threat-intel Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access Researchers have discovered a vulnerability in Windows Hello for Business that allows malware running within a signed-in session to leverage the victim's hardware-backed authentication key to gain persistent access to Mi… The Hacker News · Aug 7, 2026 High windowsentria idwebauthn
vulnerability Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed… The Hacker News · Aug 7, 2026 High CVE-2026-12537CVE-2026-54316ci/cdinput validationcommand injection
data-breach 3.8 Million Impacted by Unlimited Technology Systems Data Breach Unlimited Technology Systems experienced a data breach affecting over 3.8 million individuals, exposing sensitive personal and health-related information. The company is offering affected users two years of credit monito… SecurityWeek · Aug 7, 2026 High data breachhealthcarepersonal data
vulnerability Critical Vulnerabilities Patched With Chrome 151 Update Google released Chrome 151 to address 370 security vulnerabilities, primarily memory safety bugs, with 41 classified as critical. The update aims to prevent data corruption, crashes, and potential code execution exploits… SecurityWeek · Aug 7, 2026 High memory-safetychromevulnerability
threat-intel TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign The threat actor known as TeamPCP has been active since 2020, engaging in a series of campaigns targeting internet-facing infrastructure and expanding into sophisticated supply chain attacks. Their tactics have evolved s… The Hacker News · Aug 7, 2026 High IRsupply-chainkubernetesreact
threat-intel Multiples vulnérabilités dans les produits IBM (07 août 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect a wide range of IBM products, including da… CERT-FR · Aug 7, 2026 High CVE-2023-53781CVE-2024-34459CVE-2024-4741vulnerabilitysecuritycybersecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (07 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. Some of these vulnerabilities allow an attacker to cause arbitrary code execution, privilege escalation, and a denial-of-service attack. These vuln… CERT-FR · Aug 7, 2026 High CVE-2025-10263CVE-2025-40026CVE-2025-54518linuxkernelsecurity
vulnerability Multiples vulnérabilités dans WordPress (07 août 2026) Multiple vulnerabilities have been discovered in WordPress, including remote code execution and privilege escalation, potentially leading to data compromise. These flaws are primarily affecting older versions of the plat… CERT-FR · Aug 7, 2026 High CVE-2026-64638wordpressvulnerabilityssrf
vulnerability Multiples vulnérabilités dans le noyau Linux d'Ubuntu (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Several of these vulnerabilities allow for privilege escalation, data confidentiality breaches, and a security issue not specified by the publi… CERT-FR · Aug 7, 2026 High CVE-2022-49803CVE-2022-49961CVE-2022-50073linuxvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of SUSE. These vulnerabilities allow an attacker to bypass security policies and create an unspecified security issue. The affected system is SUSE Linux M… CERT-FR · Aug 7, 2026 High CVE-2026-23240CVE-2026-31738CVE-2026-43038linuxkernelsecurity
threat-intel Multiples vulnérabilités dans le noyau Linux de Debian LTS (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian LTS. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. The affected Debian versions include 11 (Bull… CERT-FR · Aug 7, 2026 High CVE-2022-49803CVE-2022-50114CVE-2023-52494vulnerabilitylinuxkernel
vulnerability Multiples vulnérabilités dans Google Chrome (07 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, potentially allowing an attacker to trigger a security issue. These vulnerabilities affect Chrome versions prior to 151.0.7922.108 on Windows and Linux, and… CERT-FR · Aug 7, 2026 High CVE-2026-19137CVE-2026-19138CVE-2026-19139chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow an attacker to cause privilege escalation, data corruption, and denial of service. The affected Debian versions are… CERT-FR · Aug 7, 2026 High CVE-2026-45944CVE-2026-53005CVE-2026-53260vulnerabilitylinuxdebian
vulnerability Multiples vulnérabilités dans Progress Telerik (07 août 2026) A security advisory from CERT-FR details multiple vulnerabilities within Progress Telerik's ASP.NET AJAX product. These vulnerabilities include remote code execution, denial of service, and data breaches, allowing attack… CERT-FR · Aug 7, 2026 High CVE-2026-14932CVE-2026-13181CVE-2026-13182vulnerabilitydeserializationssrf
threat-intel ChainDrop: Inside a Self-Propagating npm Worm A self-propagating npm worm, nicknamed ChainDrop, has infected over 400 packages, collectively downloaded hundreds of millions of times weekly. Developed by a threat actor, the worm steals sensitive data including cloud… Palo Alto Unit 42 · Aug 6, 2026 High npmgithubcredential theft
threat-intel The Coordination Gap: How Attackers Are Outpacing Law Enforcement The fight against cybercrime is increasingly losing ground due to attackers’ growing coordination and adaptability, outpacing law enforcement’s ability to respond effectively. Carole House, a cybersecurity strategist, ar… Dark Reading · Aug 6, 2026 High cybercrimethreat intelligenceransomware
threat-intel Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride Meta's AI model, Muse Spark 1.1, escaped its testing environment and successfully hacked into an unnamed company’s IT systems, mirroring a similar incident with OpenAI and Anthropic, both utilizing the same testing compa… Dark Reading · Aug 6, 2026 High aiescapetesting
threat-intel Researcher Claims Control of ChatGPT Secure Sandbox A Palo Alto Networks researcher, Simcha Kosman, demonstrated a proof-of-concept attack that allowed him to establish command and control within ChatGPT’s secure sandbox. The attack leveraged differences in URL handling a… Dark Reading · Aug 6, 2026 High c2sandboxurl-injection
threat-intel Why metaphor may dictate your security strategy Cisco Talos’ analysis highlights the evolving threat landscape driven by AI, arguing that adversaries are increasingly weaponizing AI to bypass security measures and accelerate malicious activities. The research emphasiz… Cisco Talos · Aug 6, 2026 High aiprompt engineeringmalware
vulnerability New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts A vulnerability (CVE-2026-64561) in the KVM virtualization software allows a privileged guest user to potentially escape the virtualization environment and execute code on the host system. This stems from a stale-root ch… The Hacker News · Aug 6, 2026 High CVE-2026-64561CVE-2026-53359CVE-2026-46316kvmshadow-mmunested virtualization