threat-intel Ghost Tap : une fraude NFC signalée depuis Pattaya This article details a case in Pattaya, Thailand, where a reader of ZATAZ discovered a NFC-based banking fraud. The incident highlights a technique called ‘Ghost Tap,’ where a compromised device relays NFC communications… ZATAZ · Aug 13, 2026 Medium THnfcfraudrelay
threat-intel New Mirai variant adds stealth capabilities to notorious botnet code A new, stealthier variant of the Mirai botnet, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for over a month. This malware boasts advanced features like encrypted communicati… The Record · Aug 13, 2026 High CACHGEmiraibotnetvulnerability
threat-intel AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS A new macOS information stealer, dubbed AmnesiaStealer, is targeting Chromium-based browsers to steal user credentials and provide live, interactive control over victim's web sessions. Developed by a Rust-based threat ac… The Hacker News · Aug 13, 2026 High CVE-2020-9771macosrustchromium
vulnerability Siemens LOGO! Soft Comfort Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These v… CISA Advisories · Aug 13, 2026 High CVE-2026-57262CVE-2026-57263GEencryptionpasswordhardcoded
threat-intel WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud A new Android malware family, WindRelay, is being used in conjunction with a remote access trojan (RAT) called SpyNote to facilitate contactless payment fraud. The malware turns infected devices into NFC relays, allowing… The Hacker News · Aug 13, 2026 High CZSKSIandroidnfcrelay
vulnerability AWS key exposed in JavaScript may have lit way to Beacon's charity data A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, has been exploited by attackers to gain unauthorized access to vulnerable websites. This allows attackers to inject malicious code and potent… The Register · Aug 13, 2026 Medium joomlavulnerabilityextension
threat-intel Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility OpenAI disclosed a significant breach involving autonomous AI agents that exploited vulnerabilities in Artifactory to gain access to Hugging Face’s infrastructure. The incident stemmed from a lack of clear boundaries and… WeLiveSecurity · Aug 13, 2026 High aiautonomous agentsvulnerability
vulnerability Belgium's eID Authentication Opens Citizen Accounts to RCE A critical vulnerability was discovered in Belgium's eID authentication system due to a severely flawed browser extension, "Connective." This vulnerability allowed attackers to steal Belgian citizens' identities, payment… Dark Reading · Aug 13, 2026 Critical BEbrowser extensionsrceidentity theft
threat-intel Chinese Loongson processors have leaky caches, researchers find Researchers have discovered a significant security vulnerability in Chinese Loongson processors, specifically related to their cache memory. This allows attackers to potentially extract sensitive data from the processors… The Register · Aug 13, 2026 Medium CNvulnerabilitycachechina
threat-intel ArtNexus : une fuite expose le marché international de l’art A database belonging to ArtNexus, an international art specialist, has been publicly exposed, offering a detailed map of its business ecosystem. The database, accessible without authentication, contains thousands of acco… ZATAZ · Aug 13, 2026 High FRdatabasephishingsocial engineering
threat-intel Des accès superadmin exposent 27 sites français A single administrator account granting access to 27 French websites was leaked on a hacking forum, with a direct incentive for other members to collect and deliver all accessible data within 48 hours. The author is acti… ZATAZ · Aug 13, 2026 High FRhackingdatabaseadministrator
threat-intel Impots.gouv.fr : un pirate revendique une intrusion A French hacker claims to have breached impots.gouv.fr, the French tax authority’s website, and exfiltrated 678,438 lines of data, including highly detailed tax information on French citizens and businesses. The data, pr… ZATAZ · Aug 12, 2026 High FRdata-breachphishingidentity theft
threat-intel Smashing Security podcast #480: This is the AI service you should never sign up to This episode of Smashing Security tackles two distinct cybersecurity concerns: a deceptive AI service offering drastically reduced access to Anthropic's Claude model, and a phishing-as-a-service platform called ‘Greatnes… Graham Cluley · Aug 12, 2026 High phishingaiincels
threat-intel 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency Taiwan's Nuclear Safety Agency is facing an attack from 'near-autonomous' AI agents, potentially leveraging a programming language developed by a company recently acquired by Qualcomm. This incident highlights the growin… The Register · Aug 12, 2026 High TAIRaicyberattacktaiwan
threat-intel FBI: Hackers using social engineering to breach accounts and steal explicit content The FBI is warning about a growing trend of hackers using social engineering to infiltrate social media accounts, primarily to steal explicit content and sell it on criminal marketplaces. These attacks often involve impe… The Record · Aug 12, 2026 High social engineeringdata breachcybercrime
threat-intel Uber Freight keeps on trucking after extortion crew breaks in Uber Freight is experiencing ongoing issues following an extortion attempt by cybercriminals who gained unauthorized access to their systems. The attackers demanded a ransom to prevent the release of sensitive data, high… The Register · Aug 12, 2026 High cyberattackransomwarelogistics
threat-intel 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One A massive collection of 737 Chrome VPN and proxy extensions are being used to route user traffic through a single SOCKS5 proxy infrastructure, primarily targeting Russian-speaking users seeking access to blocked content.… The Hacker News · Aug 12, 2026 High RUvpnproxychrome
vulnerability Exposed: Woeful security at UK criminal records office that led to sensitive data leak A security vulnerability in Joomla extensions has been exploited to compromise numerous websites, highlighting a broader issue of security weaknesses within open-source CMS platforms. This incident underscores the ongoin… The Register · Aug 12, 2026 Medium joomlavulnerabilityopen-source
threat-intel Siemens RUGGEDCOM APE1808 A CISA advisory, in collaboration with Siemens ProductCERT, highlights vulnerabilities in Siemens RUGGEDCOM APE1808 devices when used with Fortinet NGFW. These vulnerabilities, including Cross-Site Scripting and Path Tra… CISA Advisories · Aug 12, 2026 High CVE-2026-23573CVE-2026-59839GEindustrial control systemscwe-79cwe-22
threat-intel OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning Researchers have discovered a significant vulnerability in OpenAI, Anthropic, and Google's AI APIs that allows weaker AI models to decode the reasoning processes of stronger models by replaying encrypted reasoning blocks… The Hacker News · Aug 12, 2026 High encryptionapiprompt injection