This briefing covers 9 cybersecurity and geopolitics
stories published around Sunday, August 9, 2026,
and 8 disclosed vulnerabilities
(CVE-2026-71945, CVE-2026-71947, CVE-2026-71955, CVE-2026-71956 and others).
Each entry links to the original reporting.
Flock Safety plans rideshare dashcam networks and law-enforcement behavioral coaching tools; separately, water utility breaches hit a dozen U.S. states, a missile-parts supplier was phished, and a ransomware operator received a 16-year sentence.
MSI Radix AXE6600 firmware v781521 carries a CVSS 9.8 command injection flaw in the openvpn function, granting remote attackers root via the macfilter interface. Unpatched SOHO routers remain a preferred initial-access vector for state and criminal actors alike.
MSI Radix AXE6600 firmware v781521 contains a CVSS 9.8 command injection in the TelnetSSH configuration interface, enabling unauthenticated remote root execution. A second critical flaw in the same firmware batch signals systemic input-validation failure across the device.
Unsanitized pin2g, pin5g, and pin6g parameters in MSI Radix AXE6600 firmware v781521's wps.cgi enable CVSS 9.8 remote code execution with root privileges. Three critical CVEs in one firmware version raises patch-urgency for any network using this router.
D-Link DWR-M961 hardware C1 running firmware 1.1.2_C1_202602110044 has a CVSS 9.8 buffer overflow in quicksetup.cgi exploitable via test4, ssid2, and username fields for arbitrary code execution or device crash.
D-Link DWR-M961 firmware 1.1.2_C1_202602110044 allows CVSS 9.8 root-level command injection through the netDig.ping.dst field in app.cgi. Combined with co-disclosed flaws, this device's attack surface makes it an immediate liability for any network perimeter.
Four unsanitized fields in D-Link DWR-M961's /boafrm/formWsc interface enable CVSS 9.8 remote command execution with root privileges on firmware 1.1.2_C1_202602110044. The cluster of critical flaws across multiple interfaces suggests a systemic lack of input validation in this firmware branch.
D-Link DWR-M961 firmware before 1.1.5_C1_202607071108 has a CVSS 9.8 command injection in /boafrm/formTracerouteDiagnosticRun via host and ipVer fields, granting root. The existence of a patched version (1.1.5) confirms exploitability; unpatched devices remain fully exposed.
D-Link DWR-M961 firmware before 1.1.5_C1_202607071108 allows root command injection via the fota_url field in the LTE FOTA upgrade interface, CVSS 9.8. Weaponizing a firmware-update pathway is particularly dangerous as it implies persistent, privileged access to cellular-connected edge devices.