threat-intel Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Polish CERT has revealed a second, parallel cyberattack targeting a smaller CHP plant supplying heat to 50,000 residents, utilizing a novel private APN attack vector. The attack, attributed to Russian APT group Sandworm,… SecurityWeek · Aug 10, 2026 High PLicsindustrial control systemsprivate apn
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel IT threat evolution in Q2 2026. Mobile statistics In Q2 2026, mobile malware attacks continued to decline, with Trojan-Banker applications representing the most prevalent threat. Despite a drop in new Trojan variants, the landscape remained dominated by Mamont banking T… Securelist · Aug 10, 2026 Medium mobilemalwarebanking
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
threat-intel Are AI tutors safe for your kids? The market for AI tutoring tools is booming, driven by potential cost savings and improved educational outcomes, particularly for disadvantaged students. However, concerns are rising about the potential negative impacts… WeLiveSecurity · Aug 10, 2026 Medium UKaieducationprivacy
threat-intel Corporate Data Stolen in Levi Strauss Cyberattack Levi Strauss & Co. suffered a cyberattack resulting from social engineering, leading to unauthorized access to employee computers and potential corporate data theft. While initial investigations suggest no customer data… SecurityWeek · Aug 10, 2026 Medium social engineeringcyberattackdata breach
threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause OpenAI is pausing internal development of its AI model Astra due to concerns about its rapidly advancing cyber capabilities. Initial evaluations suggest the model possesses ‘Critical’ cyber capabilities, including the po… The Hacker News · Aug 10, 2026 High aicybersecurityai-safety
vulnerability Critical Flaws Discovered in Belgian eID Software Used by 2 Million People A critical vulnerability in Nitro Software Belgium’s Connective digital identity system, used by over two million people in Belgium, allowed attackers to steal sensitive data and forge electronic signatures. The flaw was… SecurityWeek · Aug 10, 2026 High BEdigital identityeidbrowser extension
threat-intel Advertisers are trying to influence AI bots with secret ads This week’s episode of The Kettle podcast explores the escalating competition in the AI world, focusing on China’s rapid advancements in open-weight AI models. The episode highlights DeepSeek, a Chinese model nearing par… The Register · Aug 10, 2026 High CHUNaiopen-sourcechina
vulnerability ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code remotely. This exploit could lead to widespread data breaches and… SANS Internet Storm Center · Aug 10, 2026 Critical log4jrcevulnerability
vulnerability Multiples vulnérabilités dans Roundcube (10 août 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, allowing attackers to execute arbitrary code remotely, compromise data confidentiality, and forge server-side requests. These flaws exist in versions 1.… CERT-FR · Aug 10, 2026 High vulnerabilitywebmailsecurity
vulnerability Vulnérabilité dans Synology Assistant (10 août 2026) A vulnerability has been identified in Synology Assistant, allowing an attacker to compromise data confidentiality, data integrity, and cause a denial of service. Users of versions prior to 7.0.7-50095 are strongly advis… CERT-FR · Aug 10, 2026 Medium CVE-2026-4793synologyvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans HPE Aruba Networking Private 5G Core (10 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking Private 5G Core, allowing attackers to elevate privileges and bypass security policies. These vulnerabilities are present in older versions of the sof… CERT-FR · Aug 10, 2026 Medium CVE-2026-33377CVE-2026-54763vulnerabilitysecurityaruba
vulnerability Multiples vulnérabilités dans VMware Tanzu Greenplum (10 août 2026) Multiple vulnerabilities have been discovered in VMware Tanzu Greenplum. These vulnerabilities allow an attacker to cause a security issue, though the specific nature of the issue is not detailed. Users are advised to co… CERT-FR · Aug 10, 2026 Medium CVE-2018-11798CVE-2019-0205CVE-2020-13949vulnerabilitycvepatch
vulnerability Vulnérabilité dans SonicWall Global VPN Client (10 août 2026) A vulnerability in SonicWall Global VPN Client allows an attacker to cause a denial-of-service. SonicWall has released a security bulletin and a corresponding CVE to address this issue. CERT-FR · Aug 10, 2026 Medium CVE-2026-66151vpnvulnerabilitydenial-of-service
vulnerability Multiples vulnérabilités dans ClamAV (10 août 2026) Multiple vulnerabilities have been discovered in ClamAV, potentially allowing attackers to compromise data confidentiality, cause denial of service, and introduce an unspecified security issue. These vulnerabilities affe… CERT-FR · Aug 10, 2026 Medium CVE-2025-8088CVE-2026-20337CVE-2026-20338vulnerabilityantivirusclamav
threat-intel Ransomware gangs skip the CEO, head straight for the 40-something IT manager Ransomware gangs are increasingly targeting IT managers, specifically those in their 40s, bypassing traditional executive channels to gain access to sensitive data and systems. This shift suggests a change in tactics by… The Register · Aug 9, 2026 Medium ransomwarecybersecuritylinux
threat-intel Cyber actualités ZATAZ de la semaine du 3 au 9 août 2026 This week, ZATAZ reports on a significant number of cyber incidents impacting France and beyond. A staggering 1.7 billion French IDs were found on the dark web, alongside 43 ransomware demands targeting France, primarily… ZATAZ · Aug 9, 2026 High FRTAdarkwebransomwaredata breach
threat-intel Un milliard d’identifiants français sur le darkweb A massive collection of over 1.7 billion unique French email addresses and passwords has been discovered on the dark web, originating from 13 years of phishing campaigns and data breaches. The data, totaling 28GB across… ZATAZ · Aug 8, 2026 High FRcredential stuffingphishingdata breach