threat-intel Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation The Linux Foundation will manage TRACE, a new open standard for verifying the behavior of AI agents and confidential workloads. Developed collaboratively by AMD, Intel, Microsoft, and the Technology Innovation Institute,… SecurityWeek · 5d ago Medium aiconfidential computingtrust
vulnerability You could've applied all 1,449 Oracle patches and still been hit by this attack A zero-day vulnerability in on-prem SharePoint, stemming from improperly applied patches, is being exploited by attackers. Despite applying 1,449 Oracle patches, attackers successfully leveraged this flaw to gain unautho… The Register · 5d ago High UNzero-dayvulnerabilitysharepoint
vulnerability A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw A vulnerability in NVIDIA NemoClaw allows an attacker to poison an AI model by serving a malicious webpage that can inject hidden instructions into every conversation. The vulnerability stems from a misconfigured Ollama… The Hacker News · 5d ago High CVE-2024-28224aimodel poisoningdns rebinding
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
threat-intel WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android WhatsApp is bolstering its security by introducing passkeys and enhanced two-step verification to combat phishing attacks and improve account protection for users on both iOS and Android. This move aims to make it signif… The Hacker News · 5d ago Medium passkeysphishingsecurity
threat-intel WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update WhatsApp has significantly boosted its account security by introducing multi-passkey support, upgrading two-step verification to stronger passwords, and providing caller information to combat scams. These changes aim to… SecurityWeek · 5d ago Medium passkeystwo-factorsecurity
vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and req… The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
threat-intel Black Hat State of Security Vendors Black Hat 2023 showcased a significant shift in the security vendor landscape, driven by the increasing influence of AI. Vendors are now heavily emphasizing AI-powered solutions, though a notable number continue to focus… Schneier on Security · 5d ago Medium aisecurityvendors
vulnerability Multiples vulnérabilités dans Keycloak (25 août 2026) Multiple vulnerabilities have been discovered in Keycloak, allowing an attacker to bypass security policies and potentially take control of an account if they know its identifier. The CERT-FR has a proof of concept for C… CERT-FR · 5d ago Medium CVE-2026-18963CVE-2026-14613CVE-2026-15571keycloakvulnerabilityauthentication
vulnerability Multiples vulnérabilités dans Cisco IOS XE (25 août 2026) Cisco has announced multiple vulnerabilities in its IOS XE software, allowing attackers to bypass security policies and potentially cause unspecified security issues. These vulnerabilities affect several versions of the… CERT-FR · 5d ago High CVE-2026-20267CVE-2026-20268CVE-2026-20269ciscoios xevulnerability
vulnerability Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited by attackers to compromise websites running on vulnerable CMS platforms. This allows attackers to gain unauthorized access… The Register · 6d ago Medium joomlaextensionvulnerability
threat-intel New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets A new phishing toolkit, iAuthFlow V2, is leveraging passkeys to maintain access to accounts even after a password reset, highlighting a significant escalation in phishing tactics. The tool, sold for $10,000, utilizes a s… SecurityWeek · Aug 21, 2026 High phishingpasskeysocial engineering
threat-intel Calling on Cyber Pros to Help Defend City Hall A local housing authority suffered a significant financial loss – nearly a million dollars – due to attackers targeting staff email accounts to intercept wire transfers intended for an affordable housing project. The age… Dark Reading · Aug 21, 2026 High local governmentsecurityrisk management
threat-intel Wazuh and AI For Enhanced SOC Workflows Wazuh is integrating artificial intelligence to enhance SOC workflows, primarily through its Wazuh AI Analyst. This tool utilizes Amazon Bedrock and Anthropic’s Claude to provide automated security reports and guidance t… The Hacker News · Aug 21, 2026 Medium aisecuritysoc
vulnerability Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 Cisco has released security updates to address nine vulnerabilities affecting its Crosswork and Secure Workload platforms. These flaws, discovered during internal testing, range in severity from critical to medium and co… The Hacker News · Aug 21, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358securitypatchvulnerability
threat-intel Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st) This script identifies users within an organization who have not yet been enrolled in multi-factor authentication (MFA) using the Microsoft Graph API. It leverages a beta command to efficiently list un-registered users,… SANS Internet Storm Center · Aug 21, 2026 Info mfamicrosoftgraph
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities allow for arbitrary code execution, privilege escalation, and denial-of-service attacks. The affected products include variou… CERT-FR · Aug 21, 2026 High CVE-2024-56602CVE-2025-39902CVE-2025-54518linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans Traefik (21 août 2026) Multiple vulnerabilities have been discovered in Traefik, allowing attackers to bypass security policies. These vulnerabilities affect older versions of the popular reverse proxy and load balancer, requiring immediate pa… CERT-FR · Aug 21, 2026 Medium vulnerabilitysecuritytraefik
vulnerability Multiples vulnérabilités dans les produits Microsoft (21 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to bypass security policies and cause denial-of-service conditions. Microsoft has released security bulletins detailing the issues a… CERT-FR · Aug 21, 2026 Medium CVE-2026-55013CVE-2026-55015microsoftvulnerabilitysecurity
threat-intel Multiples vulnérabilités dans le noyau Linux de Debian LTS (21 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian LTS. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. The affected systems include Debian 12 Bookwo… CERT-FR · Aug 21, 2026 High CVE-2025-40098CVE-2026-45897CVE-2026-45901vulnerabilitylinuxkernel