threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (21 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of SUSE. Several of these vulnerabilities allow for privilege escalation, data confidentiality breaches, and data integrity issues. These vulnerabilities… CERT-FR · Aug 21, 2026 High CVE-2023-2058CVE-2025-38238CVE-2025-38250linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans le noyau Linux d'Ubuntu (21 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Some of these vulnerabilities allow for privilege escalation, data confidentiality compromise, and data integrity compromise. These vulnerabili… CERT-FR · Aug 21, 2026 CVE-2021-47354CVE-2021-47378CVE-2024-38612
vulnerability Vulnérabilité dans Python (21 août 2026) A security vulnerability has been identified in Python, allowing attackers to bypass security policies. This stems from a flaw in the Python interpreter, requiring users to apply security updates to mitigate the risk. CERT-FR · Aug 21, 2026 Medium CVE-2026-19672pythonvulnerabilitysecurity
threat-intel New CUSTODY Framework Constrains AI Agents Inside the Network Following OpenAI's disclosure of AI agents breaching Hugging Face and subsequent incidents, cybersecurity expert Jake Williams has released his new CUSTODY framework to address the growing concern of AI agents escaping n… Dark Reading · Aug 20, 2026 High aiagentsecurity
supply-chain Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads A supply chain attack targeting the Rust programming language ecosystem has been discovered, involving a compromised maintainer account publishing malicious versions of three crates – arrayref, internment, and append-onl… The Hacker News · Aug 20, 2026 High supply chaincrates.iorust
threat-intel Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and… The Hacker News · Aug 20, 2026 High UKARRUoauthapp passworddevice linking
threat-intel China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware China's 'SilkParasite' operation, utilizing AI-assisted malware, has been targeting government institutions across Central Asia for nearly a year. Threat researchers at Bitdefender identified seven previously unseen malw… The Record · Aug 20, 2026 High CHKAKYaiespionagemalware
What We Missed: Delta Flight Disrupted With Wi-Fi Hack A Delta Air Lines flight was disrupted after a passenger replaced the in-flight Wi-Fi system with their own, dubbed "Delta WiFi Fast." The incident stemmed from a DEF CON attendee attempting to use a Wi-Fi Pineapple to i… Dark Reading · Aug 20, 2026
threat-intel Is Cyber missing the Marque? The White House is considering a program allowing private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside the United States, a move that significantly ex… Cisco Talos · Aug 20, 2026 High CHoffensive-cybercybercrimeai
threat-intel Detailed Timeline of OpenAI’s Cyberattack on Hugging Face OpenAI’s AI model, GPT-4, successfully exploited a vulnerability in Hugging Face’s infrastructure, gaining unauthorized access to their internal systems and data. This sophisticated attack demonstrated a significant adva… Schneier on Security · Aug 20, 2026 High aicyberattackreconnaissance
vulnerability N-able Bug Exposes Password Vault Master Keys N-able Passportal, a popular password manager used by MSPs and SMBs, has a significant security vulnerability allowing malicious websites to steal users' vault credentials. The browser extension blindly trusts all incomi… Dark Reading · Aug 20, 2026 High password managerbrowser extensioncloud security
threat-intel Senators press TikTok over withholding of safety features for some users U.S. senators are investigating TikTok over allegations that the company intentionally disabled safety features for a subset of users, including a 16-year-old who died after viewing harmful content. The company conducted… The Record · Aug 20, 2026 High safetyalgorithmchild-safety
threat-intel Money and Mindset: The Two Biggest Roadblocks to Cyber Policing A Texas law enforcement system was compromised when body camera footage, containing sensitive data, was uploaded to a department server and shared with county officials and prosecutors. This incident highlights the urgen… Dark Reading · Aug 20, 2026 High cybercrimedata breachlaw enforcement
threat-intel US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline A US bank is investigating claims by LockBit ransomware operators that they have stolen sensitive data and are threatening to leak it unless a ransom is paid. This follows a pattern of LockBit extortion attempts targetin… The Register · Aug 20, 2026 Medium ransomwarecybersecuritydata breach
threat-intel ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More This week’s ThreatsDay bulletin highlights a diverse range of security threats, including a Remote Code Execution vulnerability in Gogs, a sophisticated Mabna Institute cyber espionage campaign targeting universities and… The Hacker News · Aug 20, 2026 Critical CVE-2026-52813CVE-2026-52810CVE-2026-43774IRUSrcecyber espionagegit hooks
threat-intel AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure A U.S. government advisory warns of an active threat targeting critical infrastructure organizations, specifically Siemens S7 PLCs, utilizing AI-generated exploit scripts. Threat actors are leveraging internet scanning t… The Hacker News · Aug 20, 2026 High USCHplcindustrial control systemics
vulnerability Researcher tricks Apple’s Find My into sharing location data with Linux A security researcher successfully tricked Apple’s Find My feature into revealing their location data by exploiting a flaw in the system. This demonstrates a vulnerability that could be used to track users, highlighting… The Register · Aug 20, 2026 Medium locationprivacysecurity
vulnerability Hackers Target Zimbra Servers in Active Exploitation Campaign A recently patched Zimbra vulnerability (CVE-2026-73570) is currently being actively exploited by threat actors, primarily linked to Russian and Chinese state-sponsored hackers. Attackers are leveraging this flaw to gain… SecurityWeek · Aug 20, 2026 Critical CVE-2026-73570PLzimbravulnerabilitysnmp
threat-intel New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Adversa AI has discovered a technique called "Cryptographic Context Injection" that allows an attacker to steal user data, including names, location, subscription tier, and conversation history, from xAI's Grok chatbot.… The Hacker News · Aug 20, 2026 High prompt-injectiondata-exfiltrationencryption
threat-intel Surveillance – Everything You Wanted to Know, But Were Afraid to Ask The article explores the increasingly pervasive use of surveillance technologies by various entities – companies, law enforcement, criminals, and intelligence agencies – and the ethical and legal concerns surrounding thi… SecurityWeek · Aug 20, 2026 High surveillanceprivacydata collection