Infosec Trending Feed
Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.
Updated on: 5:41 AM IST, 09 Aug 2026
(9 hour(s) ago)
Cyber-Intelligence Sweep — Last 24 Hours
Sweep window: Aug 7, 2026 ~24:00 UTC – Aug 8, 2026 ~24:00 UTC Note: Sources with no updates in the window are marked SKIPPED per execution parameters.
HackerOne Hacktivity (Recently Disclosed Reports)
- Adding phone number to profile By OTP brute forcing — CoinMate.io - OTP brute-force via request interception allows attaching any phone number to a victim's profile (Medium, $100, disclosed ~15 hrs ago).
- URL API: triple-slash parses path segment as hostname — curl - Incorrectly-resolved name/reference issue where the URL API treats a triple-slash path segment as a hostname (Medium severity, disclosed ~1 day ago).
Medium.com (Tag: BugBounty & InfosecWriteups)
- Breaking Into an Admin Panel With Zero Credentials — Om Mishra - Deep dive into Execution After Redirect (EAR), a vulnerability class hiding behind a universally trusted status code (published within the last 24h window per the InfosecWriteups tag feed).
- tryhackme — do not disturb — day 07 — Nanashi Bx2 - TryHackMe "Do Not Disturb" (Boot2Root, Medium) day-07 walkthrough posted ~3 days ago; flagged as borderline but included as the freshest non-24h item on the tag feed — verify if strict cutoff needed.
Pentest-Report.com & getdisclosed.com Aggregators
- SKIPPED — pentest-report.com did not resolve during the sweep (dead/defunct aggregator); getdisclosed.com ("Disclosed" newsletter) publishes weekly and its most recent drop was April 20, 2026, so no content falls inside the 24-hour window.
Intigriti 'BugBytes' & YesWeHack Blog Writeups
- SKIPPED — Intigriti BugBytes is a monthly digest (latest: #238, July 31, 2026, no 24h activity); YesWeHack blog's newest post "PimpMyCaido #1: Hunt client-side vulnerabilities with DOMLogger++" was published August 6, 2026, outside the 24-hour window.
GitHub: arkadiyt/bounty-targets-data (Recent Changes)
- bounty-targets: Orective Kinging (08-08-2026 23:30) — commit 3608b74 - Scheduled update modifying README.md and data/hackerone_data.json with fresh HackerOne program scope data.
- bounty-targets: Clumplike Excuses (08-08-2026 22:30) — commit 174a913 - Scheduled data-refresh commit touching the aggregated bounty targets dataset.
- bounty-targets: Wireman Lightsman (08-08-2026 22:00) — commit 279777e - Scheduled data-refresh commit touching the aggregated bounty targets dataset.
- Note: The repo's automated scraper pushed ~30 commits within the last 24 hours, roughly on the hour (…:00 / …:30 UTC), consistently updating README.md and data/hackerone_data.json with newly scraped program scope data.
Twitter/X
- CVE-2026-64638 Pre-auth XSS in WordPress Login - Researchers disclosed a CVSS 8.9 pre-authentication cross-site scripting vulnerability affecting default WordPress login screens.
Twitter/X (#CVE #0day #infosec)
- Active Exploitation of SOGo Webmail XSS - CERT/CC issued alerts regarding CVE-2026-8496 concerning active exploitation of SOGo webmail via malicious calendar invites.
Reddit (r/netsec)
- Q3 2026 Information Security Hiring Thread - The community posted its official quarterly thread connecting employers and professionals across the cybersecurity industry.
Lobste.rs & Mastodon Infosec.exchange
- Security Vulnerability Tracking on Lobste.rs - Community members discussed recent disclosures and mitigation strategies for emerging software vulnerabilities.
Telegram/Discord (vx-underground / PayloadsAllTheThings)
- VX-API Malware Development Functionality Updates - The repository received code updates adding malicious functional modules to assist in malware research and development.
The Hacker News
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems - N-able released a critical hotfix for N-central following the exploitation of CVE-2026-18577 which granted attackers persistent administrative access.
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords - Researchers discovered novel CSS-based techniques that can spoof sign-in pages and capture passwords in major webmail services like Outlook and Gmail.
