threat-intel The invisible passenger in your car Researchers at Securelist discovered a new Android malware campaign targeting automotive head units, orchestrated by the MoYu Group, a group linked to the BADBOX botnet. The malware, delivered through legitimate system u… Securelist · Aug 21, 2026 High androidiotbotnet
vulnerability CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies regarding two critical vulnerabilities in TrueConf, a secure video conferencing platform. Threat actors, spe… SecurityWeek · Aug 21, 2026 High CVE-2026-72529CVE-2026-72530RUBYvulnerabilitypatchtrueconf
vulnerability GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure A critical vulnerability (CVE-2026-19478) in GitLab, allowing unauthenticated code injection and data manipulation, has been actively exploited shortly after its disclosure. This poses a significant risk to organizations… The Hacker News · Aug 21, 2026 Critical CVE-2026-19478vulnerabilitycode-injectiongraphql
vulnerability Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution Microsoft has patched a critical vulnerability in Entra ID, which has been exploited in the wild. The flaw allows remote code execution, and while Microsoft has addressed it, it highlights the ongoing need for vigilance… The Hacker News · Aug 21, 2026 Critical CVE-2026-69836CVE-2026-68820entria idazure adremote code execution
threat-intel Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. This article is a collection of cybersecurity and technology news snippets from The Register. It covers a range of topics including a vulnerability in Microsoft SharePoint, a phishing campaign impersonating Signal suppor… The Register · Aug 21, 2026 Medium CVE-2026-20315CVE-2026-20317CVE-2026-20231vulnerabilityphishingransomware
threat-intel Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st) This script identifies users within an organization who have not yet been enrolled in multi-factor authentication (MFA) using the Microsoft Graph API. It leverages a beta command to efficiently list un-registered users,… SANS Internet Storm Center · Aug 21, 2026 Info mfamicrosoftgraph
threat-intel ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 21, 2026 High phishingransomwaresupply-chain
threat-intel Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st) This article details a method for identifying password spray attacks and unusual login activity within Microsoft Entra (formerly Azure Active Directory) logs. By analyzing login events and filtering for unexpected countr… SANS Internet Storm Center · Aug 21, 2026 Medium entragraphpassword sprayconditional access
threat-intel Russian snoops add OAuth abuse to targeted phishing campaigns Google has identified three distinct groups of Russian cyber-spies – UNC6293, UNC7005, and UNC5976 – that are aggressively targeting individuals in academia, defense, government, and think tanks across Europe and the US.… The Register · Aug 21, 2026 High RUUKWEphishingoathsocial engineering
threat-intel Multiples vulnérabilités dans le noyau Linux de Debian LTS (21 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian LTS. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. The affected systems include Debian 12 Bookwo… CERT-FR · Aug 21, 2026 High CVE-2025-40098CVE-2026-45897CVE-2026-45901vulnerabilitylinuxkernel
vulnerability Vulnérabilité dans SPIP (21 août 2026) A remote code execution vulnerability has been discovered in SPIP, allowing attackers to execute arbitrary code from a remote location. The vulnerability is currently being actively exploited, and users of SPIP versions… CERT-FR · Aug 21, 2026 High CVE-2026-77806remote-code-executionvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Google Chrome (21 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser on Linux, Windows, and macOS. The exact nature of the vulnerabilities is not specified, but users are advised to upd… CERT-FR · Aug 21, 2026 Medium CVE-2026-76017CVE-2026-76018CVE-2026-76019chromevulnerabilitysecurity
vulnerability Vulnérabilité dans Microsoft Office (21 août 2026) A vulnerability has been discovered in Microsoft Office that could allow an attacker to compromise data confidentiality. Affected versions of Office, including Office 365 and Office 2019, require immediate patching to pr… CERT-FR · Aug 21, 2026 Medium CVE-2026-70105vulnerabilitymicrosoftpatch
vulnerability Multiples vulnérabilités dans les produits Microsoft (21 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to bypass security policies and cause denial-of-service conditions. Microsoft has released security bulletins detailing the issues a… CERT-FR · Aug 21, 2026 Medium CVE-2026-55013CVE-2026-55015microsoftvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (21 août 2026) Microsoft Edge is experiencing multiple vulnerabilities, as detailed in security advisories released by CERT-FR. These vulnerabilities could allow an attacker to trigger an unspecified security issue. Users of Microsoft… CERT-FR · Aug 21, 2026 Medium CVE-2026-76033CVE-2026-76034CVE-2026-76035vulnerabilitymicrosoftedge
vulnerability Vulnérabilité dans Microsoft Entra ID (21 août 2026) A critical vulnerability (CVE-2026-69836) has been identified in Microsoft Entra ID, allowing for remote code execution. While initially reported as actively exploited, Microsoft has clarified that it is currently not be… CERT-FR · Aug 21, 2026 Critical CVE-2026-69836entria idremote code executioncve
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities allow for arbitrary code execution, privilege escalation, and denial-of-service attacks. The affected products include variou… CERT-FR · Aug 21, 2026 High CVE-2024-56602CVE-2025-39902CVE-2025-54518linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans Traefik (21 août 2026) Multiple vulnerabilities have been discovered in Traefik, allowing attackers to bypass security policies. These vulnerabilities affect older versions of the popular reverse proxy and load balancer, requiring immediate pa… CERT-FR · Aug 21, 2026 Medium vulnerabilitysecuritytraefik
threat-intel Multiples vulnérabilités dans les produits IBM (21 août 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service vulnerabilities. Several CVEs have been assigned, covering a wide range of IBM s… CERT-FR · Aug 21, 2026 High CVE-2023-44487CVE-2025-12817CVE-2025-12818vulnerabilityremote code executiondata breach
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (21 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian, allowing an attacker to potentially elevate their privileges. These vulnerabilities are present in older Debian versions and require immediate… CERT-FR · Aug 21, 2026 Medium CVE-2026-13595CVE-2026-27456CVE-2026-53612linuxkerneldebian