threat-intel An analysis of incidents at Brazilian educational institutions This report details cyberattacks targeting educational institutions in Brazil since 2025, highlighting a trend of leveraging readily available tools and valid accounts to gain access and deploy ransomware and other malwa… Securelist · Aug 3, 2026 High BRransomwarethreat-intelinsider-threat
threat-intel Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says Russian state-sponsored hackers, linked to the Midnight Blizzard group (part of APT29), are compromising hotel Wi-Fi networks worldwide to steal traveler login credentials and install espionage malware. The campaign uses… The Record · Aug 3, 2026 High RUUKSAhotel wifiespionagecaptive portal
threat-intel Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking A Russian state-sponsored APT group, Storm-2945 (linked to Midnight Blizzard/APT29), is leveraging compromised public Wi-Fi gateway networks to steal Microsoft 365 credentials of traveling employees. The campaign involve… SecurityWeek · Aug 3, 2026 High aptcredential theftdns manipulation
threat-intel PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web The Police National Legal Database (PNLD) in the UK has confirmed that contact information, including names, email addresses, and organizations, belonging to police officers, government partners, and customers was expose… The Hacker News · Aug 3, 2026 High data breachpower appsdark web
threat-intel AI is 'both the weapon and the target' in latest wave of cyberattacks This article covers a range of cybersecurity and technology news, including a focus on AI's role in cyberattacks, a UK datacenter fee initiative, phishing attacks targeting Signal users, and various security updates and… The Register · Aug 3, 2026 Medium IRcybersecurityphishingransomware
vulnerability Multiples vulnérabilités dans Microsoft Edge (03 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge. Some of these allow an attacker to cause arbitrary code execution, data confidentiality breaches, and data integrity issues. These vulnerabilities are part… CERT-FR · Aug 3, 2026 High CVE-2026-17650CVE-2026-17651CVE-2026-17652vulnerabilitysecuritymicrosoft
vulnerability Vulnérabilité dans Microsoft Office (03 août 2026) A remote code execution vulnerability has been identified in Microsoft Office, allowing attackers to execute arbitrary code. This affects various versions of Office 365, Excel, and Office LTSC, requiring immediate patchi… CERT-FR · Aug 3, 2026 High CVE-2026-62870remotecodeexecution
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
threat-intel CISA Issues Fresh SBOM Guidance. Did They Get It Right? CISA has released updated guidance on Software Bill of Materials (SBOMs), adding 10 new elements and refining existing ones to improve comprehensiveness. However, critics, like OWASP founder Jeff Williams, argue that the… Dark Reading · Jul 31, 2026 Medium sbomopen sourcesupply chain
threat-intel 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 Device code phishing, a rapidly growing threat exploiting the OAuth 2.0 device authorization grant, has evolved from a niche technique to a widespread criminal and nation-state tactic in a matter of months. Attackers are… The Hacker News · Jul 31, 2026 High device-code-phishingoath2phishing-as-a-service
threat-intel EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels The European Union is establishing a new team in Brussels to combat the misuse of AI, particularly concerning deepfakes, illicit imagery, and cyber threats. This initiative is part of a broader strategy to assert tech so… SecurityWeek · Jul 31, 2026 Medium EUUSCHaideepfakeregulation
vulnerability Critical Flaw Led to Azure Cosmos DB Pwnage A critical vulnerability, dubbed CosmosEscape, in Azure Cosmos DB allowed attackers to obtain a platform-wide key, enabling them to compromise all databases on the service. Wiz researchers exploited this flaw by bypassin… SecurityWeek · Jul 31, 2026 Critical vulnerabilitycode executiondatabase
vulnerability Vulnérabilité dans Microsoft Azure (31 juillet 2026) A critical vulnerability has been identified in Microsoft Azure's Cosmos DB, allowing attackers to execute arbitrary code remotely. This could lead to significant data compromise and system control for malicious actors. CERT-FR · Jul 31, 2026 Critical CVE-2026-66803azureremote code executiondatabase
threat-intel You were onto something with “It’s the Climb,” Miley This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-… Cisco Talos · Jul 30, 2026 High USphishingauthenticationransomware
threat-intel Jailed Flock vandal wipes out three cameras, racks up thousands in damages This article is a collection of miscellaneous tech news items, including a report on corporate IT workloads moving off-site, a lament for Intel's Optane storage technology, a security alert about Joomla extensions being… The Register · Jul 30, 2026 Medium securitycybersecurityvulnerability
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
vulnerability Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database A vulnerability in Azure Cosmos DB, dubbed CosmosEscape by Wiz, allowed an attacker to bypass the service's query sandbox and gain platform-wide access to customer databases. The exploit chain began with a crafted Gremli… The Hacker News · Jul 30, 2026 High azurecosmos dbsecurity
threat-intel ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale A research firm, Silent Push, demonstrated how artificial intelligence can significantly amplify the effectiveness of ‘dangling DNS takeover’ attacks, a vulnerability where a forgotten DNS record points to a deleted clou… SecurityWeek · Jul 30, 2026 High dangling dnsdns takeovercloud security
threat-intel Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents Microsoft Copilot for Word has a vulnerability that allows hidden instructions within a Word document to be copied into new documents and then re-introduced during subsequent Copilot drafting sessions. This allows an att… The Hacker News · Jul 30, 2026 High prompt injectionai securitycopilot
threat-intel Russian spies take their half-click email attack from Zimbra to Outlook Russian intelligence operatives are leveraging a phishing campaign mimicking Signal support to trick users into revealing sensitive information. This tactic has expanded beyond Zimbra to now target Outlook users, highlig… The Register · Jul 30, 2026 High CVE-2026-42897RUCHphishingsocial engineeringrussian threat actor