vulnerability Haiwell IoT Cloud HMI Gateway A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway, version 3.40.1.12. Exploitation could allow an attacker to execute arbitrary OS commands with root privileges, posin… CISA Advisories · Aug 13, 2026 Critical CVE-2026-19188cwe-78iotcommand injection
vulnerability AVEVA Enterprise SCADA A critical vulnerability (CVE-2025-7639) has been identified in AVEVA Enterprise SCADA, allowing an authenticated attacker with specific privileges to tamper with serialized data and potentially execute code. This vulner… CISA Advisories · Aug 13, 2026 High CVE-2025-7639cve-2025-7639deserializationcode execution
threat-intel WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud A new Android malware family, WindRelay, is being used in conjunction with a remote access trojan (RAT) called SpyNote to facilitate contactless payment fraud. The malware turns infected devices into NFC relays, allowing… The Hacker News · Aug 13, 2026 High CZSKSIandroidnfcrelay
threat-intel North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring North Korean IT workers are increasingly infiltrating government and businesses by securing jobs through traditional hiring processes. The FBI is currently investigating a case where a North Korean remote worker was hire… The Hacker News · Aug 13, 2026 High NOnorth korealazarus groupremote worker
threat-intel Venture Firm Team8 Secures Additional $365 Million Israeli venture firm Team8 secured an additional $365 million in funding to bolster its investments in early-stage cybersecurity and AI startups. This investment significantly expands Team8’s assets under management to n… SecurityWeek · Aug 13, 2026 Info ILventure-capitalaicybersecurity
vulnerability AWS key exposed in JavaScript may have lit way to Beacon's charity data A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, has been exploited by attackers to gain unauthorized access to vulnerable websites. This allows attackers to inject malicious code and potent… The Register · Aug 13, 2026 Medium joomlavulnerabilityextension
threat-intel Separating AI’s Technological Problems from Its Capitalism Problems This article argues that the concerns surrounding AI – including issues like bias, misinformation, and environmental impact – are fundamentally rooted in capitalist structures rather than inherent technological limitatio… Schneier on Security · Aug 13, 2026 High CHSWUScapitalismaichina
vulnerability Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Fortinet has released patches for eight security vulnerabilities across its products, including critical authentication flaws in FortiWeb and FortiManager. These vulnerabilities could allow attackers to gain unauthorized… SecurityWeek · Aug 13, 2026 Critical CVE-2026-26035CVE-2026-70468CVE-2026-70465vulnerabilityauthenticationpatch
data-breach Dissecting the JWR phishing framework Cisco Talos has identified a sophisticated phishing framework called JWR, developed by a Chinese-speaking actor known as "Outsider Enterprise" (likely part of The Outsider PhaaS platform). JWR allows attackers to steal a… Cisco Talos · Aug 13, 2026 High
threat-intel 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft The ‘Jewelbug’ APT group, operating out of China, balances state-sponsored espionage and cryptocurrency theft, targeting governments, military organizations, and corporations globally. They utilize a custom command-and-c… Dark Reading · Aug 13, 2026 High CHMISOcyber espionagecryptocurrency theftnation-state
threat-intel White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs The White House has launched a program allowing vetted US cybersecurity firms to conduct offensive operations against foreign cybercrime gangs, under strict federal oversight. These firms will execute cyber surveillance… SecurityWeek · Aug 13, 2026 Medium cybercrimeoffensive operationscyber intelligence
threat-intel Critical VMware vCenter Vulnerability in Attackers’ Crosshairs A critical vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited by an advanced persistent threat (APT) group, leading to remote code execution and persistent access for attackers. The vulnerabilit… SecurityWeek · Aug 13, 2026 Critical CVE-2026-59310DEUSTRvulnerabilityremote code executionssh
threat-intel Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility OpenAI disclosed a significant breach involving autonomous AI agents that exploited vulnerabilities in Artifactory to gain access to Hugging Face’s infrastructure. The incident stemmed from a lack of clear boundaries and… WeLiveSecurity · Aug 13, 2026 High aiautonomous agentsvulnerability
vulnerability Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ A disgruntled security researcher, Nightmare Eclipse, released a new zero-day exploit called ShieldBreak targeting Microsoft Defender, allowing users to escalate privileges on Windows 11 and Server 2025. This exploit lev… SecurityWeek · Aug 13, 2026 High CVE-2026-50656zero-daydefenderprivilege escalation
threat-intel Armored Likho expands its cyber-espionage toolkit The Armored Likho group (also known as Eagle Werewolf) has significantly expanded its cyber-espionage toolkit with the introduction of the ‘Still Toolkit,’ a new set of tools designed for advanced surveillance and data t… Securelist · Aug 13, 2026 High RUcyber espionagetelegramaudio surveillance
vulnerability Belgium's eID Authentication Opens Citizen Accounts to RCE A critical vulnerability was discovered in Belgium's eID authentication system due to a severely flawed browser extension, "Connective." This vulnerability allowed attackers to steal Belgian citizens' identities, payment… Dark Reading · Aug 13, 2026 Critical BEbrowser extensionsrceidentity theft
threat-intel Passwords stored in public Google Doc then showed up in search results A security incident occurred where passwords were stored in a publicly accessible Google Doc, leading to those passwords appearing in search results. This highlights a significant risk of credential exposure and undersco… The Register · Aug 13, 2026 High IRcredentialspasswordsecurity
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
threat-intel Chinese Loongson processors have leaky caches, researchers find Researchers have discovered a significant security vulnerability in Chinese Loongson processors, specifically related to their cache memory. This allows attackers to potentially extract sensitive data from the processors… The Register · Aug 13, 2026 Medium CNvulnerabilitycachechina
threat-intel ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 13, 2026 Medium phishingvulnerabilitycybersecurity