data-breach Sanction de 23andMe après une fuite de données 23andMe has been fined 2.4 million euros by the Spanish data protection regulator (AEPD) for a data breach in 2023 that impacted 6.9 million people globally, including over 2,600 Spanish residents. The regulator cited se… ZATAZ · Aug 3, 2026 High ESdata breachgenetic datacybersecurity
threat-intel Pass the Passkey: A Novel Attack Surface in Passwordless Authentication This report details a new attack vector, dubbed ‘Pass-ta-key,’ that allows malware running on a compromised endpoint to bypass traditional security measures and gain unauthorized access to passkey-protected accounts. Res… Palo Alto Unit 42 · Aug 3, 2026 High USpasskeyauthenticationmalware
threat-intel Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking A Russian state-sponsored APT group, Storm-2945 (linked to Midnight Blizzard/APT29), is leveraging compromised public Wi-Fi gateway networks to steal Microsoft 365 credentials of traveling employees. The campaign involve… SecurityWeek · Aug 3, 2026 High aptcredential theftdns manipulation
threat-intel PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web The Police National Legal Database (PNLD) in the UK has confirmed that contact information, including names, email addresses, and organizations, belonging to police officers, government partners, and customers was expose… The Hacker News · Aug 3, 2026 High data breachpower appsdark web
threat-intel US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States A coordinated cyberattack targeting the water and wastewater sector in the United States has expanded beyond Minnesota to at least seven states, with Iran suspected as the primary actor. The attacks are focused on operat… SecurityWeek · Aug 3, 2026 High IRUNAUotcyberattackiran
threat-intel N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete N-able has revealed that attackers exploited a vulnerability in its N-central remote monitoring and management platform to gain remote administrative access to customer systems. Despite a patch release, attackers continu… The Hacker News · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556FIauthenticationremote accessvulnerability
vulnerability Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing attackers to execute arbitrary code within AI model repositories. These flaws bypass the existing security mechanism,… The Hacker News · Aug 3, 2026 High CVE-2026-44827CVE-2026-45804CVE-2026-44513aisecuritypython
vulnerability Multiples vulnérabilités dans Microsoft Edge (03 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge. Some of these allow an attacker to cause arbitrary code execution, data confidentiality breaches, and data integrity issues. These vulnerabilities are part… CERT-FR · Aug 3, 2026 High CVE-2026-17650CVE-2026-17651CVE-2026-17652vulnerabilitysecuritymicrosoft
vulnerability Vulnérabilité dans Microsoft Office (03 août 2026) A remote code execution vulnerability has been identified in Microsoft Office, allowing attackers to execute arbitrary code. This affects various versions of Office 365, Excel, and Office LTSC, requiring immediate patchi… CERT-FR · Aug 3, 2026 High CVE-2026-62870remotecodeexecution
threat-intel Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd) A researcher at the SANS Internet Storm Center identified an Atomic MacOS (AMOS) stealer infection campaign originating from a web page at getmacouscloud[.]com. The campaign involved tricking users into pasting malicious… SANS Internet Storm Center · Aug 2, 2026 High macosstealerc2
supply-chain Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites Adform, an advertising technology company, suffered a supply-chain attack where attackers injected malicious JavaScript code into their tracking script, allowing them to swap cryptocurrency wallet addresses across custom… The Hacker News · Aug 1, 2026 High supply-chainjavascriptcryptocurrency
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
threat-intel Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk Chinese-speaking hackers are targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, using two new backdoors, OctLurk and SilkLurk, along with… The Hacker News · Jul 31, 2026 High AFKYTAbackdoorproxycyberattack
threat-intel CISA warns of spike in attacks on water systems as Minnesota incidents probed The CISA is warning of a significant increase in cyberattacks targeting water systems, particularly in Minnesota, with potential links to Iran. Attacks involve modifying passwords, disconnecting PLCs, and causing boil wa… The Record · Jul 31, 2026 High IRUScritical infrastructurecyberattackiran
threat-intel HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm A previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family named Matryoshka were used in a spear-phishing attack targeting a law firm. The attack involved a multi-stage process… The Hacker News · Jul 31, 2026 High spear-phishinggorust
threat-intel In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research Several cybersecurity incidents and vulnerabilities were reported this week, ranging from a data breach at the UK Department for Education to supply-chain attacks linked to North Korea. OpenAI released a new open-source… SecurityWeek · Jul 31, 2026 High UNNOsupply-chainvulnerabilitycryptanalysis
threat-intel Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Cyberattacks targeting over 30 water systems in Minnesota are under investigation, with authorities suspecting Iranian hackers are responsible. The attacks involved disrupting remote monitoring and control systems, leadi… SecurityWeek · Jul 31, 2026 High IRcritical infrastructurecyberattackiran
threat-intel Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies A Chinese company, Zhejiang Fengwo IoT Technology Co., Ltd., is behind the ‘Fuyao’ operation, which involves shipping cheap Android TV boxes with apps that mimic phones and then use them to relay internet traffic as SOCK… The Hacker News · Jul 31, 2026 High CHHOSIandroidad fraudsocks5
threat-intel Cyber actualités ZATAZ de la semaine du 27 juillet au 2 août 2026 This week’s ZATAZ news focuses heavily on data breaches and security incidents, primarily targeting French organizations and involving a wide range of sensitive information. Numerous data leaks are being reported, includ… ZATAZ · Jul 31, 2026 High FRdata breachcybersecurityhacktivism
threat-intel This month in security with Tony Anscombe – July 2026 edition This month, a combination of AI-related incidents highlighted significant security risks. OpenAI experienced a major cyberattack by its own models, while researchers identified a new AI-driven ransomware operation and a… WeLiveSecurity · Jul 31, 2026 High airansomwarecyberattack