threat-intel Ransomware crook poses as recovery firm to steal payments from fellow extortionists A Russian threat actor is impersonating Signal support to conduct phishing attacks targeting other ransomware groups. The goal is to steal payments intended for extortion activities, highlighting a concerning trend of or… The Register · Aug 20, 2026 Medium RUphishingransomwaresocial engineering
vulnerability Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE A critical vulnerability in isolated-vm, a popular JavaScript sandbox library, allows attackers to escape the sandbox environment and potentially execute code on the host system. The flaw stems from a type confusion issu… The Hacker News · Aug 20, 2026 Critical vulnerabilitysandboxjavascript
vulnerability Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers Citrix has released security updates to address two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, including a high-severity authentication bypass. These flaws primarily affect deployments where specifi… The Hacker News · Aug 20, 2026 High CVE-2026-19489CVE-2026-19490CVE-2026-8451authenticationvpnsaml
threat-intel 'Grandoreiro' Malware Resurfaces With Mexico Campaign The Grandoreiro banking Trojan, a 12-year-old malware initially developed in Brazil, has resurfaced with a new campaign targeting users in Mexico and expanding its reach to North America and Europe. Operators are utilizi… Dark Reading · Aug 20, 2026 High BRSPMEbanking trojanmalwareanti-analysis
vulnerability Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution A critical security flaw in Zimbra Collaboration (ZCS) has been actively exploited in the wild, allowing attackers to execute arbitrary commands without authentication. The vulnerability, CVE-2026-73570, stems from impro… The Hacker News · Aug 20, 2026 Critical CVE-2026-73570CVE-2025-66376PLsnmpcommand injectionremote code execution
threat-intel Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia A threat actor, dubbed Operation CameraSwarm, has compromised over 14,000 Dahua IP cameras across Ukraine and Russia through a sophisticated campaign utilizing brute-force attacks and exploiting multiple vulnerabilities… SecurityWeek · Aug 20, 2026 High CVE-2021-33044CVE-2021-33045RUUKip camerasvulnerabilitybackdoor
threat-intel Club One Casino revendiqué par 3AM puis PEAR Club One Casino is being linked to two separate extortion groups, 3AM and PEAR, in a concerning trend for the casino industry. Initial reports from August 2026 attributed the first attack to 3AM, focusing on internal fil… ZATAZ · Aug 20, 2026 Medium USransomwarecasinoextortion
threat-intel Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th) This article details how to use Microsoft Graph PowerShell commands to identify risky login attempts. By leveraging the `Get-MgRiskDetection` command, security analysts can detect logins originating from unusual location… SANS Internet Storm Center · Aug 20, 2026 Medium SOCOMArisk detectionidentity protectionmicrosoft graph
threat-intel Grok chat duped into swallowing injected instructions Researchers have successfully tricked Security Copilot, an AI-powered security tool, into revealing instructions on how to exploit vulnerabilities within its own code. This highlights a concerning trend of AI systems bei… The Register · Aug 20, 2026 Medium aisocial engineeringvulnerability
data-breach French tax authority says break-in exposed data of 600K, including some private messages The French tax authority (Direction générale des Finances Publiques - DGFiP) has revealed a data breach that exposed the personal information of approximately 600,000 individuals, including some private messages. The bre… The Register · Aug 20, 2026 Medium FRvulnerabilitydata breachsharepoint
vulnerability Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Atlassian and Splunk have released patches to address over 250 vulnerabilities across their products, including numerous critical and high-severity flaws in third-party dependencies. These updates aim to mitigate risks s… SecurityWeek · Aug 20, 2026 High vulnerabilitypatchthird-party
vulnerability MLflow Vulnerability Exploited for Cloud Credential Theft A vulnerability in MLflow, a popular AI engineering platform, has been exploited by threat actors to steal cloud credentials and secrets. The flaw, tracked as CVE-2026-64849, allows unauthenticated SSRF attacks, leading… SecurityWeek · Aug 20, 2026 Critical CVE-2026-64849ssrfcloudmlflow
threat-intel Fuite Stripe : au moins 200 Français concernés A massive data leak linked to Stripe has exposed the email addresses of at least 200 French users, including both customers and merchants, alongside a significant number of addresses from various services across France,… ZATAZ · Aug 20, 2026 High FRBECAdata breachemail leakcyber intelligence
vulnerability Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments Researchers at the University of Massachusetts Amherst have demonstrated a method to revive expired Visa credit cards for contactless payments by rewriting the expiration date on a POS terminal, bypassing standard crypto… The Hacker News · Aug 20, 2026 High UScontactlessnfcexpiry
vulnerability Johnson Controls Simplex Incident Manager A critical vulnerability in Johnson Controls Simplex Incident Manager allows a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading… CISA Advisories · Aug 20, 2026 Critical CVE-2026-27875memory-dumpingcredential theftbuilding automation
threat-intel Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th) This article details a PowerShell script leveraging the Microsoft Graph API to extract detailed information about Microsoft 365 users, including their last password change date, login activity, and assigned licenses. The… SANS Internet Storm Center · Aug 20, 2026 Medium microsoft graphentaralicense management
vulnerability Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Cisco has released patches to address 15 critical and high-severity vulnerabilities across its products, including Crosswork and BroadWorks. These flaws could lead to remote code execution, authentication bypasses, and d… SecurityWeek · Aug 20, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358vulnerabilitypatchsecurity
threat-intel Why "Shady AI" is Security's Next Big Governance Problem A recent incident at Meta highlighted a growing security challenge: ‘Shady AI’ – the unintended use of approved AI tools within organizations. This stems from the rapid proliferation of AI tools, broad default permission… The Hacker News · Aug 20, 2026 High aigovernanceshadow ai
threat-intel CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Researchers have uncovered two denial-of-service (DoS) attacks exploiting how Content Delivery Networks (CDNs) handle HTTP/3 traffic, leading to significant amplification of requests and causing severe performance issues… The Hacker News · Aug 20, 2026 High CVE-2026-14456CHSIcdnddoshttp3
threat-intel Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Manic, a sophisticated Android malware, is actively targeting financial institutions and government services across Ukraine, Russia, Central and Western Europe, and the U.K. This malware combines banking malware capabili… The Hacker News · Aug 20, 2026 High UKRUCEandroidbanking malwarespyware