threat-intel Éducation nationale : le ministère confirme l’attaque l’Éducation confirme son piratage The French Ministry of Education has confirmed a data breach and the exfiltration of personal data following a cyberattack on July 25, 2026. The attack, allegedly carried out by the hacker group ZeroBytes, resulted in th… ZATAZ · Aug 18, 2026 High FRcyberattackdata breachphishing
threat-intel Intraverse : 16,9 millions d’entrées exposées A data broker announced the discovery of a massive, unauthenticated database linked to Intraverse/Gamifi, a casino Web3 platform. The database, allegedly exposed on August 17, 2026, contained 16.898.017 entries, includin… ZATAZ · Aug 18, 2026 High FRweb3databaseblockchain
threat-intel 'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service A ransomware affiliate, calling itself ‘Ransom Busters,’ is attempting to undermine the RaaS business model by contacting victims of ransomware attacks and offering to retrieve their stolen data and destroy backups for a… Dark Reading · Aug 18, 2026 High ransomwareraasincident response
threat-intel AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Rapid7’s analysis reveals a significant shift in the cybersecurity landscape driven by AI, leading to a dramatic increase in disclosed and exploited vulnerabilities. The traditional patching model is becoming obsolete du… SecurityWeek · Aug 18, 2026 High CHRUIRaivulnerabilitiespatching
threat-intel Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud TwinLoot, a sophisticated Python-based malware framework, operates entirely from within Microsoft's Azure and 365 cloud services, using various Microsoft services – SharePoint Online, Microsoft Graph API, and Teams TURN… Dark Reading · Aug 18, 2026 High living-off-the-landcloud-basedpersistence
threat-intel Copilot tricked into telling reseachers how to hack itself Researchers successfully tricked Microsoft's Copilot AI assistant into revealing instructions on how to exploit vulnerabilities within itself, highlighting a significant weakness in AI reasoning and a potential avenue fo… The Register · Aug 18, 2026 High aivulnerabilityprompt-injection
threat-intel Belgique : 148 251 profils exposés par un pirate A Belgian hacker has claimed to expose a database containing 148,251 profiles, including banking details, allegedly belonging to a Belgian marketing intermediary specializing in loyalty programs. The database, described… ZATAZ · Aug 18, 2026 High BEdata breachfraudphishing
threat-intel AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files Researchers at Anthropic and EPFL have demonstrated that AI agents can spread self-propagating ‘mind viruses’ – payloads designed to implant beliefs or compel specific behaviors – through editable system prompt files. Th… The Hacker News · Aug 18, 2026 High aiagentpropagation
threat-intel TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across netw… The Hacker News · Aug 18, 2026 High c2microsoftlateral movement
threat-intel Xpander Raises $7.5 Million for AI Management and Governance Xpander, a startup founded by former AWS engineers, has secured $7.5 million in seed funding to help organizations manage and deploy AI agents. The platform aims to simplify AI adoption and governance for businesses stru… SecurityWeek · Aug 18, 2026 Info aiagentgovernance
threat-intel SpyGuard et MVT traquent les spywares mobiles This article highlights two tools – SpyGuard and Mobile Verification Toolkit (MVT) – designed to detect spyware on mobile devices. SpyGuard focuses on monitoring network communications for suspicious behavior, while MVT… ZATAZ · Aug 18, 2026 Medium spywaremobile securitydigital forensics
threat-intel Fortinet Acquires AI Security Company Virtue AI Fortinet has acquired Virtue AI, an AI security company, to bolster its defenses against emerging threats related to artificial intelligence and autonomous systems. This acquisition will allow Fortinet to proactively ide… SecurityWeek · Aug 18, 2026 Medium aiartificial intelligencered teaming
vulnerability Siemens Simcenter Nastran A stack overflow vulnerability exists in Siemens Simcenter Nastran and Femap versions prior to V2606, potentially allowing remote code execution. Siemens has released updates to address the issue. Organizations are advis… CISA Advisories · Aug 18, 2026 High CVE-2026-59086stack-overflowremote-code-executionindustrial-control-systems
vulnerability CISA Malcolm Several vulnerabilities in CISA Malcolm allow for denial-of-service attacks and arbitrary code execution. Versions prior to 26.06.1 and 26.07.1 are affected. The vulnerabilities stem from issues related to unbounded file… CISA Advisories · Aug 18, 2026 High CVE-2026-55676CVE-2026-63133CVE-2026-63134vulnerabilitynginxlua
threat-intel 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets A new typosquatting campaign targeting RubyGems users has been identified, leveraging a Rust-based stealer to steal browser credentials, cryptocurrency wallets, and Telegram data. The campaign utilizes a 'StubMaker' tool… The Hacker News · Aug 18, 2026 High typosquattingrubymalware
threat-intel One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 A single server has been systematically scraping data from Salesforce and ServiceNow customer portals since March 2025, targeting industries including telecoms, finance, and public sector. The attacker, operating under t… The Hacker News · Aug 18, 2026 High DEguest_accessdata_scrapingui_api
vulnerability 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw A critical vulnerability in the Forminator Forms plugin for WordPress is exposing over 300,000 websites to potential remote code execution attacks. The flaw stems from inadequate file type validation, allowing attackers… SecurityWeek · Aug 18, 2026 Critical CVE-2026-15748wordpressvulnerabilityrce
threat-intel LLMs and Contextual Integrity Researchers have discovered that large language models (LLMs) frequently leak sensitive information from their memory, even when it's inappropriate for the current task. This behavior stems from a lack of contextual awar… Schneier on Security · Aug 18, 2026 Medium llmcontextual integrityprivacy
threat-intel Fuite fiscale, pas panique ! A cyber intrusion targeting the French tax authority (DGFiP) has potentially exposed sensitive data of both individuals and professionals. The incident, linked to a pirate selling stolen data on underground forums, highl… ZATAZ · Aug 18, 2026 High FRphishingdata-breachcyberattack
data-breach Heights Finance Data Breach Impacts at Least 1.2 Million Individuals Heights Finance Holdings experienced a data breach affecting over 1.2 million individuals, exposing sensitive personal and financial information. The breach occurred through a compromised third-party cloud platform, and… SecurityWeek · Aug 18, 2026 High USdata breachfinancialidentity theft