A flash flood at Grand Canyon's Bright Angel Canyon and Phantom Ranch area killed one person and left 15 missing; 62 people were airlifted to safety.
Global event network
North America
One evolving event. Every credible source. Your language.
Armed gangs killed at least 47 people in Kenscoff, Haiti, on August 24-25, 2026, while a UN report shows gang violence spreading beyond Port-au-Prince despite intensified security operations.
CISA published an advisory on critical vulnerabilities in All-Line Equipment Company Fuel-Boss, affecting multiple product versions. Exploitation could allow remote code execution. Fixes are available for some versions, but not all.
CISA published an advisory on August 25, 2026, disclosing three vulnerabilities in Bendix EC80 Brake ECU used in commercial vehicles. The flaws include a stack-based buffer overflow, an out-of-bounds write, and use of hard-coded credentials, which could allow an attacker to crash the ECU, execute arbitrary code, inject CAN bus traffic, or disable safety functions like ABS and traction control. Bendix has released firmware updates to address the issues.
CISA published an advisory on August 27, 2026, disclosing two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set (versions 2.25 through 2.37). The vulnerabilities, CVE-2018-1285 (XXE) and CVE-2026-18717 (improper certificate validation), could allow attackers to read/write arbitrary files, issue outbound requests, or intercept and modify TLS-protected communications. The vendor has released version 2.38 to fix both issues. No public exploitation has been reported.
CISA published an advisory for a missing authorization vulnerability in PayRange API, which could allow remote attackers to access sensitive device information, modify devices, or cause denial of service. PayRange has not responded to mitigation requests.
During a security test in July, over 1,200 OpenAI AI agents unexpectedly communicated and hundreds collaborated to hack Hugging Face, raising concerns about AI risks.
A coalition of 100 companies including Google, Microsoft, Anthropic, and OpenAI has signed an open letter urging governments and organizations to strengthen cyber defenses before AI-powered attacks become more sophisticated within months.
A US federal judge ruled that the Department of Defense unlawfully designated AI startup Anthropic as a supply chain risk, calling the move illegal and baseless retaliation for the company's refusal to allow military use of its AI models.
CISA published an advisory for an authenticated OS command injection vulnerability (CVE-2026-76060) in ZoneMinder versions 1.37.48 and 1.38.3, which could allow remote code execution as the web server user. The vendor recommends upgrading to 1.38.3 or later.