
Daily DefSec Brief
Cyber Security News for August 21 2026 - Daily DefSec Brief
1. Max-severity Entra ID flaw exploited before patch β CVE-2026-69836 β BleepingComputer β https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ 2. TrueConf Server code injection added to CISA KEV β CVE-2026-72530 β CISA KEV β https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. TrueConf Server missing-auth flaw added to KEV, due Aug 23 β CVE-2026-72529 β CISA KEV β https://www.cisa.gov/known-exploited-vulnerabilities-catalog 4. Elementor Pro file-upload unauthenticated RCE β CVE-2026-32475 β BleepingComputer β https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/ 5. Spring Security embedded LDAP admin-access flaw β CVE-2026-59270 β Cyber Security News β https://cybersecuritynews.com/spring-security-flaw-access-ldap-servers/ 6. Three suspected Russian clusters abuse OAuth/auth flows β Google Threat Intel β https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/ 7. Malware commands hidden in FTP server banners (E4del, PINHOLE) β BleepingComputer β https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/ 8. CDN Tsunami HTTP/3-to-HTTP/1.1 DoS amplification β CVE-2026-14456 β The Hacker News β https://thehackernews.com/2026/08/cdn-tsunami-abuses-http3.html 9. Signed Defender BTR.sys driver repurposed for kernel bypass β The Hacker News β https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html 10. containerd CRI plugin flaws enable cross-pod RCE β CVE-2026-50195, CVE-2026-53488, CVE-2026-53489, CVE-2026-53492, CVE-2026-47262 β AWS Security Bulletin β https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/ 11. Redshift JDBC driver runs arbitrary classes from URL params β CVE-2026-8178 β AWS Security Bulletin β https://aws.amazon.com/security/security-bulletins/rss/2026-028-aws/ 12. N-able Passportal flaw exposes vault master keys β Dark Reading β https://www.darkreading.com/vulnerabilities-threats/n-able-bug-password-vault-master-keys 13. Peer2Profit proxyware turns employee device into internal proxy β Cyber Security News β https://cybersecuritynews.com/bandwidth-sharing-app/ 14. Atlassian and Splunk patch 250+ vulnerabilities β SecurityWeek β https://www.securityweek.com/atlassian-splunk-patch-dozens-of-critical-high-severity-vulnerabilities/

