Infosec Trending Feed

Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.

Updated on: 10:03 AM IST, 29 Aug 2026 (6 hour(s) ago)

HackerOne Hacktivity

Medium — Bug Bounty

Medium — InfosecWriteups / Infosec

Intigriti BugBytes

  • Intigriti Bug Bytes #239 — August 2026 - The August 2026 issue covers CrowdRecon, Adobe’s bug-bounty program, CSS injection, AI security research, and related resources, and is dated August 28, 2026.

GitHub — arkadiyt/bounty-targets-data

Mastodon Infosec.exchange

  • #security activity: 28 posts today - The public tag page reports 28 new security posts today, indicating active infosec discussion during the last 24 hours, but does not expose individual post titles without login.

The Hacker News

BleepingComputer

Risky Business

SecurityWeek

Dark Reading

DataBreaches.net

Hacker News (yc)

NIST NVD & CVE.org

  • CVE-2023-43902CVSS 9.8 Critical; eMudhra emSigner’s password-reset function permits unauthenticated account takeover, including administrator accounts, via a crafted reset token; NVD modified the record on 2026-08-28.
  • CVE-2023-49105CVSS 9.8 Critical; ownCloud before 10.13.1 accepts unsigned pre-signed URLs without authentication, enabling arbitrary file access, modification, or deletion; NVD modified the record on 2026-08-28.
  • CVE-2026-1524CVSS 9.8 Critical; Neo4j Enterprise versions before 2026.02 can incorrectly grant authorization through an authentication-only OIDC provider under a multi-provider configuration; NVD modified the record on 2026-08-28.
  • CVE-2026-0545CVSS 9.8 Critical; MLflow job endpoints can bypass basic authentication and authorization, potentially enabling unauthenticated remote code execution when privileged jobs are allowlisted; NVD modified the record on 2026-08-28.
  • CVE-2026-42264CVSS 9.1 Critical; Axios versions 1.0.0 through 1.15.1 can consume attacker-polluted Object.prototype properties as HTTP-adapter configuration gadgets; NVD modified the record on 2026-08-28.
  • CVE-2026-42557CVSS 9.6 Critical; JupyterLab before 4.5.7 can execute attacker-chosen commands when a user clicks a deceptive button in pre-saved HTML output; NVD modified the record on 2026-08-28.
  • CVE-2026-5241CVSS 9.6 Critical; transformers 5.2.0 can execute arbitrary code from an attacker-controlled model repository despite trust_remote_code=False in the LightGlue loading path; NVD modified the record on 2026-08-28.
  • CVE-2026-76886CVSS 9.8 Critical; the C12.22 protocol dissector in affected 4.6.x and 4.4.x releases can be crashed to cause denial of service; NVD modified the record on 2026-08-28.
  • CVE-2026-66788CVSS 9.9 Critical; Lighthouse permits a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into namespaces on peer clusters; NVD modified the record on 2026-08-28.
  • CVE-2026-82266CVSS 9.3 Critical (CVSS 4.0); Redpanda through 26.2.2 exposes an unauthenticated Admin API that treats remote requests as superusers; published and modified on 2026-08-28.
  • CVE-2026-82277CVSS 9.3 Critical (CVSS 4.0); Argo Rollouts through 1.10.0 exposes unauthenticated mutating dashboard operations across accessible namespaces; published and modified on 2026-08-28.
  • CVE-2026-18527CVSS 9.9 Critical; IBM Administration Runtime Expert for i 1R1M0 allows an unauthenticated remote attacker to execute actions under another user’s authenticated profile and gain elevated privileges; published and modified on 2026-08-28.
  • CVE-2026-19286CVSS 9.8 Critical; Langflow OSS 1.0.0 through 1.11.1 permits arbitrary code execution through insufficient enforcement of restrictions on the A2A public endpoint; published and modified on 2026-08-28.
  • CVE-2026-19295CVSS 9.9 Critical; Langflow OSS 1.0.0 through 1.11.1 lets an authenticated flow user escalate to operating-system command execution through a crafted flow type; published and modified on 2026-08-28.
  • CVE-2026-3627CVSS 9.1 Critical; IBM Concert 1.0.0 through 2.3.1 is vulnerable to remote SQL injection that can expose or alter backend data; published and modified on 2026-08-28.

GitHub Advisories List

  • CVE-2026-80704 / GHSA-pqhq-6v8m-mfrc — GitHub published and updated an unreviewed Linux-kernel advisory on 2026-08-28 describing a NULL-pointer dereference in AMD display logging that can crash the kernel.
  • CVE-2026-80655 / GHSA-x28x-mxhh-x47j — GitHub published and updated an unreviewed Linux-kernel advisory on 2026-08-28 describing a race condition in Xilinx event registration that can cause a NULL-pointer dereference.

GhostTroops/TOP

  • BYOVD — The TOP 2026 offensive-project index records an update at 2026-08-28T06:11:52Z for vulnerable-driver research and reverse-engineering use cases covering CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, and CVE-2026-8501.

KitPloit

  • vphone-cli - New listing approximately 27 minutes ago for booting and managing virtual iPhones on Apple Silicon, including firmware patching and jailbreak variants for iOS security research.
  • ziti v2.0.4 - New listing approximately 2 hours 50 minutes ago for the OpenZiti zero-trust networking platform.
  • malvinci - New listing approximately 4 hours 49 minutes ago for a script described as providing firewall-disabling, HTTP-server, port-forwarding, and persistence capabilities.
  • conductai - New listing approximately 5 hours 19 minutes ago for an AI-agent governance tool focused on runtime firewalls and policy enforcement.

Help Net Security

Hack The Box

CTFtime.org

LinkedIn

Indeed


⚠️ This content is automatically collected by an AI bot from public web sources and may contain inaccuracies.


Developed by @win3zz