threat-intel New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA Recent research has revealed significant vulnerabilities in passkey authentication systems, demonstrating ways to bypass security measures and impersonate users. SpecterOps found that Windows stored past YubiKey signatur… The Hacker News · Aug 10, 2026 High CVE-2026-34348passkeyauthenticationvulnerability
threat-intel Cyber vulnerability sweep picks up Royal Navy drones sending data to China A vulnerability in Royal Navy drones is allowing Chinese entities to access sensitive data. The flaw stems from a misconfigured system that transmits data to servers in China, raising significant national security concer… The Register · Aug 10, 2026 High UKCHvulnerabilitynational securitydata transmission
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
threat-intel Claude Code puts auto mode in the driver's seat Several security incidents and developments are highlighted, including a vulnerability in Joomla extensions, a Microsoft SharePoint issue leading to a zero-day attack, and ongoing efforts to combat Iranian propaganda and… The Register · Aug 10, 2026 Medium IRUSvulnerabilityphishingransomware
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
vulnerability Critical Flaws Discovered in Belgian eID Software Used by 2 Million People A critical vulnerability in Nitro Software Belgium’s Connective digital identity system, used by over two million people in Belgium, allowed attackers to steal sensitive data and forge electronic signatures. The flaw was… SecurityWeek · Aug 10, 2026 High BEdigital identityeidbrowser extension
vulnerability ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code remotely. This exploit could lead to widespread data breaches and… SANS Internet Storm Center · Aug 10, 2026 Critical log4jrcevulnerability
vulnerability Multiples vulnérabilités dans HPE Aruba Networking Private 5G Core (10 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking Private 5G Core, allowing attackers to elevate privileges and bypass security policies. These vulnerabilities are present in older versions of the sof… CERT-FR · Aug 10, 2026 Medium CVE-2026-33377CVE-2026-54763vulnerabilitysecurityaruba
vulnerability Multiples vulnérabilités dans VMware Tanzu Greenplum (10 août 2026) Multiple vulnerabilities have been discovered in VMware Tanzu Greenplum. These vulnerabilities allow an attacker to cause a security issue, though the specific nature of the issue is not detailed. Users are advised to co… CERT-FR · Aug 10, 2026 Medium CVE-2018-11798CVE-2019-0205CVE-2020-13949vulnerabilitycvepatch
vulnerability Multiples vulnérabilités dans Roundcube (10 août 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, allowing attackers to execute arbitrary code remotely, compromise data confidentiality, and forge server-side requests. These flaws exist in versions 1.… CERT-FR · Aug 10, 2026 High vulnerabilitywebmailsecurity
vulnerability Vulnérabilité dans Synology Assistant (10 août 2026) A vulnerability has been identified in Synology Assistant, allowing an attacker to compromise data confidentiality, data integrity, and cause a denial of service. Users of versions prior to 7.0.7-50095 are strongly advis… CERT-FR · Aug 10, 2026 Medium CVE-2026-4793synologyvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans ClamAV (10 août 2026) Multiple vulnerabilities have been discovered in ClamAV, potentially allowing attackers to compromise data confidentiality, cause denial of service, and introduce an unspecified security issue. These vulnerabilities affe… CERT-FR · Aug 10, 2026 Medium CVE-2025-8088CVE-2026-20337CVE-2026-20338vulnerabilityantivirusclamav
vulnerability Vulnérabilité dans SonicWall Global VPN Client (10 août 2026) A vulnerability in SonicWall Global VPN Client allows an attacker to cause a denial-of-service. SonicWall has released a security bulletin and a corresponding CVE to address this issue. CERT-FR · Aug 10, 2026 Medium CVE-2026-66151vpnvulnerabilitydenial-of-service
threat-intel Ransomware gangs skip the CEO, head straight for the 40-something IT manager Ransomware gangs are increasingly targeting IT managers, specifically those in their 40s, bypassing traditional executive channels to gain access to sensitive data and systems. This shift suggests a change in tactics by… The Register · Aug 9, 2026 Medium ransomwarecybersecuritylinux
threat-intel Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Several security-related stories are emerging, including a focus on AI security and vulnerabilities, a Russian phishing campaign mimicking Signal support, and ongoing efforts to improve security across various Linux and… The Register · Aug 8, 2026 Medium RUIRaisecurityphishing
vulnerability Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data A critical one-click vulnerability, dubbed RovoBlast, has been discovered in Atlassian’s Rovo AI assistant, allowing attackers to inject malicious prompts and exfiltrate sensitive data from various Atlassian products and… SecurityWeek · Aug 8, 2026 Critical aiprompt injectiondata exfiltration
vulnerability Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers Atlassian’s Rovo assistant has two vulnerabilities that could allow attackers to exfiltrate data. The first, a one-click link flaw, has been patched by Atlassian. The second, a content-borne prompt injection attack, allo… The Hacker News · Aug 8, 2026 High prompt-injectiondata-exfiltrationatlassian
vulnerability Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A zero-day vulnerability in Metabase has been exploited in the wild, allowing unauthenticated attackers to gain administrator access to the application and steal data. The vulnerability affects versions 1.58 and above, a… The Hacker News · Aug 8, 2026 Critical CVE-2023-38646zero-daysql injectiondata breach
vulnerability N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for… The Hacker News · Aug 8, 2026 Critical CVE-2026-18577CVE-2026-18556zero-dayremote accesscloudflare
vulnerability Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts A critical command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's KEV catalog, following reports of widespread exploitation attempts. The vulnerability allows unauthenticated attackers to ex… The Hacker News · Aug 8, 2026 Critical CVE-2026-8037AUCHINcommand injectionload balancerpatching