threat-intel Une fausse lettre AR24 vole les identifiants mail This article details a phishing campaign mimicking AR24 to steal email credentials. The attackers use a fake ‘letter of recommendation’ email with a fabricated ‘invoice due’ to create a sense of urgency and trick victims… ZATAZ · Aug 10, 2026 High phishingsocial engineeringcredential theft
threat-intel Multistate Water System Attacks Widen, Iran Suspected A coordinated campaign targeting water and wastewater systems across multiple states is underway, potentially linked to Iran and the CyberAv3ngers hacktivist group. Threat actors are exploiting poorly secured PLCs – indu… Dark Reading · Aug 10, 2026 High IRplccyberattackcritical infrastructure
threat-intel DEF CON hackers add new muscle to water utility protection DEF CON hackers are focusing on bolstering water utility protection by leveraging their skills to identify and address vulnerabilities in critical infrastructure. This initiative follows successful 'Voting Village' proje… The Register · Aug 10, 2026 Medium cybersecurityinfrastructurevulnerabilities
vulnerability Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius A zero-day SQL-injection vulnerability in Metabase Cloud is actively being exploited, potentially impacting a wide range of organizations beyond Metabase customers. The vulnerability allows remote attackers to gain admin… Dark Reading · Aug 10, 2026 High sql-injectionzero-dayvulnerability
threat-intel Une nouvelle fuite pour la FF Handball ? A hacker claims to have compromised an internal tool of the French Handball Federation (FFHB), exposing over 1.3 million lines of data and sensitive documents, including IDs, passports, and medical records. The hacker in… ZATAZ · Aug 10, 2026 High FRdata breachcredential stuffingdata leak
threat-intel À vendre : les coulisses d’un empire du pari A cybersecurity news platform has uncovered a pattern of suspicious activity by a single online seller offering access to vast databases of gambling-related data, including player information, casino prospects, and crypt… ZATAZ · Aug 10, 2026 High AZGEINdata-breachthreat-intelgambling
threat-intel Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres Meta's Ray-Ban smart glasses are facing increasing bans in venues across the UK due to concerns about covert surveillance. The glasses, which resemble ordinary spectacles, can record audio and video, and a recent investi… Graham Cluley · Aug 10, 2026 High UKKESWprivacysurveillanceai
threat-intel FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure The FBI and South Korea’s government have issued a cybersecurity advisory warning of the Gunra ransomware gang, which is exploiting vulnerabilities in Fortinet firewalls to target critical infrastructure organizations gl… The Record · Aug 10, 2026 High CVE-2024-55591CVE-2025-24472SONOransomwarevulnerabilitysupply-chain
threat-intel The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists The article highlights a significant gap between the speed at which attackers discover and exploit vulnerabilities and the speed at which defenders can patch them. Traditional CVSS-based prioritization is inadequate beca… Dark Reading · Aug 10, 2026 High CVE-2024-9474CVE-2024-0012vulnerabilityattack-pathchoke-point
threat-intel North Korean spies are running local LLMs to cause AI mischief North Korean intelligence operatives are leveraging locally hosted Large Language Models (LLMs) to conduct sophisticated disinformation campaigns and potentially cause broader AI-related mischief. This indicates a growin… The Register · Aug 10, 2026 Medium NOaillmcyberespionage
threat-intel Coruna, DarkSword iOS Exploits Proliferate Globally Sophisticated iPhone exploit chains, DarkSword and Coruna, are rapidly spreading beyond nation-state actors and into the hands of organized cybercrime groups. These advanced tools, initially developed for surveillance an… Dark Reading · Aug 10, 2026 High CVE-2025-31277CVE-2025-43529CVE-2026-20700CHMASAexploitioscybercrime
threat-intel Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list A user exploited a waitlist API for a gym class booking service by prompting an AI agent to bypass the normal process, demonstrating a vulnerability in how AI systems can be manipulated to access and abuse online service… The Register · Aug 10, 2026 Medium aiautomationsecurity
threat-intel China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw China-linked threat actor Storm-1175 has deployed a new ransomware strain, StormEncryptor, leveraging a vulnerability in N-able N‑central to gain initial access and subsequently deploy ransomware. This follows a pattern… The Hacker News · Aug 10, 2026 High CVE-2026-18577CVE-2026-18556CVE-2023-37679CHransomwarevulnerabilitypatch-bypass
threat-intel Outdated Cybercrime Laws Put Security Researchers at Risk Security researchers in the UK and globally face legal risks due to outdated cybercrime laws that don't differentiate between malicious hacking and responsible vulnerability research. Katharina Sommer, of NCC Group, has… Dark Reading · Aug 10, 2026 Medium UKPOARvulnerability researchcybersecurity lawethical hacking
threat-intel Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th) The SANS Internet Storm Center is observing a scanning campaign targeting Solana infrastructure, likely conducted by automated tools. These scans are attempting to enumerate Solana API endpoints and potentially extract c… SANS Internet Storm Center · Aug 10, 2026 Medium solanascanningreconnaissance
threat-intel Sherlock Holmes was the “OG” Social Engineer This article draws parallels between the social engineering techniques of Sir Arthur Conan Doyle's Sherlock Holmes and modern-day cyberattacks. The author, a cybersecurity professor, argues that the core principles of de… Dark Reading · Aug 10, 2026 Medium social engineeringcybersecurityhuman behavior
threat-intel Poland uncovers second heat plant cyberattack that went hidden for months Poland’s CERT Polska uncovered a cyberattack targeting a combined heat and power plant that went undetected for months, highlighting a previously unknown attack vector involving private cellular networks. The attack, occ… The Record · Aug 10, 2026 High PORUcyberattackindustrial control systemsprivate cellular network
threat-intel Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity Senate Democrats are proposing a $300 million annual investment to bolster cybersecurity for U.S. water and wastewater systems, following a series of attacks targeting over 30 systems in approximately 12 states. The legi… The Record · Aug 10, 2026 High IRcybersecurityinfrastructurewater systems
threat-intel Russian military hackers pose as recruiters to target Ukrainian IT workers Russian military hackers, linked to the Sandworm group (APT44/Seashell Blizzard), are impersonating IT recruiters to target Ukrainian IT workers and install malicious software. The operation involves using legitimate job… The Record · Aug 10, 2026 High UKRUrecruitmentvpnwireguard
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing