threat-intel Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Mozilla has revoked a signing key for Firefox after an unencrypted copy of the key was accidentally uploaded to GitHub. This significantly increases the risk of malicious actors creating fake Firefox installations. The i… The Register · Aug 11, 2026 High key-managementfirefoxvulnerability
threat-intel OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber OpenAI has released GPT-5.6-Cyber, a new AI model specifically designed for advanced cybersecurity tasks, including finding zero-days and creating exploit chains. This model addresses limitations of its predecessor, GPT-… SecurityWeek · Aug 11, 2026 High aicybersecurityvulnerability
ransomware Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain… The Hacker News · Aug 11, 2026 High CVE-2024-5559CVE-2025-24472SOBRSPransomwarevulnerabilitysupply-chain
vulnerability ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Aug 11, 2026 Critical log4jrcevulnerability
vulnerability Multiples vulnérabilités dans SPIP (11 août 2026) A series of vulnerabilities have been discovered in SPIP, a popular French content management system. These include remote code execution, SQL injection, and server-side request forgery, impacting versions prior to 4.4.1… CERT-FR · Aug 11, 2026 Medium vulnerabilitysql-injectionssrf
vulnerability Vulnérabilité dans Docker (11 août 2026) A vulnerability has been identified in Docker Desktop, allowing an attacker to compromise data integrity. Users of versions prior to 4.86.0 should immediately update to mitigate the risk. CERT-FR · Aug 11, 2026 Medium CVE-2026-17106dockervulnerabilitysecurity
vulnerability Vulnérabilité dans CPython (11 août 2026) A denial-of-service vulnerability has been identified in CPython, allowing an attacker to disrupt remote systems. The vulnerability stems from a lack of recent security updates and requires immediate patching to prevent… CERT-FR · Aug 11, 2026 Medium CVE-2026-18503pythondenial-of-servicevulnerability
vulnerability Multiples vulnérabilités dans OpenSSH (11 août 2026) Multiple vulnerabilities have been discovered in OpenSSH, impacting versions prior to 10.5. The exact nature of the security issue is not specified by the publisher, but users are advised to consult the vendor's security… CERT-FR · Aug 11, 2026 Medium sshvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Postfix (11 août 2026) Multiple vulnerabilities have been discovered in Postfix, potentially allowing attackers to cause a denial-of-service, bypass security policies, and create an unspecified security issue. Users of Postfix versions prior t… CERT-FR · Aug 11, 2026 Medium vulnerabilitymail serversecurity
threat-intel Multiples vulnérabilités dans les produits SAP (11 août 2026) Multiple vulnerabilities have been discovered in SAP products, including remote code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities can be exploited to cause significant damage.… CERT-FR · Aug 11, 2026 High CVE-2025-42947CVE-2025-58057CVE-2026-33871vulnerabilitysapsecurity
threat-intel Deux pirates revendiquent le piratage de pro du Cloud Two hackers, Misere and Chimeraz, claim to have breached BlgCloud, a French cloud software provider, gaining access to approximately 159 client environments and allegedly stealing sensitive professional data. They are no… ZATAZ · Aug 10, 2026 High FRdata breachextortioncloud security
threat-intel Des kiosques Pokémon exposés par une fuite Firebase A clandestine publication alleges that a US-based automated distribution operator exposed sensitive data – including bank details, email addresses, source code, and technical access – across multiple continents via expos… ZATAZ · Aug 10, 2026 High USJPAUdata breachapiauthentication
vulnerability Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius A zero-day SQL-injection vulnerability in Metabase Cloud is actively being exploited, potentially impacting a wide range of organizations beyond Metabase customers. The vulnerability allows remote attackers to gain admin… Dark Reading · Aug 10, 2026 High sql-injectionzero-dayvulnerability
threat-intel FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure The FBI and South Korea’s government have issued a cybersecurity advisory warning of the Gunra ransomware gang, which is exploiting vulnerabilities in Fortinet firewalls to target critical infrastructure organizations gl… The Record · Aug 10, 2026 High CVE-2024-55591CVE-2025-24472SONOransomwarevulnerabilitysupply-chain
threat-intel The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists The article highlights a significant gap between the speed at which attackers discover and exploit vulnerabilities and the speed at which defenders can patch them. Traditional CVSS-based prioritization is inadequate beca… Dark Reading · Aug 10, 2026 High CVE-2024-9474CVE-2024-0012vulnerabilityattack-pathchoke-point
threat-intel North Korean spies are running local LLMs to cause AI mischief North Korean intelligence operatives are leveraging locally hosted Large Language Models (LLMs) to conduct sophisticated disinformation campaigns and potentially cause broader AI-related mischief. This indicates a growin… The Register · Aug 10, 2026 Medium NOaillmcyberespionage
threat-intel Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list A user exploited a waitlist API for a gym class booking service by prompting an AI agent to bypass the normal process, demonstrating a vulnerability in how AI systems can be manipulated to access and abuse online service… The Register · Aug 10, 2026 Medium aiautomationsecurity
threat-intel China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw China-linked threat actor Storm-1175 has deployed a new ransomware strain, StormEncryptor, leveraging a vulnerability in N-able N‑central to gain initial access and subsequently deploy ransomware. This follows a pattern… The Hacker News · Aug 10, 2026 High CVE-2026-18577CVE-2026-18556CVE-2023-37679CHransomwarevulnerabilitypatch-bypass
vulnerability Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Cisco has warned of seven high-severity vulnerabilities in its Secure Endpoint Connector software, stemming from flaws within the ClamAV antivirus engine. These vulnerabilities could lead to denial-of-service conditions… SecurityWeek · Aug 10, 2026 High CVE-2026-20337CVE-2026-20339CVE-2026-20345clamavvulnerabilitypatch
supply-chain China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns China-linked hackers, believed to be part of the Storm-1175 group, are exploiting a critical vulnerability in N-central, a remote monitoring and management (RMM) tool, to deploy ransomware. This supply-chain attack is le… The Record · Aug 10, 2026 High CVE-2026-18577CHsupply-chainransomwarezero-day