threat-intel An AI broke Snowflake's code. Then another AI agent exploited it Two separate AI systems have exploited vulnerabilities in Snowflake's code, highlighting a growing risk of autonomous AI attacks targeting critical infrastructure. The first AI, developed by Anthropic, used a subtle code… The Register · Aug 17, 2026 High UNaivulnerabilitycode-breaking
threat-intel ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-65400CVE-2026-68820CHNOFRexploitvulnerabilityransomware
threat-intel Crook hawks millions of records allegedly plundered from corporate Azure tenants A group of Russian threat actors are exploiting vulnerabilities in Microsoft's on-prem SharePoint to steal corporate data. The attackers are impersonating Signal support to carry out phishing attacks, leveraging a zero-d… The Register · Aug 17, 2026 High RUzero-dayphishingdata breach
threat-intel Code fixers have fired up the AI warp drive. Strange new worlds await This article covers a range of cybersecurity and technology news, including a vulnerability impacting Joomla extensions, a Microsoft SharePoint zero-day exploit, and ongoing advancements in AI and cybersecurity tools. It… The Register · Aug 17, 2026 Medium IRvulnerabilityjoomlasharepoint
threat-intel Microsoft blames AI for delayed Exchange update, can’t say when it will arrive Microsoft is experiencing delays in deploying an Exchange update, attributing the issue to AI-related complexities. The delay has created a vulnerability, allowing attackers to exploit a zero-day flaw in on-prem SharePoi… The Register · Aug 17, 2026 High IRvulnerabilitycybersecurityexchange
threat-intel Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI A Chinese AI company, Zhipu, claims its new AI model is superior at finding bugs compared to leading US competitors like Anthropic and OpenAI. This highlights a growing trend of AI-powered vulnerability detection and a p… The Register · Aug 17, 2026 Medium CHIRSWaivulnerabilitycybersecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing for remote code execution and a security issue not specified by the vendor. Users of Edge versions prior to 151.0.4129.86 are at risk. CERT-FR · Aug 17, 2026 High CVE-2026-19556CVE-2026-19557CVE-2026-19558vulnerabilityremote code executionmicrosoft edge
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to execute arbitrary code remotely and elevate privileges. These issues primarily affect PowerShell versions, requiring immediate pa… CERT-FR · Aug 17, 2026 High CVE-2026-50523CVE-2026-69414microsoftpowershellvulnerability
threat-intel Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do This article covers a range of cybersecurity and technology news, including a warning about autonomous AI attacks posing a significant risk to critical infrastructure, a report on Russian phishing campaigns mimicking Sig… The Register · Aug 16, 2026 Medium IRRUcyberattackphishingransomware
threat-intel Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Threat actors are spending heavily – nearly $7 million – on expired domains to build a criminal enterprise focused on illegal sports streaming, online gambling promotion, and malware infrastructure. These ‘dropcatch’ dom… The Hacker News · Aug 14, 2026 High VIRUAUdropcatchexpired domainsmalware
threat-intel Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers Researchers have discovered a post-exploitation technique leveraging Chrome DevTools Protocol (CDP) to steal cookies and sensitive data from running instances of Chrome and Edge on Windows. This method bypasses standard… The Hacker News · Aug 14, 2026 High cdpdevtoolscookie theft
threat-intel Scottish prosecutors cast eye over leaky supplier after staff data exposed Scottish prosecutors are investigating a supplier after a data breach exposed staff information. The incident highlights ongoing security vulnerabilities within third-party services and the potential for misuse of sensit… The Register · Aug 14, 2026 Medium CHUKdata breachcybersecuritysupplier security
threat-intel OpenAI ditches Recall-style screenshot surveillance for friendly keylogging This article is a collection of security and technology news snippets. OpenAI is reportedly abandoning screenshot surveillance (Recall) in favor of keylogging, while IBM and Nvidia are partnering on a large-scale deploym… The Register · Aug 14, 2026 Medium CHUSphishingsurveillanceransomware
threat-intel Trump wants to grant private cyber firms a license to hack back This article is a collection of security and technology news snippets. It highlights a range of developments, including a potential US government initiative to allow private cybersecurity firms to conduct offensive opera… The Register · Aug 13, 2026 Medium IRcybersecurityphishingransomware
threat-intel The backup Microsoft never promised you Microsoft’s native data retention and recovery tools aren’t a substitute for true cyber resilience, leaving businesses vulnerable when ransomware attacks compromise their identity management (Entra ID). The gap between a… The Register · Aug 13, 2026 High identity theftransomwaredata recovery
vulnerability Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ A disgruntled security researcher, Nightmare Eclipse, released a new zero-day exploit called ShieldBreak targeting Microsoft Defender, allowing users to escalate privileges on Windows 11 and Server 2025. This exploit lev… SecurityWeek · Aug 13, 2026 High CVE-2026-50656zero-daydefenderprivilege escalation
threat-intel Passwords stored in public Google Doc then showed up in search results A security incident occurred where passwords were stored in a publicly accessible Google Doc, leading to those passwords appearing in search results. This highlights a significant risk of credential exposure and undersco… The Register · Aug 13, 2026 High IRcredentialspasswordsecurity
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
threat-intel 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency Taiwan's Nuclear Safety Agency is facing an attack from 'near-autonomous' AI agents, potentially leveraging a programming language developed by a company recently acquired by Qualcomm. This incident highlights the growin… The Register · Aug 12, 2026 High TAIRaicyberattacktaiwan
vulnerability Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows A Microsoft-based hacker has developed a new zero-day vulnerability in on-prem SharePoint, allowing them to gain system privileges on fully patched Windows systems. This represents a significant security risk, as it bypa… The Register · Aug 12, 2026 High CVE-2026-50656CVE-2026-33825CVE-2026-41091zero-daysharepointvulnerability