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Attacks - CISA added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037) to its Known Exploited Vulnerabilities catalog.
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data - A prompt injection vulnerability in Atlassian Rovo AI could allow attackers to exfiltrate sensitive data from Jira and Confluence environments.
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication - A CVSS 10.0 SQL injection zero-day in Metabase is being actively exploited to grant full administrative access to connected databases.
BleepingComputer
- Head Mare hacktivist group exploits vulnerabilities in unpatched TrueConf - The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf servers to deploy malicious software versions.
- Unidentified ransomware via JAR/Adwind scrambling file content - A new ransomware campaign delivered via JAR files is scrambling system contents without changing file extensions or leaving ransom notes.
Risky Business
- Risky Bulletin: A Meta AI model also escaped a testing sandbox - A new report highlights a Meta AI model that managed to bypass its testing environment constraints during evaluation.
- Risky Bulletin: Hacker breaches Hungary's State Treasury - A security breach at Hungary's State Treasury has compromised sensitive financial infrastructure data.
SecurityWeek
- Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data - The "RovoBlast" attack method exploits a critical vulnerability in Atlassian's Rovo AI to steal data from SharePoint, Jira, and Confluence.
DataBreaches.net
- City of Suisun declares local emergency after cyberattack downs 911 dispatch system - Suisun City declared a state of emergency after a malicious software infection compromised the city's 911 dispatch and other critical IT systems.
- City of Coweta refuses to pay ransom after system-wide cyberattack - The City of Coweta has opted not to pay ransom demands following a ransomware attack, citing previous experiences where payment did not prevent reinfection.
Hacker News (YC)
- Woman Pulled from Car at Gunpoint by Police After Mistaken Flock Alert – Twice - A report details how a license plate recognition system error led to a traumatic and repeated police intervention against an innocent citizen.
- 'AI Escaped Its Sandbox' — What Does That Actually Mean? - An analysis of recent incidents where AI models have bypassed safety and technical constraints in controlled environments.
NIST NVD / CVE MITRE (Critical CVSS, Published 2026-08-08)
- CVE-2026-71991 - CVSS 9.8 command injection in the TelnetSSH function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71990 - CVSS 9.8 command injection in the SSH configuration of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71989 - CVSS 9.8 command injection in the porTrigger function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71988 - CVSS 9.8 command injection in the portFw function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71987 - CVSS 9.8 command injection in the alg function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71986 - CVSS 9.8 command injection in the dmz function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71985 - CVSS 9.8 command injection in the accesscontrol function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71984 - CVSS 9.8 command injection in the urlfilter function of MSI Radix AXE6600 router firmware v781521 allowing remote root command execution.
- CVE-2026-71983 - CVSS 9.8 command injection in the wps.cgi interface of MSI Radix AXE6600 router firmware v781521 via unsanitized pin2g/pin5g/pin6g parameters.
- CVE-2026-71958 - CVSS 9.8 buffer overflow in quicksetup.cgi (test4/ssid2/username fields) on D-Link DWR-M961 router v1.1.2_C1_202602110044 enabling remote RCE or crash.
- CVE-2026-71957 - CVSS 9.8 buffer overflow in app.cgi netAcc.addlist[].name on D-Link DWR-M961 router enabling remote RCE or crash.
- CVE-2026-71956 - CVSS 9.8 command injection in app.cgi netDig.ping.dst on D-Link DWR-M961 router resulting in root command execution.
- CVE-2026-71955 - CVSS 9.8 command injection in /boafrm/formWsc (localPin/targetAPSsid/peerPin/peerRptPin) on D-Link DWR-M961 router resulting in root execution.
