threat-intel CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign The CISA has ordered federal agencies to patch a critical Windows vulnerability being actively exploited by North Korean hackers as part of Operation ‘Dream Job’. This campaign, led by the Lazarus Group, impersonates rec… The Record · Aug 12, 2026 Critical CVE-2026-68820FRGEBRzero-daynorth koreaoperation dream job
threat-intel Siemens RUGGEDCOM APE1808 A CISA advisory, in collaboration with Siemens ProductCERT, highlights vulnerabilities in Siemens RUGGEDCOM APE1808 devices when used with Fortinet NGFW. These vulnerabilities, including Cross-Site Scripting and Path Tra… CISA Advisories · Aug 12, 2026 High CVE-2026-23573CVE-2026-59839GEindustrial control systemscwe-79cwe-22
threat-intel OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning Researchers have discovered a significant vulnerability in OpenAI, Anthropic, and Google's AI APIs that allows weaker AI models to decode the reasoning processes of stronger models by replaying encrypted reasoning blocks… The Hacker News · Aug 12, 2026 High encryptionapiprompt injection
threat-intel Enterprise Defenses Recovered at the Edge and Collapsed Inside A new report from Picus Labs reveals a concerning trend in cybersecurity defenses: while overall prevention effectiveness has improved, defenses are significantly weaker *inside* a network, failing to stop quiet, reconna… The Hacker News · Aug 12, 2026 High detectionloggingreconnaissance
threat-intel Ceva Logistics Operations Disrupted by Cyberattack Ceva Logistics, a major shipping and logistics firm, has experienced a significant cyberattack that disrupted operations across eight European warehouses. The attack has impacted numerous downstream customers, including… SecurityWeek · Aug 12, 2026 High NLdata breachcyberattacklogistics
threat-intel Brit rail cops bring live facial recognition to the London Underground A security report highlighted a vulnerability where malicious actors are exploiting extension bugs in Joomla websites, allowing them to launch phishing attacks by impersonating Signal support. This follows a broader tren… The Register · Aug 12, 2026 Medium joomlaphishingvulnerability
vulnerability Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws Adobe has released critical security patches to address multiple vulnerabilities in ColdFusion, Commerce, and Campaign Classic. These flaws could lead to arbitrary code execution and privilege escalation, and while no ex… The Hacker News · Aug 12, 2026 Critical CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined Intel and AMD released patches addressing over 80 vulnerabilities across their products, including fixes for privilege escalation, denial-of-service attacks, and information disclosure. The updates cover a wide range of… SecurityWeek · Aug 12, 2026 High patch tuesdayvulnerabilitiessecurity
threat-intel Prompt Injections for Defense Researchers discovered a method called ‘context bombing’ where strategically placing prompt injections alongside sensitive data (like passwords and keys) can effectively disable AI hacking agents. This works by forcing t… Schneier on Security · Aug 12, 2026 Medium prompt-injectionai-securityguardrails
supply-chain Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner,… SecurityWeek · Aug 12, 2026 High supply chainaicredentials
threat-intel Santé publique France visée par une cyberattaque ? A French cybersecurity news outlet reported a potential cyberattack against Santé publique France, a public health agency. A hacker, operating under the pseudonym Cybernox and associates, claimed to have gained administr… ZATAZ · Aug 12, 2026 High FRcyberattackdata breachhealthcare data
vulnerability Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-59310) in Broadcom VMware vCenter to gain persistent remote access. QUIRSO discovered a campaign involving 361 unique victim IP ad… The Hacker News · Aug 12, 2026 High CVE-2026-59310CVE-2026-59309GEUNTUvulnerabilityexploitreverse_ssh
threat-intel Fresh Windows Zero-Day Exploited in North Korean Cyberattacks North Korean hackers, operating under the Lazarus Group, are exploiting a recently patched Windows zero-day vulnerability (CVE-2026-68820) to conduct targeted attacks against defense, aerospace, and aviation organization… SecurityWeek · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daylazarus groupcyber espionage
vulnerability Ivanti EPM Update Patches Remotely Exploitable Flaws Ivanti has released patches to address four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. Two of the EPM flaws are remotely exploitable, allowing attackers to steal credentials and gain cont… SecurityWeek · Aug 12, 2026 High CVE-2026-18129CVE-2026-18125CVE-2026-18127vulnerabilitypatchremote
supply-chain Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially ex… The Hacker News · Aug 12, 2026 High CVE-2026-33634USEUsupply chaincredential theftpypi
vulnerability ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Several major industrial automation vendors – Siemens, Schneider Electric, and Phoenix Contact – released security patches to address critical vulnerabilities in their ICS products. These flaws could allow attackers to e… SecurityWeek · Aug 12, 2026 High icsindustrial control systemspatch tuesday
vulnerability SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a critical security flaw in its Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability stems from insufficient autho… The Hacker News · Aug 12, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-34265securitypatcharbitrary code execution
vulnerability SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform SonicWall has released patches to address eight critical vulnerabilities in its discontinued GMS platform and Email Security products. These flaws, including remote code execution and command injection, could allow attac… SecurityWeek · Aug 12, 2026 Critical CVE-2026-66147CVE-2026-66145CVE-2026-66149vulnerabilitypatchrce
vulnerability ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access A security researcher, Chaotic Eclipse, has released a proof-of-concept (PoC) demonstrating a patch bypass for a Microsoft Defender zero-day vulnerability, dubbed ShieldBreak. This vulnerability, CVE-2026-50656 (RoguePla… The Hacker News · Aug 12, 2026 High CVE-2026-50656CVE-2026-62832CVE-2026-68820zero-daypatch-bypassprivilege escalation
vulnerability Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS A critical vulnerability (CVE-2026-20349, CVSS: 8.6) in Cisco ASA and FTD software has been actively exploited in the wild. This flaw, triggered by a crafted HTTP request, can lead to a denial-of-service condition and is… The Hacker News · Aug 12, 2026 Critical CVE-2026-20349cveasaftd