vulnerability Multiples vulnérabilités dans Oracle Systems (19 août 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality and integrity. These vulnerabilities affect several Oracle products and require immed… CERT-FR · Aug 19, 2026 High CVE-2026-60822CVE-2026-70737CVE-2026-70829oraclevulnerabilitypatch
vulnerability Multiples vulnérabilités dans Oracle Virtualization (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Virtualization, primarily affecting Oracle VM VirtualBox version 7.2.14. These vulnerabilities allow for denial of service, data confidentiality breaches, and data… CERT-FR · Aug 19, 2026 High CVE-2026-71113CVE-2026-71114CVE-2026-71115vulnerabilityvirtualizationoracle
vulnerability Multiples vulnérabilités dans Joomla! (19 août 2026) Multiple vulnerabilities have been discovered in Joomla!, including those allowing for remote code execution, data integrity compromise, and cross-site scripting (XSS). These vulnerabilities are present in Joomla! versio… CERT-FR · Aug 19, 2026 High CVE-2026-71572CVE-2026-71573CVE-2026-71574joomlavulnerabilitycve
threat-intel Multiples vulnérabilités dans les produits Mozilla (19 août 2026) Mozilla has disclosed multiple vulnerabilities across its Firefox and Thunderbird products. These vulnerabilities include potential for remote code execution, denial of service, and information disclosure. Affected versi… CERT-FR · Aug 19, 2026 High CVE-2026-74934CVE-2026-74935CVE-2026-74936vulnerabilityfirefoxthunderbird
vulnerability Multiples vulnérabilités dans Oracle Database Server (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, allowing attackers to potentially execute code remotely, cause denial of service, and compromise data confidentiality. These vulnerabilities affect… CERT-FR · Aug 19, 2026 High CVE-2026-59889CVE-2026-71062CVE-2026-71063oracledatabasevulnerability
vulnerability Multiples vulnérabilités dans Oracle Weblogic (19 août 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic Server, allowing attackers to cause denial of service, compromise data confidentiality, and potentially execute arbitrary code remotely. These vulnerabilit… CERT-FR · Aug 19, 2026 High CVE-2023-21839CVE-2024-20931CVE-2026-60415oracleweblogicvulnerability
vulnerability Multiples vulnérabilités dans Oracle PeopleSoft (19 août 2026) A French security advisory from CERT-FR details multiple vulnerabilities within Oracle PeopleSoft versions 9.2 and 8.61-8.63. These flaws could lead to data breaches, data integrity issues, denial of service attacks, and… CERT-FR · Aug 19, 2026 High CVE-2026-60742CVE-2026-60821CVE-2026-60831oraclepeoplesoftvulnerability
vulnerability Multiples vulnérabilités dans Oracle Java SE (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, including those allowing for remote code execution, denial of service, and data confidentiality breaches. These vulnerabilities affect various Java SE vers… CERT-FR · Aug 19, 2026 High CVE-2026-60589CVE-2026-61308CVE-2026-62574javavulnerabilityoracle
vulnerability Multiples vulnérabilités dans Oracle MySQL (19 août 2026) Multiple vulnerabilities have been discovered in Oracle MySQL, including remote code execution, denial of service, and data confidentiality issues. These vulnerabilities affect various MySQL versions and related products… CERT-FR · Aug 19, 2026 High CVE-2025-13151CVE-2025-14821CVE-2025-68161mysqloraclevulnerability
threat-intel OpenAI's overhead will rise 20 percent for some workloads as it hardens security OpenAI is increasing its security overhead, raising prices by 20% for some workloads to bolster its defenses. This move reflects a broader trend in the AI industry as companies grapple with the security challenges of dep… The Register · Aug 18, 2026 High aisecurityautonomous systems
threat-intel Expired credit cards revived by researchers to make unauthorized payments Researchers have discovered a method to revive expired credit cards and use them for unauthorized payments. This vulnerability stems from a flaw in how Stripe handles AI token sales, allowing attackers to manipulate the… The Register · Aug 18, 2026 High credit-cardsaitokenization
threat-intel 'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture Researchers discovered a novel 'meta-hacking' technique that tricked Microsoft Copilot Personal into revealing its own security vulnerabilities, allowing attackers to map out its architecture and subsequently steal enter… Dark Reading · Aug 18, 2026 High CVE-2026-24301prompt-injectionmeta-hackingdata-exfiltration
threat-intel The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed Rich Mogull, a senior analyst at the Cloud Security Alliance, highlights a growing trend of "industrial accidents" – rogue AI agent attacks – stemming from a lack of robust safety protocols and sandboxing around increasi… Dark Reading · Aug 18, 2026 High CHUNaiartificial intelligencecybersecurity
threat-intel Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) A significant campaign, dubbed “TheHatman” and “FortiBleed,” is targeting organizations with leaked credentials, primarily leveraging password spraying against Fortinet and Sophos devices. TheHatman, an actor offering st… Palo Alto Unit 42 · Aug 18, 2026 High RUcredential theftpassword sprayingfortigate
threat-intel CISOs Break Their Silence in 'Declassified' Docuseries Red Mirror Studios, led by Danielle Lewan and Clint Howard II, is releasing an 11-episode docuseries titled "Declassified" featuring 11 cybersecurity CISOs sharing their real-world breach-response stories and personal st… Dark Reading · Aug 18, 2026 High cybersecuritycisosburnout
threat-intel More than 200 victims of Medusa ransomware identified over the last year, CISA says The CISA and FBI have updated their advisory on the Medusa ransomware gang, revealing that over 500 victims have been identified in the last year, with a significant focus on the healthcare sector. Medusa is known for ra… The Record · Aug 18, 2026 High ransomwaremedusazero-day
vulnerability Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps Varonis Threat Labs discovered three vulnerabilities, collectively named ‘CoSnitch,’ in Microsoft Copilot Personal that could allow a single click on a crafted link to silently exfiltrate data from connected apps. The fl… The Hacker News · Aug 18, 2026 High CVE-2026-24301CVE-2026-24299prompt injectiondata exfiltrationmemory poisoning
threat-intel Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 A threat actor calling itself Ransom Busters is offering to delete stolen ransomware data from servers in exchange for a payment, ranging from $20,000 to $60,000. GuidePoint Research and Intelligence Team (GRIT) has iden… The Hacker News · Aug 18, 2026 High USransomwaredata exfiltrationcredential theft
vulnerability CISA gives feds 3 days to fix actively exploited Ray RCE bug The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency advisory to federal agencies, demanding they address a rapidly exploited Remote Code Execution (RCE) vulnerability in Ray Ray, a widely… The Register · Aug 18, 2026 High CVE-2025-62593ray rayrcevulnerability
threat-intel Apple plugs image-processing hole ripe for spyware abuse Apple has patched a security vulnerability in its image processing system that could have been exploited to install spyware. The flaw allowed attackers to trick an AI system into revealing instructions on how to self-hac… The Register · Aug 18, 2026 High CVE-2026-65346CVE-2026-65329aispywarevulnerability