Cyber Security Brief — 2026-08-22
Today's brief: TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit (The Hacker News) — The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.…
- Hackers infect Android car head units with proxy botnet malware (BleepingComputer) — A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [..…
- Named Pipes Under Attack: Securing Windows Interprocess Communication (BleepingComputer) — Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command au…
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 (The Hacker News) — Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence …
- New SynkLoader malware pushed in Microsoft Teams phishing campaign (BleepingComputer) — A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
Newly published, high-severity CVEs
- CVE-2026-61539 (CVSS 10, CRITICAL) — Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/ll…
- CVE-2026-77946 (CVSS 10, CRITICAL) — A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Execut…
- CVE-2026-77810 (CVSS 9.9, CRITICAL) — In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade …
- CVE-2026-62283 (CVSS 9.9, CRITICAL) — Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in ser…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 12 Security Score scans across our customers in the past 7 days.
- high: 29
- medium: 31
- critical: 12
- low: 10
- info: 27
Most common issues:
- No CAA records (seen 6x)
- DNSSEC not detected (seen 6x)
- No DMARC record — phishing using your domain is possible (seen 5x)
- No DMARC record (seen 5x)
- No SPF record (seen 4x)
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan