threat-intel [Virtual Event] Building a Secure AI Strategy for the Enterprise As AI rapidly integrates into businesses, organizations are facing a significant security challenge. This event focuses on establishing a robust AI security strategy, addressing key areas like AI discovery, governance, and implementing necessary safeguards to mitigate risks associated with AI adoption. Dark Reading · 2026-10-08 Info aiartificial-intelligencesecurity
threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
threat-intel The safety penalty: Reclaiming operational sovereignty in the age of AI As AI models become more powerful, their built-in safety mechanisms are increasingly causing friction for security teams, leading to a "safety penalty" where analysts are forced to redo work that a model refuses to compl… Cisco Talos · 5d ago High aifrontier-modelsguardrails
threat-intel Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th) This article details a PowerShell script leveraging the Microsoft Graph API to extract detailed information about Microsoft 365 users, including their last password change date, login activity, and assigned licenses. The… SANS Internet Storm Center · Aug 20, 2026 Medium microsoft graphentaralicense management
threat-intel Why "Shady AI" is Security's Next Big Governance Problem A recent incident at Meta highlighted a growing security challenge: ‘Shady AI’ – the unintended use of approved AI tools within organizations. This stems from the rapid proliferation of AI tools, broad default permission… The Hacker News · Aug 20, 2026 High aigovernanceshadow ai
threat-intel UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities Chinese-speaking intrusion actor UAT-10147 is employing a sophisticated, cross-platform intrusion toolset, SPECTRE, leveraging AI-assisted development to evade detection. SPECTRE is a cross-platform backdoor with Linux r… Cisco Talos · Aug 20, 2026 High CVE-2019-16098CVE-2021-21551CHaiedrlinux
threat-intel Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data A sophisticated, custom-built web shell, specifically designed for PTC Windchill and FlexPLM, has been deployed by the Clop ransomware gang. This web shell is capable of decrypting credentials, mapping sensitive data, an… The Hacker News · Aug 19, 2026 High CVE-2026-12569CVE-2021-27101CVE-2023-34362web shellcredential theftransomware
vulnerability ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a log message. This vulnerability, alongside related exp… SANS Internet Storm Center · Aug 18, 2026 Critical log4jlog4j2apache
supply-chain Trivy, Not LiteLLM Behind the 2,500 Org Compromise A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vul… SecurityWeek · Aug 14, 2026 High GEBRFRsupply-chainvulnerabilitycredential-theft
supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The att… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss
threat-intel Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th) This article details Atuin, a tool that enhances shell history tracking by storing command history in a SQLite database, providing richer context (directory, duration, exit code, hostname) and end-to-end encryption acros… SANS Internet Storm Center · Aug 7, 2026 Medium forensicsshellhistory
vulnerability Vulnérabilité dans Sonicwall SonicOS (06 août 2026) SonicWall has announced a vulnerability in its SonicOS firmware that allows attackers to bypass security policies. This affects a range of firewalls, including models from the Gen6, Gen7, and Gen8 series. The vulnerabili… CERT-FR · Aug 6, 2026 High CVE-2026-0516securityfirmwarepatch
vulnerability Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw A public exploit for a remote code execution vulnerability in vBulletin has been released, targeting versions 6.2.1 and earlier, and 6.1.6 and earlier. The vulnerability allows unauthenticated code execution, but the exp… The Hacker News · Jul 27, 2026 High CVE-2026-61511CVE-2025-48827CVE-2025-48828rcevbulletinremote-code-execution
vulnerability Vulnérabilité dans les produits Moxa (24 juillet 2026) A critical vulnerability has been identified in Moxa products, allowing attackers to elevate their privileges. This security issue stems from a flaw within the Linux kernel and requires immediate attention to prevent pot… CERT-FR · Jul 24, 2026 Critical CVE-2026-46333linuxsshprivilege-escalation
threat-intel Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push Ivanti is leveraging large language models (LLMs) to automate vulnerability remediation and discovery, a project initially sparked by the surprising effectiveness of the Claude 4.6 model. Daniel Spicer, Ivanti’s CSO, des… Dark Reading · Jul 20, 2026 Medium CVE-2026-10520llmvulnerabilityautomation
threat-intel CISOs Feel the Heat Over AI Risk CISOs are facing increased pressure and job insecurity due to the rapid and often chaotic adoption of AI within companies. A recent Splunk survey revealed that 26% of top security executives are considering leaving their… Dark Reading · Jul 20, 2026 High aicybersecurityrisk
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
threat-intel Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook? Several states – Illinois, New York, and California – are enacting laws to regulate the deployment of increasingly powerful frontier AI models, requiring developers to establish comprehensive AI frameworks addressing ris… Dark Reading · Jul 14, 2026 High aifrontier-airegulation
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware