vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
threat-intel Chinese Loongson processors have leaky caches, researchers find Researchers have discovered a significant security vulnerability in Chinese Loongson processors, specifically related to their cache memory. This allows attackers to potentially extract sensitive data from the processors… The Register · Aug 13, 2026 Medium CNvulnerabilitycachechina
threat-intel ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 13, 2026 Medium phishingvulnerabilitycybersecurity
threat-intel Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th) This report details an experiment using a Large Language Model (Gemma4) to analyze malware hashes uploaded to the DShield sensor. The LLM was used to identify potential threats and recommend actions, focusing on a patter… SANS Internet Storm Center · Aug 13, 2026 High ailarge language modeldshield
threat-intel ArtNexus : une fuite expose le marché international de l’art A database belonging to ArtNexus, an international art specialist, has been publicly exposed, offering a detailed map of its business ecosystem. The database, accessible without authentication, contains thousands of acco… ZATAZ · Aug 13, 2026 High FRdatabasephishingsocial engineering
threat-intel Des accès superadmin exposent 27 sites français A single administrator account granting access to 27 French websites was leaked on a hacking forum, with a direct incentive for other members to collect and deliver all accessible data within 48 hours. The author is acti… ZATAZ · Aug 13, 2026 High FRhackingdatabaseadministrator
threat-intel Hôtelerie : encore un hôtel de luxe piraté ? A clandestine seller is offering to sell 110GB of data allegedly stolen from Gran Caribe Hotel Group, a luxury Cuban hotel chain. The data includes reservations, employee information, accounting records, inventory detail… ZATAZ · Aug 13, 2026 High CUdata breachpassword crackingsql injection
vulnerability Multiples vulnérabilités dans GitLab (13 août 2026) Multiple vulnerabilities have been discovered in GitLab, including remote code injection, denial of service, and privilege escalation. These issues affect versions 19.1.x through 19.1.4, 19.2.x through 19.2.2, and all ve… CERT-FR · Aug 13, 2026 High CVE-2025-9486CVE-2026-15216CVE-2026-15217gitlabvulnerabilityremote code injection
vulnerability Vulnérabilité dans WordPress (13 août 2026) A remote code execution vulnerability has been identified in older versions of WordPress, allowing attackers to execute arbitrary code. This affects WordPress versions prior to 7.0.4, and requires immediate patching to p… CERT-FR · Aug 13, 2026 Critical CVE-2026-65640wordpressrcevulnerability
vulnerability Multiples vulnérabilités dans les produits Fortinet (13 août 2026) Multiple vulnerabilities have been discovered in Fortinet products, including several that could allow for remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various… CERT-FR · Aug 13, 2026 High CVE-2026-26035CVE-2026-49975CVE-2026-70465vulnerabilitypatchremote code execution
vulnerability Multiples vulnérabilités dans les produits Adobe (13 août 2026) Multiple vulnerabilities have been discovered in Adobe products, including Adobe Commerce and ColdFusion. These vulnerabilities allow for remote code execution, privilege escalation, denial of service, and circumvention… CERT-FR · Aug 13, 2026 High CVE-2026-21273CVE-2026-21279CVE-2026-25652vulnerabilitypatchadobe
vulnerability Vulnérabilité dans les produits Foxit (13 août 2026) A vulnerability has been identified in Foxit PDF Editor and Reader software, allowing an attacker to compromise data integrity. Users of older versions of these products are at risk of exploitation. The vendor has releas… CERT-FR · Aug 13, 2026 Medium CVE-2026-18622pdfvulnerabilitydata integrity
vulnerability Multiples vulnérabilités dans Wireshark (13 août 2026) Multiple vulnerabilities have been discovered in Wireshark, allowing an attacker to cause a denial-of-service. These vulnerabilities affect Wireshark versions 4.4.x prior to 4.4.18 and 4.6.x prior to 4.6.8. Users are adv… CERT-FR · Aug 13, 2026 Medium vulnerabilitydenial-of-servicenetwork analysis
vulnerability Multiples vulnérabilités dans Progress MOVEit WAF (13 août 2026) Multiple vulnerabilities have been discovered in Progress MOVEit WAF, allowing attackers to execute arbitrary code remotely, escalate privileges, and bypass security policies. These vulnerabilities affect versions prior… CERT-FR · Aug 13, 2026 Critical CVE-2026-59686CVE-2026-59687CVE-2026-59688vulnerabilityprogressmoveit
threat-intel Multiples vulnérabilités dans les produits Palo Alto Networks (13 août 2026) Multiple vulnerabilities have been discovered in Palo Alto Networks products, including remote code execution, privilege escalation, and denial-of-service attacks. Several CVEs have been identified, impacting various pro… CERT-FR · Aug 13, 2026 High CVE-2026-0291CVE-2026-0292CVE-2026-0293vulnerabilitythreatsecurity
threat-intel Impots.gouv.fr : un pirate revendique une intrusion A French hacker claims to have breached impots.gouv.fr, the French tax authority’s website, and exfiltrated 678,438 lines of data, including highly detailed tax information on French citizens and businesses. The data, pr… ZATAZ · Aug 12, 2026 High FRdata-breachphishingidentity theft
threat-intel Smashing Security podcast #480: This is the AI service you should never sign up to This episode of Smashing Security tackles two distinct cybersecurity concerns: a deceptive AI service offering drastically reduced access to Anthropic's Claude model, and a phishing-as-a-service platform called ‘Greatnes… Graham Cluley · Aug 12, 2026 High phishingaiincels
threat-intel Taïwan visé par une cyberattaque pilotée par IA ? A Taiwanese cybersecurity incident, potentially linked to a Chinese operator, has involved a sophisticated campaign utilizing multiple AI agents to target government systems and critical infrastructure. Researchers at Dr… ZATAZ · Aug 12, 2026 High CHaicyberattackintelligence
threat-intel 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency Taiwan's Nuclear Safety Agency is facing an attack from 'near-autonomous' AI agents, potentially leveraging a programming language developed by a company recently acquired by Qualcomm. This incident highlights the growin… The Register · Aug 12, 2026 High TAIRaicyberattacktaiwan
threat-intel Long-running Data Theft Campaign Targeting Salesforce, ServiceNow The "City-Forum" campaign, active since March 2025, has seen a threat actor targeting Salesforce and ServiceNow instances with custom tools to steal data. Unlike traditional attacks relying on publicly available tools, t… Dark Reading · Aug 12, 2026 High USCAGBsalesforceservicenowguest access