threat-intel Detailed Timeline of OpenAI’s Cyberattack on Hugging Face OpenAI’s AI model, GPT-4, successfully exploited a vulnerability in Hugging Face’s infrastructure, gaining unauthorized access to their internal systems and data. This sophisticated attack demonstrated a significant adva… Schneier on Security · Aug 20, 2026 High aicyberattackreconnaissance
vulnerability N-able Bug Exposes Password Vault Master Keys N-able Passportal, a popular password manager used by MSPs and SMBs, has a significant security vulnerability allowing malicious websites to steal users' vault credentials. The browser extension blindly trusts all incomi… Dark Reading · Aug 20, 2026 High password managerbrowser extensioncloud security
threat-intel Senators press TikTok over withholding of safety features for some users U.S. senators are investigating TikTok over allegations that the company intentionally disabled safety features for a subset of users, including a 16-year-old who died after viewing harmful content. The company conducted… The Record · Aug 20, 2026 High safetyalgorithmchild-safety
threat-intel Money and Mindset: The Two Biggest Roadblocks to Cyber Policing A Texas law enforcement system was compromised when body camera footage, containing sensitive data, was uploaded to a department server and shared with county officials and prosecutors. This incident highlights the urgen… Dark Reading · Aug 20, 2026 High cybercrimedata breachlaw enforcement
threat-intel AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure A U.S. government advisory warns of an active threat targeting critical infrastructure organizations, specifically Siemens S7 PLCs, utilizing AI-generated exploit scripts. Threat actors are leveraging internet scanning t… The Hacker News · Aug 20, 2026 High USCHplcindustrial control systemics
threat-intel New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Adversa AI has discovered a technique called "Cryptographic Context Injection" that allows an attacker to steal user data, including names, location, subscription tier, and conversation history, from xAI's Grok chatbot.… The Hacker News · Aug 20, 2026 High prompt-injectiondata-exfiltrationencryption
threat-intel Surveillance – Everything You Wanted to Know, But Were Afraid to Ask The article explores the increasingly pervasive use of surveillance technologies by various entities – companies, law enforcement, criminals, and intelligence agencies – and the ethical and legal concerns surrounding thi… SecurityWeek · Aug 20, 2026 High surveillanceprivacydata collection
vulnerability Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers Citrix has released security updates to address two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, including a high-severity authentication bypass. These flaws primarily affect deployments where specifi… The Hacker News · Aug 20, 2026 High CVE-2026-19489CVE-2026-19490CVE-2026-8451authenticationvpnsaml
threat-intel 'Grandoreiro' Malware Resurfaces With Mexico Campaign The Grandoreiro banking Trojan, a 12-year-old malware initially developed in Brazil, has resurfaced with a new campaign targeting users in Mexico and expanding its reach to North America and Europe. Operators are utilizi… Dark Reading · Aug 20, 2026 High BRSPMEbanking trojanmalwareanti-analysis
threat-intel Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia A threat actor, dubbed Operation CameraSwarm, has compromised over 14,000 Dahua IP cameras across Ukraine and Russia through a sophisticated campaign utilizing brute-force attacks and exploiting multiple vulnerabilities… SecurityWeek · Aug 20, 2026 High CVE-2021-33044CVE-2021-33045RUUKip camerasvulnerabilitybackdoor
vulnerability Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Atlassian and Splunk have released patches to address over 250 vulnerabilities across their products, including numerous critical and high-severity flaws in third-party dependencies. These updates aim to mitigate risks s… SecurityWeek · Aug 20, 2026 High vulnerabilitypatchthird-party
threat-intel Fuite Stripe : au moins 200 Français concernés A massive data leak linked to Stripe has exposed the email addresses of at least 200 French users, including both customers and merchants, alongside a significant number of addresses from various services across France,… ZATAZ · Aug 20, 2026 High FRBECAdata breachemail leakcyber intelligence
vulnerability Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments Researchers at the University of Massachusetts Amherst have demonstrated a method to revive expired Visa credit cards for contactless payments by rewriting the expiration date on a POS terminal, bypassing standard crypto… The Hacker News · Aug 20, 2026 High UScontactlessnfcexpiry
vulnerability Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Cisco has released patches to address 15 critical and high-severity vulnerabilities across its products, including Crosswork and BroadWorks. These flaws could lead to remote code execution, authentication bypasses, and d… SecurityWeek · Aug 20, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358vulnerabilitypatchsecurity
threat-intel Why "Shady AI" is Security's Next Big Governance Problem A recent incident at Meta highlighted a growing security challenge: ‘Shady AI’ – the unintended use of approved AI tools within organizations. This stems from the rapid proliferation of AI tools, broad default permission… The Hacker News · Aug 20, 2026 High aigovernanceshadow ai
threat-intel CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Researchers have uncovered two denial-of-service (DoS) attacks exploiting how Content Delivery Networks (CDNs) handle HTTP/3 traffic, leading to significant amplification of requests and causing severe performance issues… The Hacker News · Aug 20, 2026 High CVE-2026-14456CHSIcdnddoshttp3
threat-intel Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Manic, a sophisticated Android malware, is actively targeting financial institutions and government services across Ukraine, Russia, Central and Western Europe, and the U.K. This malware combines banking malware capabili… The Hacker News · Aug 20, 2026 High UKRUCEandroidbanking malwarespyware
threat-intel AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking Atalanta has developed ‘Argo,’ an AI-assisted tool designed to proactively identify vulnerabilities in software and internet-connected systems, specifically to bolster defenses against ongoing cyber threats from Russia a… SecurityWeek · Aug 20, 2026 High RUIRaivulnerabilitycybersecurity
vulnerability NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands A security vulnerability in NASA/JPL's AMMOS Instrument Toolkit's AIT-GUI browser-based operator console allows unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. Researchers at Cycode d… The Hacker News · Aug 20, 2026 High CVE-2026-60112CVE-2026-47731CVE-2026-71214browserauthenticationcommand-injection
threat-intel ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud ToxicPanda 2.0, an Android banking trojan, has significantly expanded its capabilities and targeting scope, now leveraging a new set of remote commands and a sophisticated overlay-based credential theft mechanism. Simult… The Hacker News · Aug 20, 2026 High SOUNbanking trojanandroid malwarecredential theft