๐ต๏ธ RESEARCH & DEEP DIVES
- Beacon CRM AWS Key Breach Exposes Data From 1,500 UK Charities
Beacon CRM exposed data from about 1,500 UK charities after an AWS key compromise.- Beacon CRM customers included about 1,500 UK charities, including healthcare and victim-support organizations.
- Names, email addresses, phone numbers, postal addresses, donation records and attachments were exposed.
- The AWS access key was potentially published in public JavaScript build artifacts.
- The attacker used valid credentials to download CRM data from July 27 to 28, 2026, during a 1-hour-27-minute session.
- AWS encryption at rest did not prevent readable downloads because the valid credentials enabled decryption.
๐ Coverage: infosecurity-magazine.com ยท ๐ via BleepingComputer
๐ ADVISORIES
-
๐ Source for Android Malware Infects DoFun Car Head Units for Ad Fraud and Proxy Botnets โ ics-cert.kaspersky.com
-
๐ Source for Calix GS7 XGS Router Flaw Allows Unauthenticated NAT Rule Changes โ drkq.github.io
๐ CVEs & KEV
-
CVE-2026-69502 โ CVSS 10.0 โ Azure SQL Database Elevation of Privilege VulnerabilityServer-side request fo...
-
CVE-2026-63343 โ CVSS 9.9 โ Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesys...
-
CVE-2026-63125 โ CVSS 9.9 โ Incus vulnerable to root RCE via image backup.yaml symlinkIncus is a system c...
-
CVE-2026-62941 โ CVSS 9.9 โ Incus: Cross-project instance copy bypasses target project restrictions via T...
-
CVE-2026-62940 โ CVSS 9.9 โ Incus has a project restriction bypass via instance migration config override...
-
CVE-2026-62867 โ CVSS 9.9 โ Incus has an argument injection in storage volume block.create_options that l...
-
CVE-2026-77087 โ CVSS 9.4 โ Paperclip before 0.3.1 Remote Code Execution via DNS RebindingPaperclip befor...
-
CVE-2026-75932 โ CVSS 9.2 โ Jet Admin tenant isolation failureJet Admin allows an attacker to create a ma...
-
CVE-2026-75933 โ CVSS 8.5 โ Jet Admin Stored XSSJet Admin allows an authenticated attacker to inject Java...
-
CVE-2026-55622 โ CVSS 7.7 โ Incus has a project restriction bypass in instance copy across projectsIncus ...
-
CVE-2026-55621 โ CVSS 7.7 โ Incus has a project restriction bypass for custom volume copy across projects...
-
CVE-2026-54789 โ CVSS 7.5 โ mod_auth_openidc has out-of-bounds read and write in state cookie parsingmod_...
-
CVE-2026-49114 โ CVSS 6.8 โ ONNX symlink-following and path-traversal arbitrary file writeIn ONNX before ...