threat-intel Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Polish CERT has revealed a second, parallel cyberattack targeting a smaller CHP plant supplying heat to 50,000 residents, utilizing a novel private APN attack vector. The attack, attributed to Russian APT group Sandworm,… SecurityWeek · Aug 10, 2026 High PLicsindustrial control systemsprivate apn
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause OpenAI is pausing internal development of its AI model Astra due to concerns about its rapidly advancing cyber capabilities. Initial evaluations suggest the model possesses ‘Critical’ cyber capabilities, including the po… The Hacker News · Aug 10, 2026 High aicybersecurityai-safety
vulnerability Critical Flaws Discovered in Belgian eID Software Used by 2 Million People A critical vulnerability in Nitro Software Belgium’s Connective digital identity system, used by over two million people in Belgium, allowed attackers to steal sensitive data and forge electronic signatures. The flaw was… SecurityWeek · Aug 10, 2026 High BEdigital identityeidbrowser extension
threat-intel Advertisers are trying to influence AI bots with secret ads This week’s episode of The Kettle podcast explores the escalating competition in the AI world, focusing on China’s rapid advancements in open-weight AI models. The episode highlights DeepSeek, a Chinese model nearing par… The Register · Aug 10, 2026 High CHUNaiopen-sourcechina
vulnerability Multiples vulnérabilités dans Roundcube (10 août 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, allowing attackers to execute arbitrary code remotely, compromise data confidentiality, and forge server-side requests. These flaws exist in versions 1.… CERT-FR · Aug 10, 2026 High vulnerabilitywebmailsecurity
threat-intel Cyber actualités ZATAZ de la semaine du 3 au 9 août 2026 This week, ZATAZ reports on a significant number of cyber incidents impacting France and beyond. A staggering 1.7 billion French IDs were found on the dark web, alongside 43 ransomware demands targeting France, primarily… ZATAZ · Aug 9, 2026 High FRTAdarkwebransomwaredata breach
threat-intel Un milliard d’identifiants français sur le darkweb A massive collection of over 1.7 billion unique French email addresses and passwords has been discovered on the dark web, originating from 13 years of phishing campaigns and data breaches. The data, totaling 28GB across… ZATAZ · Aug 8, 2026 High FRcredential stuffingphishingdata breach
threat-intel Rançongiciels : 43 revendications ciblent la France Between July 1st and August 8th, 43 French organizations were targeted in cybercriminal extortion claims, with a strong concentration among several ransomware-as-a-service groups. The Gentlemen and Qilin were the most ac… ZATAZ · Aug 8, 2026 High FRransomwarecybercrimeextortion
threat-intel Des pirates revendiquent le piratage d’un miroir de Coco A mirror site for the defunct Coco discussion forum, presented as a successor to the original site shut down due to illegal activities, has been compromised by the threat actor CuteSec. The attackers gained extensive con… ZATAZ · Aug 8, 2026 High data breachpassword compromiseuser data
vulnerability Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers Atlassian’s Rovo assistant has two vulnerabilities that could allow attackers to exfiltrate data. The first, a one-click link flaw, has been patched by Atlassian. The second, a content-borne prompt injection attack, allo… The Hacker News · Aug 8, 2026 High prompt-injectiondata-exfiltrationatlassian
threat-intel Un pirate plaide coupable après 165 piratages A Canadian man, Connor Riley Moucka, has pleaded guilty to a massive cloud-based hacking and extortion scheme targeting over 165 organizations. Between February and October 2024, his group exploited stolen credentials to… ZATAZ · Aug 8, 2026 High CAUNSPcloud-securitycredential-theftextortion
threat-intel New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens Researchers at PortSwigger have discovered several new attack vectors targeting webmail interfaces, allowing attackers to steal passwords, take over accounts, and manipulate AI tools. The vulnerabilities exploit weakness… The Hacker News · Aug 8, 2026 High webmailcsshtml
threat-intel Inside the Modern SOC: The Identity Front Door A significant trend in cyberattacks is the increasing reliance on compromised identities rather than exploiting technical vulnerabilities. Nearly 90% of Unit 42 investigations involved identity weaknesses, with 65% of in… Palo Alto Unit 42 · Aug 7, 2026 High identity theftcredential abusesocial engineering
threat-intel Water utilities group partners with DEF CON offshoot for Water Watch Center The National Rural Water Association (NRWA) has partnered with DEF CON Franklin to establish the Water Watch Center (WWC), a program designed to provide cybersecurity services to underfunded water and wastewater systems… The Record · Aug 7, 2026 High IRUNcybersecuritywater systemsoperational technology
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ClickFix-style attacks are being used to deliver a Go-based macOS stealer that can drain cryptocurrency wallets and steal browser-stored passwords and Apple iCloud Keychain data. The malware, developed by the Aeza Group… The Hacker News · Aug 7, 2026 High USUKAUmacoscryptocurrencystealer
threat-intel UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data UNC6671, a data extortion group linked to ShinyHunters and potentially SLH, is leveraging sophisticated vishing tactics to steal SaaS data from organizations across multiple sectors. They impersonate IT help desks, direc… The Hacker News · Aug 7, 2026 High NOAUU.vishingphishingdata-breach
threat-intel AI-Generated Patches Fail Half the Time A study by 1Password found that AI-generated patches are significantly flawed, with only around 46% successfully fixing vulnerabilities and many introducing new bugs or requiring code modification. The research, dubbed F… Dark Reading · Aug 7, 2026 High UNaipatchingvulnerability