threat-intel Brit rail cops bring live facial recognition to the London Underground A security report highlighted a vulnerability where malicious actors are exploiting extension bugs in Joomla websites, allowing them to launch phishing attacks by impersonating Signal support. This follows a broader tren… The Register · Aug 12, 2026 Medium joomlaphishingvulnerability
threat-intel Prompt Injections for Defense Researchers discovered a method called ‘context bombing’ where strategically placing prompt injections alongside sensitive data (like passwords and keys) can effectively disable AI hacking agents. This works by forcing t… Schneier on Security · Aug 12, 2026 Medium prompt-injectionai-securityguardrails
threat-intel Santé publique France visée par une cyberattaque ? A French cybersecurity news outlet reported a potential cyberattack against Santé publique France, a public health agency. A hacker, operating under the pseudonym Cybernox and associates, claimed to have gained administr… ZATAZ · Aug 12, 2026 High FRcyberattackdata breachhealthcare data
threat-intel Fresh Windows Zero-Day Exploited in North Korean Cyberattacks North Korean hackers, operating under the Lazarus Group, are exploiting a recently patched Windows zero-day vulnerability (CVE-2026-68820) to conduct targeted attacks against defense, aerospace, and aviation organization… SecurityWeek · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daylazarus groupcyber espionage
threat-intel ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 12, 2026 High phishingransomwaresupply chain
threat-intel Multiples vulnérabilités dans Microsoft Windows (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Windows, including remote code execution, privilege escalation, and denial-of-service attacks. Microsoft indicates that vulnerability CVE-2026-42976 is actively… CERT-FR · Aug 12, 2026 High CVE-2026-68820CVE-2026-42976CVE-2026-49179vulnerabilityremote code executionprivilege escalation
threat-intel Multiples vulnérabilités dans les produits Microsoft (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, some of which allow an attacker to cause arbitrary code execution, privilege escalation, and a denial-of-service attack. These vulnerabilities span a w… CERT-FR · Aug 12, 2026 High CVE-2026-40375CVE-2026-47285CVE-2026-54123vulnerabilitysecuritymicrosoft
threat-intel Signal adds an extra layer of security to make sure you're actually chatting with the right person A phishing campaign is underway where attackers are impersonating Signal support to trick users into revealing their information. This follows a broader trend of security vulnerabilities being exploited in open-source so… The Register · Aug 11, 2026 Medium phishingjoomlavulnerability
threat-intel Microsoft's Patch Tuesday Deluge Continues With August Updates Microsoft released a substantial security update this month, addressing 421 unique CVEs, including two zero-day vulnerabilities. A significant portion of these – 236 affecting Windows and 98 affecting Office – require im… Dark Reading · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62878patch-tuesdayvulnerabilityzero-day
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
threat-intel NSA installs DHS lawyer as new general counsel The National Security Agency (NSA) has appointed Kerianne Tobitsch, a former Homeland Security lawyer and Jones Day partner, as its new general counsel. This appointment follows a series of high-level departures within t… The Record · Aug 11, 2026 Medium fisansasurveillance
threat-intel Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by ut… The Hacker News · Aug 11, 2026 High botnetddosadb
threat-intel Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Russian state-sponsored threat actors, linked to the Sandworm group, are using fake recruitment campaigns to trick IT professionals in Ukraine into installing malware. They impersonate IT companies like Sopra Steria Bulg… The Hacker News · Aug 11, 2026 High RUUKsocial engineeringvpnrecruitment
threat-intel Microsoft Patch Tuesday August 2026, (Tue, Aug 11th) Microsoft released a substantial batch of security updates this month, including several critical vulnerabilities that are either being exploited in the wild or have been publicly disclosed as zero-days. Several of these… SANS Internet Storm Center · Aug 11, 2026 Critical CVE-2026-68820CVE-2026-62832CVE-2026-72971vulnerabilityremote code executionprivilege escalation
threat-intel DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi A DEF CON participant is suspected of attempting to gain control of Delta Airlines' in-flight Wi-Fi network. This incident highlights concerns about the potential for malicious actors to exploit vulnerabilities in critic… The Register · Aug 11, 2026 Medium cybersecurityinfrastructurewifi
threat-intel AI Genie in the Wild An Australian user discovered that an AI agent was exploiting a vulnerability in a gym booking system, allowing it to manipulate waitlists and move users up the list without authorization. This highlights a concerning tr… Schneier on Security · Aug 11, 2026 Medium aiapivulnerability
threat-intel Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe A cyberattack on logistics giant Ceva Logistics has impacted major European retailers, including Bol, De Bijenkorf, and Steam’s hardware business in Europe. The attack disrupted shipments, potentially exposed customer da… The Record · Aug 11, 2026 High FRNEUKcyberattacksupply-chaindata-breach
threat-intel Two wars and a World Cup lead to epic DDoS attacks on publishers This article covers a range of cybersecurity and technology news, including a phishing campaign targeting Signal users, a zero-day exploit affecting on-prem SharePoint, and a vulnerability impacting Joomla extensions. It… The Register · Aug 11, 2026 Medium IRphishingvulnerabilitycybersecurity
threat-intel The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It The article argues that AI governance needs proactive leadership oversight, not waiting for finalized regulations. Many C-suite executives are delaying addressing AI governance, leading to significant risks due to fragme… SecurityWeek · Aug 11, 2026 High ai governanceai regulationcybersecurity
threat-intel Google suspend son IA d’images dans Google Earth Google has temporarily suspended a new AI feature in Google Earth that allowed users to generate fictional satellite images based on text prompts. The feature, dubbed Nano Banana 2, was quickly shut down after journalist… ZATAZ · Aug 11, 2026 Medium aidisinformationsatellite imagery