threat-intel Iran-Linked Hackers Shut Down UK Power Plant for Four Days Iranian-linked hackers successfully shut down a British power plant for four days, raising significant concerns about the escalating cyber threat landscape and the vulnerability of UK critical infrastructure. The inciden… SecurityWeek · 6d ago High UKIRUSirancyberattackcritical infrastructure
threat-intel TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy TikTok has agreed to a $400 million settlement with the U.S. Department of Justice to address allegations of violating children's privacy laws and failing to adequately protect user data. This settlement follows a long-s… SecurityWeek · 6d ago Medium USprivacychildrensocial media
threat-intel Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund Anthropic is expanding access to its advanced AI cybersecurity model, Mythos 5, to bolster defenses against cyberattacks. They are doing this through partnerships, a new open-source funding program, and an updated Claude… SecurityWeek · 6d ago Medium USaicybersecurityvulnerability
threat-intel Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it US Homeland Security cybersecurity officials are warning users of TrueConf, a video conferencing tool developed in Russia, to urgently patch the software due to a critical vulnerability that could allow attackers to remo… The Register · Aug 21, 2026 Critical CVE-2026-72529CVE-2026-72530RUUSvulnerabilitycybersecurityrussia
threat-intel Target visé par une nouvelle revendication de fuite A new ransomware group, Xpl0itrs, claims to possess source code stolen from Target, threatening to release it unless the company negotiates. While the claim is unverified and a previous incident in January 2026 involved… ZATAZ · Aug 21, 2026 High USAUransomwaresource codedata breach
threat-intel ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More This week’s ThreatsDay bulletin highlights a diverse range of security threats, including a Remote Code Execution vulnerability in Gogs, a sophisticated Mabna Institute cyber espionage campaign targeting universities and… The Hacker News · Aug 20, 2026 Critical CVE-2026-52813CVE-2026-52810CVE-2026-43774IRUSrcecyber espionagegit hooks
threat-intel AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure A U.S. government advisory warns of an active threat targeting critical infrastructure organizations, specifically Siemens S7 PLCs, utilizing AI-generated exploit scripts. Threat actors are leveraging internet scanning t… The Hacker News · Aug 20, 2026 High USCHplcindustrial control systemics
threat-intel Club One Casino revendiqué par 3AM puis PEAR Club One Casino is being linked to two separate extortion groups, 3AM and PEAR, in a concerning trend for the casino industry. Initial reports from August 2026 attributed the first attack to 3AM, focusing on internal fil… ZATAZ · Aug 20, 2026 Medium USransomwarecasinoextortion
vulnerability Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments Researchers at the University of Massachusetts Amherst have demonstrated a method to revive expired Visa credit cards for contactless payments by rewriting the expiration date on a POS terminal, bypassing standard crypto… The Hacker News · Aug 20, 2026 High UScontactlessnfcexpiry
threat-intel Hackers Using AI to Target Siemens PLCs in Critical US Sectors US government agencies have issued a cybersecurity advisory warning critical infrastructure organizations about a growing threat of hackers using AI to target Siemens PLCs. The attackers are scanning for exposed PLCs and… SecurityWeek · Aug 20, 2026 High USicsplccybersecurity
threat-intel US charges Iranians for sprawling hacking campaign on government agencies, universities The U.S. Justice Department has charged 17 Iranians linked to Iran’s military for a sprawling hacking campaign targeting U.S. government agencies, universities, and companies since 2013. The campaign, allegedly orchestra… The Record · Aug 19, 2026 High IRUShackingcyberattackiran
threat-intel StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data A sophisticated cybercrime operation, dubbed StopAndProtect, is leveraging over 6,000 compromised WordPress sites globally to distribute malware, steal data, and deploy ransomware. The attackers use a multi-stage attack… The Hacker News · Aug 19, 2026 High USRUINwordpressmalwareransomware
threat-intel Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation Four critical vulnerabilities – affecting macOS, SharePoint, vCenter, and IKE – are currently being actively exploited in the wild. These flaws have led to widespread attacks, including the deployment of ransomware and b… The Hacker News · Aug 19, 2026 Critical CVE-2026-65400CVE-2026-55040CVE-2026-59310DEUSTRvulnerabilitycyberattackransomware
threat-intel Prison for data analyst who tried to extort $2.5 million from his employer A former data analyst, Cameron Curry, was sentenced to 24 months in prison after attempting to extort $2.5 million from his former employer, Brightly Software (now part of Siemens). Curry gained access to sensitive emplo… Graham Cluley · Aug 19, 2026 High USinsider threatdata breachextortion
threat-intel Stripe visé par une fuite revendiquée de 662 bases de données ! A purported data leak claiming to contain 33GB of Stripe data, including 1.033 API keys and 662 customer databases, has been published by a known data broker. The leak includes 6.16 million email addresses, 688,000 compl… ZATAZ · Aug 19, 2026 High USLUFRdata leakapi keyscustomer data
threat-intel Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 A threat actor calling itself Ransom Busters is offering to delete stolen ransomware data from servers in exchange for a payment, ranging from $20,000 to $60,000. GuidePoint Research and Intelligence Team (GRIT) has iden… The Hacker News · Aug 18, 2026 High USransomwaredata exfiltrationcredential theft
data-breach Heights Finance Data Breach Impacts at Least 1.2 Million Individuals Heights Finance Holdings experienced a data breach affecting over 1.2 million individuals, exposing sensitive personal and financial information. The breach occurred through a compromised third-party cloud platform, and… SecurityWeek · Aug 18, 2026 High USdata breachfinancialidentity theft
vulnerability SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch A critical security vulnerability (CVE-2026-58231) in SAP Commerce Cloud is being actively exploited, despite a patch being available for days. The flaw stems from inadequate input validation, potentially leading to code… The Hacker News · Aug 15, 2026 Critical CVE-2026-58231CVE-2025-31324USsapvulnerabilitypatch
vulnerability Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner A critical vulnerability in Apple's macOS Screen Sharing component has been actively exploited in the wild to install a cryptocurrency miner. Researchers have discovered a pre-authentication vulnerability (CVE-2026-65400… The Hacker News · Aug 15, 2026 Critical CVE-2026-65400CVE-2026-43779CVE-2026-43777USmacosscreen sharingvulnerability
threat-intel 14,000 Trezor Customers Impacted by Data Breach at ShipMonk Nearly 14,000 Trezor customers were affected by a data breach stemming from a vulnerability exploited by the ShinyHunters group within ShipMonk’s systems. The breach exposed customer data including names, addresses, emai… SecurityWeek · Aug 14, 2026 Medium USUKSWdata breachshippingvulnerability