Security, p. 4
Security
68 stories · page 4 of 8A hole in Gitea entered the actively exploited catalogue, and no fix exists yet
On 25 August CISA added CVE-2026-60004 to its catalogue of confirmed exploited flaws, with a patch deadline of 28 August. The latest Gitea release is from 14 August, older than the entry itself.
Read →WhatsApp replaced the six-digit PIN with a real password
The second step at login can now be a long password with letters and symbols instead of six digits. Android also gets more information about calls from unknown numbers, and passkeys are no longer limited to one.
Read →Microsoft corrected its own field: the 10.0 hole in Entra ID was not exploited
On 20 August Microsoft announced a critical hole in Entra ID with the maximum score of 10.0 and noted in its record that it was being exploited. A day later it corrected the field. The patch is entirely on their side, and for customers there is nothing to do.
Read →The Zimbra hole went from theoretical to actively exploited in eight days
On 13 August the exploitation field for CVE-2026-73570 read one word: none. On 21 August CISA added it to the catalogue of actively exploited vulnerabilities, with a deadline of 24 August. The hole lets an attacker without a password run commands on the mail server.
Read →The poisoned arrayref lived 86 minutes on crates.io. Compiling once was enough
On 20 August three packages by the same author in the Rust registry come out with a new dependency whose build script downloads and runs a malicious payload during compilation. They were deleted within an hour and a half to two hours. The maintainer's account is locked - the Rust team believes their computer or their access credentials were taken over.
Read →Five holes entered the actively exploited catalogue in two days
On 17 and 18 August the US agency CISA added five vulnerabilities to its catalogue of known exploited flaws. Inside are macOS, VMware vCenter, SharePoint, a Microsoft service for encrypted connections, and Ray, which sits under part of the world's AI training.
Read →You approve a harmless command and somebody else's code runs. The hole is in the allowlist
Docker walks through a flaw in Cursor that let hidden text change environment settings without ever asking for approval. After that, an entirely ordinary command the developer approved themselves was running somebody else's code.
Read →Vercel hid which site you are opening from whoever watches the network
ECH encrypts the hostname during the handshake. From outside the connection looks like it is going to a shared address, not to your domain.
Read →Cloudflare now shows you which MCP server your people are using
A new dashboard counts requests, users and servers, and separately shows the shadow ones nobody approved. It ships for all Zero Trust customers.
Read →