threat-intel China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw China-linked threat actor Storm-1175 has deployed a new ransomware strain, StormEncryptor, leveraging a vulnerability in N-able N‑central to gain initial access and subsequently deploy ransomware. This follows a pattern… The Hacker News · Aug 10, 2026 High CVE-2026-18577CVE-2026-18556CVE-2023-37679CHransomwarevulnerabilitypatch-bypass
threat-intel Outdated Cybercrime Laws Put Security Researchers at Risk Security researchers in the UK and globally face legal risks due to outdated cybercrime laws that don't differentiate between malicious hacking and responsible vulnerability research. Katharina Sommer, of NCC Group, has… Dark Reading · Aug 10, 2026 Medium UKPOARvulnerability researchcybersecurity lawethical hacking
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
supply-chain China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns China-linked hackers, believed to be part of the Storm-1175 group, are exploiting a critical vulnerability in N-central, a remote monitoring and management (RMM) tool, to deploy ransomware. This supply-chain attack is le… The Record · Aug 10, 2026 High CVE-2026-18577CHsupply-chainransomwarezero-day
threat-intel Cyber vulnerability sweep picks up Royal Navy drones sending data to China A vulnerability in Royal Navy drones is allowing Chinese entities to access sensitive data. The flaw stems from a misconfigured system that transmits data to servers in China, raising significant national security concer… The Register · Aug 10, 2026 High UKCHvulnerabilitynational securitydata transmission
threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Advertisers are trying to influence AI bots with secret ads This week’s episode of The Kettle podcast explores the escalating competition in the AI world, focusing on China’s rapid advancements in open-weight AI models. The episode highlights DeepSeek, a Chinese model nearing par… The Register · Aug 10, 2026 High CHUNaiopen-sourcechina
vulnerability Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts A critical command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's KEV catalog, following reports of widespread exploitation attempts. The vulnerability allows unauthenticated attackers to ex… The Hacker News · Aug 8, 2026 Critical CVE-2026-8037AUCHINcommand injectionload balancerpatching
threat-intel US cyber ambassador nominee Cassady confirmed in Senate The Senate confirmed Adam Cassady as the next U.S. ambassador for cyber and digital policy. This appointment follows a reorganization within the State Department, leading to a restructuring of the Bureau of Cyberspace an… The Record · Aug 7, 2026 Info CHHOUScybersecuritytechnology exportschina
threat-intel In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Several significant cybersecurity events are unfolding this week, including a coordinated AI-powered scam network originating in Cambodia, a data breach at Amgen, a supply chain attack targeting QuickFox VPN, and a serie… SecurityWeek · Aug 7, 2026 High CHCAUSsupply-chainphishingransomware
vulnerability MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs This article discusses a vulnerability related to Spectre defenses on Intel and AMD CPUs, where an AI-powered attack, dubbed TONTOU, successfully bypassed existing security measures. The vulnerability stems from AI's str… The Register · Aug 7, 2026 Medium CHIRspectrevulnerabilityai
threat-intel L’ingérence informationnelle teste le terrain électoral français This article examines a sophisticated disinformation campaign targeting French political figures, likely orchestrated by external actors. The campaign employs tactics such as impersonating media outlets, creating fake we… ZATAZ · Aug 7, 2026 Medium FRRUCHdisinformationinfluencefake news
threat-intel Commerce pirate : un cybercriminel vend des dizaines de téraoctets de données A cybercriminal is offering a massive stock of personal and corporate data, spanning over 25 countries and multiple sensitive categories, for sale. The offering includes over 100,000 distinct datasets, encompassing phone… ZATAZ · Aug 7, 2026 High FRGEUNdata breachcybercrimedata theft
vulnerability 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers A 18-year-old vulnerability in Linux's SCTP networking code allows local users to gain root access on a host, potentially escaping containers. Tencent researchers discovered and demonstrated this flaw, which has existed… The Hacker News · Aug 7, 2026 High CVE-2026-64564CHlinuxsctpuse-after-free
threat-intel How the famed USENIX Security conf is managing a flood of papers in the AI era The USENIX Security conference is grappling with a surge in research papers, particularly those leveraging AI and machine learning. While AI usage is increasing, concerns are being raised about the potential for autonomo… The Register · Aug 6, 2026 Medium USCHRUaimachine learningvulnerability
threat-intel ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories This week's 'ThreatsDay' bulletin highlights a diverse range of security threats, including a China-linked telecom risk, a multi-stage phishing attack leveraging ClickOnce files, a supply chain attack involving 846 softw… The Hacker News · Aug 6, 2026 High CVE-2025-21079CVE-2025-58486CVE-2026-25177CHUSsupply-chainmalwarephishing
threat-intel IT department put sticky notes on the laptops to help employees log in This article is a collection of security-related news snippets from The Register. It covers a range of topics including a phishing campaign mimicking Signal support, a zero-day exploit targeting on-prem SharePoint, and a… The Register · Aug 6, 2026 Medium CHIRSWphishingzero-dayransomware
threat-intel Token Jacking: Cybercriminals Could Be Stealing Your AI Resources Cybercriminals are exploiting a growing trend of AI token jacking to generate significant financial losses. As AI adoption increases and costs for accessing powerful models rise, attackers are stealing API keys – known a… Palo Alto Unit 42 · Aug 6, 2026 High CHaitoken jackingtransfer station