threat-intel Amid AI-Driven Bug Tsunami, NIST Looks to…AI The National Institute of Standards and Technology (NIST) is seeking public input on how to modernize the National Vulnerability Database (NVD) in light of a massive surge in software vulnerabilities, driven in part by A… Dark Reading · Aug 14, 2026 Medium vulnerabilityaicybersecurity
vulnerability Multiples vulnérabilités dans Stormshield Network Security (14 août 2026) Multiple vulnerabilities have been discovered in Stormshield Network Security, potentially allowing for remote code execution, denial of service, and data compromise. These vulnerabilities affect various versions of the… CERT-FR · Aug 14, 2026 Medium CVE-2026-25075CVE-2026-34180CVE-2026-35058vulnerabilityremote code executiondenial of service
vulnerability Multiples vulnérabilités dans Tenable Security Center (14 août 2026) Multiple vulnerabilities have been discovered in Tenable Security Center, including remote code execution, privilege escalation, and SQL injection. These vulnerabilities affect versions of Security Center prior to 6.9.0.… CERT-FR · Aug 14, 2026 High CVE-2026-11564CVE-2026-11586CVE-2026-11856vulnerabilityremote code executionsql injection
threat-intel Global Threat Campaign Hits Critical VMware vCenter Flaw A single threat actor has been aggressively exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, initiating a global threat campaign that began shortly after public disclosure. The vulnerability, a dir… Dark Reading · Aug 13, 2026 High USFRIRvulnerabilityexploitreverse_ssh
threat-intel ZATAZ FAIT SON GRAND MÉNAGE D’ÉTÉ : LES OUTILS CYBER FONT PEAU NEUVE ZATAZ has revamped its cybersecurity resource page, offering a comprehensive collection of tools and educational materials designed to enhance cybersecurity awareness and skills. The update includes a wide range of resou… ZATAZ · Aug 13, 2026 Medium cyber threat intelligenceosintdark web
threat-intel Venture Firm Team8 Secures Additional $365 Million Israeli venture firm Team8 secured an additional $365 million in funding to bolster its investments in early-stage cybersecurity and AI startups. This investment significantly expands Team8’s assets under management to n… SecurityWeek · Aug 13, 2026 Info ILventure-capitalaicybersecurity
threat-intel White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs The White House has launched a program allowing vetted US cybersecurity firms to conduct offensive operations against foreign cybercrime gangs, under strict federal oversight. These firms will execute cyber surveillance… SecurityWeek · Aug 13, 2026 Medium cybercrimeoffensive operationscyber intelligence
threat-intel Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th) This report details an experiment using a Large Language Model (Gemma4) to analyze malware hashes uploaded to the DShield sensor. The LLM was used to identify potential threats and recommend actions, focusing on a patter… SANS Internet Storm Center · Aug 13, 2026 High ailarge language modeldshield
vulnerability Multiples vulnérabilités dans Progress MOVEit WAF (13 août 2026) Multiple vulnerabilities have been discovered in Progress MOVEit WAF, allowing attackers to execute arbitrary code remotely, escalate privileges, and bypass security policies. These vulnerabilities affect versions prior… CERT-FR · Aug 13, 2026 Critical CVE-2026-59686CVE-2026-59687CVE-2026-59688vulnerabilityprogressmoveit
threat-intel Linux Kernel Process Accounting, (Wed, Aug 12th) This article details the Linux kernel process accounting feature, a tool for logging process activity on Linux systems. It’s a relatively simple-to-implement feature that doesn’t require kernel recompilation and can be u… SANS Internet Storm Center · Aug 12, 2026 Medium linuxprocess-monitoringlogging
supply-chain Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially ex… The Hacker News · Aug 12, 2026 High CVE-2026-33634USEUsupply chaincredential theftpypi
vulnerability SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform SonicWall has released patches to address eight critical vulnerabilities in its discontinued GMS platform and Email Security products. These flaws, including remote code execution and command injection, could allow attac… SecurityWeek · Aug 12, 2026 Critical CVE-2026-66147CVE-2026-66145CVE-2026-66149vulnerabilitypatchrce
vulnerability Multiples vulnérabilités dans les produits Ivanti (12 août 2026) Multiple vulnerabilities have been discovered in Ivanti products, including Endpoint Manager and Neurons for MDM. These flaws could lead to data integrity compromise, data confidentiality breaches, and denial-of-service… CERT-FR · Aug 12, 2026 Medium CVE-2026-18125CVE-2026-18127CVE-2026-18129ivantivulnerabilityendpoint
vulnerability 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one Microsoft released a Patch Tuesday update containing 421 bugs, and a group known as ‘The Norks’ has already exploited one of these vulnerabilities to launch an attack. This highlights a continuing issue with Microsoft’s… The Register · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62893microsoftpatch tuesdayvulnerability
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
threat-intel OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development OpenAI has released GPT-5.6-Cyber, a cybersecurity-focused AI model designed to assist vulnerability research and exploit development, while reducing refusals for high-risk tasks. The model, accessible through the Daybre… The Hacker News · Aug 11, 2026 High CVE-2026-15903UNaicybersecurityvulnerability
threat-intel Deepfake hiccup unmasks suspected digital certificate fraudster This article discusses a potential digital certificate fraud scheme linked to deepfake technology, where Russian actors are impersonating Signal support to launch phishing attacks. The vulnerability stems from flaws in J… The Register · Aug 11, 2026 Medium RUdeepfakephishingjoomla
threat-intel OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber OpenAI has released GPT-5.6-Cyber, a new AI model specifically designed for advanced cybersecurity tasks, including finding zero-days and creating exploit chains. This model addresses limitations of its predecessor, GPT-… SecurityWeek · Aug 11, 2026 High aicybersecurityvulnerability
threat-intel The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists The article highlights a significant gap between the speed at which attackers discover and exploit vulnerabilities and the speed at which defenders can patch them. Traditional CVSS-based prioritization is inadequate beca… Dark Reading · Aug 10, 2026 High CVE-2024-9474CVE-2024-0012vulnerabilityattack-pathchoke-point
threat-intel Coruna, DarkSword iOS Exploits Proliferate Globally Sophisticated iPhone exploit chains, DarkSword and Coruna, are rapidly spreading beyond nation-state actors and into the hands of organized cybercrime groups. These advanced tools, initially developed for surveillance an… Dark Reading · Aug 10, 2026 High CVE-2025-31277CVE-2025-43529CVE-2026-20700CHMASAexploitioscybercrime