threat-intel US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ The US is bolstering its defenses against cyberattacks targeting water infrastructure through a combination of new legislation and a grassroots initiative. The Water Cyber Shield Act will expand federal oversight, while… SecurityWeek · Aug 11, 2026 Medium cybersecuritywater systemsdigital twins
threat-intel Deepfake hiccup unmasks suspected digital certificate fraudster This article discusses a potential digital certificate fraud scheme linked to deepfake technology, where Russian actors are impersonating Signal support to launch phishing attacks. The vulnerability stems from flaws in J… The Register · Aug 11, 2026 Medium RUdeepfakephishingjoomla
threat-intel Corma Raises $60 Million for Defensive Cybersecurity AI Model Corma, a new cybersecurity firm, has secured $60 million in funding to develop an AI-powered defensive cybersecurity model. Unlike general AI models, Corma’s system is specifically designed to analyze security telemetry… SecurityWeek · Aug 11, 2026 Medium aicybersecuritydefense
threat-intel AI for Military Support Research suggests that despite concerns about AI automating military decisions, human operators exhibit ‘algorithmic aversion’ when presented with AI recommendations, particularly in scenarios with potential for signific… Schneier on Security · Aug 11, 2026 Medium ILaimilitarydecision-making
supply-chain Mozilla Issues New Firefox GPG Key Following Exposure Mozilla has revoked a compromised GPG signing key used for Firefox and Thunderbird, following its accidental exposure in a GitHub repository. While the immediate risk was mitigated due to limited access, the incident hig… SecurityWeek · Aug 11, 2026 Medium gpgsupply-chainkey-rotation
vulnerability Multiples vulnérabilités dans Postfix (11 août 2026) Multiple vulnerabilities have been discovered in Postfix, potentially allowing attackers to cause a denial-of-service, bypass security policies, and create an unspecified security issue. Users of Postfix versions prior t… CERT-FR · Aug 11, 2026 Medium vulnerabilitymail serversecurity
vulnerability Vulnérabilité dans CPython (11 août 2026) A denial-of-service vulnerability has been identified in CPython, allowing an attacker to disrupt remote systems. The vulnerability stems from a lack of recent security updates and requires immediate patching to prevent… CERT-FR · Aug 11, 2026 Medium CVE-2026-18503pythondenial-of-servicevulnerability
vulnerability Vulnérabilité dans Docker (11 août 2026) A vulnerability has been identified in Docker Desktop, allowing an attacker to compromise data integrity. Users of versions prior to 4.86.0 should immediately update to mitigate the risk. CERT-FR · Aug 11, 2026 Medium CVE-2026-17106dockervulnerabilitysecurity
vulnerability Multiples vulnérabilités dans SPIP (11 août 2026) A series of vulnerabilities have been discovered in SPIP, a popular French content management system. These include remote code execution, SQL injection, and server-side request forgery, impacting versions prior to 4.4.1… CERT-FR · Aug 11, 2026 Medium vulnerabilitysql-injectionssrf
vulnerability Multiples vulnérabilités dans OpenSSH (11 août 2026) Multiple vulnerabilities have been discovered in OpenSSH, impacting versions prior to 10.5. The exact nature of the security issue is not specified by the publisher, but users are advised to consult the vendor's security… CERT-FR · Aug 11, 2026 Medium sshvulnerabilitysecurity
threat-intel DEF CON hackers add new muscle to water utility protection DEF CON hackers are focusing on bolstering water utility protection by leveraging their skills to identify and address vulnerabilities in critical infrastructure. This initiative follows successful 'Voting Village' proje… The Register · Aug 10, 2026 Medium cybersecurityinfrastructurevulnerabilities
threat-intel North Korean spies are running local LLMs to cause AI mischief North Korean intelligence operatives are leveraging locally hosted Large Language Models (LLMs) to conduct sophisticated disinformation campaigns and potentially cause broader AI-related mischief. This indicates a growin… The Register · Aug 10, 2026 Medium NOaillmcyberespionage
threat-intel Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list A user exploited a waitlist API for a gym class booking service by prompting an AI agent to bypass the normal process, demonstrating a vulnerability in how AI systems can be manipulated to access and abuse online service… The Register · Aug 10, 2026 Medium aiautomationsecurity
threat-intel Outdated Cybercrime Laws Put Security Researchers at Risk Security researchers in the UK and globally face legal risks due to outdated cybercrime laws that don't differentiate between malicious hacking and responsible vulnerability research. Katharina Sommer, of NCC Group, has… Dark Reading · Aug 10, 2026 Medium UKPOARvulnerability researchcybersecurity lawethical hacking
threat-intel Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th) The SANS Internet Storm Center is observing a scanning campaign targeting Solana infrastructure, likely conducted by automated tools. These scans are attempting to enumerate Solana API endpoints and potentially extract c… SANS Internet Storm Center · Aug 10, 2026 Medium solanascanningreconnaissance
threat-intel Sherlock Holmes was the “OG” Social Engineer This article draws parallels between the social engineering techniques of Sir Arthur Conan Doyle's Sherlock Holmes and modern-day cyberattacks. The author, a cybersecurity professor, argues that the core principles of de… Dark Reading · Aug 10, 2026 Medium social engineeringcybersecurityhuman behavior
threat-intel Attackers pick Levi's pockets in social engineering attack Attackers are leveraging social engineering to steal data from Levi's customers. The attackers impersonated Signal support to trick users into providing their credentials, leading to a data breach. The Register · Aug 10, 2026 Medium social engineeringdata breachphishing
threat-intel Wetherspoons bars smart glasses from filming customers Wetherspoons, a UK pub chain, has been accused of using smart glasses to film customers without their consent. The glasses, reportedly used to assist staff, were found to be capable of recording video, raising significan… The Register · Aug 10, 2026 Medium privacysurveillancedata-protection
threat-intel Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development As AI accelerates software development, security teams are struggling to keep pace, leading to a massive backlog of vulnerabilities and an expanded attack surface. This webinar explores how to adapt security practices to… The Hacker News · Aug 10, 2026 Medium aisecuritydevelopment
threat-intel Python Now Has a Post-Quantum Encryption Library Python’s popular cryptography library, pyca/cryptography, has gained post-quantum encryption support thanks to funding from the Sovereign Tech Agency. This means developers can now integrate algorithms designed to withst… Schneier on Security · Aug 10, 2026 Medium post-quantumcryptographypython