Security researchers disclosed CVE-2026-82222, a maximum-severity vulnerability in the GiveWP donation plugin affecting versions through 4.16.7.1. By chaining an unauthenticated registration bypass, an insecure PHP unserialize function, and a gadget chain in bundled libraries, attackers can create an account, plant a malicious object in the plugin's session data, and trigger arbitrary command execution on the server by simply loading a front-end page.
bleepingcomputer.com
· 2026-08-28
Shadowserver reports over 8,300 internet-facing Gitea instances remain unpatched against CVE-2026-60004, a critical code injection bug already being exploited in the wild. The flaw lets an attacker with repository write access run arbitrary shell commands as the Gitea service account, and since Gitea allows open self-registration by default, unauthenticated users can create an account and repository to gain that access. Gitea patched the issue in version 1.27.1 on July 27, and CISA has added it to its known exploited vulnerabilities list, giving federal agencies just three days to remediate.
bleepingcomputer.com
· 2026-08-28
ServiceNow issued fixes for three critical vulnerabilities in its AI Platform that could let unauthenticated attackers run arbitrary code, escalate privileges, or manipulate data via SQL injection, all without user interaction. The company also patched a separate high-severity sandbox escape bug that could allow low-privileged users to achieve remote code execution. ServiceNow says it has no evidence of active exploitation but is urging customers to apply the updates immediately.
bleepingcomputer.com
· 2026-08-28
At Hot Chips 2026, Cerebras detailed its next two wafer-scale accelerator generations, including a new Nexus rack architecture for the CS-4 system that triples rack-scale performance using three WS-3T engines. The company also confirmed that its future CS-6 system will introduce 3D-stacked DRAM directly on top of its wafer-scale logic and SRAM, marking a first for its chip design.
tomshardware.com
· 2026-08-27
Plaud, a major player in AI note-taking hardware, has introduced the Plaud One, a pair of earbuds that embed its agentic AI software directly into headphones. The device can record conversations and phone calls via a built-in eSIM with 4G LTE, then transcribe them and generate summaries, follow-ups, or reports, integrating with tools like Gmail, Slack, and Notion. The product will be shown publicly for the first time at IFA 2026 in Berlin.
cnet.com
· 2026-08-27
At Gamescom, Samsung revealed its 2027 Odyssey gaming monitor lineup, headlined by the 27-inch Odyssey G6 G60H now hitting a 1,100Hz refresh rate, up from the 1,040Hz figure teased at CES. The dual-mode IPS panel still caps at 600Hz in native 1440p, reserving the extreme speed for 1080p. Samsung also unveiled updated OLED G9, G8, and G7 models, including a 49-inch G9 that reaches 360Hz at DQHD resolution or 720Hz in a dual-HD mode.
theverge.com
· 2026-08-27
CISA has added CVE-2026-8452, a memory overflow bug in Citrix NetScaler ADC and Gateway appliances, to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to patch by August 29. Originally described by Citrix as only enabling denial-of-service, researchers at watchTowr later demonstrated it can be exploited for root-level remote code execution, and reports indicate attackers are already deploying web shells on unpatched systems.
bleepingcomputer.com
· 2026-08-27
At Black Hat USA 2026, PortSwigger research director James Kettle unveiled an open source AI-driven tool called HTTP Terminator, designed to test whether AI could invent original hacking techniques rather than just find known bugs. The tool autonomously produced new HTTP desync, or request smuggling, attacks and used them to breach real enterprise sites, including several belonging to financial services firms.
darkreading.com
· 2026-08-26
ASUS revealed three new 24.5-inch gaming monitors under its Ace lineup: the 720Hz ROG Swift OLED PG259QWS Ace with a Tandem WOLED panel and Dolby Vision support, and two QD-OLED models, the 560Hz XG259QDPG Ace and 360Hz XG259QDNS Ace, both featuring a new anti-glare 'BlackShield' film. The PG259QWS Ace launches in early Q4 for $1,099, while pricing and availability for the QD-OLED models remain unannounced except for the previously shown XG259QWPG Ace at $699.
engadget.com
· 2026-08-26
At FOSSY 2026, Software Freedom Conservancy members Bradley Kühn, Karen Sandler, and Denver Gingerich detailed an unresolved license violation involving Bambu Lab's 3D-printer software, which is licensed under the AGPLv3. They explained that the company's method of restricting user control over the software is exactly the kind of network-based circumvention the AGPL was designed to block, and described SFC's outreach to build alternatives for affected users.
lwn.net
· 2026-08-26
Wordfence researchers found a critical vulnerability chain, tracked as CVE-2026-18431 with a 9.8 severity score, in the Avada theme and its companion Fusion Builder plugin for WordPress. By chaining six separate weaknesses in a specific sequence, an attacker with no login credentials could execute arbitrary PHP code on a vulnerable server, fully compromising the site.
bleepingcomputer.com
· 2026-08-26
Samsung has started pushing a software update that resolves the red discoloration issue affecting some Galaxy S26 Ultra displays, according to a notice posted on the Samsung Members app. The fix appears bundled with the August 2026 security update rolling out first in South Korea, and unlike the initial workaround, users won't need to visit a service center to get it.
androidauthority.com
· 2026-08-26