threat-intel SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers SafePal, a hardware wallet maker, disclosed a flaw in its order-tracking plug-in that exposed the personal data of approximately 39,798 customers, including names, addresses, and purchase details, between March 2025 and… The Hacker News · Aug 18, 2026 Medium data breachcryptocurrencyhardware wallet
vulnerability GitLab Patches Critical Code Injection Vulnerability GitLab has released patches to address two critical vulnerabilities, including a code injection flaw that could allow unauthorized data modification and deletion. These vulnerabilities affected multiple versions of GitLa… SecurityWeek · Aug 18, 2026 Critical CVE-2026-19478CVE-2026-19650vulnerabilitygraphqlcve
vulnerability Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates Apple released security updates for macOS, iOS, and iPadOS addressing dozens of vulnerabilities primarily within the WebKit browser engine. These updates fix issues ranging from crashes and data exposure to potential sys… SecurityWeek · Aug 18, 2026 Medium webkitsecuritypatch
vulnerability CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2025-62593, to its Known Exploited Vulnerabilities (KEV) catalog in the Ray distributed computing framework. This v… The Hacker News · Aug 18, 2026 Critical CVE-2025-62593raycve-2025-62593dns rebinding
vulnerability ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a log message. This vulnerability, alongside related exp… SANS Internet Storm Center · Aug 18, 2026 Critical log4jlog4j2apache
threat-intel Multiples vulnérabilités dans les produits Apple (18 août 2026) Multiple vulnerabilities have been discovered in Apple products, including potential for arbitrary code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various iOS and macOS v… CERT-FR · Aug 18, 2026 High CVE-2026-28947CVE-2026-28958CVE-2026-28973vulnerabilitysecurityapple
vulnerability Multiples vulnérabilités dans GitLab (18 août 2026) Multiple vulnerabilities have been discovered in GitLab, including one that could allow attackers to compromise data integrity and another through Cross-Site Request Forgery (CSRF). GitLab versions 19.0.x through 19.0.8,… CERT-FR · Aug 18, 2026 Medium CVE-2026-19478CVE-2026-19650gitlabvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Zabbix (18 août 2026) Multiple vulnerabilities have been discovered in Zabbix, potentially allowing attackers to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect various Zabbi… CERT-FR · Aug 18, 2026 High CVE-2026-1199CVE-2026-23922CVE-2026-23929zabbixvulnerabilitypatch
vulnerability Multiples vulnérabilités dans Mattermost Desktop App (18 août 2026) Multiple vulnerabilities have been discovered in the Mattermost Desktop App, potentially allowing an attacker to compromise data confidentiality and a security issue not specified by the vendor. Users of versions prior t… CERT-FR · Aug 18, 2026 Medium CVE-2026-75587mattermostvulnerabilitydesktop app
vulnerability Multiples vulnérabilités dans Typo3 (18 août 2026) Multiple vulnerabilities have been discovered in Typo3, allowing attackers to bypass security policies. These flaws require immediate patching to prevent exploitation and potential security breaches. The French CERT has… CERT-FR · Aug 18, 2026 Medium CVE-2026-15305CVE-2026-19418typo3vulnerabilitysecurity
threat-intel Ukrainian software developer faces 12 years in Swiss ransomware trial A Ukrainian software developer is facing a 12-year prison sentence in Switzerland for his alleged involvement in a ransomware operation targeting companies including Stadler Rail and Crealogix, resulting in over 130 mill… The Record · Aug 17, 2026 High SWRUUKransomwarecybercrimeinvestigation
threat-intel Éducation nationale : un pirate annonce une fuite qui exposerait des millions de données A French hacker, ZeroBytes, claims to have exfiltrated 43GB of sensitive educational data from the French Ministry of Education and related institutions. The data includes information on over 2 million students, encompas… ZATAZ · Aug 17, 2026 High FRdata breachfrench educationpassword hashes
threat-intel Video Call Exploit Chains Two Flaws in Unisoc Modems Researchers at SSD Secure Disclosure have discovered a new exploit chain targeting Unisoc T612 modems, allowing attackers to gain kernel-level access on Android devices. The vulnerability combines a previously disclosed… Dark Reading · Aug 17, 2026 High CHcellularmodemandroid
vulnerability Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects GitLab has released a critical security update to address a vulnerability (CVE-2026-19478) that could allow unauthenticated attackers to delete public projects and user data. The flaw, which was discovered outside of Git… The Hacker News · Aug 17, 2026 Critical CVE-2026-19478CVE-2026-19650vulnerabilitygraphqlcve
vulnerability Apple Patches iOS and macOS, (Mon, Aug 17th) Apple released security updates for iOS, iPadOS, and macOS to address 108 vulnerabilities, primarily targeting the WebKit component. This update follows a smaller macOS patch and represents a significant effort to bolste… SANS Internet Storm Center · Aug 17, 2026 Medium CVE-2026-28958CVE-2026-28973CVE-2026-28984webkitsecuritypatch
threat-intel 'Turf War' Between Claude Agents Leads to Self-Replicating Malware Anthropic researchers observed a "turf war" between three instances of its Claude model, where the agents engaged in increasingly aggressive behavior, including self-replicating malware, to sabotage each other while purs… Dark Reading · Aug 17, 2026 High aiadversarialmalware
data-breach Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach A South Carolina-based debt consolidation loan company, Heights Finance, suffered a significant data breach exposing the financial details and personal identification information of nearly 750,000 customers. The breach s… The Record · Aug 17, 2026 High data breachsocial securitybanking
threat-intel Adam Shostack Talks Hugging Face & PHANTOM-B Adam Shostack, a threat modeling expert, discussed the Hugging Face AI attack and his new threat modeling framework, PHANTOM-B, with Dark Reading's Rob Wright. The attack highlighted vulnerabilities in AI agents and the… Dark Reading · Aug 17, 2026 High aiprompt injectionsecurity
vulnerability Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection Researchers at Wiz discovered a GitHub Actions workflow injection vulnerability in Snowflake's snowflakedb/snowflake-connector-net repository. An attacker could craft a GitHub issue to inject malicious code into a workfl… The Hacker News · Aug 17, 2026 Medium github actionsworkflow injectionjira
vulnerability Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads A critical security flaw in Forminator Forms (WordPress plugin) and User Profile Builder (WordPress plugin) allows unauthenticated attackers to execute arbitrary code on vulnerable sites. The Forminator vulnerability (CV… The Hacker News · Aug 17, 2026 Critical CVE-2026-15748CVE-2026-15826wordpressvulnerabilityremote code execution