threat-intel GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption GitHub has implemented a three-day cooldown period for Dependabot to mitigate the risk of malicious packages being rapidly adopted by downstream projects. This new feature aims to slow down the spread of poisoned package… The Hacker News · Jul 27, 2026 Medium supply-chainpackage-managementdependency-updates
vulnerability Vulnérabilité dans Traefik (27 juillet 2026) A security vulnerability has been identified in Traefik, allowing attackers to bypass security policies. This affects older versions of the popular reverse proxy and load balancer, requiring immediate patching to prevent… CERT-FR · Jul 27, 2026 Medium traefikvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities are detailed in a series of security… CERT-FR · Jul 27, 2026 Medium CVE-2026-57978CVE-2026-57989CVE-2026-57990vulnerabilitymicrosoftedge
vulnerability Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th) A scan targeting ESAFENET CDG, a Chinese-focused document management system, revealed weak default passwords and vulnerabilities, including SQL injection and XSS. Threat actors are leveraging existing exploit scripts to… SANS Internet Storm Center · Jul 26, 2026 Medium CNdefault passwordsql injectionxss
threat-intel CISOs vs. Boards: Myth or Misunderstanding? The article explores the persistent disconnect between CISOs and boards regarding cybersecurity, despite increasing cyber threats. While boards are increasingly recognizing the importance of security, a lack of understan… Dark Reading · Jul 24, 2026 Medium cybersecurityboard communicationrisk management
threat-intel Friday Squid Blogging: Illex Squid Catch in the Falklands This article discusses a recent operation by the Illex squid fishing company in the Falkland Islands, where they used a sophisticated network of underwater drones to illegally catch squid. The operation highlights a conc… Schneier on Security · Jul 24, 2026 Medium FKfishingautomationillegality
threat-intel Europol flags 4,340 'horrific' URLs linked to The Com This article is a collection of security-related news snippets from The Register. It highlights a phishing campaign targeting Signal users by Russian actors, a zero-day vulnerability in on-prem SharePoint, and a signific… The Register · Jul 24, 2026 Medium RUCHphishingvulnerabilitycybersecurity
threat-intel Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry Following a government reshuffle, UK cybersecurity minister Liz Lloyd has been reappointed to her role, maintaining continuity on the Cyber Security and Resilience Bill. The government has reorganized departments, splitt… The Record · Jul 24, 2026 Medium UKcybersecurityukcyber policy
threat-intel Quatre rendez-vous cyber à suivre jusqu’en octobre This article details upcoming cybersecurity events across France and Quebec, focusing on a blend of technical learning, community engagement, and offensive security practices. The events – Barbhack in Toulon, Cyberbrew i… ZATAZ · Jul 24, 2026 Medium FRCAcybersecurityoffensive securitysocial engineering
threat-intel Un faux portail FPR pour piéger des pirates A hacker created a convincing fake police portal to trick other hackers into revealing their identities and providing information. The portal mimicked a French police database, complete with authentication and search fun… ZATAZ · Jul 24, 2026 Medium FRsocial engineeringfake portalpolice database
threat-intel Uncle Sam tells overseas cybercrooks their visas are canceled This article covers a range of cybersecurity and technology news, including a US government action targeting Iranian propaganda sites, a security acquisition by EQT, and vulnerabilities impacting Joomla extensions. It al… The Register · Jul 24, 2026 Medium IRSWcybersecuritythreat intelligencevulnerability
threat-intel AegisAI Raises $36 Million for AI-Powered Email Security AegisAI, a startup specializing in AI-powered email security, has raised $36 million in Series A funding to bolster its autonomous detection agents and expand its market reach. The company’s platform utilizes AI to analy… SecurityWeek · Jul 24, 2026 Medium aiphishingemail_security
threat-intel ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of Log4j exploitation attempts. The threat landscape remains volatile, with attack… SANS Internet Storm Center · Jul 24, 2026 Medium phishinglog4jbec
vulnerability Multiples vulnérabilités dans les produits ESET (24 juillet 2026) Multiple vulnerabilities have been discovered in ESET’s security products, primarily for macOS, allowing attackers to potentially elevate their privileges. These vulnerabilities require immediate patching to prevent expl… CERT-FR · Jul 24, 2026 Medium CVE-2026-10610CVE-2026-7483macosvulnerabilitypatch
vulnerability Multiples vulnérabilités dans Google Chrome (24 juillet 2026) Google Chrome has been found to have multiple vulnerabilities, requiring users to update to a secure version to prevent potential security issues. The CERT-FR report details several CVEs associated with these flaws, urgi… CERT-FR · Jul 24, 2026 Medium CVE-2026-16804CVE-2026-16805CVE-2026-16806chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Edge (24 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, impacting versions prior to 150.0.4078.96. The exact nature of the vulnerabilities and the resulting security issue are not specified by the publisher. Use… CERT-FR · Jul 24, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415vulnerabilitypatchsecurity
threat-intel OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be This article covers a range of cybersecurity and technology news, including a competitive landscape in AI hardware between AMD and Nvidia, a security incident involving Joomla extensions, and a general overview of variou… The Register · Jul 23, 2026 Medium IRSWcybersecurityj2eex11
threat-intel Researchers replace downloaded macOS apps with evil twins, Apple shrugs Researchers have discovered a method to replace downloaded macOS applications with malicious 'evil twin' versions, while Apple has not responded to the issue. This highlights a significant vulnerability in how users obta… The Register · Jul 23, 2026 Medium IRUSmacosmalwarephishing
vulnerability Millions of California-bought cars can be hijacked via Bluetooth A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited to compromise websites running the CMS. Attackers are leveraging these flaws to gain unauthorized access to vulnerable sit… The Register · Jul 23, 2026 Medium joomlavulnerabilityextension
threat-intel Oracle drops 1,449 security patches like it's the new normal This article is a collection of security-related news snippets from The Register. It covers a range of topics including security patches from Oracle, advancements in AI hardware (AMD vs Nvidia), phishing attacks targetin… The Register · Jul 23, 2026 Medium CVE-2026-47056CVE-2026-60217CVE-2026-61211securityvulnerabilitiesphishing