threat-intel Le deface, ce piratage que personne ne regarde The article highlights a significant trend beyond just data breaches and ransomware – the prevalence of ‘deface’ attacks. ZATAZ documented 975 deface attacks in August alone, with a large percentage of these sites still displaying the attacker’s signature. These attacks are not simply cosmetic; they can be used for rec… ZATAZ · 2d ago High FRCHNOdefacereconnaissancethreat intelligence
threat-intel Learn How to Build Security Operations Ready for AI-Powered Attacks AI is significantly accelerating the speed at which attackers can discover vulnerabilities and exploit systems. This requires security teams to improve their visibility, prioritize risks, and streamline the process of mo… The Hacker News · 3d ago Medium aisecurity operationsvulnerability management
threat-intel Virtual Event Today: CodeSecCon – Secure Your Code and Applications CodeSecCon, a virtual event focused on software security, is taking place today. The event aims to help developers and cybersecurity professionals improve application security practices and address challenges in DevSecOp… SecurityWeek · Aug 19, 2026 Info devsecopssecure codingai security
supply-chain Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th) A sophisticated supply-chain attack leveraging compromised npm packages (keyv and cacheable) has been active since August 4th, 2026. Attackers exploited a vulnerability to inject malicious code into widely used libraries… SANS Internet Storm Center · Aug 5, 2026 High supply-chainnpmcredential theft
threat-intel Microsoft and Wiz mind-meld agents catch more than 90% of bugs Microsoft and Wiz have partnered to create a new agent-based security solution that significantly improves bug detection. The system, leveraging AI and machine learning, can identify a high percentage of vulnerabilities,… The Register · Jul 28, 2026 High UNvulnerabilityaimachine learning
threat-intel Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Glow, a new AI-powered endpoint security startup, secured $180 million in Series A funding, valuing the company at $1.2 billion. Founded by former Meta and Snowflake executives, Glow focuses on mitigating security risks… SecurityWeek · Jul 22, 2026 Info aiendpoint securitycybersecurity
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
threat-intel Google Bets 'Agentic Defense' Strategy Can Outpace Attackers Google is implementing an ‘agentic defense’ strategy, leveraging its acquisition of Wiz to automate threat detection and response in a rapidly evolving cybersecurity landscape. This involves deploying AI-powered agents a… Dark Reading · Jul 17, 2026 High UNCHaicloud securitygraph analysis
threat-intel AI Coding: Do Security Risks Outweigh Productivity Gains? AI coding tools are rapidly increasing in popularity, with 91% of organizations using two or more and 54% using three or more. While developers report productivity gains and ROI, significant security risks are associated… Dark Reading · Jul 10, 2026 High aicodingsecurity
threat-intel Amazon Q VS Extension Flaw Leads to Cloud Credential Theft A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of M… Dark Reading · Jun 29, 2026 High CVE-2026-12957CVE-2025-59536CVE-2026-21852aimcpcredentials
vulnerability Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execut… SecurityWeek · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958USaivscodecredentials
threat-intel Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A critical vulnerability was discovered in Amazon Q Developer, allowing attackers to execute arbitrary code and steal developer credentials by leveraging Model Context Protocol (MCP) configurations within a cloned reposi… The Hacker News · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958CVE-2025-59536mcpcloud securitydeveloper credentials
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
vulnerability Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) A 2-year-old remote code execution (RCE) vulnerability, CVE-2026-23479, was discovered in Redis 7.2.0 by an autonomous AI security tool, Team Xint Code. The flaw, stemming from a use-after-free issue in the `unblockClien… The Hacker News · Jun 3, 2026 High CVE-2026-23479UKuse-after-freerceredis
vulnerability Gogs Zero-Day Exposes Servers to Remote Code Execution A critical zero-day vulnerability has been discovered in the open-source self-hosted Git service, Gogs, allowing for remote code execution (RCE) on affected servers. The flaw, identified by Rapid7, stems from an argument… SecurityWeek · May 29, 2026 Critical CVE-2025-8110zero-dayremote code executiongit
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks Google has launched an AI-powered cybersecurity platform, AI Threat Defense, designed to proactively combat increasingly sophisticated cyberattacks leveraging artificial intelligence. This platform utilizes AI to identif… SecurityWeek · May 28, 2026 High GBaicybersecuritythreat detection
threat-intel JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware A previously undocumented threat actor, dubbed JINX-0164, is targeting cryptocurrency firms through sophisticated social engineering tactics and bespoke macOS malware to steal digital assets. The campaign involves luring… The Hacker News · May 28, 2026 High KPmacossocial engineeringcryptocurrency
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer