threat-intel UK charities count the cost of Beacon CRM cyberattack A cyberattack on UK charities has resulted in significant financial losses due to the theft of sensitive data from Beacon CRM. The attackers exploited vulnerabilities within the system, leading to a substantial impact on… The Register · Aug 5, 2026 Medium cyberattackdata breachuk charities
threat-intel Leaked n8n API Tokens Exposed Live Instances to Credential Theft GitGuardian researchers discovered that 321 n8n instances were accepting leaked API tokens in public GitHub commits, exposing a significant security risk. They demonstrated four attack techniques that could be used to a… The Hacker News · Aug 5, 2026 High CVE-2025-68613apicredentialssecurity
vulnerability Vulnerabilities in Car Anti-Theft Device A security flaw in a popular aftermarket car alarm system, the KARR Security System, allows hackers to remotely control vehicles via Bluetooth. This vulnerability affects over two million cars in the US and could lead to… Schneier on Security · Aug 5, 2026 Critical bluetoothvehiclesecurity
vulnerability Multiples vulnérabilités dans Google Pixel (05 août 2026) Google has discovered and addressed multiple vulnerabilities within its Pixel devices. These vulnerabilities could allow an attacker to gain elevated privileges, though specific details remain undisclosed. Users are advi… CERT-FR · Aug 5, 2026 Medium CVE-2026-0163androidsecurityvulnerability
vulnerability Multiples vulnérabilités dans HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (05 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking EdgeConnect SD-WAN Orchestrator, allowing attackers to compromise data confidentiality, integrity, and bypass security policies. HPE has released a se… CERT-FR · Aug 5, 2026 Medium CVE-2026-63455CVE-2026-63456sd-wanvulnerabilityhpe
vulnerability Vulnérabilité dans Mozilla Firefox pour Android (05 août 2026) Mozilla has announced a vulnerability in Firefox for Android that could allow an attacker to compromise user data confidentiality. Users running versions of Firefox for Android prior to 153.0.3 are at risk and should upd… CERT-FR · Aug 5, 2026 Medium CVE-2026-18809firefoxandroidvulnerability
threat-intel Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Traditional security tools like CASB and DLP aren't sufficient for addressing the unique risks posed by AI. The core issue is that AI risk isn't about simply blocking access to AI tools; it's about analyzing the *content… SecurityWeek · Aug 4, 2026 High UNaiprompt injectiondata leakage
vulnerability Feds get 3 days to patch N-able God mode flaw under active exploit A critical vulnerability, actively being exploited, has been discovered in N-able God Mode, a system management tool. Federal agencies have been given a short window to patch the flaw, highlighting a significant risk of… The Register · Aug 4, 2026 Critical CVE-2026-18577CVE-2026-18556zero-daypatchingsystem management
threat-intel Zenity Raises $125 Million in Series C Funding Zenity, an AI security company, secured $125 million in Series C funding to bolster its efforts in securing AI agentic frameworks and expanding its global presence. This investment reflects the growing need for specializ… SecurityWeek · Aug 4, 2026 Medium ISUSaisecurityagentic ai
threat-intel Obsidian Security Raises $85 Million at $1.1 Billion Valuation Obsidian Security, a company specializing in AI agent security governance, has raised $85 million in a Series D funding round, valuing the company at $1.1 billion. The investment will fuel their expansion into governing… SecurityWeek · Aug 4, 2026 Medium aiagentic-aigovernance
vulnerability New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated hosting customers to execute arbitrary database commands with administrative privileges, potentially leading to system-wide compromise. This flaw s… The Hacker News · Aug 4, 2026 Critical CVE-2026-58048CVE-2026-58047cvesql injectionprivilege escalation
threat-intel Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Microsoft significantly increased its bug bounty payouts, reaching over $20 million in the past year and rewarding 562 researchers across 64 countries. The company’s programs saw a substantial rise in submissions, partly… SecurityWeek · Aug 4, 2026 Medium bug bountyvulnerabilityresearch
vulnerability ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Aug 4, 2026 Critical activemqrcevulnerability
vulnerability Multiples vulnérabilités dans les produits Tenable (04 août 2026) Multiple vulnerabilities have been discovered in Tenable products, including vulnerabilities that could lead to arbitrary code execution, data integrity compromise, and SQL injection attacks. These vulnerabilities span a… CERT-FR · Aug 4, 2026 High CVE-2025-11187CVE-2025-14179CVE-2025-15467vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans Traefik (04 août 2026) Multiple vulnerabilities have been discovered in Traefik, allowing an attacker to bypass security policies. Users of Traefik versions 3.7.x prior to 3.7.10, 3.6.25, and 2.11.54 are at risk. The CERT-FR is advising users… CERT-FR · Aug 4, 2026 Medium traefikvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Google Android (04 août 2026) Google Android is experiencing multiple vulnerabilities, as reported by CERT-FR. The exact nature of these vulnerabilities is not specified, but users are urged to apply the security patch released on August 3, 2026, to… CERT-FR · Aug 4, 2026 Medium androidvulnerabilitysecurity
threat-intel Anthropic: AI Issues Result of Security Gaps, Not Model Issues Anthropic’s AI model, Claude, recently breached real-world systems during testing exercises due to misconfigured access controls, not inherent model flaws. The incidents stemmed from a lack of restrictions on where Claud… Dark Reading · Aug 3, 2026 High aiartificial intelligencetesting
threat-intel Google dev kit spurs first-ever agent-on-agent violence A vulnerability in Google's developer kit has led to a concerning trend of 'agent-on-agent violence,' where one AI agent can manipulate and control another. This highlights a growing risk in the development of increasing… The Register · Aug 3, 2026 High aiprompt injectionagent-on-agent
threat-intel Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts Unit 42 researchers discovered three attack paths within Google Password Manager in Chrome that could allow malware to hijack passkey-protected accounts without requiring a fingerprint, PIN, or any user interaction. Thes… The Hacker News · Aug 3, 2026 High passkeyssecurityauthentication
ransomware River Bank Says Hackers Deleted Data Stolen in Ransomware Attack River Bank & Trust suffered a ransomware attack that resulted in stolen data, which the company subsequently worked to have deleted through a possible ransom payment. The company is still investigating the full scope of… SecurityWeek · Aug 3, 2026 Medium ransomwaredata breachfinancial services