threat-intel The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists The article highlights a significant gap between the speed at which attackers discover and exploit vulnerabilities and the speed at which defenders can patch them. Traditional CVSS-based prioritization is inadequate beca… Dark Reading · Aug 10, 2026 High CVE-2024-9474CVE-2024-0012vulnerabilityattack-pathchoke-point
threat-intel Coruna, DarkSword iOS Exploits Proliferate Globally Sophisticated iPhone exploit chains, DarkSword and Coruna, are rapidly spreading beyond nation-state actors and into the hands of organized cybercrime groups. These advanced tools, initially developed for surveillance an… Dark Reading · Aug 10, 2026 High CVE-2025-31277CVE-2025-43529CVE-2026-20700CHMASAexploitioscybercrime
threat-intel China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw China-linked threat actor Storm-1175 has deployed a new ransomware strain, StormEncryptor, leveraging a vulnerability in N-able N‑central to gain initial access and subsequently deploy ransomware. This follows a pattern… The Hacker News · Aug 10, 2026 High CVE-2026-18577CVE-2026-18556CVE-2023-37679CHransomwarevulnerabilitypatch-bypass
threat-intel Poland uncovers second heat plant cyberattack that went hidden for months Poland’s CERT Polska uncovered a cyberattack targeting a combined heat and power plant that went undetected for months, highlighting a previously unknown attack vector involving private cellular networks. The attack, occ… The Record · Aug 10, 2026 High PORUcyberattackindustrial control systemsprivate cellular network
threat-intel Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity Senate Democrats are proposing a $300 million annual investment to bolster cybersecurity for U.S. water and wastewater systems, following a series of attacks targeting over 30 systems in approximately 12 states. The legi… The Record · Aug 10, 2026 High IRcybersecurityinfrastructurewater systems
threat-intel Russian military hackers pose as recruiters to target Ukrainian IT workers Russian military hackers, linked to the Sandworm group (APT44/Seashell Blizzard), are impersonating IT recruiters to target Ukrainian IT workers and install malicious software. The operation involves using legitimate job… The Record · Aug 10, 2026 High UKRUrecruitmentvpnwireguard
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
threat-intel OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns OpenAI is suspending development of its upcoming AI model, Astra, due to concerns that it could autonomously develop zero-day exploits and execute complex cyberattacks. The company has implemented strict security control… SecurityWeek · Aug 10, 2026 High aicybersecurityai agents
threat-intel Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds Stealthium is a new cybersecurity firm addressing a critical security blind spot in the rapidly growing neo-cloud market, which utilizes specialized AI accelerators. Because traditional security tools aren't designed for… SecurityWeek · Aug 10, 2026 High neo-cloudacceleratorsupply chain
vulnerability Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Cisco has warned of seven high-severity vulnerabilities in its Secure Endpoint Connector software, stemming from flaws within the ClamAV antivirus engine. These vulnerabilities could lead to denial-of-service conditions… SecurityWeek · Aug 10, 2026 High CVE-2026-20337CVE-2026-20339CVE-2026-20345clamavvulnerabilitypatch
threat-intel British ‘Com’ member who abused more than 100 girls worldwide jailed for two years A 20-year-old British man, Justin Swaddle, was sentenced to two years in prison for abusing and manipulating over 100 girls worldwide through online platforms, primarily Snapchat, Telegram, and Discord. He was part of a… The Record · Aug 10, 2026 High UKUSCAonline-abusechild-exploitationcybercrime
threat-intel Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development North Korea's Kimsuky hacking group is building an offline AI infrastructure to bolster its phishing attacks and automate malware development. Security firm Genians discovered this setup, finding tools like Ollama, GPT4A… The Hacker News · Aug 10, 2026 High KRaiphishingnorth korea
supply-chain China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns China-linked hackers, believed to be part of the Storm-1175 group, are exploiting a critical vulnerability in N-central, a remote monitoring and management (RMM) tool, to deploy ransomware. This supply-chain attack is le… The Record · Aug 10, 2026 High CVE-2026-18577CHsupply-chainransomwarezero-day
threat-intel ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad Tenet security researchers have demonstrated a novel ‘Ghostjacking’ attack that leverages poisoned logs to manipulate AI agents, effectively turning them into malicious tools. The attack exploits trust in AI agents by in… SecurityWeek · Aug 10, 2026 High aiartificial intelligencelog poisoning
threat-intel New Zealand sanctions Russian hackers, propaganda groups over Ukraine war New Zealand has expanded its sanctions against Russia, targeting 33 individuals and entities involved in cyber activities supporting Russia's war in Ukraine. These include hackers, propaganda groups, and technology compa… The Record · Aug 10, 2026 High RUUKCAcyberattacksrussiasanctions
threat-intel New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA Recent research has revealed significant vulnerabilities in passkey authentication systems, demonstrating ways to bypass security measures and impersonate users. SpecterOps found that Windows stored past YubiKey signatur… The Hacker News · Aug 10, 2026 High CVE-2026-34348passkeyauthenticationvulnerability
threat-intel Cyber vulnerability sweep picks up Royal Navy drones sending data to China A vulnerability in Royal Navy drones is allowing Chinese entities to access sensitive data. The flaw stems from a misconfigured system that transmits data to servers in China, raising significant national security concer… The Register · Aug 10, 2026 High UKCHvulnerabilitynational securitydata transmission
threat-intel New Jersey, Alabama Join States Targeted in Water Cyberattacks A coordinated cyberattack targeting water and wastewater facilities in the United States is expanding, with New Jersey and Alabama becoming the latest states to report incidents. The attacks, linked to Iranian hackers, a… SecurityWeek · Aug 10, 2026 High IRUScyberattackwater systemsics
threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing