1. Max-severity Entra ID flaw exploited before patch — CVE-2026-69836 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/
2. TrueConf Server code injection added to CISA KEV — CVE-2026-72530 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
3. TrueConf Server missing-auth flaw added to KEV, due Aug 23 — CVE-2026-72529 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
4. Elementor Pro file-upload unauthenticated RCE — CVE-2026-32475 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/
5. Spring Security embedded LDAP admin-access flaw — CVE-2026-59270 — Cyber Security News — https://cybersecuritynews.com/spring-security-flaw-access-ldap-servers/
6. Three suspected Russian clusters abuse OAuth/auth flows — Google Threat Intel — https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/
7. Malware commands hidden in FTP server banners (E4del, PINHOLE) — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/
8. CDN Tsunami HTTP/3-to-HTTP/1.1 DoS amplification — CVE-2026-14456 — The Hacker News — https://thehackernews.com/2026/08/cdn-tsunami-abuses-http3.html
9. Signed Defender BTR.sys driver repurposed for kernel bypass — The Hacker News — https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html
10. containerd CRI plugin flaws enable cross-pod RCE — CVE-2026-50195, CVE-2026-53488, CVE-2026-53489, CVE-2026-53492, CVE-2026-47262 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/
11. Redshift JDBC driver runs arbitrary classes from URL params — CVE-2026-8178 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-028-aws/
12. N-able Passportal flaw exposes vault master keys — Dark Reading — https://www.darkreading.com/vulnerabilities-threats/n-able-bug-password-vault-master-keys
13. Peer2Profit proxyware turns employee device into internal proxy — Cyber Security News — https://cybersecuritynews.com/bandwidth-sharing-app/
14. Atlassian and Splunk patch 250+ vulnerabilities — SecurityWeek — https://www.securityweek.com/atlassian-splunk-patch-dozens-of-critical-high-severity-vulnerabilities/