HebridesCyber
← back to Security Weekly

This Week in Small Business Security — 2026-08-24

24 August 2026·3 min read

This week: UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit, plus 3 sites scanned and what we found.

A roundup of what's actually happened in security over the past week — real incidents and newly disclosed vulnerabilities, not filler.

In the news

Newly published, high-severity CVEs

  • CVE-2026-74843 (CVSS 10, CRITICAL) — A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrac…
  • CVE-2026-66792 (CVSS 9.9, CRITICAL) — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Succe…
  • CVE-2026-47686 (CVSS 9.9, CRITICAL) — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.…
  • CVE-2026-74872 (CVSS 9.8, CRITICAL) — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can…

Source: NIST National Vulnerability Database.

This week in our own scan data

We ran 3 Security Score scans across our customers in the past 7 days.

  • medium: 4
  • info: 19
  • high: 7
  • low: 9

Most common issues:

  1. Cross-origin stylesheet loaded without Subresource Integrity (seen 6x)
  2. DKIM not detected at common selectors (seen 3x)
  3. No DMARC record (seen 3x)
  4. DNSSEC not detected (seen 3x)
  5. Missing recommended headers (1) (seen 2x)

If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.

This roundup is generated weekly from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.

$ ./get-your-score

Get a free Security Score for your site

Automated TLS, headers, DNS, and exposure checks — results in under a minute.

Request a free scan