1. CISA adds actively exploited Gitea code-injection flaw to KEV — CVE-2026-60004 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. SonicWall NetExtender Linux client path traversal allows root file write — CVE-2026-66152 — Cyber Security News — https://cybersecuritynews.com/sonicwall-netextender-vulnerabilities/
3. Chrome 152 patches over 300 flaws, most found internally by AI — CVE-2026-79282 (+300 more) — SecurityWeek — https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/
4. NVIDIA NemoClaw flaw lets a malicious webpage poison a local AI model — CVE-2026-65105 — Cyber Security News — https://cybersecuritynews.com/nvidia-nemoclaw-flaw/
5. Siemens SIMATIC IoT2050 Advanced unauthenticated RCE via Node-RED — CVE-2026-58115 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03
6. Mirage2FA phishing kit bypasses MFA to hijack Microsoft 365 sessions — The Hacker News — https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
7. Malicious npm packages abuse trusted mirrors to host ClickFix phishing — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/
8. Iran-linked actors hide Dindoor backdoor behind the Deno runtime — Cyber Security News — https://cybersecuritynews.com/iran-linked-hackers-abuse-developer-tool/
9. SLEEPWALKER backdoor waits for a magic packet, then runs its own bytecode — The Hacker News — https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html
10. 28,000 exposed .git repositories leak credentials and financial records — Cyber Security News — https://cybersecuritynews.com/28000-exposed-git-repositories/
11. RMM tools abused in 46-country phishing campaign for remote access — Cyber Security News — https://cybersecuritynews.com/hackers-abuse-legitimate-rmm-tools-3/
12. Marimo notebook flaw runs MCP commands before cells execute — CVE-2026-75149, CVE-2026-39987, CVE-2026-67618 — The Hacker News — https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html
13. AWS Strands Agents python_repl consent bypass allows RCE — CVE-2026-78379 — AWS — https://aws.amazon.com/security/security-bulletins/rss/2026-089-aws/
14. Fake Indeed interview apps push Android spyware to job seekers — Malwarebytes Labs — https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware