Cyber Security Brief — 2026-08-25
Today's brief: Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data (The Hacker News) — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnera…
- Unpatched Calix flaw lets hackers bypass NAT to expose internal devices (BleepingComputer) — An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can e…
- Hackers target WordPress sites in miniOrange auth bypass attacks (BleepingComputer) — Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in …
- TikTok reaches $400M settlement with US over COPPA violations (BleepingComputer) — The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (CO…
- Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt (The Hacker News) — If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI ca…
Newly published, high-severity CVEs
- CVE-2026-66897 (CVSS 9.9, CRITICAL) — A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. Whe…
- CVE-2026-28165 (CVSS 9.8, CRITICAL) — Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
- CVE-2026-32558 (CVSS 9.8, CRITICAL) — Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
- CVE-2026-66587 (CVSS 9.8, CRITICAL) — Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 3 Security Score scans across our customers in the past 7 days.
- medium: 4
- info: 19
- high: 7
- low: 9
Most common issues:
- Cross-origin stylesheet loaded without Subresource Integrity (seen 6x)
- DKIM not detected at common selectors (seen 3x)
- No DMARC record (seen 3x)
- DNSSEC not detected (seen 3x)
- Missing recommended headers (1) (seen 2x)
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan