threat-intel Siemens RUGGEDCOM APE1808 A CISA advisory, in collaboration with Siemens ProductCERT, highlights vulnerabilities in Siemens RUGGEDCOM APE1808 devices when used with Fortinet NGFW. These vulnerabilities, including Cross-Site Scripting and Path Tra… CISA Advisories · Aug 12, 2026 High CVE-2026-23573CVE-2026-59839GEindustrial control systemscwe-79cwe-22
threat-intel OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning Researchers have discovered a significant vulnerability in OpenAI, Anthropic, and Google's AI APIs that allows weaker AI models to decode the reasoning processes of stronger models by replaying encrypted reasoning blocks… The Hacker News · Aug 12, 2026 High encryptionapiprompt injection
threat-intel Microsoft's Patch Tuesday Deluge Continues With August Updates Microsoft released a substantial security update this month, addressing 421 unique CVEs, including two zero-day vulnerabilities. A significant portion of these – 236 affecting Windows and 98 affecting Office – require im… Dark Reading · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62878patch-tuesdayvulnerabilityzero-day
threat-intel Local governments in four states dealing with cyberattacks that have shut down services Local governments across four states – California, Oklahoma, South Dakota, Texas, and Wisconsin – are experiencing a surge in cyberattacks, leading to service disruptions and shutdowns. These attacks have impacted critic… The Record · Aug 11, 2026 High UScyberattacklocal governmentransomware
threat-intel Kids’ online safety bill faces dim prospects of passage this session despite progress The Kids Online Safety Act (KOSA), a landmark bill aimed at increasing online safety for children, faces significant obstacles in Congress, particularly regarding a ‘duty of care’ provision requiring companies to take re… The Record · Aug 11, 2026 High UNonline safetychildrenfirst amendment
threat-intel A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices Researchers at the University of Birmingham and Fuzzware discovered a vulnerability in cellular IoT devices that allows a malicious SIM card to execute commands on the device. The vulnerability stems from a SIM card's ab… The Hacker News · Aug 11, 2026 High CVE-2025-48618CVE-2026-57550CVE-2021-31698UNiotcellularsim card
threat-intel Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets A malicious tool server leveraging the Model Context Protocol (MCP) can silently exfiltrate sensitive data – including SSH keys, source code, and customer data – from AI coding assistants. The attack works by splitting r… The Hacker News · Aug 11, 2026 High aimodel context protocolghostsplice
threat-intel Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Polish power plant operators suffered a significant cyberattack that led to the shutdown of a steam turbine and process-water treatment system. The attack exploited a private cellular network used by the grid operator to… The Hacker News · Aug 11, 2026 High CVE-2023-32349CVE-2023-32350PLprivate apnindustrial control systemscyberattack
threat-intel Des kiosques Pokémon exposés par une fuite Firebase A clandestine publication alleges that a US-based automated distribution operator exposed sensitive data – including bank details, email addresses, source code, and technical access – across multiple continents via expos… ZATAZ · Aug 10, 2026 High USJPAUdata breachapiauthentication
vulnerability Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius A zero-day SQL-injection vulnerability in Metabase Cloud is actively being exploited, potentially impacting a wide range of organizations beyond Metabase customers. The vulnerability allows remote attackers to gain admin… Dark Reading · Aug 10, 2026 High sql-injectionzero-dayvulnerability
threat-intel The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists The article highlights a significant gap between the speed at which attackers discover and exploit vulnerabilities and the speed at which defenders can patch them. Traditional CVSS-based prioritization is inadequate beca… Dark Reading · Aug 10, 2026 High CVE-2024-9474CVE-2024-0012vulnerabilityattack-pathchoke-point
threat-intel Attackers pick Levi's pockets in social engineering attack Attackers are leveraging social engineering to steal data from Levi's customers. The attackers impersonated Signal support to trick users into providing their credentials, leading to a data breach. The Register · Aug 10, 2026 Medium social engineeringdata breachphishing
threat-intel New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA Recent research has revealed significant vulnerabilities in passkey authentication systems, demonstrating ways to bypass security measures and impersonate users. SpecterOps found that Windows stored past YubiKey signatur… The Hacker News · Aug 10, 2026 High CVE-2026-34348passkeyauthenticationvulnerability
threat-intel OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause OpenAI is pausing internal development of its AI model Astra due to concerns about its rapidly advancing cyber capabilities. Initial evaluations suggest the model possesses ‘Critical’ cyber capabilities, including the po… The Hacker News · Aug 10, 2026 High aicybersecurityai-safety
threat-intel New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens Researchers at PortSwigger have discovered several new attack vectors targeting webmail interfaces, allowing attackers to steal passwords, take over accounts, and manipulate AI tools. The vulnerabilities exploit weakness… The Hacker News · Aug 8, 2026 High webmailcsshtml
threat-intel AI-Generated Patches Fail Half the Time A study by 1Password found that AI-generated patches are significantly flawed, with only around 46% successfully fixing vulnerabilities and many introducing new bugs or requiring code modification. The research, dubbed F… Dark Reading · Aug 7, 2026 High UNaipatchingvulnerability
threat-intel N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands A flaw in N-able’s God mode feature allowed attackers to gain unauthorized access to customer networks. The vendor has confirmed that attackers exploited this vulnerability to compromise systems, and a second hotfix has… The Register · Aug 7, 2026 Critical CVE-2026-18577vulnerabilityremote managementcyberattack
data-breach Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder A Scottish NHS trust is investigating a security breach that may have exposed the medical records of a 9-year-old girl. This follows the arrest of a man on suspicion of murder, and authorities are examining how unauthori… The Register · Aug 7, 2026 High UKvulnerabilitysharepointhealthcare
vulnerability New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A high-severity cross-site scripting (XSS) vulnerability in WordPress's login screen allows attackers to execute PHP code on a server, potentially leading to database compromise and full system control. The vulnerability… The Hacker News · Aug 7, 2026 High CVE-2026-64638xsswordpresscve-2026-64638
vulnerability Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed… The Hacker News · Aug 7, 2026 High CVE-2026-12537CVE-2026-54316ci/cdinput validationcommand injection