threat-intel AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls An AI meeting assistant, tl;dv, is vulnerable due to a misconfiguration in its Firebase environment, allowing unauthorized access to users' video calls and meeting data. A security researcher discovered that users could… Dark Reading · Aug 4, 2026 High MAUKBRfirebaseaimeeting assistant
threat-intel Apple launches new legal challenge against UK over iCloud access Apple is challenging the UK government’s legal demands for access to user data stored on iCloud, specifically related to a Technical Capability Notice (TCN) that requires Apple to retain the ability to access iCloud cont… The Record · Aug 4, 2026 High UKUSencryptiondata-privacylaw-enforcement
threat-intel Almost Half of Malware Samples Communicate Direct to IP Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including… Palo Alto Unit 42 · Aug 4, 2026 High BRd2ipdnsc2
vulnerability Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected The Swiss Federal Office for Information Technology and Communications (BIT) was hacked, with approximately 200 accounts compromised due to vulnerabilities in on-premises Microsoft SharePoint servers. Hackers exploited k… The Record · Aug 4, 2026 High SWsharepointvulnerabilityiis
threat-intel How legitimate cloud platforms enable phishers to bypass MFA Threat actors are increasingly leveraging legitimate cloud platforms – like Cloudflare, Vercel, Netlify, and GitHub Pages – to conduct sophisticated phishing attacks. These attacks utilize multi-stage adversary-in-the-mi… Securelist · Aug 4, 2026 High phishingaitmbitb
vulnerability Thermo Fisher Applied Biosystems Genetic Analyzers Thermo Fisher Scientific has issued a security advisory regarding vulnerabilities in its Applied Biosystems Genetic Analyzers, specifically the data collection software and instrument software. These vulnerabilities coul… CISA Advisories · Aug 4, 2026 High CVE-2026-17583vulnerabilitydnadata manipulation
vulnerability TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Researchers at Forescout discovered 15 vulnerabilities in TP-Link’s Omada networking ecosystem’s zero-touch provisioning (ZTP) system, allowing attackers to potentially take over entire networks by chaining together thes… SecurityWeek · Aug 4, 2026 High CVE-2025-7850CVE-2025-7851ztpnetworkvulnerability
threat-intel When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted Generative AI is lowering the barrier to entry for cyberattacks, allowing individuals with limited technical expertise to rapidly learn and adapt attack techniques. This shift is changing the dynamics of offensive securi… The Hacker News · Aug 4, 2026 High aicyberattackoffensive security
threat-intel Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent Google removed three AI agent workflows from its ADK Python repository after a public GitHub issue allowed a malicious bot to trigger a privileged code-fixing agent, leading to potential code execution and credential exp… The Hacker News · Aug 4, 2026 High botcredential exposuregit
vulnerability Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering A vulnerability in Google’s Agent Development Kit (ADK) for Python allowed an attacker to manipulate low-privileged agents to gain access to high-privilege capabilities, potentially leading to pull request poisoning and… SecurityWeek · Aug 4, 2026 High agent-to-agentpull request poisoningremote code execution
threat-intel “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Cisco Talos researchers have discovered that threat actors are increasingly leveraging artificial intelligence (AI) to significantly enhance their malicious capabilities, bypassing traditional safeguards and exhibiting a… Cisco Talos · Aug 4, 2026 High aiartificial intelligencethreat intelligence
vulnerability Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks A 22-year-old vulnerability in BMC management processors is exposing thousands of data centers to attack. The flaw allows attackers to retrieve password hashes and crack them offline, potentially gaining unauthorized acc… SecurityWeek · Aug 4, 2026 High CVE-2013-4786bmcipmipassword cracking
threat-intel DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution… The Hacker News · Aug 4, 2026 High RUsteganographyclickfixransomware
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
data-breach 150,000 Impacted by Madera Community Hospital Data Breach Madera Community Hospital in California experienced a data breach affecting over 150,000 individuals, exposing sensitive personal and financial information. The attackers initially demanded a ransom, which they subsequen… SecurityWeek · Aug 4, 2026 High USdata breachhealthcarecybersecurity
threat-intel CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its KEV catalog due to active exploitation. This flaw, stemming from incomplete patching of… The Hacker News · Aug 4, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875GEICSWvulnerabilityremote monitoringremote management
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
vulnerability Vulnérabilité dans les produits Check Point (04 août 2026) A vulnerability has been identified in Check Point’s security products, allowing attackers to execute arbitrary code remotely and bypass security policies. This affects older versions of their Multi-Domain Security Manag… CERT-FR · Aug 4, 2026 High CVE-2026-18574vulnerabilityremote code executionsecurity policy
vulnerability Multiples vulnérabilités dans les produits Tenable (04 août 2026) Multiple vulnerabilities have been discovered in Tenable products, including vulnerabilities that could lead to arbitrary code execution, data integrity compromise, and SQL injection attacks. These vulnerabilities span a… CERT-FR · Aug 4, 2026 High CVE-2025-11187CVE-2025-14179CVE-2025-15467vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans LibreNMS (04 août 2026) Multiple vulnerabilities have been discovered in LibreNMS, allowing attackers to execute arbitrary code remotely, perform server-side request forgery (SSRF), and inject code remotely via XSS. These vulnerabilities affect… CERT-FR · Aug 4, 2026 High CVE-2026-45694librenmsvulnerabilitycve