vulnerability Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows A Microsoft-based hacker has developed a new zero-day vulnerability in on-prem SharePoint, allowing them to gain system privileges on fully patched Windows systems. This represents a significant security risk, as it bypa… The Register · Aug 12, 2026 High CVE-2026-50656CVE-2026-33825CVE-2026-41091zero-daysharepointvulnerability
vulnerability SharePoint Vulnerability Exploited Shortly After PoC Release A SharePoint vulnerability, patched last month, is now being actively exploited in the wild, with attackers leveraging a publicly released proof-of-concept. This follows a series of similar vulnerabilities discovered thi… SecurityWeek · Aug 12, 2026 High CVE-2026-55040CVE-2026-63520CVE-2026-50522sharepointvulnerabilityexploitation
threat-intel Ceva Logistics Operations Disrupted by Cyberattack Ceva Logistics, a major shipping and logistics firm, has experienced a significant cyberattack that disrupted operations across eight European warehouses. The attack has impacted numerous downstream customers, including… SecurityWeek · Aug 12, 2026 High NLdata breachcyberattacklogistics
threat-intel ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 12, 2026 High phishingransomwaresupply chain
vulnerability Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688… The Hacker News · Aug 11, 2026 High CVE-2026-68820CVE-2026-62878CVE-2026-62893zero-dayrceexploit
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
threat-intel Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers Security researchers simulated a cryptocurrency startup and hired three individuals they believe were North Korean operatives to test recruitment processes and identify potential risks. The operation involved sophisticat… The Hacker News · Aug 11, 2026 High USNOnorth korearecruitmentidentity theft
threat-intel Multiples vulnérabilités dans les produits SAP (11 août 2026) Multiple vulnerabilities have been discovered in SAP products, including remote code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities can be exploited to cause significant damage.… CERT-FR · Aug 11, 2026 High CVE-2025-42947CVE-2025-58057CVE-2026-33871vulnerabilitysapsecurity
supply-chain China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns China-linked hackers, believed to be part of the Storm-1175 group, are exploiting a critical vulnerability in N-central, a remote monitoring and management (RMM) tool, to deploy ransomware. This supply-chain attack is le… The Record · Aug 10, 2026 High CVE-2026-18577CHsupply-chainransomwarezero-day
vulnerability Critical Flaws Discovered in Belgian eID Software Used by 2 Million People A critical vulnerability in Nitro Software Belgium’s Connective digital identity system, used by over two million people in Belgium, allowed attackers to steal sensitive data and forge electronic signatures. The flaw was… SecurityWeek · Aug 10, 2026 High BEdigital identityeidbrowser extension
threat-intel Rançongiciels : 43 revendications ciblent la France Between July 1st and August 8th, 43 French organizations were targeted in cybercriminal extortion claims, with a strong concentration among several ransomware-as-a-service groups. The Gentlemen and Qilin were the most ac… ZATAZ · Aug 8, 2026 High FRransomwarecybercrimeextortion
threat-intel Un pirate plaide coupable après 165 piratages A Canadian man, Connor Riley Moucka, has pleaded guilty to a massive cloud-based hacking and extortion scheme targeting over 165 organizations. Between February and October 2024, his group exploited stolen credentials to… ZATAZ · Aug 8, 2026 High CAUNSPcloud-securitycredential-theftextortion
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Several significant cybersecurity events are unfolding this week, including a coordinated AI-powered scam network originating in Cambodia, a data breach at Amgen, a supply chain attack targeting QuickFox VPN, and a serie… SecurityWeek · Aug 7, 2026 High CHCAUSsupply-chainphishingransomware
threat-intel Commerce pirate : un cybercriminel vend des dizaines de téraoctets de données A cybercriminal is offering a massive stock of personal and corporate data, spanning over 25 countries and multiple sensitive categories, for sale. The offering includes over 100,000 distinct datasets, encompassing phone… ZATAZ · Aug 7, 2026 High FRGEUNdata breachcybercrimedata theft
threat-intel ICE Is Buying Access to Credit Card Records The U.S. Department of Homeland Security’s Intelligence and Operations (I&O) division is reportedly purchasing access to credit card transaction data from a private company, effectively giving them a massive window into… Schneier on Security · Aug 7, 2026 High surveillanceprivacydata-collection
threat-intel AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day An AI-powered research tool, HTTP Terminator, developed by PortSwigger, autonomously discovered several novel HTTP desynchronization techniques, including a zero-day vulnerability in Apache Traffic Server. The tool, usin… The Hacker News · Aug 7, 2026 High CVE-2026-63078UShttpdesyncrqt
vulnerability ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Aug 7, 2026 Critical activemqvulnerabilityremote code execution
threat-intel Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Graham Cluley recounts a bizarre experience where he was contacted by someone posing as a police detective investigating a cybercrime. The individual claimed to have evidence suggesting they possessed a 24-word seed key… Graham Cluley · Aug 5, 2026 High cryptocurrencyhardware walletphishing
threat-intel AI Sends Global Crime Syndicates Into Fraud Nirvana AI is dramatically accelerating and industrializing fraud operations globally, enabling organized crime syndicates to bypass traditional security measures and create highly convincing synthetic identities and impersonati… Dark Reading · Aug 5, 2026 High AUNICAaifraudkyc