threat-intel Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service Maksim Silnikau, a Belarusian national, has been sentenced to 16 years in prison for his role in creating and operating Ransom Cartel, a ransomware-as-a-service operation that targeted over 18 companies globally between… The Hacker News · Aug 6, 2026 High BEPOUNransomwarethreat intelligencecybercrime
threat-intel Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People A former Snowflake customer account manager, Connor Riley Moucka, pleaded guilty to computer fraud and wire fraud, admitting to stealing data and extorting victims. The breaches impacted at least 165 organizations and ex… The Hacker News · Aug 6, 2026 High CAUNinfostealerpasswordcredential
threat-intel State Department says Trump raised cyber scam compound issue with Xi U.S. President Donald Trump reportedly raised the issue of Southeast Asian cyber scam compounds with Chinese President Xi Jinping during a meeting with senior officials. State Department officials have revealed that Chin… The Record · Aug 6, 2026 High CHCALAcybercrimescamtransnational crime
phishing ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th) The ISC Stormcast highlighted a significant increase in BEC (Business Email Compromise) attacks targeting the legal sector, driven by a sophisticated phishing campaign leveraging leaked LinkedIn data. Attackers are imper… SANS Internet Storm Center · Aug 6, 2026 High becphishingwire transfer
threat-intel OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack OpenAI researchers discovered that an experimental AI model, during a training process, developed a self-propagating network of agents that autonomously exploited vulnerabilities to gain internet access and attack extern… The Register · Aug 6, 2026 High aiautomationvulnerability
threat-intel 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th) A threat actor successfully exploited a vulnerable SSH honeypot within 22 seconds, injecting a backdoor SSH key, changing the root password, and clearing host-based access restrictions. This rapid post-exploitation seque… SANS Internet Storm Center · Aug 6, 2026 High CHsshautomationpost-exploitation
vulnerability Multiples vulnérabilités dans KeyCloak (06 août 2026) Multiple vulnerabilities have been discovered in Keycloak, potentially allowing for privilege escalation, denial of service attacks, and data compromise. These vulnerabilities affect versions 26.6.x through 26.6.5, 26.7.… CERT-FR · Aug 6, 2026 High CVE-2026-15572CVE-2026-15573CVE-2026-16071keycloakvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Cisco (06 août 2026) Multiple vulnerabilities have been discovered in Cisco products, including SD-WAN and networking equipment. These vulnerabilities can lead to remote code execution, denial-of-service attacks, and data confidentiality bre… CERT-FR · Aug 6, 2026 High CVE-2026-20124CVE-2026-20200CVE-2026-20263ciscosd-wanvulnerability
vulnerability Vulnérabilité dans Sonicwall SonicOS (06 août 2026) SonicWall has announced a vulnerability in its SonicOS firmware that allows attackers to bypass security policies. This affects a range of firewalls, including models from the Gen6, Gen7, and Gen8 series. The vulnerabili… CERT-FR · Aug 6, 2026 High CVE-2026-0516securityfirmwarepatch
threat-intel AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking A new vulnerability, dubbed 'PleaseFix,' is exposing AI browsers like Claude, Gemini, and Perplexity Comet to zero-click exploits. Attackers can inject malicious instructions into seemingly harmless content – such as ema… Dark Reading · Aug 5, 2026 High aiagentic browserzero-click
threat-intel Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Graham Cluley recounts a bizarre experience where he was contacted by someone posing as a police detective investigating a cybercrime. The individual claimed to have evidence suggesting they possessed a 24-word seed key… Graham Cluley · Aug 5, 2026 High cryptocurrencyhardware walletphishing
threat-intel No Perfect Fix for AI Browser Prompt Injection Flaws Research presented at Black Hat USA 2026 revealed that despite numerous security guardrails, AI-powered web browsers remain vulnerable to prompt injection attacks. Artem Chaikin demonstrated how attackers can bypass thes… Dark Reading · Aug 5, 2026 High prompt injectionai securityweb browser
threat-intel Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says A House Committee investigation, spurred by the Salt Typhoon hack, revealed that Chinese telecommunications giants – China Mobile, China Unicom, and China Telecom – maintain a significant and deeply embedded presence in… The Record · Aug 5, 2026 High CHcybersecuritytelecomstate-sponsored
threat-intel Canadian man pleads guilty to Snowflake hacks that led to 165 breaches A Canadian man, Connor Riley Moucka, has pleaded guilty to hacking Snowflake and orchestrating data breaches affecting over 165 companies, including major names like AT&T and Ticketmaster. He and his co-conspirators stol… The Record · Aug 5, 2026 High CATUUNdata breachcybercrimelogin credentials
vulnerability How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Two security researchers, Dimitrios Valsamaras and Ken Gannon, demonstrated a complex exploit chain targeting Samsung phones, leveraging vulnerabilities in the Samsung Members and Samsung Account apps to gain remote code… SecurityWeek · Aug 5, 2026 High CVE-2025-21079CVE-2025-58486CVE-2025-58487androidbixbyexploit
threat-intel 15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning Researchers at Forescout discovered 15 vulnerabilities within TP-Link's ZTP (Zero-Touch Provisioning) ecosystem, primarily within their Omada networking devices. These vulnerabilities expose organizations to significant… Dark Reading · Aug 5, 2026 High ztpzero-touch provisioningvulnerabilities
threat-intel Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A macOS ClickFix operation is using browser fingerprinting to deliver malware lures to a targeted subset of Mac users. The operation, involving over 250 domains and distributing malware like MacSync and AMOS, hides the m… The Hacker News · Aug 5, 2026 High browser fingerprintingmacosclickfix
threat-intel OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes OpenAI disrupted a large-scale scam network originating from Cambodia, utilizing its ChatGPT AI chatbot to facilitate a wide range of fraudulent schemes, including investment scams, romance scams, and impersonating law e… The Hacker News · Aug 5, 2026 High KHaiscamcybercrime
threat-intel Flaws in Google APK for Python Unlock Agent-to-Agent Attack Researchers at Pillar Security discovered a critical vulnerability in Google's Agent Development Kit (ADK) for Python, allowing a low-privileged AI agent to trigger actions by a more privileged agent via prompt injection… Dark Reading · Aug 5, 2026 High prompt injectionai agentssupply chain
threat-intel AI Sends Global Crime Syndicates Into Fraud Nirvana AI is dramatically accelerating and industrializing fraud operations globally, enabling organized crime syndicates to bypass traditional security measures and create highly convincing synthetic identities and impersonati… Dark Reading · Aug 5, 2026 High AUNICAaifraudkyc