Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Aug 6, 2026·4m

Cyber Security News for August 6 2026 - Daily DefSec Brief

Show notes

1. JetBrains TeamCity deserialization RCE added to CISA KEV — CVE-2026-63077 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Zbtlink Chinese routers ship a factory backdoor (ENDLESSDOORS) with unauth root shell — The Hacker News / VulnCheck — https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
3. Critical Cisco IMC bug gives root via web interface, public PoC out — CVE-2026-20200, CVE-2026-20272 — Help Net Security — https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/
4. Attackers compile khunt toolkit inside Oracle to reach Windows SYSTEM — The Hacker News / Huntress — https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html
5. keyv/cacheable npm compromise — don't revoke the stolen token first — SANS ISC — https://isc.sans.edu/diary/rss/33218 · Cyber Security News — https://cybersecuritynews.com/new-npm-supply-chain-attack/
6. Paperclip AI control plane unauth RCE — CVE-2026-41679 (also GHSA-x8hx-rhr2-9rf7) — SecurityWeek — https://www.securityweek.com/critical-paperclip-flaw-allowed-admin-access-code-execution/
7. Agent frameworks from AWS, Google, Vercel let attackers trigger tools with no model turn — CVE-2026-18236, CVE-2026-18830, CVE-2026-64650, CVE-2026-64651 — The Hacker News — https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
8. Cisco Secure FMC static-credential flaw, hot fixes out — CVE-2026-20316 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
9. Pre-auth RCE in Bonita and OFBiz enterprise Java servers — CVE-2026-31986 — Help Net Security — https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/
10. OVSwrap Linux kernel flaw gives local users root via Open vSwitch — CVE-2026-64531 — The Hacker News — https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html
11. macOS ClickFix campaign adds browser fingerprinting to hide AMOS lures — Microsoft — https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/ · The Hacker News — https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
12. Kali365 device-code phishing abuses real Microsoft login against US firms — The Hacker News — https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html
13. NullReceiver: npm packages hide C2 IP in empty Ethereum transfers — The Hacker News — https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
14. Apple iCloud Private Relay WebKit flaws leak users' real IP — Cyber Security News — https://cybersecuritynews.com/apple-icloud-private-relay/
15. AI browsers vulnerable to zero-click agent hijacking via hidden instructions — Dark Reading — https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
16. Poison Claude gray-market AI access exposes every prompt to the operator — The Hacker News — https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html · Help Net Security — https://www.helpnetsecurity.com/2026/08/06/ai-model-access-fraud-gray-market/