This briefing covers 7 cybersecurity and geopolitics
stories published around Sunday, August 2, 2026,
and 6 disclosed vulnerabilities
(CVE-2026-18556, CVE-2026-67305, CVE-2026-67308, CVE-2026-67328 and others).
Each entry links to the original reporting.
Cyberattacks likely tied to Iran compromised water systems in seven states, marking a continued pattern of Iranian targeting of U.S. critical infrastructure. Attacks on water utilities signal escalating willingness to threaten public safety infrastructure, not just data.
CVE-2026-67336 (CVSS 8.7) in better-auth before 1.6.11 lets attackers exploit algorithm negotiation to accept unsigned tokens or intercept OAuth codes via plain PKCE. Any app using the oidcProvider or mcp plugins is exposed to authentication bypass by default configuration.
CVE-2026-67328 (CVSS 8.1) in @better-auth/sso before 1.6.21 allows full account takeover via domain parsing mismatches, unbound SAML assertions, orphaned providers, or reflected XSS. SSO chain vulnerabilities at this severity level threaten every downstream tenant in multi-provider deployments.
CVE-2026-18556 (CVSS 8.2) allows authentication bypass via alternate path in N-able N-central through version 2026.1, enabling unauthenticated administrative account takeover. N-central's role as an MSP management platform means exploitation gives attackers cascading access to managed customer environments.
CVE-2026-67342 (CVSS 9.8) in ArcadeDB before 26.7.2 allows unauthenticated read and write access to arbitrary databases via unprotected HTTP endpoints for Prometheus, Grafana, batch, and time series handlers. Critical severity with no auth required makes this a priority patch for any internet-exposed ArcadeDB instance.
CVE-2026-67308 in Wazuh workflows before commit 44bf114 allows shell injection through crafted VERSION.json files in fork pull requests, exposing GITHUB_TOKEN and pipeline secrets. Supply chain risk is high: Wazuh is widely deployed in security operations, making its own CI pipeline a high-value target.
CVE-2026-67305 in FreeRDP Windows client before 3.29.0 allows a malicious RDP server to trigger heap buffer overflow via oversized CLIPRDR_FILE_CONTENTS_RESPONSE PDUs, potentially enabling remote code execution.