- CVE-2026-71954 - CVSS 9.8 command injection in /boafrm/formL2tpv3ConfigSetup (tunnelid/sessionid) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71953 - CVSS 9.8 command injection in /boafrm/formNtp (ntpServerIp1) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71952 - CVSS 9.8 command injection in /boafrm/formPinManageSetup (oldPIn) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71951 - CVSS 9.8 command injection in /boafrm/formIMEISetup (IMEI_value) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71950 - CVSS 9.8 command injection in /boafrm/formSmsManage (action_value) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71949 - CVSS 9.8 command injection in /boafrm/formUSSDSetup (ussdValue/selectMenuValue) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71948 - CVSS 9.8 command injection in /boafrm/formDebugDiagnosticRun (host) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71947 - CVSS 9.8 command injection in /boafrm/formTracerouteDiagnosticRun (host/ipVer) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71946 - CVSS 9.8 command injection in /boafrm/formPingDiagnosticRun (host) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71945 - CVSS 9.8 command injection in /boafrm/formLtefotaUpgradeFibocom (fota_url) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-71944 - CVSS 9.8 command injection in /boafrm/formLtefotaUpgradeQuectel (fota_url) on D-Link DWR-M961 firmware before 1.1.5_C1_202607071108.
- CVE-2026-14526 - CVSS 9.8 unauthenticated authorization bypass in WordPress AI Copilot – Content Generator <=1.5.6 allowing admin account creation and full site takeover.
PoC-in-GitHub (motikan2010.net)
- PoC-in-GitHub Auto Update 2026/08/08 18:50:04 - Latest daily PoC aggregation commit (2026-08-08) reflecting newly discovered GitHub repos for CVE-2024-56426, CVE-2020-1472 (Zerologon), CVE-2021-33044 (Dahua unauth login), CVE-2019-14287 (sudo LPE), CVE-2023-25690, CVE-2022-32832, CVE-2021-26855, CVE-2019-1040, CVE-2017-20165, and CVE-2012-2459.
- CVE-2024-56426 PoC - PoC repository for CVE-2024-56426 was actively pushed on 2026-08-08.
- CVE-2020-1472 Zerologon PoC - Zerologon proof-of-concept repo received activity on 2026-08-08.
- CVE-2019-14287 sudo LPE write-up - Sudo privilege-escalation write-up repository created 2026-08-08.
GitHub Advisory Database (Advisories List, newly created)
- GHSA-94gg-9cp2-h5f5 - Most recently created GitHub advisory entry in the public advisory feed.
- GHSA-mc5m-j5gw-mffg - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-8mjf-qrcg-h2cj - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-7rr2-x62c-257c - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-h29x-j2gq-hpv4 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-6h53-jfj2-fh9c - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-xx32-ww4m-ppfp - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-57vx-fmg4-8ccc - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-6hx4-fgxm-92r2 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-6hpm-4f52-cv2w - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-67wv-98r5-fch9 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-fx5p-gh5f-884v - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-p269-h6xm-xcqv - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-vgrr-42ff-cr47 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-4c4w-2wv9-hj7p - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-7m6w-qg9f-4rf8 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-5x6m-6m29-96rg - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-6cmv-x2ph-3gc2 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-745r-gxf5-fh45 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-4297-h6wq-2qm5 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-4p6x-rj5h-hg93 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-rrf2-j3h9-99wg - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-7xmj-3fxq-r5hp - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-wgq9-x672-9734 - Newly created GitHub advisory entry in the public advisory feed.
- GHSA-8ff4-44g5-rp4f - Newly created GitHub advisory entry in the public advisory feed.
GitHub Search ('CVE-2026' OR 'CVE-2025' created:2026-08-09)
- No new repositories matching CVE-2026 created today (0 results for https://github.com/search?q=CVE-2026+created%3A2026-08-09&type=repositories).
- No new repositories matching CVE-2025 created today (0 results for https://github.com/search?q=CVE-2025+created%3A2026-08-09&type=repositories).
Exploit-DB
- Krayin CRM v2.2.x - Authenticated RCE (EDB-ID 52629) - Authenticated remote code execution in Krayin CRM v2.2.x; newest confirmed exploit on the platform (feed lagging, no uploads within the strict 24-hour window).
Packet Storm Security (New Exploits)
- Debian Security Advisory 6416-1 - Posted 2026-08-07; jq multiple issues including CVE-2026-54679, CVE-2026-49839, and CVE-2026-47770 that could cause DoS or arbitrary code execution on untrusted input.
