CVE-2025-49506, CVE-2026-18839, CVE-2026-34191, CVE-2026-34501, CVE-2026-44605, CVE-2026-47243, CVE-2026-50540, CVE-2026-54876, CVE-2026-64542, CVE-2026-64560, CVE-2026-64561, CVE-2026-64562, CVE-2026-64564, CVE-2026-64565, CVE-2026-64567, CVE-2026-64569, CVE-2026-64571, CVE-2026-64572, CVE-2026-64573, CVE-2026-64574, CVE-2026-64576, CVE-2026-64577, CVE-2026-64578, CVE-2026-64579, CVE-2026-64580, CVE-2026-64583, CVE-2026-64584, CVE-2026-64590, CVE-2026-64604, CVE-2026-64676, CVE-2026-68081, CVE-2026-68082, CVE-2026-71225, CVE-2026-71226, CVE-2026-71227
Get tomorrow's brief in your inbox
Today: Atlassian's Rovo AI exposed enterprise data through a one-click parameter injection flaw that let attackers seed malicious prompts directly into live AI sessions. Two California cities are dealing with ransomware attacks, with Suisun declaring a local emergency after their 911 dispatch system went down. The Sovcali ransomware group claims 5 terabytes of Lucid Motors engineering data including CATIA models and CFD simulations.
Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data
Varonis Threat Labs disclosed RovoBlast, a one-click vulnerability in Rovo (Atlassian's enterprise AI assistant) that let attackers seed malicious instructions directly into a user's live AI session through a specially crafted link. The flaw exploited the rovoChatPrompt URL parameter, which pre-fills content into Rovo's chat window without any warning that the session was seeded externally. The attack required no jailbreak or permission bypass. Rovo has access to Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, databases, and uploaded files. Researchers demonstrated exfiltration of Confluence pages, Jira tickets, and SharePoint content containing personal data using Rovo's ResearchAgent tool, which can autonomously navigate arbitrary sites.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Sovcali | Lucid Motors | Automotive | US |
1 claim tracked from 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
Sovcali Claims Lucid Motors Engineering Archive
The Sovcali ransomware group claims possession of 5.078 terabytes of Lucid Motors and eShocan engineering data, including CATIA and STEP models, FEA and NVH analyses, multi-gigabyte CFD simulations of the LiDAR washing system, topology optimization studies, static and modal results for the Gravity and Midsize enclosures, BOMs, and internal progress reports. The claim was posted 2026-08-08.
City of Suisun Declares Local Emergency After Cyberattack Downs 911 Dispatch System
Suisun City, California declared a state of emergency on Saturday, August 8, after a cyberattack took out the city's emergency dispatch line and other key systems. Malicious software infected and compromised IT systems at about 5:45 a.m. on Friday. The cybersecurity issue forced the city to shut down multiple systems, including the 911 dispatch line.
City of Coweta Refuses to Pay Ransom After System-Wide Cyberattack
The City of Coweta is dealing with a ransomware attack and has decided not to pay any ransom demands. The city manager reported that in a previous ransomware attack at another city, they paid the ransom and were reinfected weeks later, so Coweta will not be paying.
Apache Portable Runtime Utility Multiple Vulnerabilities
Three vulnerabilities disclosed in Apache Portable Runtime Utility. CVE-2025-49506 is a timing attack vulnerability in apr_password_validate() with EPSS score 0.004 (32nd percentile). CVE-2026-34191 is a SQL injection flaw in apr_dbd_oracle with EPSS 0.004 (29th percentile). CVE-2026-34501 is a heap buffer overflow in the APR Redis client with EPSS 0.005 (42nd percentile).
Kata Containers Multiple Container Escape Vulnerabilities
Three vulnerabilities in Kata Containers allow container escape and unauthorized access. CVE-2026-64676 (EPSS 0.001, 2nd percentile) allows unauthorized mem-agent ttRPC methods to tamper with confidential-guest memory. CVE-2026-47243 (EPSS 0.002, 8th percentile) is a runtime-rs guest-root to host-root escape via virtiofs. CVE-2026-50540 (EPSS 0.004, 31st percentile) allows arbitrary file loading via config path annotation.
Linux Kernel Multiple CVEs
24 Linux kernel CVEs published covering KVM virtualization (CVE-2026-64561, CVE-2026-64562, CVE-2026-68081, CVE-2026-64604), networking stack (CVE-2026-64572, CVE-2026-64569, CVE-2026-64577, CVE-2026-64564, CVE-2026-64542, CVE-2026-64579, CVE-2026-64580), WiFi (CVE-2026-64571, CVE-2026-64574), Bluetooth (CVE-2026-64573), USB (CVE-2026-64583, CVE-2026-64584), filesystems (CVE-2026-64567), and other components. Most have EPSS scores in the 0.001-0.002 range (2nd-11th percentile). All are low-severity kernel hardening fixes with limited exploitation likelihood.
Libkcapi Cryptographic Library Multiple Flaws
Three vulnerabilities in Libkcapi. CVE-2026-71225 (EPSS 0.002, 15th percentile) causes IV reuse in one-shot symmetric cipher chunking, resetting cipher state across chunk boundaries. CVE-2026-71226 (EPSS 0.001, 2nd percentile) allows memory corruption via uncanceled aio requests on error in the one-shot aio path. CVE-2026-71227 (EPSS 0.001, 1st percentile) is an infinite loop denial of service in _kcapi_aio_read_all() due to unhandled io_getevents() timeout return.
Additional CVEs
CVE-2026-64578 (ksmbd compound request validation), CVE-2026-68082 (libceph unsafe decodes), CVE-2026-54876 (OpenSSL client-side memory leak in OCSP response checking, EPSS 0.003/18th percentile), CVE-2026-44605 (RPM heap buffer overflow in ndb slot table parsing, EPSS 0.001/3rd percentile), CVE-2026-64565 (Input: ims-pcu heap-buffer-overflow), CVE-2026-64560 (posix-cpu-timers UAF prevention), CVE-2026-18839 (popt size_t underflow), CVE-2026-64590 (dma-buf/udmabuf cacheline warning fix), CVE-2026-64576 (nexthop extack initialization).
AI assistant platforms are emerging as a significant attack surface. The RovoBlast vulnerability demonstrates that enterprise AI tools with broad data access and autonomous capabilities can be weaponized through simple parameter manipulation. The attack pattern (parameter-to-prompt injection) appears across multiple vendors and represents a fundamental design challenge in AI assistant security. The two California city ransomware attacks show municipalities remain high-value targets, with critical infrastructure like 911 dispatch systems at risk.