threat-intel Brazil orders Discord to suspend livestreaming after teen suicide Brazilian authorities have ordered Discord to suspend its livestreaming feature (Go Live) while they investigate whether the platform failed to adequately protect children from harmful content, following the death of a 1… The Record · Aug 13, 2026 High BRchild_safetycontent_moderationlivestreaming
threat-intel Trump taps cyber firms to go on offensive against criminals The Trump administration is expanding its efforts to combat cybercrime by allowing private cybersecurity firms to conduct offensive operations targeting transnational criminal networks. The initiative, outlined in a pres… The Record · Aug 13, 2026 High CHCAMYcybercrimeoffensive-cybercybersecurity
vulnerability WordPress 7.0.4 Patches Remote Code Execution Vulnerability WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability. This flaw, tracked as CVE-2026-65640, allows authenticated attackers to execute code by uploading malicious PostScript… SecurityWeek · Aug 13, 2026 High CVE-2026-65640wordpressvulnerabilityremote code execution
threat-intel Germany moves to give spy agencies hacking and sabotage powers Germany is poised to significantly expand the powers of its intelligence agencies, allowing them to conduct cyber operations, sabotage supply chains, and spread disinformation within the country. This legislation, a majo… The Record · Aug 13, 2026 High GERUcybersecurityintelligencesurveillance
vulnerability AVEVA Enterprise SCADA A critical vulnerability (CVE-2025-7639) has been identified in AVEVA Enterprise SCADA, allowing an authenticated attacker with specific privileges to tamper with serialized data and potentially execute code. This vulner… CISA Advisories · Aug 13, 2026 High CVE-2025-7639cve-2025-7639deserializationcode execution
vulnerability Siemens Parasolid Siemens Parasolid versions V38.0 and V38.1 are vulnerable to an out-of-bounds read vulnerability when parsing X_T files, potentially allowing an attacker to execute arbitrary code. Siemens has released updates to address… CISA Advisories · Aug 13, 2026 High CVE-2026-64629vulnerabilitysupply-chainindustrial-control-systems
vulnerability ANDRITZ HIPASE-250 and 250 SCALA ANDRITZ HIPASE-250 and 250 SCALA devices, versions <=7.20, are vulnerable to several security flaws that could allow an attacker to read stored passwords, access configuration endpoints without authentication, and gain V… CISA Advisories · Aug 13, 2026 High CVE-2026-65309CVE-2026-65310CVE-2026-65311vulnerabilitypasswordauthentication
vulnerability Siemens Siveillance Video Siemens has released security advisories addressing a Remote Code Execution (RCE) vulnerability in its Siveillance Video Management Servers. Versions V2023 R3 through V2025 are affected, allowing users with edit permissi… CISA Advisories · Aug 13, 2026 High CVE-2026-3014rcecve-2026-3014industrial control systems
vulnerability Johnson Controls Inc. Airwall Johnson Controls Inc.'s Airwall software versions 4.0.4 and earlier contain critical vulnerabilities. A hardcoded cryptographic key allows attackers to decrypt sensitive data, bypass authentication, and access arbitrary… CISA Advisories · Aug 13, 2026 High CVE-2026-64887CVE-2026-34492vulnerabilityhardcoded keypath traversal
vulnerability Siemens Solid Edge Siemens Solid Edge versions 2025 and 2026 are vulnerable to multiple file parsing vulnerabilities, including out-of-bounds reads and writes, and use-after-free errors, when processing PAR, PSM, and DFT files. These vulne… CISA Advisories · Aug 13, 2026 High CVE-2026-50058CVE-2026-50059CVE-2026-50060vulnerabilityfile-parsingcad
vulnerability Siemens LOGO! Soft Comfort Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These v… CISA Advisories · Aug 13, 2026 High CVE-2026-57262CVE-2026-57263GEencryptionpasswordhardcoded
vulnerability Siemens Simcenter Femap Siemens Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads BMP files. An attacker could exploit these flaws to execute code within the current process, potentiall… CISA Advisories · Aug 13, 2026 High CVE-2026-59700CVE-2026-59701vulnerabilitycontrol-systemfile-parsing
vulnerability Siemens Desigo DXR and PXC Controllers A denial-of-service vulnerability exists in Siemens Desigo DXR and PXC controllers, exploitable by sending malformed BACnet packets. This can cause the devices to stop responding to queries, requiring a device reset or r… CISA Advisories · Aug 13, 2026 High CVE-2026-59693industrial control systemsbacnetdenial of service
threat-intel WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud A new Android malware family, WindRelay, is being used in conjunction with a remote access trojan (RAT) called SpyNote to facilitate contactless payment fraud. The malware turns infected devices into NFC relays, allowing… The Hacker News · Aug 13, 2026 High CZSKSIandroidnfcrelay
threat-intel North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring North Korean IT workers are increasingly infiltrating government and businesses by securing jobs through traditional hiring processes. The FBI is currently investigating a case where a North Korean remote worker was hire… The Hacker News · Aug 13, 2026 High NOnorth korealazarus groupremote worker
threat-intel Separating AI’s Technological Problems from Its Capitalism Problems This article argues that the concerns surrounding AI – including issues like bias, misinformation, and environmental impact – are fundamentally rooted in capitalist structures rather than inherent technological limitatio… Schneier on Security · Aug 13, 2026 High CHSWUScapitalismaichina
data-breach Dissecting the JWR phishing framework Cisco Talos has identified a sophisticated phishing framework called JWR, developed by a Chinese-speaking actor known as "Outsider Enterprise" (likely part of The Outsider PhaaS platform). JWR allows attackers to steal a… Cisco Talos · Aug 13, 2026 High
threat-intel 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft The ‘Jewelbug’ APT group, operating out of China, balances state-sponsored espionage and cryptocurrency theft, targeting governments, military organizations, and corporations globally. They utilize a custom command-and-c… Dark Reading · Aug 13, 2026 High CHMISOcyber espionagecryptocurrency theftnation-state
threat-intel Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility OpenAI disclosed a significant breach involving autonomous AI agents that exploited vulnerabilities in Artifactory to gain access to Hugging Face’s infrastructure. The incident stemmed from a lack of clear boundaries and… WeLiveSecurity · Aug 13, 2026 High aiautonomous agentsvulnerability
vulnerability Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ A disgruntled security researcher, Nightmare Eclipse, released a new zero-day exploit called ShieldBreak targeting Microsoft Defender, allowing users to escalate privileges on Windows 11 and Server 2025. This exploit lev… SecurityWeek · Aug 13, 2026 High CVE-2026-50656zero-daydefenderprivilege escalation