DefendEdge Cyber Security Blog
Vulnerability Summary for the Week of September 14, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 03-lovepreetSingh–MCP A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might…
The Developer Is the Perimeter: Inside This Week’s Supply Chain Espionage Campaigns
1,090 attacks tracked this week — but the sharpest threat wasn’t ransomware. It was fake job tests and poisoned supply chains aimed at developers.
Vulnerability Summary for the Week of September 7, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 100plugins–Open User Map Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. 2026-09-08 7.1 CVE-2026-84818 92181–markdown A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f. Affected by this issue is the function lds of the file md.c. Executing a manipulation…
Faking Authority: What the Revolut Breach Reveals About Financial Sector Cyber Threats
Revolut’s breach via fake government requests exposes authority impersonation hitting finance — 70 attacks this week. Six steps to defend your firm.
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging…
Vulnerability Summary for the Week of August 31, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 1Hive–gardens-v2 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into…
No Patch Available: The Zero-Day Assault on Remote Access Tools
A critical ScreenConnect flaw ships with no patch, 122,500 MikroTik routers expose SSH, and zero-days hit Adobe Commerce and N-able. What to do now.
Vulnerability Summary for the Week of August 24, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 4MOSAn Security Technology–4MOSAn GCB Doctor 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server. 2026-08-24 9.8 CVE-2026-78211…
Attackers Now Wield AI: Aurora Ransomware, Gryxa Malware, and This Week’s Threat Landscape
Aurora ransomware used an AI coding assistant to breach 10 victims while AI-built malware fights cleanup – lessons from 854 attacks tracked this week.
A Tale of Two SOCs: Insights From Two Red Team Assessments
Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed…
