threat-intel Water Sector Cyberattacks Reportedly Hit at Least 12 States A growing number of US states, including Minnesota, Michigan, and Georgia, are experiencing cyberattacks targeting water and wastewater facilities. The FBI has linked these attacks to Iran, specifically targeting interne… SecurityWeek · Aug 5, 2026 High IRicsiotcyberattack
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of sophisticated phishing attacks leveraging leaked credentials. The report emphas… SANS Internet Storm Center · Aug 5, 2026 High phishingcredential-stuffingbec
threat-intel AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project Researchers have demonstrated a concerning vulnerability where large language models (LLMs) can be manipulated to inject malware into open-source projects. By simply releasing a model, developers inadvertently enabled ma… The Register · Aug 5, 2026 High llmprompt injectionopen source
vulnerability Multiples vulnérabilités dans les produits Veeam (05 août 2026) Multiple vulnerabilities have been discovered in Veeam products, including vulnerabilities that could allow for remote code execution, privilege escalation, and denial of service attacks. These issues affect Service Prov… CERT-FR · Aug 5, 2026 High CVE-2026-58067CVE-2026-58071CVE-2026-58072vulnerabilitypatchremote code execution
threat-intel OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud OpenAI has disrupted a network of scam centers in Cambodia that were using ChatGPT to facilitate investment fraud targeting Indian nationals. The scammers leveraged the AI chatbot for a wide range of tasks, including cre… The Record · Aug 4, 2026 High CACHUGaiscamcybercrime
threat-intel Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook The Smoke#Screen campaign is a sophisticated social engineering attack leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically ScreenConnect, to gain persistent remote access to compromised netwo… Dark Reading · Aug 4, 2026 High social engineeringremote managementphishing
threat-intel Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal… The Hacker News · Aug 4, 2026 High phishingdevice-code-phishingmfa
threat-intel Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) This document summarizes key vendor announcements from the 2026 Black Hat conference, focusing on advancements in cybersecurity products and services. Several companies are leveraging AI to enhance their security offerin… SecurityWeek · Aug 4, 2026 High aivulnerability remediationthreat hunting
threat-intel Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence Former head of British Defence Intelligence, Jim Hockenhull, revealed that Britain’s next war won’t be a traditional battlefield conflict, but a cyber war. He explained how his team, led by Ben Wallace, proactively decla… The Record · Aug 4, 2026 High UKRUUNcybersecurityintelligenceukraine
threat-intel Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Traditional security tools like CASB and DLP aren't sufficient for addressing the unique risks posed by AI. The core issue is that AI risk isn't about simply blocking access to AI tools; it's about analyzing the *content… SecurityWeek · Aug 4, 2026 High UNaiprompt injectiondata leakage
threat-intel AI helps Microsoft bug hunters chase a record $20M payday Microsoft security researchers are experiencing a surge in zero-day attacks targeting on-prem SharePoint, fueled by a new wave of exploits leveraging vulnerabilities in third-party extensions. Simultaneously, Chinese act… The Register · Aug 4, 2026 High CHzero-dayphishingcybersecurity
threat-intel CISO Conversation: Russ Kirby – Passion Is the Antidote to Burnout Russ Kirby, a CISO with extensive experience at companies like Ping Identity, Creditsafe, and ForgeRock, attributes his success and longevity in cybersecurity to a deep passion for the field and a proactive approach to c… SecurityWeek · Aug 4, 2026 High cisoburnoutai
threat-intel Russian businesses erase Durov-linked products after 'terrorist' designation Following Russia's designation of Telegram founder Pavel Durov as a terrorist and extremist, numerous Russian businesses are removing products associated with him, including books, films, and merchandise. Despite these e… The Record · Aug 4, 2026 High RUFRUAcensorshipduraovtelegram
threat-intel Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Attackers are leveraging compromised email accounts and their built-in AI assistants to bypass security measures and conduct sophisticated phishing attacks against executives. By using the AI assistant to gather informat… SecurityWeek · Aug 4, 2026 High phishingaiemail
threat-intel Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverage… The Hacker News · Aug 4, 2026 High npmsupply-chaincredential-stealing
threat-intel Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access A multi-wave campaign leveraging social engineering to deploy Remote Monitoring and Management (RMM) software, specifically ScreenConnect, is actively targeting users with fake Adobe and Zoom updates, as well as business… The Hacker News · Aug 4, 2026 High phishingmalwaresupply-chain
threat-intel The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software Palo Alto Unit 42’s research demonstrates a significant shift in vulnerability discovery due to the emergence of frontier AI. Their system, NOVA, autonomously analyzed 3,915 open-source projects in just two months, uncov… Palo Alto Unit 42 · Aug 4, 2026 High vulnerabilityopen-sourceai
threat-intel AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls An AI meeting assistant, tl;dv, is vulnerable due to a misconfiguration in its Firebase environment, allowing unauthorized access to users' video calls and meeting data. A security researcher discovered that users could… Dark Reading · Aug 4, 2026 High MAUKBRfirebaseaimeeting assistant
threat-intel Apple launches new legal challenge against UK over iCloud access Apple is challenging the UK government’s legal demands for access to user data stored on iCloud, specifically related to a Technical Capability Notice (TCN) that requires Apple to retain the ability to access iCloud cont… The Record · Aug 4, 2026 High UKUSencryptiondata-privacylaw-enforcement