SOC manager brief
High-signal items — worth prioritizing for SOC triage and manager awareness.
Ranked using headline + RSS summary text (CVEs, incidents, vulns, ransomware, phishing, and related terms). Not a replacement for analyst judgment.
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Sponsored search results lead developers straight into a ClickFix malware trap
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
Patching brief
CVEs, advisories, and patch-focused items from your current feed view — use for patch planning and change windows.
Heuristic filter on headline + RSS summary (CVE patterns, vuln/patch language). Verify severity and applicability in your environment.
CVE-2026-61979
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.
CVE-2026-18963
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.
CVE-2026-21962
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek .
CVE-2026-73570
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
Feed snapshot
Time window
Last 24 hours
Since Mon Aug 24 · 10:29 · UTC
Stories in this view
29
Feeds configured
8
6 source(s) represented below
Time span (local)
10:59 – 10:00
By source
- The Hacker News10
- BleepingComputer9
- SecurityWeek9
- Dark Reading5
- The Register: Security5
- Schneier on Security1
-
Silent Patches Don’t Stop Attackers – They Blind Defenders
SecurityWeek
10:00
-
Crooks push Mac malware through fake OpenAI Codex ads
The Register: Security
09:15
-
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
The Hacker News
08:34
-
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
SecurityWeek, Schneier on Security
08:30
Links (2)
-
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
SecurityWeek, The Hacker News
07:46
Links (2)
-
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
Dark Reading
21:46
-
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
The Register: Security, The Hacker News
21:39
Links (2)
-
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
BleepingComputer
21:14
-
Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks
The Register: Security
21:07
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Dark Reading, The Hacker News
20:51
Links (2)
-
Hackers target WordPress sites in miniOrange auth bypass attacks
BleepingComputer
19:26
-
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
BleepingComputer, SecurityWeek
17:56
Links (2)
-
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
The Hacker News
17:41
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
The Hacker News, BleepingComputer
17:41
Links (2)
-
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
SecurityWeek, BleepingComputer
17:38
Links (2)
-
Iran-linked cyberattack shut down a UK power plant
The Register: Security
16:59
-
Tricky 'SynkLoader' Multitool May Herald Ransomware
Dark Reading
15:02
-
ToxicPanda Android malware uses VPN permissions to block Google Play
Dark Reading, BleepingComputer
14:34
Links (2)
-
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
The Hacker News
14:32
-
Microsoft Teams now lets admins block external bots from meetings
BleepingComputer
14:00
-
South Korean startup platform breach exposes key management failures
BleepingComputer, SecurityWeek
14:00
Links (2)
-
Hired for One Job, Judged on Another: The CISO’s Real Problem
SecurityWeek
14:00
-
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Dark Reading, The Hacker News
14:00
Links (2)
-
Microsoft: August updates break printing, PDF export in WPF apps
BleepingComputer
12:40
-
AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones
The Register: Security
12:32
-
91 Vulnerabilities Patched in Spring Application Framework
SecurityWeek
11:58
-
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
The Hacker News
11:56
-
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
The Hacker News
11:30
-
Venezuelan Gets Record Federal Prison Term for ATM Jackpotting
SecurityWeek
10:59