Critical

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

The Hacker News

Overview

HashiCorp, Veeam, and the Django Software Foundation have addressed 11 vulnerabilities in their respective products, with three being particularly severe. Veeam's Service Provider Console has a critical flaw that allows unauthenticated access to a managed agent's credentials, rated at 9.5 on the CVSS scale. HashiCorp's Terraform MCP server has a cross-tenant vulnerability that could let one user's token be reused by others, potentially exposing sensitive data. Django has also patched vulnerabilities that could affect its web framework. These issues are important because they could allow unauthorized access to systems and sensitive information. Users of these platforms should update their software to mitigate these risks.

Key Takeaways

  • Affected Systems: Veeam Service Provider Console, HashiCorp Terraform MCP Server, Django web framework
  • Action Required: Users should apply the latest patches released by Veeam, HashiCorp, and the Django Software Foundation for their respective products.
  • Timeline: Newly disclosed

Original Article Summary

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'

Impact

Veeam Service Provider Console, HashiCorp Terraform MCP Server, Django web framework

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Users should apply the latest patches released by Veeam, HashiCorp, and the Django Software Foundation for their respective products.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Vulnerability, Patch, Update, and 1 more.

Related Coverage

COLDCARD security audit phishing attack installs remote access tool

BleepingComputer

A recent phishing campaign is taking advantage of concerns related to the COLDCARD wallet vulnerability and a significant Bitcoin theft, estimated at $88.6 million. Cybercriminals are using this fear to trick users into downloading ScreenConnect, a remote access tool. This software could allow attackers to gain control over victims' devices, potentially leading to further theft of digital assets. Users of the COLDCARD wallet are particularly at risk as they may be targeted due to their connection to the vulnerability. The situation underscores the need for heightened vigilance among cryptocurrency users, especially in the face of ongoing scams exploiting current events.

Aug 5, 2026

Fake Open VSX Extensions Harvest Private Repo and CI Data

Infosecurity Magazine

A recent investigation uncovered 77 counterfeit Open VSX extensions that were designed to steal information from private repositories and continuous integration (CI) systems. These malicious extensions were found to communicate with a single domain, with 19 of them specifically targeting Git and CI identities. This type of attack poses a significant risk to developers and organizations using Open VSX, as it can lead to unauthorized access to sensitive code and credentials. Users of these extensions should be cautious and verify the authenticity of any tools they install, as attackers are increasingly using such tactics to compromise security. The incident raises concerns about the safety of third-party extensions in development environments.

Aug 5, 2026

Google Blogger locks hundreds of blogs in malware false positive

BleepingComputer

Google has mistakenly locked hundreds of Blogger accounts, claiming they violated its malware policy. This error has led to some blogs being deleted entirely, causing significant distress for users who rely on the platform for their content. Affected users are now struggling to regain access to their blogs, and this situation raises concerns about how automated systems can misidentify threats. The incident highlights the potential risks of relying too heavily on automated security measures without proper checks. Users and content creators on Blogger should be aware of this issue and consider backing up their content elsewhere as a precaution.

Aug 5, 2026

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

Infosecurity Magazine

Researchers have identified three security flaws in Paperclip, an AI platform, which could allow attackers to access sensitive data and execute commands without authentication. These vulnerabilities affect two different deployment modes of the platform. This means that anyone with malicious intent could potentially manipulate the system without needing valid credentials. Organizations using Paperclip should be particularly vigilant, as these flaws can lead to unauthorized access and significant data breaches. The issue raises concerns about the security of AI tools and the need for robust safeguards to protect against such vulnerabilities.

Aug 5, 2026

Open-source software’s archenemy TeamPCP goes back further than anyone thought

CyberScoop

Oligo Security has found that TeamPCP, a group known for targeting open-source software, has a longer history of attacks than previously thought. Their research indicates that TeamPCP has used the same infrastructure and tools for multiple attacks over time, raising concerns about their ongoing threat to software projects that rely on open-source components. This revelation is significant for developers and organizations that depend on open-source software, as they may need to reassess their security protocols and defenses against this persistent group. The findings suggest that TeamPCP is not just a recent threat but has been active for a considerable period, potentially impacting a wide range of software applications. Organizations should remain vigilant and ensure they are implementing strong security measures to protect against such attacks.

Aug 5, 2026

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

The Hacker News

A newly discovered vulnerability in the Linux kernel's Open vSwitch datapath allows local users to gain root access on several default-configured distributions. This memory corruption flaw, identified as CVE-2026-64531 and given the codename OVSwrap, has a CVSS score of 7.8, indicating a high severity. Security researcher Asim disclosed this issue, which comes with a public exploit that has pre-built records for about 800 different kernel builds. This broad impact means that many users could be affected if they have systems running these vulnerable kernel versions. Companies and system administrators should take immediate action to assess their environments and apply necessary patches to mitigate this risk.

Aug 5, 2026