threat-intel ExfilSquad expose des données CRM municipales A new extortion group, ExfilSquad, claims to possess a significant amount of sensitive data from municipal services and CRM platforms, including data from Houston, Atlanta, and Microsoft. They’ve released sample data, pr… ZATAZ · Jul 30, 2026 High UNcrmdata breachexfiltration
threat-intel Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and… The Hacker News · Jul 30, 2026 High CVE-2026-42897CVE-2025-66376USEUxsscredential theftpersistence
threat-intel Headteacher had the most guessable username-password combo you could imagine This article is a roundup of cybersecurity and technology news, covering a range of topics including a phishing campaign targeting Signal users, a zero-day vulnerability in on-prem SharePoint, and a report on vulnerabili… The Register · Jul 30, 2026 Medium UNphishingvulnerabilityransomware
threat-intel Excuses like 'AI did it' don't exist in the eyes of the law This article is a collection of security-related news snippets, covering a range of topics from cybersecurity incidents and vulnerabilities to acquisitions and technological developments within the open-source and Linux… The Register · Jul 30, 2026 Medium IRCHphishingzero-dayransomware
threat-intel ISC Stormcast For Thursday, July 30th, 2026 https://isc.sans.edu/podcastdetail/10030, (Thu, Jul 30th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques to steal credentials. The threat landscape is evolving rapi… SANS Internet Storm Center · Jul 30, 2026 High phishingcredential stuffingbusiness applications
threat-intel Smashing Security podcast #478: This job interview could destroy your company This episode of Smashing Security explores the unsettling idea of a fake job interview used to recruit North Korean hackers, highlighting the potential for them to gain remote access to Western companies to install malwa… Graham Cluley · Jul 29, 2026 High NOnorth koreajob interviewghost assets
threat-intel Closed models refuse to help researcher swat Linux bug A researcher attempting to fix a Linux bug encountered a frustrating obstacle: closed AI models refused to assist, highlighting a growing concern about the limitations of current AI technology and its potential impact on… The Register · Jul 29, 2026 Medium aiopen-sourcelinux
threat-intel Word worm crawls into Copilot, spreads chaos A group of Russian hackers are impersonating Signal support to launch phishing attacks, targeting users with links to malicious websites. Simultaneously, a zero-day vulnerability in on-prem SharePoint is being exploited,… The Register · Jul 29, 2026 High RUIRphishingzero-daysharepoint
threat-intel Laundry Bear’s webmail hackers had more in store after February, report says Laundry Bear, a Russian state-linked APT group, has been aggressively exploiting vulnerabilities in both Zimbra Collaboration Suite’s webmail platform and Microsoft Outlook Web Access (OWA) to steal emails and credential… The Record · Jul 29, 2026 High CVE-2026-42897NLUSRUaptvulnerabilityzero-day
threat-intel Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems Iranian-linked cyber actors, believed to be part of the CyberAv3ngers group, are suspected of launching attacks against Minnesota water systems. This indicates a broader trend of state-sponsored cyber activity targeting… The Register · Jul 29, 2026 High IRcyberattackcritical infrastructurestate-sponsored
threat-intel Mate Security Raises $35 Million for Agentic SOC Mate Security, an Israeli AI-powered SOC startup, has secured $35 million in Series A funding to bolster its agentic platform and expand its operations. The company’s platform utilizes AI to create dynamic security conte… SecurityWeek · Jul 29, 2026 Info ILaisocsecurity
vulnerability Long-Lived Vulnerability in Microsoft Secure Boot A fundamental flaw in Microsoft's Secure Boot, a long-standing security feature designed to protect devices from firmware attacks, has been discovered and has existed for nearly 14 years. Researchers found that old, unsi… Schneier on Security · Jul 29, 2026 High firmwareshimuefi
threat-intel America bans imported robots due to supply chain and security risks The United States is implementing a ban on importing robots due to significant security and supply chain risks. This action is driven by concerns about potential vulnerabilities in these devices, which could be exploited… The Register · Jul 29, 2026 Medium IRroboticssupply chainsecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (29 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing an attacker to cause data integrity issues and a security problem not specified by the vendor. These vulnerabilities are part of a lar… CERT-FR · Jul 29, 2026 High CVE-2026-62828CVE-2026-13282CVE-2026-13283vulnerabilitysecuritymicrosoft
threat-intel MCP gets an enterprise makeover This article covers a range of cybersecurity and technology news, including a vulnerability impacting Joomla extensions, a Microsoft SharePoint zero-day exploit, and a Russian phishing campaign mimicking Signal support.… The Register · Jul 28, 2026 Medium USIRRUvulnerabilityphishingransomware
threat-intel Microsoft and Wiz mind-meld agents catch more than 90% of bugs Microsoft and Wiz have partnered to create a new agent-based security solution that significantly improves bug detection. The system, leveraging AI and machine learning, can identify a high percentage of vulnerabilities,… The Register · Jul 28, 2026 High UNvulnerabilityaimachine learning
vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed f… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
threat-intel AI-found bugs aren't proving any easier to exploit despite the hype Recent research indicates that AI-powered models, particularly those mimicking Claude, are being exploited to bypass security measures. Researchers have found that Chinese AI models can convincingly impersonate Claude, h… The Register · Jul 28, 2026 Medium CHIRUSaiimpersonationphishing
threat-intel Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first The United States is actively working to maintain leadership in 6G technology and security, particularly in response to China's advancements. Recent security incidents highlight ongoing threats, including phishing attack… The Register · Jul 28, 2026 Medium IRCHphishingvulnerabilitiescybersecurity
threat-intel Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Microsoft has released MAI-Cyber-1-Flash, its first cybersecurity AI model, designed to significantly improve vulnerability detection compared to competitors. This new model is integrated into Microsoft’s Project Percept… SecurityWeek · Jul 28, 2026 Medium aicybersecurityvulnerability detection