Infosec Trending Feed

Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.

Updated on: 5:41 AM IST, 09 Aug 2026 (9 hour(s) ago)

Cyber-Intelligence Sweep — Last 24 Hours

Sweep window: Aug 7, 2026 ~24:00 UTC – Aug 8, 2026 ~24:00 UTC Note: Sources with no updates in the window are marked SKIPPED per execution parameters.

HackerOne Hacktivity (Recently Disclosed Reports)

Medium.com (Tag: BugBounty & InfosecWriteups)

Pentest-Report.com & getdisclosed.com Aggregators

  • SKIPPED — pentest-report.com did not resolve during the sweep (dead/defunct aggregator); getdisclosed.com ("Disclosed" newsletter) publishes weekly and its most recent drop was April 20, 2026, so no content falls inside the 24-hour window.

Intigriti 'BugBytes' & YesWeHack Blog Writeups

  • SKIPPED — Intigriti BugBytes is a monthly digest (latest: #238, July 31, 2026, no 24h activity); YesWeHack blog's newest post "PimpMyCaido #1: Hunt client-side vulnerabilities with DOMLogger++" was published August 6, 2026, outside the 24-hour window.

GitHub: arkadiyt/bounty-targets-data (Recent Changes)

Twitter/X

Twitter/X (#CVE #0day #infosec)

Reddit (r/netsec)

Lobste.rs & Mastodon Infosec.exchange

Telegram/Discord (vx-underground / PayloadsAllTheThings)

The Hacker News

BleepingComputer

Risky Business

SecurityWeek

DataBreaches.net

Hacker News (YC)

NIST NVD / CVE MITRE (Critical CVSS, Published 2026-08-08)

  • CVE-2026-71991 - CVSS 9.8 command injection in the TelnetSSH function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71990 - CVSS 9.8 command injection in the SSH configuration of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71989 - CVSS 9.8 command injection in the porTrigger function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71988 - CVSS 9.8 command injection in the portFw function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71987 - CVSS 9.8 command injection in the alg function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71986 - CVSS 9.8 command injection in the dmz function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71985 - CVSS 9.8 command injection in the accesscontrol function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71984 - CVSS 9.8 command injection in the urlfilter function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
  • CVE-2026-71983 - CVSS 9.8 command injection in the wps.cgi interface of MSI Radix AXE6600 router firmware v781521 via unsanitized pin2g/pin5g/pin6g parameters.
  • CVE-2026-71958 - CVSS 9.8 buffer overflow in quicksetup.cgi (test4/ssid2/username fields) on D-Link DWR-M961 router v1.1.2_C1_202602110044 enabling remote RCE or crash.
  • CVE-2026-71957 - CVSS 9.8 buffer overflow in app.cgi netAcc.addlist[].name on D-Link DWR-M961 router enabling remote RCE or crash.
  • CVE-2026-71956 - CVSS 9.8 command injection in app.cgi netDig.ping.dst on D-Link DWR-M961 router resulting in root command execution.
  • CVE-2026-71955 - CVSS 9.8 command injection in /boafrm/formWsc (localPin/targetAPSsid/peerPin/peerRptPin) on D-Link DWR-M961 router resulting in root execution.
  • CVE-2026-71954 - CVSS 9.8 command injection in /boafrm/formL2tpv3ConfigSetup (tunnelid/sessionid) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71953 - CVSS 9.8 command injection in /boafrm/formNtp (ntpServerIp1) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71952 - CVSS 9.8 command injection in /boafrm/formPinManageSetup (oldPIn) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71951 - CVSS 9.8 command injection in /boafrm/formIMEISetup (IMEI_value) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71950 - CVSS 9.8 command injection in /boafrm/formSmsManage (action_value) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71949 - CVSS 9.8 command injection in /boafrm/formUSSDSetup (ussdValue/selectMenuValue) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71948 - CVSS 9.8 command injection in /boafrm/formDebugDiagnosticRun (host) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71947 - CVSS 9.8 command injection in /boafrm/formTracerouteDiagnosticRun (host/ipVer) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71946 - CVSS 9.8 command injection in /boafrm/formPingDiagnosticRun (host) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71945 - CVSS 9.8 command injection in /boafrm/formLtefotaUpgradeFibocom (fota_url) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-71944 - CVSS 9.8 command injection in /boafrm/formLtefotaUpgradeQuectel (fota_url) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
  • CVE-2026-14526 - CVSS 9.8 unauthenticated authorization bypass in WordPress AI Copilot – Content Generator <=1.5.6 allowing admin account creation and full site takeover.

PoC-in-GitHub (motikan2010.net)

  • PoC-in-GitHub Auto Update 2026/08/08 18:50:04 - Latest daily PoC aggregation commit (2026-08-08) reflecting newly discovered GitHub repos for CVE-2024-56426, CVE-2020-1472 (Zerologon), CVE-2021-33044 (Dahua unauth login), CVE-2019-14287 (sudo LPE), CVE-2023-25690, CVE-2022-32832, CVE-2021-26855, CVE-2019-1040, CVE-2017-20165, and CVE-2012-2459.
  • CVE-2024-56426 PoC - PoC repository for CVE-2024-56426 was actively pushed on 2026-08-08.
  • CVE-2020-1472 Zerologon PoC - Zerologon proof-of-concept repo received activity on 2026-08-08.
  • CVE-2019-14287 sudo LPE write-up - Sudo privilege-escalation write-up repository created 2026-08-08.

GitHub Advisory Database (Advisories List, newly created)

GitHub Search ('CVE-2026' OR 'CVE-2025' created:2026-08-09)

Exploit-DB

Packet Storm Security (New Exploits)

GhostTroops/TOP (Trending Offensive Projects, updated within last 24-48h)

GitHub Trending (Security Topic)

CTFtime.org (Upcoming)

Infosec-Conferences.com

LinkedIn/Indeed Jobs (Last 24h)


⚠️ This content is automatically collected by an AI bot from public web sources and may contain inaccuracies.


Developed by @win3zz