threat-intel OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns OpenAI is suspending development of its upcoming AI model, Astra, due to concerns that it could autonomously develop zero-day exploits and execute complex cyberattacks. The company has implemented strict security control… SecurityWeek · Aug 10, 2026 High aicybersecurityai agents
threat-intel Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds Stealthium is a new cybersecurity firm addressing a critical security blind spot in the rapidly growing neo-cloud market, which utilizes specialized AI accelerators. Because traditional security tools aren't designed for… SecurityWeek · Aug 10, 2026 High neo-cloudacceleratorsupply chain
vulnerability Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Cisco has warned of seven high-severity vulnerabilities in its Secure Endpoint Connector software, stemming from flaws within the ClamAV antivirus engine. These vulnerabilities could lead to denial-of-service conditions… SecurityWeek · Aug 10, 2026 High CVE-2026-20337CVE-2026-20339CVE-2026-20345clamavvulnerabilitypatch
threat-intel British ‘Com’ member who abused more than 100 girls worldwide jailed for two years A 20-year-old British man, Justin Swaddle, was sentenced to two years in prison for abusing and manipulating over 100 girls worldwide through online platforms, primarily Snapchat, Telegram, and Discord. He was part of a… The Record · Aug 10, 2026 High UKUSCAonline-abusechild-exploitationcybercrime
threat-intel Attackers pick Levi's pockets in social engineering attack Attackers are leveraging social engineering to steal data from Levi's customers. The attackers impersonated Signal support to trick users into providing their credentials, leading to a data breach. The Register · Aug 10, 2026 Medium social engineeringdata breachphishing
threat-intel Wetherspoons bars smart glasses from filming customers Wetherspoons, a UK pub chain, has been accused of using smart glasses to film customers without their consent. The glasses, reportedly used to assist staff, were found to be capable of recording video, raising significan… The Register · Aug 10, 2026 Medium privacysurveillancedata-protection
threat-intel Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development North Korea's Kimsuky hacking group is building an offline AI infrastructure to bolster its phishing attacks and automate malware development. Security firm Genians discovered this setup, finding tools like Ollama, GPT4A… The Hacker News · Aug 10, 2026 High KRaiphishingnorth korea
supply-chain China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns China-linked hackers, believed to be part of the Storm-1175 group, are exploiting a critical vulnerability in N-central, a remote monitoring and management (RMM) tool, to deploy ransomware. This supply-chain attack is le… The Record · Aug 10, 2026 High CVE-2026-18577CHsupply-chainransomwarezero-day
threat-intel ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad Tenet security researchers have demonstrated a novel ‘Ghostjacking’ attack that leverages poisoned logs to manipulate AI agents, effectively turning them into malicious tools. The attack exploits trust in AI agents by in… SecurityWeek · Aug 10, 2026 High aiartificial intelligencelog poisoning
threat-intel New Zealand sanctions Russian hackers, propaganda groups over Ukraine war New Zealand has expanded its sanctions against Russia, targeting 33 individuals and entities involved in cyber activities supporting Russia's war in Ukraine. These include hackers, propaganda groups, and technology compa… The Record · Aug 10, 2026 High RUUKCAcyberattacksrussiasanctions
threat-intel New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA Recent research has revealed significant vulnerabilities in passkey authentication systems, demonstrating ways to bypass security measures and impersonate users. SpecterOps found that Windows stored past YubiKey signatur… The Hacker News · Aug 10, 2026 High CVE-2026-34348passkeyauthenticationvulnerability
threat-intel Cyber vulnerability sweep picks up Royal Navy drones sending data to China A vulnerability in Royal Navy drones is allowing Chinese entities to access sensitive data. The flaw stems from a misconfigured system that transmits data to servers in China, raising significant national security concer… The Register · Aug 10, 2026 High UKCHvulnerabilitynational securitydata transmission
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
threat-intel Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development As AI accelerates software development, security teams are struggling to keep pace, leading to a massive backlog of vulnerabilities and an expanded attack surface. This webinar explores how to adapt security practices to… The Hacker News · Aug 10, 2026 Medium aisecuritydevelopment
threat-intel New Jersey, Alabama Join States Targeted in Water Cyberattacks A coordinated cyberattack targeting water and wastewater facilities in the United States is expanding, with New Jersey and Alabama becoming the latest states to report incidents. The attacks, linked to Iranian hackers, a… SecurityWeek · Aug 10, 2026 High IRUScyberattackwater systemsics
threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
threat-intel Python Now Has a Post-Quantum Encryption Library Python’s popular cryptography library, pyca/cryptography, has gained post-quantum encryption support thanks to funding from the Sovereign Tech Agency. This means developers can now integrate algorithms designed to withst… Schneier on Security · Aug 10, 2026 Medium post-quantumcryptographypython
threat-intel Claude Code puts auto mode in the driver's seat Several security incidents and developments are highlighted, including a vulnerability in Joomla extensions, a Microsoft SharePoint issue leading to a zero-day attack, and ongoing efforts to combat Iranian propaganda and… The Register · Aug 10, 2026 Medium IRUSvulnerabilityphishingransomware