vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Several of these vulnerabilities can lead to data confidentiality and integrity breaches, as well as the circumvention of security policies and deni… CERT-FR · Jul 31, 2026 High CVE-2023-20585CVE-2025-10263CVE-2025-39894kernelpatchsecurity
vulnerability Multiples vulnérabilités dans PHP (31 juillet 2026) Multiple vulnerabilities have been discovered in PHP versions 8.2, 8.3, 8.4, and 8.5, including SQL injection and denial of service attacks. Users are strongly advised to apply the security updates released by PHP’s publ… CERT-FR · Jul 31, 2026 Medium CVE-2026-17543CVE-2026-17544CVE-2026-7260phpvulnerabilitysql injection
threat-intel Multiples vulnérabilités dans les produits IBM (31 juillet 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service attacks. Several of these vulnerabilities are related to older versions of QRada… CERT-FR · Jul 31, 2026 High CVE-2018-10237CVE-2018-16487CVE-2020-13955vulnerabilitysecuritypatch
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026) Multiple vulnerabilities have been discovered within the Linux kernel of Debian LTS. These vulnerabilities include potential for data confidentiality breaches, denial of service attacks, and privilege escalation. Several… CERT-FR · Jul 31, 2026 High CVE-2025-23131CVE-2026-23272CVE-2026-23278vulnerabilitylinuxdebian
threat-intel AI Harnesses Burst With Potential Exploit Opps Researchers at Novee Security discovered significant security vulnerabilities in AI agent harnesses used by major vendors like Anthropic, Google, and OpenAI. These vulnerabilities stem from the complex, interconnected na… Dark Reading · Jul 30, 2026 High aisecurityvulnerability
threat-intel Claude Mythos — Hype vs. Reality: What Security Teams Need to Know The Anthropic Claude Mythos AI model has sparked significant debate and concern within the cybersecurity community. Initially touted for its ability to autonomously discover and exploit critical vulnerabilities in decade… Dark Reading · Jul 30, 2026 High CHUNaivulnerabilitycybersecurity
threat-intel Jailed Flock vandal wipes out three cameras, racks up thousands in damages This article is a collection of miscellaneous tech news items, including a report on corporate IT workloads moving off-site, a lament for Intel's Optane storage technology, a security alert about Joomla extensions being… The Register · Jul 30, 2026 Medium securitycybersecurityvulnerability
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
vulnerability Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database A vulnerability in Azure Cosmos DB, dubbed CosmosEscape by Wiz, allowed an attacker to bypass the service's query sandbox and gain platform-wide access to customer databases. The exploit chain began with a crafted Gremli… The Hacker News · Jul 30, 2026 High azurecosmos dbsecurity
threat-intel Cantina Emerges From Stealth With $8 Million in Funding Cantina, a cybersecurity startup, secured $8 million in funding to bolster its agentic vulnerability management platform. The platform utilizes AI to automate vulnerability identification, prioritization, and remediation… SecurityWeek · Jul 30, 2026 Medium vulnerabilityaiautomation
threat-intel ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale A research firm, Silent Push, demonstrated how artificial intelligence can significantly amplify the effectiveness of ‘dangling DNS takeover’ attacks, a vulnerability where a forgotten DNS record points to a deleted clou… SecurityWeek · Jul 30, 2026 High dangling dnsdns takeovercloud security
threat-intel Mitsubishi Electric CC-Link IE TSN Communication Protocol A critical vulnerability (CVE-2026-13584) exists in the CC-Link IE TSN communication protocol used by Mitsubishi Electric industrial controllers. Attackers with network access can manipulate communication data by sending… CISA Advisories · Jul 30, 2026 Critical CVE-2026-13584cc-linkindustrial control systemsvulnerability
threat-intel Open Source Software: Security Principles and Practices The CISA released guidance on securing open source software (OSS) usage across various systems, including critical infrastructure. This guidance focuses on a comprehensive approach to OSS risk management, covering everyt… CISA Advisories · Jul 30, 2026 Info open sourceossvulnerability
vulnerability Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module A vulnerability exists in Rockwell Automation's CompactLogix, ControlLogix, and GuardLogix communication modules (specifically the 1756-EN4TR module) due to improper certificate revocation handling. An attacker could exp… CISA Advisories · Jul 30, 2026 High CVE-2026-9636certificate revocationcip securityindustrial control systems
vulnerability Toptech Systems RCU II+ and Multiload II+ Toptech Systems has issued a vulnerability notice regarding RCU II+ and Multiload II+ devices, exposing a critical unauthenticated service that allows for full system control. Exploitation is not currently possible remot… CISA Advisories · Jul 30, 2026 High CVE-2026-12562vulnerabilitycontrol systemsauthentication
vulnerability Schneider Electric IGSS Schneider Electric has identified and issued a security advisory (SEVD-2026-195-01) regarding a critical out-of-bounds write vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) p… CISA Advisories · Jul 30, 2026 High CVE-2026-12927scadaindustrial control systemscwe-787
vulnerability MZ Automation GmbH libiec61850 CISA has issued an advisory regarding multiple vulnerabilities in MZ Automation GmbH’s libiec61850 software, specifically version <1.6.2. These vulnerabilities, all related to out-of-bounds reads, can lead to denial-of-s… CISA Advisories · Jul 30, 2026 High CVE-2026-66720CVE-2026-66369CVE-2026-63550vulnerabilityout-of-bounds readdenial-of-service
vulnerability MikroTik RouterOS A critical vulnerability (CVE-2026-14227) exists in MikroTik RouterOS, allowing an attacker with low-privilege API access to extract the router's WireGuard private key and decrypt VPN traffic. This could enable full VPN… CISA Advisories · Jul 30, 2026 Critical CVE-2026-14227LVvulnerabilitywireguardcve-2026-14227
threat-intel o6 Automation open62541 Multiple vulnerabilities have been identified in o6 Automation open62541, a control system software, potentially allowing for denial of service, arbitrary code execution, and information disclosure. These vulnerabilities… CISA Advisories · Jul 30, 2026 Critical CVE-2026-63362CVE-2026-65423CVE-2026-63035vulnerabilitycontrol-systemcisa
vulnerability Johnson Controls OpenBlue Employee Johnson Controls has released a security advisory (JCI-PSA-2026-09) addressing critical vulnerabilities in its OpenBlue Employee system. These vulnerabilities – including stored XSS, HTML injection, and file upload flaws… CISA Advisories · Jul 30, 2026 High CVE-2026-21662CVE-2026-34495CVE-2026-34497vulnerabilityxsshtml injection