Cyber Security Brief — 2026-08-23
Today's brief: TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit (The Hacker News) — The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.…
- Hackers infect Android car head units with proxy botnet malware (BleepingComputer) — A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [..…
- Named Pipes Under Attack: Securing Windows Interprocess Communication (BleepingComputer) — Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command au…
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 (The Hacker News) — Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence …
- New SynkLoader malware pushed in Microsoft Teams phishing campaign (BleepingComputer) — A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
Newly published, high-severity CVEs
- CVE-2026-77946 (CVSS 10, CRITICAL) — A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Execut…
- CVE-2026-78003 (CVSS 9.8, CRITICAL) — The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() …
- CVE-2026-4703 (CVSS 9.8, CRITICAL) — The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission met…
- CVE-2026-59808 (CVSS 8.8, HIGH) — AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and u…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 7 Security Score scans across our customers in the past 7 days.
- medium: 17
- high: 12
- low: 14
- info: 33
Most common issues:
- No CAA records (seen 7x)
- DNSSEC not detected (seen 7x)
- No DMARC record (seen 6x)
- Cross-origin stylesheet loaded without Subresource Integrity (seen 6x)
- No SPF record (seen 4x)
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan