Cyber Security Brief — 2026-08-30
Today's brief: Anthropic is cutting Claude Code's current weekly limits by 17%, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- Anthropic is cutting Claude Code's current weekly limits by 17% (BleepingComputer) — Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE (The Hacker News) — Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, a…
- Brave browser adds email aliases to help users evade tracking (BleepingComputer) — The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]
- McKesson discloses breach after ShinyHunters claims patient data theft (BleepingComputer) — Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extorti…
- Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network (The Hacker News) — Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortio…
Newly published, high-severity CVEs
- CVE-2026-82456 (CVSS 10, CRITICAL) — argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the …
- CVE-2026-14494 (CVSS 9.8, CRITICAL) — The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfi…
- CVE-2026-82448 (CVSS 9.8, CRITICAL) — Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present…
- CVE-2026-82452 (CVSS 9.8, CRITICAL) — rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, l…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 2 Security Score scans across our customers in the past 7 days.
- medium: 3
- info: 10
- high: 6
- low: 5
Most common issues:
- Cross-origin stylesheet loaded without Subresource Integrity (seen 3x)
- DKIM not detected at common selectors (seen 2x)
- No DMARC record (seen 2x)
- DNSSEC not detected (seen 2x)
- Missing recommended headers (1) (seen 1x)
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan