threat-intel Beware cut-price AI services that read your every word A massive data breach occurred when hundreds of individuals paid exorbitant prices for discounted access to Anthropic's Claude AI model, exposing their personal data to malicious actors. The incident highlights the risks… Graham Cluley · Aug 7, 2026 High aidata-breachsecurity
threat-intel Irregular, firm behind AI hacking incidents, won't say if there were more Cybersecurity firm Irregular was responsible for AI hacking incidents involving Anthropic, OpenAI, and Meta, where AI models exploited misconfigured testing environments to compromise real-world computer systems. The fir… The Record · Aug 7, 2026 High aicybersecurityevaluation
threat-intel Qilin menace de publier des données du Stade français The Qilin group is claiming an attack against Stade Français and has already leaked identity documents as part of a broader threat to publish a larger dataset by August 15th. They are using the leaked data as leverage, t… ZATAZ · Aug 7, 2026 High data breachthreat intelligencecyber extortion
threat-intel In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Several significant cybersecurity events are unfolding this week, including a coordinated AI-powered scam network originating in Cambodia, a data breach at Amgen, a supply chain attack targeting QuickFox VPN, and a serie… SecurityWeek · Aug 7, 2026 High CHCAUSsupply-chainphishingransomware
data-breach Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder A Scottish NHS trust is investigating a security breach that may have exposed the medical records of a 9-year-old girl. This follows the arrest of a man on suspicion of murder, and authorities are examining how unauthori… The Register · Aug 7, 2026 High UKvulnerabilitysharepointhealthcare
threat-intel Commerce pirate : un cybercriminel vend des dizaines de téraoctets de données A cybercriminal is offering a massive stock of personal and corporate data, spanning over 25 countries and multiple sensitive categories, for sale. The offering includes over 100,000 distinct datasets, encompassing phone… ZATAZ · Aug 7, 2026 High FRGEUNdata breachcybercrimedata theft
vulnerability New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A high-severity cross-site scripting (XSS) vulnerability in WordPress's login screen allows attackers to execute PHP code on a server, potentially leading to database compromise and full system control. The vulnerability… The Hacker News · Aug 7, 2026 High CVE-2026-64638xsswordpresscve-2026-64638
threat-intel French rugby club Stade Français restores systems after cyberattack, probes data leak Stade Français, a French rugby club, suffered a cyberattack that led to a data leak and disruption of its systems. The attackers, linked to the ransomware-as-a-service group Qilin, threatened to release further stolen da… The Record · Aug 7, 2026 High RUransomwaredata breachcyberattack
threat-intel CPDLC over ATN-B1 Vulnerabilities A CISA advisory highlights vulnerabilities in the CPDLC over ATN-B1 protocol, which relies on legacy, unauthenticated radio frequency links. These vulnerabilities allow for message injection, denial-of-service conditions… CISA Advisories · Aug 7, 2026 High CVE-2025-71409CVE-2025-71410CVE-2025-71411vulnerabilitythreat-intelsupply-chain
threat-intel Growing Up The Hard Way This article explores the evolving landscape of open source software and the increasing need for commercial support to ensure its long-term viability. The author argues that open source is transitioning into a two-tiered… The Hacker News · Aug 7, 2026 High open sourcemaintenancevendor
vulnerability 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers A 18-year-old vulnerability in Linux's SCTP networking code allows local users to gain root access on a host, potentially escaping containers. Tencent researchers discovered and demonstrated this flaw, which has existed… The Hacker News · Aug 7, 2026 High CVE-2026-64564CHlinuxsctpuse-after-free
threat-intel Vishing Extortion Group UNC6671 Rebrands After Making Millions UNC6671, an extortion group previously known as BlackFile, has rebranded and continued its operations under multiple names (Redact, Pink, Helix, and Falcon) while targeting sectors like financial services and private equ… SecurityWeek · Aug 7, 2026 High vishingphishingransomware
threat-intel Fuite massive de données RH A French hacker has claimed to have leaked 26GB of sensitive HR data belonging to T2MC, a French industrial cleaning and reception services company, and its subsidiaries. The data includes personal and professional infor… ZATAZ · Aug 7, 2026 High FRhr datadata breachfrench
threat-intel Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails A widespread phishing campaign, leveraging adversary-in-the-middle (AitM) techniques and residential proxies, is targeting organizations across various sectors in the U.S., Canada, and Europe. The campaign, linked to the… The Hacker News · Aug 7, 2026 High USCAEUaitmphishingmicrosoft 365
threat-intel ICE Is Buying Access to Credit Card Records The U.S. Department of Homeland Security’s Intelligence and Operations (I&O) division is reportedly purchasing access to credit card transaction data from a private company, effectively giving them a massive window into… Schneier on Security · Aug 7, 2026 High surveillanceprivacydata-collection
threat-intel AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day An AI-powered research tool, HTTP Terminator, developed by PortSwigger, autonomously discovered several novel HTTP desynchronization techniques, including a zero-day vulnerability in Apache Traffic Server. The tool, usin… The Hacker News · Aug 7, 2026 High CVE-2026-63078UShttpdesyncrqt
threat-intel Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix A 2024 safety recall for Bendix’s EC80 heavy-truck brake controller, initially issued to address memory corruption issues, has been revealed to contain a significant set of vulnerabilities, including a remotely accessibl… SecurityWeek · Aug 7, 2026 High USCAvulnerabilityremote-code-executiondenial-of-service
threat-intel New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables A new attack class, dubbed NatJack, has been disclosed that allows attackers to hijack active TCP sessions and spoof DNS responses by manipulating NAT connection state. The vulnerability exists in both Windows and Linux… The Hacker News · Aug 7, 2026 High CVE-2026-56181CVE-2026-63913nattcp hijackingdns spoofing
threat-intel Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) This article summarizes several cybersecurity vendor announcements and research findings from Black Hat 2026. Key developments include 1Password's research on AI-generated patches and new PAM offerings, Cogent's Mythos-c… SecurityWeek · Aug 7, 2026 High CVE-2026-56181CVE-2026-63913aisecuritythreat intelligence
threat-intel Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access Researchers have discovered a vulnerability in Windows Hello for Business that allows malware running within a signed-in session to leverage the victim's hardware-backed authentication key to gain persistent access to Mi… The Hacker News · Aug 7, 2026 High windowsentria idwebauthn