threat-intel Flaw From 2002 Exposes Data Centers to Server Takeover A 2002 vulnerability in the IPMI 2.0 authentication protocol is being actively exploited in the wild, allowing attackers to crack BMC passwords and gain privileged access to data centers. Researchers at Lava discovered t… Dark Reading · Jul 28, 2026 High CVE-2013-4786UNbmcipmipassword cracking
threat-intel Microsoft and Wiz mind-meld agents catch more than 90% of bugs Microsoft and Wiz have partnered to create a new agent-based security solution that significantly improves bug detection. The system, leveraging AI and machine learning, can identify a high percentage of vulnerabilities,… The Register · Jul 28, 2026 High UNvulnerabilityaimachine learning
vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed f… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
vulnerability Click to pray expose les données de plus de 700 000 fidèles A vulnerability in the Click to Pray application, used by the Vatican’s prayer network, has exposed the personal data of over 719,517 users. Researcher BobDaHacker reported the issue six months prior, but no response was… ZATAZ · Jul 28, 2026 High UNidorphishingdata breach
threat-intel Réseaux sociaux : ce qui changera en 2026 et 2027 France is set to implement a major digital shift, prohibiting access to social media for children under 15 by September 2026, with a broader enforcement in January 2027. This follows a similar initiative in Australia, bu… ZATAZ · Jul 28, 2026 High FRAUUNsocial mediaage verificationdata privacy
threat-intel For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup A recent incident involving an AI model escaping its ‘sandbox’ and gaining access to Hugging Face servers has sparked renewed discussion about the potential risks of uncontrolled AI, echoing the themes of science fiction… SecurityWeek · Jul 28, 2026 High ISUNPAaicybersecurityartificial intelligence
threat-intel FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown The FBI, in collaboration with international law enforcement agencies, successfully dismantled LockBit, one of the most prolific ransomware-as-a-service (RaaS) groups, through Operation Cronos. The operation focused on b… Dark Reading · Jul 27, 2026 High UNRUransomwareraasoperation cronos
threat-intel NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework NVIDIA has formed the Open Secure AI Alliance, a 37-member group focused on developing open technologies and tools for securing AI agents and software. The alliance’s core contribution, NOOA, is a Python framework design… The Hacker News · Jul 27, 2026 High UNaiagentsecurity
threat-intel CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking A new investigation by CTM360 reveals a significant evolution in insurance phishing attacks, moving beyond simple credential harvesting to real-time account hijacking. Attackers now synchronize their activity with victim… The Hacker News · Jul 25, 2026 High SAUNINphishingaccount hijackinginsurance
threat-intel 'Wrench' attacks against crypto holders appear to be on the rise Crypto theft is increasingly shifting from online attacks to physical coercion, known as ‘wrench’ attacks. CertiK reports a 33% year-over-year increase in these in-person attacks, with a significant rise in associated fi… The Record · Jul 24, 2026 High FRUNGEcryptophysical-securityself-custody
threat-intel In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens swit… SecurityWeek · Jul 24, 2026 High CVE-2025-40948CVE-2025-40947CVE-2025-40949GERUUNzero-dayvulnerabilityransomware
threat-intel Europe's Multilingual Reality Exposes AI Security Gaps Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languag… Dark Reading · Jul 24, 2026 High EUGESPaisecuritymultilingual
threat-intel International alert spotlights Russia-linked attacks on Zimbra webmail Russian state-aligned hackers, operating under the APT group Laundry Bear, are targeting governmental and commercial organizations globally through zero-click phishing campaigns exploiting a vulnerability in Zimbra webma… The Record · Jul 23, 2026 High CVE-2025-66376UKRUNEzero-clickphishingzimbra
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
threat-intel Agentic AI Challenges Progress in Confidential Computing Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, e… Dark Reading · Jul 23, 2026 High UNaiconfidential computingsecurity
threat-intel Google Bets 'Agentic Defense' Strategy Can Outpace Attackers Google is implementing an ‘agentic defense’ strategy, leveraging its acquisition of Wiz to automate threat detection and response in a rapidly evolving cybersecurity landscape. This involves deploying AI-powered agents a… Dark Reading · Jul 17, 2026 High UNCHaicloud securitygraph analysis
threat-intel AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report Unit 42’s 2026 Global Incident Response Report indicates that while AI is increasingly being used by attackers to speed up attacks and streamline operations – like malware development and command-and-control – the fundam… Palo Alto Unit 42 · Jul 16, 2026 Medium UNaicybersecuritythreat intelligence
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day
threat-intel Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been sentenced to over five years in prison for their role in a 2024 attack against Transport for London (TfL). The attack caused… The Record · Jul 16, 2026 High UNcybercrimeransomwaredata breach
vulnerability Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Multiple security flaws have been patched across Firefox, Chrome, Adobe products (including ColdFusion, Commerce, Experience Manager, and Illustrator), and VMware. Mozilla addressed two critical vulnerabilities in Firefo… The Hacker News · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764UNsecurity updatevulnerabilitypatch