Daily Briefing

Cybersecurity & Geopolitics Briefing — Sunday, August 23, 2026

Geopolitical cyber intelligence in 5 minutes
Sunday, August 23, 2026 · 12 stories

This briefing covers 12 cybersecurity and geopolitics stories published around Sunday, August 23, 2026, and 9 disclosed vulnerabilities (CVE-2026-0551, CVE-2026-12710, CVE-2026-16149, CVE-2026-4703 and others). Each entry links to the original reporting.

Share this digest:

Expired Visa Cards Can Be Zombified for Unauthorized Contactless Payments (1 minute read)

Researchers demonstrate that expired Visa cards retain contactless payment capability, enabling unauthorized transactions without cardholder knowledge; Apple simultaneously issued an unprecedented volume of mercenary spyware alerts.

Wired Security · 21h ago · Read full article →

Supply-Chain Attack Turns Android Car Head Units Into Proxy Botnet Nodes (1 minute read)

Unknown threat actors trojanized a legitimate Android device-update app to deploy malware on car head units, enlisting them in a proxy botnet or ad-fraud network.

BleepingComputer · 17h ago · Read full article →

Manic, Grandoreiro, ToxicPanda 2.0 Banking Trojans Expand Global Reach (1 minute read)

Three active banking trojan campaigns — spyware-laden Manic, Grandoreiro hitting Latin America and Europe, and an upgraded ToxicPanda 2.0 — are targeting financial sector victims simultaneously.

SecurityWeek · 23h ago · Read full article →

CVE-2026-78050: Comfast CF-N1-S Stack Overflow Exploit Goes Public (2 minute read)

A remotely exploitable stack-based buffer overflow in Comfast CF-N1-S 2.6.0.1's web management NTP handler (CVE-2026-78050) is now publicly disclosed with working exploit code. Consumer-grade router flaws with public exploits are primary recruitment vectors for IoT botnets.

CVE Feed (High Severity) · 7h ago · Read full article →

CVE-2026-77946: TRENDnet TEW-821DAP NTP Handler Enables Remote Stack Overflow (2 minute read)

CVE-2026-77946 exposes a stack-based buffer overflow in TRENDnet TEW-821DAP 2.2.01b05 via manipulated NTP timezone configuration arguments, exploitable remotely. Unpatched SOHO routers with network-accessible management interfaces remain low-friction entry points for botnet operators.

CVE Feed (High Severity) · 20h ago · Read full article →

CVE-2026-16149: WordPress Security Hardener Plugin Enables Privilege Escalation (3 minute read)

CVE-2026-16149 lets subscriber-level authenticated users escalate privileges in Security Hardener plugin ≤2.4.4 by exploiting a permission_callback overwrite on the /wp/v2/users REST endpoint.

CVE Feed (High Severity) · 7h ago · Read full article →

CVE-2026-0551: WordPress PPWP Plugin Exposes PHP Object Injection to Contributors (4 minute read)

CVE-2026-0551 allows contributor-level authenticated attackers to inject PHP objects via deserialization in PPWP – Password Protect Pages ≤1.9.18. No POP chain is currently known, but plugin-chaining attacks routinely weaponize such primitives post-disclosure.

CVE Feed (High Severity) · 7h ago · Read full article →

CVE-2026-4703: Unauthenticated PHP Object Injection Hits WS Form LITE Plugin (4 minute read)

CVE-2026-4703 exposes WordPress sites running WS Form LITE ≤1.10.80 to unauthenticated PHP object injection via form submission metadata deserialization. Zero authentication required lowers exploitation threshold significantly; risk escalates sharply if a viable POP chain surfaces in any co-installed plugin.

CVE Feed (High Severity) · 15h ago · Read full article →

CVE-2026-71513: NLTK AllowlistUnpickler Bypass Enables Remote Code Execution (2 minute read)

CVE-2026-71513 allows remote code execution in NLTK 3.10.0–3.10.2 by bypassing AllowlistUnpickler through dotted-name attribute traversal, triggered when loading a malicious TransitionParser model.

CVE Feed (High Severity) · 17h ago · Read full article →

CVE-2026-60084: SiYuan Before v3.7.4 Allows Arbitrary Host Filesystem Deletion (2 minute read)

CVE-2026-60084 lets authenticated admin attackers pass absolute paths to SiYuan's /api/search/removeTemplate endpoint, triggering recursive deletion of any host filesystem directory via os.RemoveAll.

CVE Feed (High Severity) · 18h ago · Read full article →

CVE-2026-59808: AVideo Auth Bypass Grants Admin Account Takeover via Video Hash (2 minute read)

CVE-2026-59808 in AVideo through commit 9c39d8c8 lets any user with upload permission retrieve an administrator's video_id_hash and convert it into a passwordless admin login session. The flaw requires only a standard upload account, making full platform takeover trivially accessible to low-privilege attackers.

CVE Feed (High Severity) · 18h ago · Read full article →

CVE-2026-12710: Critical Google Cloud Auth Flaw Exposes Internal Data (2 minute read)

A missing authorization bug (CVE-2026-12710, CVSS 9.3) in Google Cloud Application Integration's QueryEngineTask exposed sensitive internal data to unauthenticated external attackers across versions spanning April 2025–April 2026.

CVE Feed (High Severity) · 22h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now