endpoints, SaaS, and cloud environments.
Authentication Bypass in Single Sign On For TNG WordPress Plugin
1 rule 1 CVE 1 IOCAn unauthenticated password reset vulnerability in the Single Sign On For TNG plugin (CVE-2026-15964) allows attackers to perform full site takeover by bypassing AJAX nonce protections.
ClickFix Campaign Activity
16 IOCsTracking brief for the ClickFix campaign; individual sightings are folded in as reported.
Heap Out-of-Bounds Read in FreeRDP Glyph Caching
1 TTP 1 CVEFreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.