vulnerability Feds get 3 days to patch N-able God mode flaw under active exploit A critical vulnerability, actively being exploited, has been discovered in N-able God Mode, a system management tool. Federal agencies have been given a short window to patch the flaw, highlighting a significant risk of… The Register · Aug 4, 2026 Critical CVE-2026-18577CVE-2026-18556zero-daypatchingsystem management
threat-intel AI helps Microsoft bug hunters chase a record $20M payday Microsoft security researchers are experiencing a surge in zero-day attacks targeting on-prem SharePoint, fueled by a new wave of exploits leveraging vulnerabilities in third-party extensions. Simultaneously, Chinese act… The Register · Aug 4, 2026 High CHzero-dayphishingcybersecurity
threat-intel AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls An AI meeting assistant, tl;dv, is vulnerable due to a misconfiguration in its Firebase environment, allowing unauthorized access to users' video calls and meeting data. A security researcher discovered that users could… Dark Reading · Aug 4, 2026 High MAUKBRfirebaseaimeeting assistant
threat-intel Apple launches new legal challenge against UK over iCloud access Apple is challenging the UK government’s legal demands for access to user data stored on iCloud, specifically related to a Technical Capability Notice (TCN) that requires Apple to retain the ability to access iCloud cont… The Record · Aug 4, 2026 High UKUSencryptiondata-privacylaw-enforcement
threat-intel Almost Half of Malware Samples Communicate Direct to IP Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including… Palo Alto Unit 42 · Aug 4, 2026 High BRd2ipdnsc2
vulnerability Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected The Swiss Federal Office for Information Technology and Communications (BIT) was hacked, with approximately 200 accounts compromised due to vulnerabilities in on-premises Microsoft SharePoint servers. Hackers exploited k… The Record · Aug 4, 2026 High SWsharepointvulnerabilityiis
threat-intel CAF Bank reopens online service but warns of further outages This article is a collection of cybersecurity and technology news snippets. It covers a range of topics including a phishing campaign mimicking Signal support, a vulnerability impacting Joomla extensions, and a new X11 s… The Register · Aug 4, 2026 Medium CHIRphishingvulnerabilitycybersecurity
threat-intel CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its KEV catalog due to active exploitation. This flaw, stemming from incomplete patching of… The Hacker News · Aug 4, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875GEICSWvulnerabilityremote monitoringremote management
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations Hackers breached the Liechtenstein Register of Beneficial Owners, exposing data on 31,000 individuals linked to companies, foundations, and trusts. This breach, prompted by a cyberattack, highlights the vulnerability of… The Record · Aug 3, 2026 Medium LIgovernmentdata breachfinancial
threat-intel AI slop pollutes the CVE pipeline with fake vulns This article covers a range of cybersecurity and technology news, including a report on fake vulnerabilities polluting the CVE pipeline due to AI, a phishing campaign impersonating Signal support, and a discussion of var… The Register · Aug 3, 2026 Medium CHUKvulnerabilityphishingransomware
vulnerability INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws The INC Ransomware operation has become the dominant threat actor exploiting a series of zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances. Since the beginning of August 2026, the group has been aggressively… The Hacker News · Aug 3, 2026 High CVE-2026-15409CVE-2026-15410AUU.UAzero-dayvpnransomware
threat-intel Russian spies turn public Wi-Fi into malware delivery systems Russian state actors are leveraging public Wi-Fi networks to deliver malware to victims, specifically by impersonating Signal support to launch phishing attacks. This tactic is part of a broader trend of Russian intellig… The Register · Aug 3, 2026 High RUIRphishingmalwarerussian
threat-intel Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations A cyberattack compromised the Liechtenstein Register of People Behind Companies and Foundations, exposing data of approximately 31,000 individuals. The breach was discovered during a routine check and prompted a governme… SecurityWeek · Aug 3, 2026 High LIdata-breachmoney launderingfinancial crime
threat-intel Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict Multiple US water systems, including those in Georgia and Michigan, are experiencing cyberattacks, potentially linked to the ongoing US-Iran conflict. These attacks are targeting critical infrastructure, raising serious… The Register · Aug 3, 2026 High IRUScyberattackcritical infrastructurewater systems
threat-intel Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says Russian state-sponsored hackers, linked to the Midnight Blizzard group (part of APT29), are compromising hotel Wi-Fi networks worldwide to steal traveler login credentials and install espionage malware. The campaign uses… The Record · Aug 3, 2026 High RUUKSAhotel wifiespionagecaptive portal
threat-intel UK government investment arm cops to 40-hour leak of officials' contact details The UK government’s investment arm experienced a 40-hour data leak exposing officials’ contact details. This incident highlights a broader vulnerability within government systems and raises concerns about data security p… The Register · Aug 3, 2026 Medium UKIRCHdata breachphishingvulnerability
vulnerability Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks The INC Ransomware group has been aggressively exploiting two vulnerabilities in SonicWall’s SMA1000 secure remote access appliances to deploy ransomware, targeting organizations across multiple countries. These vulnerab… SecurityWeek · Aug 3, 2026 High CVE-2026-15409CVE-2026-15410USAUUAvulnerabilityransomwarezero-day
threat-intel PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web The Police National Legal Database (PNLD) in the UK has confirmed that contact information, including names, email addresses, and organizations, belonging to police officers, government partners, and customers was expose… The Hacker News · Aug 3, 2026 High data breachpower appsdark web
vulnerability ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Aug 3, 2026 Critical log4jrcejndi