threat-intel Is Cyber missing the Marque? The White House is considering a program allowing private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside the United States, a move that significantly ex… Cisco Talos · Aug 20, 2026 High CHoffensive-cybercybercrimeai
threat-intel Money and Mindset: The Two Biggest Roadblocks to Cyber Policing A Texas law enforcement system was compromised when body camera footage, containing sensitive data, was uploaded to a department server and shared with county officials and prosecutors. This incident highlights the urgen… Dark Reading · Aug 20, 2026 High cybercrimedata breachlaw enforcement
threat-intel ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More This week’s ThreatsDay bulletin highlights a diverse range of security threats, including a Remote Code Execution vulnerability in Gogs, a sophisticated Mabna Institute cyber espionage campaign targeting universities and… The Hacker News · Aug 20, 2026 Critical CVE-2026-52813CVE-2026-52810CVE-2026-43774IRUSrcecyber espionagegit hooks
threat-intel AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure A U.S. government advisory warns of an active threat targeting critical infrastructure organizations, specifically Siemens S7 PLCs, utilizing AI-generated exploit scripts. Threat actors are leveraging internet scanning t… The Hacker News · Aug 20, 2026 High USCHplcindustrial control systemics
threat-intel Surveillance – Everything You Wanted to Know, But Were Afraid to Ask The article explores the increasingly pervasive use of surveillance technologies by various entities – companies, law enforcement, criminals, and intelligence agencies – and the ethical and legal concerns surrounding thi… SecurityWeek · Aug 20, 2026 High surveillanceprivacydata collection
vulnerability Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution A critical security flaw in Zimbra Collaboration (ZCS) has been actively exploited in the wild, allowing attackers to execute arbitrary commands without authentication. The vulnerability, CVE-2026-73570, stems from impro… The Hacker News · Aug 20, 2026 Critical CVE-2026-73570CVE-2025-66376PLsnmpcommand injectionremote code execution
data-breach French tax authority says break-in exposed data of 600K, including some private messages The French tax authority (Direction générale des Finances Publiques - DGFiP) has revealed a data breach that exposed the personal information of approximately 600,000 individuals, including some private messages. The bre… The Register · Aug 20, 2026 Medium FRvulnerabilitydata breachsharepoint
threat-intel Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th) This article details a PowerShell script leveraging the Microsoft Graph API to extract detailed information about Microsoft 365 users, including their last password change date, login activity, and assigned licenses. The… SANS Internet Storm Center · Aug 20, 2026 Medium microsoft graphentaralicense management
threat-intel Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Manic, a sophisticated Android malware, is actively targeting financial institutions and government services across Ukraine, Russia, Central and Western Europe, and the U.K. This malware combines banking malware capabili… The Hacker News · Aug 20, 2026 High UKRUCEandroidbanking malwarespyware
vulnerability NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands A security vulnerability in NASA/JPL's AMMOS Instrument Toolkit's AIT-GUI browser-based operator console allows unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. Researchers at Cycode d… The Hacker News · Aug 20, 2026 High CVE-2026-60112CVE-2026-47731CVE-2026-71214browserauthenticationcommand-injection
threat-intel UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publ… Cisco Talos · Aug 20, 2026 High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOaiautomationpost-exploitation
vulnerability Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler Citrix has announced patches for a critical authentication bypass vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, with a CVSS score of 9.3, allows unauthenticated remote attackers to gain ac… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19490CVE-2026-19489patchauthenticationvulnerability
threat-intel Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks Pakistan's Transparent Tribe, a known advanced persistent threat (APT) group, has been aggressively targeting organizations in Afghanistan and India, utilizing a refined toolset including the Patchcord backdoor and other… Dark Reading · Aug 20, 2026 High AFINPAaptsocial engineeringbrowser hijacking
vulnerability Multiples vulnérabilités dans Microsoft Windows (20 août 2026) Multiple vulnerabilities have been discovered in Microsoft Windows, allowing an attacker to elevate privileges and compromise data confidentiality. These vulnerabilities affect a wide range of Windows versions and server… CERT-FR · Aug 20, 2026 High CVE-2026-62727CVE-2026-69550securitypatchvulnerability
threat-intel ICE boss to agents: Leave the Meta spy glasses at home Several security-related stories are emerging, including a warning about Meta’s spy glasses being used for phishing, a vulnerability exploited in Joomla extensions, and ongoing efforts to combat Iranian propaganda and ra… The Register · Aug 19, 2026 Medium IRcybersecuritythreat intelligencephishing
threat-intel SilkParasite Threatens Central Asian Orgs With Flurry of RATs A Chinese-nexus cyber-espionage group, linked to FamousSparrow and the ShadowPad ecosystem, known as SilkParasite, is targeting government organizations across Central Asia (Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikist… Dark Reading · Aug 19, 2026 High UZTMKGchinaespionagerat
threat-intel Flock surveillance backlash mounts as fiendish Halloween plans circulate Several security-related stories are circulating, including a backlash against surveillance technology from Flock, a method for social engineering AI reasoning engines, a zero-day attack targeting vulnerable SharePoint s… The Register · Aug 19, 2026 Medium CHIRsurveillancephishingvulnerability
threat-intel Latvian officials resign after cyberattack exposes data on 1.2 million people A major cyberattack targeting Latvia’s Road Traffic Safety Directorate (CSDD) has exposed data on approximately 1.2 million people and 200,000 businesses, prompting political turmoil and calls for the agency’s leadership… The Record · Aug 19, 2026 High LVcyberattackdata breachgovernment
threat-intel Comcast gives its Wi-Fi motion detector a security makeover This article highlights a variety of cybersecurity and technology news stories, including a security update for Comcast's Wi-Fi motion detector, a method for social engineering AI reasoning engines, and ongoing efforts t… The Register · Aug 19, 2026 Medium IRsecurityphishingransomware
threat-intel SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs A previously unreported cyber espionage campaign, dubbed SilkParasite, is targeting government bodies in Central Asia, utilizing a set of five new remote access tool (RAT) families. The operation, linked to China, employ… The Hacker News · Aug 19, 2026 High CHKATAcyber espionagedll sideloadingremote access tool