Daily Briefing

Cybersecurity & Geopolitics Briefing — Sunday, August 2, 2026

Geopolitical cyber intelligence in 5 minutes
Sunday, August 2, 2026 · 7 stories

This briefing covers 7 cybersecurity and geopolitics stories published around Sunday, August 2, 2026, and 6 disclosed vulnerabilities (CVE-2026-18556, CVE-2026-67305, CVE-2026-67308, CVE-2026-67328 and others). Each entry links to the original reporting.

Share this digest:

Iran-Linked Actors Hit Water Systems Across 7 U.S. States (1 minute read)

Cyberattacks likely tied to Iran compromised water systems in seven states, marking a continued pattern of Iranian targeting of U.S. critical infrastructure. Attacks on water utilities signal escalating willingness to threaten public safety infrastructure, not just data.

Wired Security · 22h ago · Read full article →

CVE-2026-67336: better-auth OIDC Plugin Allows Unsigned Token Acceptance (2 minute read)

CVE-2026-67336 (CVSS 8.7) in better-auth before 1.6.11 lets attackers exploit algorithm negotiation to accept unsigned tokens or intercept OAuth codes via plain PKCE. Any app using the oidcProvider or mcp plugins is exposed to authentication bypass by default configuration.

CVE Feed (High Severity) · 19h ago · Read full article →

CVE-2026-67328: better-auth SSO Flaws Enable Arbitrary Account Takeover (2 minute read)

CVE-2026-67328 (CVSS 8.1) in @better-auth/sso before 1.6.21 allows full account takeover via domain parsing mismatches, unbound SAML assertions, orphaned providers, or reflected XSS. SSO chain vulnerabilities at this severity level threaten every downstream tenant in multi-provider deployments.

CVE Feed (High Severity) · 19h ago · Read full article →

CVE-2026-18556: N-able N-central Exposes Unauthenticated Admin Takeover (1 minute read)

CVE-2026-18556 (CVSS 8.2) allows authentication bypass via alternate path in N-able N-central through version 2026.1, enabling unauthenticated administrative account takeover. N-central's role as an MSP management platform means exploitation gives attackers cascading access to managed customer environments.

CVE Feed (High Severity) · 12h ago · Read full article →

CVE-2026-67342: ArcadeDB CVSS 9.8 Flaw Bypasses All Database Authorization (2 minute read)

CVE-2026-67342 (CVSS 9.8) in ArcadeDB before 26.7.2 allows unauthenticated read and write access to arbitrary databases via unprotected HTTP endpoints for Prometheus, Grafana, batch, and time series handlers. Critical severity with no auth required makes this a priority patch for any internet-exposed ArcadeDB instance.

CVE Feed (High Severity) · 19h ago · Read full article →

CVE-2026-67308: Wazuh GitHub Actions Flaw Leaks CI Secrets via Fork PRs (2 minute read)

CVE-2026-67308 in Wazuh workflows before commit 44bf114 allows shell injection through crafted VERSION.json files in fork pull requests, exposing GITHUB_TOKEN and pipeline secrets. Supply chain risk is high: Wazuh is widely deployed in security operations, making its own CI pipeline a high-value target.

CVE Feed (High Severity) · 19h ago · Read full article →

CVE-2026-67305: FreeRDP Heap Overflow Lets Malicious RDP Server Execute Code (2 minute read)

CVE-2026-67305 in FreeRDP Windows client before 3.29.0 allows a malicious RDP server to trigger heap buffer overflow via oversized CLIPRDR_FILE_CONTENTS_RESPONSE PDUs, potentially enabling remote code execution.

CVE Feed (High Severity) · 19h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now