vulnerability Exposed: Woeful security at UK criminal records office that led to sensitive data leak A security vulnerability in Joomla extensions has been exploited to compromise numerous websites, highlighting a broader issue of security weaknesses within open-source CMS platforms. This incident underscores the ongoin… The Register · Aug 12, 2026 Medium joomlavulnerabilityopen-source
threat-intel Akira ransomware scum blocked victim's security tools – and broke their own encryptor Russian threat actors are impersonating Signal support to conduct phishing attacks, targeting users to steal their information. This follows a trend of Iranian propaganda sites being taken down by the US, and a marketing… The Register · Aug 12, 2026 Medium IRRUphishingthreat intelligencesocial engineering
threat-intel Brit rail cops bring live facial recognition to the London Underground A security report highlighted a vulnerability where malicious actors are exploiting extension bugs in Joomla websites, allowing them to launch phishing attacks by impersonating Signal support. This follows a broader tren… The Register · Aug 12, 2026 Medium joomlaphishingvulnerability
vulnerability Multiples vulnérabilités dans Microsoft Edge (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing an attacker to trigger arbitrary code execution and a security issue not specified by the vendor. These vulnerabilities are part of a larger set o… CERT-FR · Aug 12, 2026 High CVE-2026-19137CVE-2026-19138CVE-2026-19139vulnerabilitysecuritymicrosoft
threat-intel Signal adds an extra layer of security to make sure you're actually chatting with the right person A phishing campaign is underway where attackers are impersonating Signal support to trick users into revealing their information. This follows a broader trend of security vulnerabilities being exploited in open-source so… The Register · Aug 11, 2026 Medium phishingjoomlavulnerability
threat-intel Microsoft's Patch Tuesday Deluge Continues With August Updates Microsoft released a substantial security update this month, addressing 421 unique CVEs, including two zero-day vulnerabilities. A significant portion of these – 236 affecting Windows and 98 affecting Office – require im… Dark Reading · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62878patch-tuesdayvulnerabilityzero-day
vulnerability Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688… The Hacker News · Aug 11, 2026 High CVE-2026-68820CVE-2026-62878CVE-2026-62893zero-dayrceexploit
threat-intel Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by ut… The Hacker News · Aug 11, 2026 High botnetddosadb
threat-intel Two wars and a World Cup lead to epic DDoS attacks on publishers This article covers a range of cybersecurity and technology news, including a phishing campaign targeting Signal users, a zero-day exploit affecting on-prem SharePoint, and a vulnerability impacting Joomla extensions. It… The Register · Aug 11, 2026 Medium IRphishingvulnerabilitycybersecurity
threat-intel Deepfake hiccup unmasks suspected digital certificate fraudster This article discusses a potential digital certificate fraud scheme linked to deepfake technology, where Russian actors are impersonating Signal support to launch phishing attacks. The vulnerability stems from flaws in J… The Register · Aug 11, 2026 Medium RUdeepfakephishingjoomla
threat-intel Kids’ online safety bill faces dim prospects of passage this session despite progress The Kids Online Safety Act (KOSA), a landmark bill aimed at increasing online safety for children, faces significant obstacles in Congress, particularly regarding a ‘duty of care’ provision requiring companies to take re… The Record · Aug 11, 2026 High UNonline safetychildrenfirst amendment
supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The att… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss
vulnerability Multiples vulnérabilités dans SPIP (11 août 2026) A series of vulnerabilities have been discovered in SPIP, a popular French content management system. These include remote code execution, SQL injection, and server-side request forgery, impacting versions prior to 4.4.1… CERT-FR · Aug 11, 2026 Medium vulnerabilitysql-injectionssrf
vulnerability Multiples vulnérabilités dans Postfix (11 août 2026) Multiple vulnerabilities have been discovered in Postfix, potentially allowing attackers to cause a denial-of-service, bypass security policies, and create an unspecified security issue. Users of Postfix versions prior t… CERT-FR · Aug 11, 2026 Medium vulnerabilitymail serversecurity
threat-intel Une fausse lettre AR24 vole les identifiants mail This article details a phishing campaign mimicking AR24 to steal email credentials. The attackers use a fake ‘letter of recommendation’ email with a fabricated ‘invoice due’ to create a sense of urgency and trick victims… ZATAZ · Aug 10, 2026 High phishingsocial engineeringcredential theft
threat-intel British ‘Com’ member who abused more than 100 girls worldwide jailed for two years A 20-year-old British man, Justin Swaddle, was sentenced to two years in prison for abusing and manipulating over 100 girls worldwide through online platforms, primarily Snapchat, Telegram, and Discord. He was part of a… The Record · Aug 10, 2026 High UKUSCAonline-abusechild-exploitationcybercrime
threat-intel Claude Code puts auto mode in the driver's seat Several security incidents and developments are highlighted, including a vulnerability in Joomla extensions, a Microsoft SharePoint issue leading to a zero-day attack, and ongoing efforts to combat Iranian propaganda and… The Register · Aug 10, 2026 Medium IRUSvulnerabilityphishingransomware
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Un milliard d’identifiants français sur le darkweb A massive collection of over 1.7 billion unique French email addresses and passwords has been discovered on the dark web, originating from 13 years of phishing campaigns and data breaches. The data, totaling 28GB across… ZATAZ · Aug 8, 2026 High FRcredential stuffingphishingdata breach
threat-intel Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Several security-related stories are emerging, including a focus on AI security and vulnerabilities, a Russian phishing campaign mimicking Signal support, and ongoing efforts to improve security across various Linux and… The Register · Aug 8, 2026 Medium RUIRaisecurityphishing