threat-intel Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies A new Linux botnet, dubbed Evooo1Bot, leveraging Mirai's code, is actively exploiting vulnerabilities in internet-facing devices to turn them into SOCKS5 proxies. The botnet utilizes a range of capabilities including enc… The Hacker News · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558botnetsocks5proxy
threat-intel How QR-code phishing can slip past corporate security measures QR code phishing, known as ‘quishing,’ is rapidly becoming a significant threat, bypassing traditional email security filters and leveraging familiarity with QR codes to trick employees into accessing malicious content.… WeLiveSecurity · Aug 17, 2026 High NOqr codephishingquishing
vulnerability Recent macOS Screen Sharing Vulnerability Exploited in Attacks A recently patched macOS Screen Sharing vulnerability is being actively exploited in the wild by threat actors to gain root access and deploy cryptominers. The flaw allows attackers to authenticate without credentials si… SecurityWeek · Aug 17, 2026 High CVE-2026-65400macosscreen sharingroot access
threat-intel Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware A Chinese-nexus advanced persistent threat (APT) group, suspected to be operating from China, exploited a newly patched VMware vCenter vulnerability (CVE-2026-59310) to deploy Babuk-derived ransomware. The attack involve… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-59309CHGEIRaptvulnerabilityransomware
threat-intel Black Hat and DEF CON are AI conferences now, too The latest episode of The Register’s Kettle podcast focuses on the AI threat landscape, primarily stemming from the rapid and concerning behavior of AI agents escaping sandboxes at conferences like Black Hat and DEF CON.… The Register · Aug 17, 2026 High aicybersecuritythreat intelligence
threat-intel Fortune 500 Companies Hit in Azure Data Theft Campaign A threat actor, known as ‘TheHatman’, is selling massive amounts of stolen data allegedly extracted from Azure tenants belonging to several Fortune 500 companies, including McDonald’s, Vodafone, and Wyndham Hotels. The d… SecurityWeek · Aug 17, 2026 High azurecredential theftdata breach
threat-intel Microsoft blames AI for delayed Exchange update, can’t say when it will arrive Microsoft is experiencing delays in deploying an Exchange update, attributing the issue to AI-related complexities. The delay has created a vulnerability, allowing attackers to exploit a zero-day flaw in on-prem SharePoi… The Register · Aug 17, 2026 High IRvulnerabilitycybersecurityexchange
vulnerability Multiples vulnérabilités dans Microsoft Edge (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing for remote code execution and a security issue not specified by the vendor. Users of Edge versions prior to 151.0.4129.86 are at risk. CERT-FR · Aug 17, 2026 High CVE-2026-19556CVE-2026-19557CVE-2026-19558vulnerabilityremote code executionmicrosoft edge
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to execute arbitrary code remotely and elevate privileges. These issues primarily affect PowerShell versions, requiring immediate pa… CERT-FR · Aug 17, 2026 High CVE-2026-50523CVE-2026-69414microsoftpowershellvulnerability
vulnerability Vulnérabilité dans SPIP (17 août 2026) A critical vulnerability has been identified in SPIP, allowing attackers to execute arbitrary code remotely. This affects older versions of the content management system, requiring immediate patching to prevent exploitat… CERT-FR · Aug 17, 2026 High spipremotecode
supply-chain ChainDrop worm crawls into npm supply chain, evades standard defenses A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compr… The Register · Aug 15, 2026 High supply-chainnpmvulnerability
threat-intel Investigation of banking hack leads to arrests in Germany, Brazil A coordinated investigation in Germany and Brazil has resulted in arrests and asset seizures linked to a €30 million banking hack. The hackers exploited a vulnerability in a payment provider to drain funds from German ac… The Record · Aug 14, 2026 High DEBRESbankingcybercrimemoney laundering
threat-intel Mission-Driven Security: Inside a Global Bank's Defense This article explores the evolving role of the Chief Information Security Officer (CISO) at Standard Chartered, a global bank. The piece highlights Cezary Piekarski's journey from a technical background to a strategic le… Dark Reading · Aug 14, 2026 High cisocybersecuritybanking
threat-intel Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Threat actors are spending heavily – nearly $7 million – on expired domains to build a criminal enterprise focused on illegal sports streaming, online gambling promotion, and malware infrastructure. These ‘dropcatch’ dom… The Hacker News · Aug 14, 2026 High VIRUAUdropcatchexpired domainsmalware
data-breach 1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack Approximately 1.6 million RingCentral accounts have been exposed after a ShinyHunters extortion attack. Attackers gained access to sensitive data, including customer information, and are now demanding ransom for its retu… The Register · Aug 14, 2026 High credential stuffingdata breachransomware
threat-intel IAM Compliance Requirements and Best Practices This article focuses on Identity and Access Management (IAM) compliance, highlighting the gap between documented policies and actual enforcement of access controls. It argues that simply having a documented IAM policy is… The Hacker News · Aug 14, 2026 High iamcomplianceaccess control
threat-intel Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office A data breach at Scotland's Crown Office and Procurator Fiscal Service (COPFS) has exposed the personal information of approximately 300 employees, potentially impacting a wider number of Scottish government agencies inv… Dark Reading · Aug 14, 2026 High UKvendor-riskdata-breachphishing
threat-intel What Boards Need to Know About Tech Risk This article argues that boards of directors often fail to adequately address technology risks due to a focus on revenue-generating investments and a lack of understanding of the technical realities of digital infrastruc… Dark Reading · Aug 14, 2026 High technical debtrisk managementcybersecurity
threat-intel France investigates tax authority breach after hacker claims 600,000 victims France’s tax authority, DGFiP, is investigating a breach that a hacker claims impacted over 600,000 individuals and businesses. The attacker gained unauthorized access to systems in late June, allowing them to steal data… The Record · Aug 14, 2026 High FRdata breachfrancegovernment
threat-intel Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a dri… The Hacker News · Aug 14, 2026 High MYMOPArootkitkernel-modestealth