This day 02:02 06:02 10:02 14:03 18:03 22:04
Info  2026-08-17 10:02Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-08-17 — Defender zero-day, Tether audited

Executive summary: Microsoft is patching a Defender zero-day ("ShieldBreak," CVE-2026-69414) disclosed last week — no fix yet, so detection and mitigation workarounds are the only current defence. Tether has completed its first full financial audit by KPMG, a milestone after years of reserve-opacity concerns. On the mobile front, Android is moving toward per-shortcut fingerprint re-authentication even when the device is already unlocked. A SecurityLab browser-privacy comparison of 13 browsers also lands today, useful for hardening recommendations.

Top items

Themes

Authentication hardening. Android's per-shortcut fingerprint requirement and the broader browser-privacy comparison both point toward defense-in-depth at the endpoint layer — assuming the device is unlocked is no longer sufficient trust for sensitive app access.

Crypto maturity signals. Tether's first full audit, alongside recent exchange breaches and lawsuits, reflects a maturing but still volatile crypto threat landscape where financial transparency and attack surface are both expanding.

===

[{"slug":"shieldbreak-defender-zero-day-cve-2026-69414","headline":"Microsoft patching Defender ShieldBreak zero-day CVE-2026-69414","findingIds":[8710],"status":"new"},{"slug":"tether-kpmg-full-audit","headline":"Tether completes first full financial audit by KPMG","findingIds":[8711],"status":"new"},{"slug":"android-per-shortcut-fingerprint","headline":"Android to require fingerprint for every shortcut even when unlocked","findingIds":[8709],"status":"new"},{"slug":"securitylab-browser-privacy-rating","headline":"SecurityLab publishes 13-browser privacy comparison","findingIds":[8695],"status":"new"},{"slug":"linux-7-2-released","headline":"Linux 7.2 released despite busy final week","findingIds":[8696],"status":"new"},{"slug":"moscow-court-fines-telegram-channels-roskomnadzor","headline":"Moscow court fines Telegram channels for Roskomnadzor banking-outage blame","findingIds":[8694],"status":"new"}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db