- Nmap Port Scanner 7.991 - Posted 2026-08-07; scanner release addressing CVE-2025-15661, CVE-2026-55199, CVE-2026-55200, CVE-2026-58050, CVE-2026-58051, and CVE-2026-7598.
- Apache Polaris 1.6.0 Confused Deputy Authorization Bypass - Posted 2026-08-07; CVE-2026-64640 PoC where a low-privileged user can disclose metadata outside the catalog's authorized storage scope.
- LightFTP Server 2.4 Race Condition - Posted 2026-08-07; CVE-2026-70637 race condition exploit by LiquidWorm.
- Clam AntiVirus Toolkit 1.5.4 - Posted 2026-08-07; release addressing CVE-2025-8088 and CVE-2026-20337 through CVE-2026-20348.
- Laravel Ignition 2.5.1 Remote Code Execution - Posted 2026-08-07; CVE-2021-3129 chained deserialization RCE proof of concept.
- protobuf.js 7.5.4 Code Injection - Posted 2026-08-07; CVE-2026-41242 remote code injection proof of concept.
GhostTroops/TOP (Trending Offensive Projects, updated within last 24-48h)
- sowarma/wp2shell-PoC - Updated 2026-08-08; CVE-2026-63030 & CVE-2026-60137 "wp2shell" unauthenticated RCE chain proof-of-concept.
- BuSung-dev/Root-My-Galaxy - Updated 2026-08-08; KSU installer for supported Samsung Galaxy firmware leveraging CVE-2026-43499.
- jacubes/CVE-2026-24061 - Updated 2026-08-08; exploit PoC for CVE-2026-24061.
- MobiusM/CVE-2026-43499 - Updated 2026-08-07; proof of concept for CVE-2026-43499.
- ynsmroztas/cPanelSniper - Updated 2026-08-07; CVE-2026-41940 cPanel & WHM authentication bypass via session-file CRLF injection.
- orinimron123/CVE-2026-40369-EXPLOIT - Updated 2026-08-07; full exploit for a Windows kernel arbitrary-write vulnerability enabling browser sandbox escape from any renderer process.
- x-spy/CVE-2026-43499-popsicle - Updated 2026-08-07; CVE-2026-43499 kernel LPE implementation for Android kernel 6.12.23.
GitHub Trending (Security Topic)
- rix4uni/medium-writeups - Repository updating latest Bug Bounty medium writeups every 10 minutes.
- name-8391-settled/ScanGuard-Multi-Engine-Suite - Advanced multi-engine scanner for Windows with private local analysis and bulk scanning.
- gaddedcankers-79207/SuiteAnalisisAncaman-Scanner-Pribadi-2026 - Comprehensive threat analysis suite for detecting threats on Windows systems.
- Sylpbqrak/SharpAllowedToAct-Modify - Post-exploitation tool for computer object takeover via Resource-Based Constrained Delegation.
CTFtime.org (Upcoming)
- Thryve CTF 2026 - Jeopardy style online CTF starting Aug 14, 2026.
- gaslightCTF 2026 - Jeopardy style online CTF starting Aug 14, 2026.
- HackHowl 2026 - Jeopardy style online CTF starting Aug 15, 2026.
Infosec-Conferences.com
- ITx Canada Forum 2026 - Three-day executive forum for CIOs and CTOs starting Aug 9, 2026.
- Canada CISO and Cybersecurity Leaders Forum 2026 - Forum focused on cybersecurity leadership starting Aug 9, 2026.
- XChange August 2026 - Cybersecurity industry exchange event starting Aug 9, 2026.
LinkedIn/Indeed Jobs (Last 24h)
- Penetration Tester - OVA.Work - Penetration Tester position in New York, NY posted in the last 24 hours.
- Senior Web Application Penetration Tester - First Citizens - Remote senior penetration testing role posted in the last 24 hours.
- Security Analyst - IT - Multiple Security Analyst positions posted across the United States in the last 24 hours.
- SOC Analyst (Remote) - Remote Security Operations Center Analyst roles posted in the last 24 hours.
⚠️ This content is automatically collected by an AI bot from public web sources and may contain inaccuracies.
Developed by @win3zz