ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
threat-intel In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Several significant cybersecurity events are unfolding this week, including a coordinated AI-powered scam network originating in Cambodia, a data breach at Amgen, a supply chain attack targeting QuickFox VPN, and a serie… SecurityWeek · Aug 7, 2026 High CHCAUSsupply-chainphishingransomware
vulnerability Microsoft, Apple Release Fresh Security Updates Microsoft and Apple released a combined set of security updates addressing dozens of vulnerabilities across their products, including critical remote code execution flaws. These updates target a wide range of products, i… SecurityWeek · Aug 7, 2026 Critical CVE-2026-63508CVE-2026-56162CVE-2026-65667vulnerabilityremote code executionpatch
vulnerability Vulnérabilité dans Apple macOS (07 août 2026) Apple has disclosed a security vulnerability in macOS that allows attackers to bypass security policies. This vulnerability could lead to unauthorized access and potential compromise of user systems. Users of affected ma… CERT-FR · Aug 7, 2026 Medium CVE-2026-65400macossecurityvulnerability
threat-intel ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories This week's 'ThreatsDay' bulletin highlights a diverse range of security threats, including a China-linked telecom risk, a multi-stage phishing attack leveraging ClickOnce files, a supply chain attack involving 846 softw… The Hacker News · Aug 6, 2026 High CVE-2025-21079CVE-2025-58486CVE-2026-25177CHUSsupply-chainmalwarephishing
vulnerability Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Researchers have discovered a vulnerability in Apple's iCloud Private Relay tool that allows users' real IP addresses to be exposed, even when the tool is active. The issue stems from three WebKit features – DNS prefetch… The Hacker News · Aug 6, 2026 High webkitprivacyip leak
threat-intel Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple has implemented strict limits on its bug bounty program to combat a surge of low-quality, AI-generated vulnerability reports. The issue stems from amateur bug hunters using AI to create plausible-but-nonexistent se… Graham Cluley · Aug 6, 2026 High aivulnerabilitybug bounty
threat-intel Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A macOS ClickFix operation is using browser fingerprinting to deliver malware lures to a targeted subset of Mac users. The operation, involving over 250 domains and distributing malware like MacSync and AMOS, hides the m… The Hacker News · Aug 5, 2026 High browser fingerprintingmacosclickfix
threat-intel Apple launches new legal challenge against UK over iCloud access Apple is challenging the UK government’s legal demands for access to user data stored on iCloud, specifically related to a Technical Capability Notice (TCN) that requires Apple to retain the ability to access iCloud cont… The Record · Aug 4, 2026 High UKUSencryptiondata-privacylaw-enforcement
threat-intel Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS A Chinese threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to deploy GHOSTBLADE, an information-stealing malware, targeting Apple iOS devices. Censys identified over 100 web properties us… The Hacker News · Aug 3, 2026 High HOJACHiosexploit kitmalware
threat-intel The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version The XCSSET malware family has returned with version 40, exhibiting enhanced stealth and persistence techniques to evade detection and compromise macOS systems, particularly those of software developers. This latest itera… Palo Alto Unit 42 · Jul 31, 2026 High SOmacossupply chainmalware
threat-intel ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale A research firm, Silent Push, demonstrated how artificial intelligence can significantly amplify the effectiveness of ‘dangling DNS takeover’ attacks, a vulnerability where a forgotten DNS record points to a deleted clou… SecurityWeek · Jul 30, 2026 High dangling dnsdns takeovercloud security
vulnerability Chrome 151 Patches 370 Vulnerabilities Google released Chrome 151, addressing a massive 370 security vulnerabilities. This update includes critical and high-severity bugs across various components, highlighting the ongoing need for diligent security practices… SecurityWeek · Jul 30, 2026 High vulnerabilitychromesecurity
vulnerability Apple Patches Everything (July 2026), (Wed, Jul 29th) Apple released a substantial security update addressing 187 vulnerabilities across its macOS, iOS, and Safari operating systems. The update focuses on patching a range of issues, including DoS attacks, privilege escalati… SANS Internet Storm Center · Jul 29, 2026 Medium CVE-2026-28849CVE-2026-28900CVE-2026-28914macosiossafari
vulnerability Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Apple has released security updates addressing a significant number of vulnerabilities across its iOS, macOS, Safari, watchOS, tvOS, and visionOS operating systems. These patches address a wide range of issues, including… SecurityWeek · Jul 28, 2026 High CVE-2026-43810securitypatchvulnerabilities
vulnerability Multiples vulnérabilités dans les produits Apple (28 juillet 2026) Multiple vulnerabilities have been discovered in Apple products, including iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. Several of these vulnerabilities allow for arbitrary code execution, privilege escalation, and d… CERT-FR · Jul 28, 2026 High CVE-2025-43325CVE-2026-20672CVE-2026-23918securityvulnerabilitypatch
threat-intel Researchers replace downloaded macOS apps with evil twins, Apple shrugs Researchers have discovered a method to replace downloaded macOS applications with malicious 'evil twin' versions, while Apple has not responded to the issue. This highlights a significant vulnerability in how users obta… The Register · Jul 23, 2026 Medium IRUSmacosmalwarephishing
threat-intel Agentic AI Challenges Progress in Confidential Computing Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, e… Dark Reading · Jul 23, 2026 High UNaiconfidential computingsecurity