threat-intel Une fausse lettre AR24 vole les identifiants mail This article details a phishing campaign mimicking AR24 to steal email credentials. The attackers use a fake ‘letter of recommendation’ email with a fabricated ‘invoice due’ to create a sense of urgency and trick victims… ZATAZ · Aug 10, 2026 High phishingsocial engineeringcredential theft
vulnerability Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius A zero-day SQL-injection vulnerability in Metabase Cloud is actively being exploited, potentially impacting a wide range of organizations beyond Metabase customers. The vulnerability allows remote attackers to gain admin… Dark Reading · Aug 10, 2026 High sql-injectionzero-dayvulnerability
threat-intel Une nouvelle fuite pour la FF Handball ? A hacker claims to have compromised an internal tool of the French Handball Federation (FFHB), exposing over 1.3 million lines of data and sensitive documents, including IDs, passports, and medical records. The hacker in… ZATAZ · Aug 10, 2026 High FRdata breachcredential stuffingdata leak
threat-intel À vendre : les coulisses d’un empire du pari A cybersecurity news platform has uncovered a pattern of suspicious activity by a single online seller offering access to vast databases of gambling-related data, including player information, casino prospects, and crypt… ZATAZ · Aug 10, 2026 High AZGEINdata-breachthreat-intelgambling
threat-intel Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres Meta's Ray-Ban smart glasses are facing increasing bans in venues across the UK due to concerns about covert surveillance. The glasses, which resemble ordinary spectacles, can record audio and video, and a recent investi… Graham Cluley · Aug 10, 2026 High UKKESWprivacysurveillanceai
threat-intel The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists The article highlights a significant gap between the speed at which attackers discover and exploit vulnerabilities and the speed at which defenders can patch them. Traditional CVSS-based prioritization is inadequate beca… Dark Reading · Aug 10, 2026 High CVE-2024-9474CVE-2024-0012vulnerabilityattack-pathchoke-point
threat-intel Attackers pick Levi's pockets in social engineering attack Attackers are leveraging social engineering to steal data from Levi's customers. The attackers impersonated Signal support to trick users into providing their credentials, leading to a data breach. The Register · Aug 10, 2026 Medium social engineeringdata breachphishing
threat-intel ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad Tenet security researchers have demonstrated a novel ‘Ghostjacking’ attack that leverages poisoned logs to manipulate AI agents, effectively turning them into malicious tools. The attack exploits trust in AI agents by in… SecurityWeek · Aug 10, 2026 High aiartificial intelligencelog poisoning
threat-intel New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA Recent research has revealed significant vulnerabilities in passkey authentication systems, demonstrating ways to bypass security measures and impersonate users. SpecterOps found that Windows stored past YubiKey signatur… The Hacker News · Aug 10, 2026 High CVE-2026-34348passkeyauthenticationvulnerability
threat-intel Cyber vulnerability sweep picks up Royal Navy drones sending data to China A vulnerability in Royal Navy drones is allowing Chinese entities to access sensitive data. The flaw stems from a misconfigured system that transmits data to servers in China, raising significant national security concer… The Register · Aug 10, 2026 High UKCHvulnerabilitynational securitydata transmission
threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor
threat-intel IT threat evolution in Q2 2026. Mobile statistics In Q2 2026, mobile malware attacks continued to decline, with Trojan-Banker applications representing the most prevalent threat. Despite a drop in new Trojan variants, the landscape remained dominated by Mamont banking T… Securelist · Aug 10, 2026 Medium mobilemalwarebanking
threat-intel OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause OpenAI is pausing internal development of its AI model Astra due to concerns about its rapidly advancing cyber capabilities. Initial evaluations suggest the model possesses ‘Critical’ cyber capabilities, including the po… The Hacker News · Aug 10, 2026 High aicybersecurityai-safety
threat-intel New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens Researchers at PortSwigger have discovered several new attack vectors targeting webmail interfaces, allowing attackers to steal passwords, take over accounts, and manipulate AI tools. The vulnerabilities exploit weakness… The Hacker News · Aug 8, 2026 High webmailcsshtml
vulnerability N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for… The Hacker News · Aug 8, 2026 Critical CVE-2026-18577CVE-2026-18556zero-dayremote accesscloudflare
threat-intel AI-Generated Patches Fail Half the Time A study by 1Password found that AI-generated patches are significantly flawed, with only around 46% successfully fixing vulnerabilities and many introducing new bugs or requiring code modification. The research, dubbed F… Dark Reading · Aug 7, 2026 High UNaipatchingvulnerability
threat-intel N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands A flaw in N-able’s God mode feature allowed attackers to gain unauthorized access to customer networks. The vendor has confirmed that attackers exploited this vulnerability to compromise systems, and a second hotfix has… The Register · Aug 7, 2026 Critical CVE-2026-18577vulnerabilityremote managementcyberattack
data-breach Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder A Scottish NHS trust is investigating a security breach that may have exposed the medical records of a 9-year-old girl. This follows the arrest of a man on suspicion of murder, and authorities are examining how unauthori… The Register · Aug 7, 2026 High UKvulnerabilitysharepointhealthcare
vulnerability New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A high-severity cross-site scripting (XSS) vulnerability in WordPress's login screen allows attackers to execute PHP code on a server, potentially leading to database compromise and full system control. The vulnerability… The Hacker News · Aug 7, 2026 High CVE-2026-64638xsswordpresscve-2026-64638
threat-intel Growing Up The Hard Way This article explores the evolving landscape of open source software and the increasing need for commercial support to ensure its long-term viability. The author argues that open source is transitioning into a two-tiered… The Hacker News · Aug 7, 2026 High open sourcemaintenancevendor