threat-intel OpenAI ditches Recall-style screenshot surveillance for friendly keylogging This article is a collection of security and technology news snippets. OpenAI is reportedly abandoning screenshot surveillance (Recall) in favor of keylogging, while IBM and Nvidia are partnering on a large-scale deploym… The Register · Aug 14, 2026 Medium CHUSphishingsurveillanceransomware
threat-intel Global Threat Campaign Hits Critical VMware vCenter Flaw A single threat actor has been aggressively exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, initiating a global threat campaign that began shortly after public disclosure. The vulnerability, a dir… Dark Reading · Aug 13, 2026 High USFRIRvulnerabilityexploitreverse_ssh
threat-intel ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories This week's ThreatsDay Bulletin highlights a diverse range of security threats, including AI-related attacks, data breaches, and malware campaigns. Key concerns include GhostJacking, where AI agents are hijacked to execu… The Hacker News · Aug 13, 2026 High CVE-2026-20685USUKSWaiagentjackingdata breach
vulnerability VMware vCenter : des serveurs français compromis A critical vulnerability, CVE-2026-59310, affecting VMware vCenter has been actively exploited since August 3rd, with over 360 compromised IP addresses across 47 countries, including a significant number in France. The v… ZATAZ · Aug 13, 2026 High CVE-2026-59310CVE-2026-47876CVE-2026-59309DEUSTRvulnerabilityexploitreverse shell
threat-intel Separating AI’s Technological Problems from Its Capitalism Problems This article argues that the concerns surrounding AI – including issues like bias, misinformation, and environmental impact – are fundamentally rooted in capitalist structures rather than inherent technological limitatio… Schneier on Security · Aug 13, 2026 High CHSWUScapitalismaichina
threat-intel Critical VMware vCenter Vulnerability in Attackers’ Crosshairs A critical vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited by an advanced persistent threat (APT) group, leading to remote code execution and persistent access for attackers. The vulnerabilit… SecurityWeek · Aug 13, 2026 Critical CVE-2026-59310DEUSTRvulnerabilityremote code executionssh
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
threat-intel Long-running Data Theft Campaign Targeting Salesforce, ServiceNow The "City-Forum" campaign, active since March 2025, has seen a threat actor targeting Salesforce and ServiceNow instances with custom tools to steal data. Unlike traditional attacks relying on publicly available tools, t… Dark Reading · Aug 12, 2026 High USCAGBsalesforceservicenowguest access
supply-chain Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially ex… The Hacker News · Aug 12, 2026 High CVE-2026-33634USEUsupply chaincredential theftpypi
ransomware Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout A ransomware group, believed to be “The Gentlemen,” has hijacked the Facebook page of AnMed, a nonprofit medical system in Georgia and South Carolina, to demand ransom after a prolonged cyberattack. The group claims to h… The Record · Aug 11, 2026 High USransomwarehealthcarecyberattack
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
threat-intel Local governments in four states dealing with cyberattacks that have shut down services Local governments across four states – California, Oklahoma, South Dakota, Texas, and Wisconsin – are experiencing a surge in cyberattacks, leading to service disruptions and shutdowns. These attacks have impacted critic… The Record · Aug 11, 2026 High UScyberattacklocal governmentransomware
threat-intel Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers Security researchers simulated a cryptocurrency startup and hired three individuals they believe were North Korean operatives to test recruitment processes and identify potential risks. The operation involved sophisticat… The Hacker News · Aug 11, 2026 High USNOnorth korearecruitmentidentity theft
threat-intel Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption Marcus Hutchins, a cybersecurity professional, rose to prominence in 2017 for his role in stopping the WannaCry ransomware attack. Initially involved in a cybercrime forum and creating a blog (MalwareTech) that inadverte… SecurityWeek · Aug 11, 2026 High USUKneurodiversitywannacrymalwaretech
threat-intel Des kiosques Pokémon exposés par une fuite Firebase A clandestine publication alleges that a US-based automated distribution operator exposed sensitive data – including bank details, email addresses, source code, and technical access – across multiple continents via expos… ZATAZ · Aug 10, 2026 High USJPAUdata breachapiauthentication
threat-intel British ‘Com’ member who abused more than 100 girls worldwide jailed for two years A 20-year-old British man, Justin Swaddle, was sentenced to two years in prison for abusing and manipulating over 100 girls worldwide through online platforms, primarily Snapchat, Telegram, and Discord. He was part of a… The Record · Aug 10, 2026 High UKUSCAonline-abusechild-exploitationcybercrime
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
threat-intel New Jersey, Alabama Join States Targeted in Water Cyberattacks A coordinated cyberattack targeting water and wastewater facilities in the United States is expanding, with New Jersey and Alabama becoming the latest states to report incidents. The attacks, linked to Iranian hackers, a… SecurityWeek · Aug 10, 2026 High IRUScyberattackwater systemsics
threat-intel Claude Code puts auto mode in the driver's seat Several security incidents and developments are highlighted, including a vulnerability in Joomla extensions, a Microsoft SharePoint issue leading to a zero-day attack, and ongoing efforts to combat Iranian propaganda and… The Register · Aug 10, 2026 Medium IRUSvulnerabilityphishingransomware
threat-intel ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ClickFix-style attacks are being used to deliver a Go-based macOS stealer that can drain cryptocurrency wallets and steal browser-stored passwords and Apple iCloud Keychain data. The malware, developed by the Aeza Group… The Hacker News · Aug 7, 2026 High USUKAUmacoscryptocurrencystealer