vulnerability Multiples vulnérabilités dans Microsoft Edge (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing for remote code execution and a security issue not specified by the vendor. Users of Edge versions prior to 151.0.4129.86 are at risk. CERT-FR · Aug 17, 2026 High CVE-2026-19556CVE-2026-19557CVE-2026-19558vulnerabilityremote code executionmicrosoft edge
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to execute arbitrary code remotely and elevate privileges. These issues primarily affect PowerShell versions, requiring immediate pa… CERT-FR · Aug 17, 2026 High CVE-2026-50523CVE-2026-69414microsoftpowershellvulnerability
vulnerability Vulnérabilité dans SPIP (17 août 2026) A critical vulnerability has been identified in SPIP, allowing attackers to execute arbitrary code remotely. This affects older versions of the content management system, requiring immediate patching to prevent exploitat… CERT-FR · Aug 17, 2026 High spipremotecode
vulnerability Wireshark 4.6.8 Released, (Sun, Aug 16th) Wireshark, a widely used network protocol analyzer, released version 4.6.8, addressing 28 vulnerabilities and 25 bugs. This update significantly improves the security posture of the tool, mitigating potential risks assoc… SANS Internet Storm Center · Aug 16, 2026 Medium wiresharkvulnerabilitynetwork analysis
threat-intel Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do This article covers a range of cybersecurity and technology news, including a warning about autonomous AI attacks posing a significant risk to critical infrastructure, a report on Russian phishing campaigns mimicking Sig… The Register · Aug 16, 2026 Medium IRRUcyberattackphishingransomware
supply-chain ChainDrop worm crawls into npm supply chain, evades standard defenses A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compr… The Register · Aug 15, 2026 High supply-chainnpmvulnerability
vulnerability SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch A critical security vulnerability (CVE-2026-58231) in SAP Commerce Cloud is being actively exploited, despite a patch being available for days. The flaw stems from inadequate input validation, potentially leading to code… The Hacker News · Aug 15, 2026 Critical CVE-2026-58231CVE-2025-31324USsapvulnerabilitypatch
vulnerability Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner A critical vulnerability in Apple's macOS Screen Sharing component has been actively exploited in the wild to install a cryptocurrency miner. Researchers have discovered a pre-authentication vulnerability (CVE-2026-65400… The Hacker News · Aug 15, 2026 Critical CVE-2026-65400CVE-2026-43779CVE-2026-43777USmacosscreen sharingvulnerability
threat-intel Amid AI-Driven Bug Tsunami, NIST Looks to…AI The National Institute of Standards and Technology (NIST) is seeking public input on how to modernize the National Vulnerability Database (NVD) in light of a massive surge in software vulnerabilities, driven in part by A… Dark Reading · Aug 14, 2026 Medium vulnerabilityaicybersecurity
threat-intel In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities This week’s cybersecurity news highlights a range of concerning developments, including a government contract sparking AI concerns, a North Korean IT worker infiltrating a US federal agency, vulnerabilities discovered in… SecurityWeek · Aug 14, 2026 High NOransomwarecyberattackvulnerability
supply-chain Trivy, Not LiteLLM Behind the 2,500 Org Compromise A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vul… SecurityWeek · Aug 14, 2026 High GEBRFRsupply-chainvulnerabilitycredential-theft
threat-intel Scottish prosecutors cast eye over leaky supplier after staff data exposed Scottish prosecutors are investigating a supplier after a data breach exposed staff information. The incident highlights ongoing security vulnerabilities within third-party services and the potential for misuse of sensit… The Register · Aug 14, 2026 Medium CHUKdata breachcybersecuritysupplier security
threat-intel 14,000 Trezor Customers Impacted by Data Breach at ShipMonk Nearly 14,000 Trezor customers were affected by a data breach stemming from a vulnerability exploited by the ShinyHunters group within ShipMonk’s systems. The breach exposed customer data including names, addresses, emai… SecurityWeek · Aug 14, 2026 Medium USUKSWdata breachshippingvulnerability
vulnerability Hackers Exploiting Unpatched GeoServer Zero-Day A zero-day vulnerability in GeoServer is being actively exploited by threat actors shortly after its public disclosure. The flaw, a SQL injection, allows remote code execution and has prompted immediate action from secur… SecurityWeek · Aug 14, 2026 High sql injectionzero-dayremote code execution
threat-intel ISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 14, 2026 Medium phishingcredential stuffinglegacy systems
vulnerability Multiples vulnérabilités dans les produits Netgate (14 août 2026) Multiple vulnerabilities have been discovered in Netgate products, including pfSense. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and remote code execution. Several CVEs have… CERT-FR · Aug 14, 2026 High CVE-2026-56126CVE-2026-56127CVE-2026-56128vulnerabilitypfsenseremote code execution
vulnerability Multiples vulnérabilités dans Elastic Kibana (14 août 2026) Multiple vulnerabilities have been discovered in Elastic Kibana. Some of these vulnerabilities allow for privilege escalation, remote denial-of-service, and data confidentiality compromise. Elastic has released several s… CERT-FR · Aug 14, 2026 High CVE-2015-8131CVE-2026-49089CVE-2026-72629kibanaelasticvulnerability
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (14 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. Affected Debian versions are those prior to 6.12.… CERT-FR · Aug 14, 2026 High CVE-2025-40098CVE-2026-45897CVE-2026-45901linuxkerneldebian
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (14 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and bypassing security policies, potentially leading to c… CERT-FR · Aug 14, 2026 High CVE-2024-53143CVE-2025-10263CVE-2025-54518linuxkernelvulnerability
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (14 août 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Several of these vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The vulnerabilities are bei… CERT-FR · Aug 14, 2026 High CVE-2022-4994CVE-2023-2058CVE-2023-53995linuxkernelvulnerability