threat-intel OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber OpenAI has released GPT-5.6-Cyber, a new AI model specifically designed for advanced cybersecurity tasks, including finding zero-days and creating exploit chains. This model addresses limitations of its predecessor, GPT-… SecurityWeek · Aug 11, 2026 High aicybersecurityvulnerability
threat-intel Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G This article discusses a security vulnerability where malicious actors are exploiting SIM cards to disable phones, steal data, and potentially downgrade connections to 2G, enabling more sophisticated phishing attacks. Th… The Register · Aug 11, 2026 High CVE-2025-48618CHRUsim cardphishingtelecom security
ransomware Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain… The Hacker News · Aug 11, 2026 High CVE-2024-5559CVE-2025-24472SOBRSPransomwarevulnerabilitysupply-chain
threat-intel Steam : une fuite chez CEVA expose des clients européens A data breach at CEVA Logistics, a logistics provider for Steam, has exposed customer delivery data, including names, addresses, phone numbers, and order details. This exposes Steam users, particularly in Europe, to targ… ZATAZ · Aug 11, 2026 High DEdata breachphishingsupply chain
threat-intel Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Polish power plant operators suffered a significant cyberattack that led to the shutdown of a steam turbine and process-water treatment system. The attack exploited a private cellular network used by the grid operator to… The Hacker News · Aug 11, 2026 High CVE-2023-32349CVE-2023-32350PLprivate apnindustrial control systemscyberattack
supply-chain Mozilla Issues New Firefox GPG Key Following Exposure Mozilla has revoked a compromised GPG signing key used for Firefox and Thunderbird, following its accidental exposure in a GitHub repository. While the immediate risk was mitigated due to limited access, the incident hig… SecurityWeek · Aug 11, 2026 Medium gpgsupply-chainkey-rotation
supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The att… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss
vulnerability ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Aug 11, 2026 Critical log4jrcevulnerability
vulnerability Vulnérabilité dans Docker (11 août 2026) A vulnerability has been identified in Docker Desktop, allowing an attacker to compromise data integrity. Users of versions prior to 4.86.0 should immediately update to mitigate the risk. CERT-FR · Aug 11, 2026 Medium CVE-2026-17106dockervulnerabilitysecurity
vulnerability Multiples vulnérabilités dans SPIP (11 août 2026) A series of vulnerabilities have been discovered in SPIP, a popular French content management system. These include remote code execution, SQL injection, and server-side request forgery, impacting versions prior to 4.4.1… CERT-FR · Aug 11, 2026 Medium vulnerabilitysql-injectionssrf
vulnerability Multiples vulnérabilités dans Postfix (11 août 2026) Multiple vulnerabilities have been discovered in Postfix, potentially allowing attackers to cause a denial-of-service, bypass security policies, and create an unspecified security issue. Users of Postfix versions prior t… CERT-FR · Aug 11, 2026 Medium vulnerabilitymail serversecurity
vulnerability Vulnérabilité dans CPython (11 août 2026) A denial-of-service vulnerability has been identified in CPython, allowing an attacker to disrupt remote systems. The vulnerability stems from a lack of recent security updates and requires immediate patching to prevent… CERT-FR · Aug 11, 2026 Medium CVE-2026-18503pythondenial-of-servicevulnerability
vulnerability Multiples vulnérabilités dans OpenSSH (11 août 2026) Multiple vulnerabilities have been discovered in OpenSSH, impacting versions prior to 10.5. The exact nature of the security issue is not specified by the publisher, but users are advised to consult the vendor's security… CERT-FR · Aug 11, 2026 Medium sshvulnerabilitysecurity
threat-intel Multiples vulnérabilités dans les produits SAP (11 août 2026) Multiple vulnerabilities have been discovered in SAP products, including remote code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities can be exploited to cause significant damage.… CERT-FR · Aug 11, 2026 High CVE-2025-42947CVE-2025-58057CVE-2026-33871vulnerabilitysapsecurity
threat-intel Deux pirates revendiquent le piratage de pro du Cloud Two hackers, Misere and Chimeraz, claim to have breached BlgCloud, a French cloud software provider, gaining access to approximately 159 client environments and allegedly stealing sensitive professional data. They are no… ZATAZ · Aug 10, 2026 High FRdata breachextortioncloud security
threat-intel Cars.no : une fuite revendiquée expose 148 288 automobilistes A Norwegian security researcher claims to have discovered a publicly accessible database belonging to Cars Software, an automotive software provider used by over 500 garages, dealerships, and wholesalers in Norway. The d… ZATAZ · Aug 10, 2026 High NOdatabasephishingdata breach
threat-intel Des kiosques Pokémon exposés par une fuite Firebase A clandestine publication alleges that a US-based automated distribution operator exposed sensitive data – including bank details, email addresses, source code, and technical access – across multiple continents via expos… ZATAZ · Aug 10, 2026 High USJPAUdata breachapiauthentication
threat-intel Un phishing Ameli qui observe avant de frapper This article details a sophisticated phishing campaign mimicking the French Assurance Maladie (health insurance) to steal user data and potentially launch further attacks. The campaign uses a layered approach, including… ZATAZ · Aug 10, 2026 High FRINphishingsocial engineeringcloaking
threat-intel The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications Aeternum is a newly discovered blockchain-based botnet loader utilizing the Polygon blockchain for command and control. Instead of relying on traditional servers, threat actors use smart contracts to issue encrypted inst… Palo Alto Unit 42 · Aug 10, 2026 High blockchainc2polygon
threat-intel 'GhostJacking' Exposes Identity Governance Gaps in AI Agents Researchers at Tenet Security have demonstrated a significant vulnerability in AI agents, dubbed ‘GhostJacking,’ where attackers can manipulate security alerts and logs to trick agents into executing malicious commands a… Dark Reading · Aug 10, 2026 High aiartificial intelligenceagentjacking