threat-intel Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Several security-related stories are emerging, including a focus on AI security and vulnerabilities, a Russian phishing campaign mimicking Signal support, and ongoing efforts to improve security across various Linux and… The Register · Aug 8, 2026 Medium RUIRaisecurityphishing
vulnerability Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data A critical one-click vulnerability, dubbed RovoBlast, has been discovered in Atlassian’s Rovo AI assistant, allowing attackers to inject malicious prompts and exfiltrate sensitive data from various Atlassian products and… SecurityWeek · Aug 8, 2026 Critical aiprompt injectiondata exfiltration
threat-intel Rançongiciels : 43 revendications ciblent la France Between July 1st and August 8th, 43 French organizations were targeted in cybercriminal extortion claims, with a strong concentration among several ransomware-as-a-service groups. The Gentlemen and Qilin were the most ac… ZATAZ · Aug 8, 2026 High FRransomwarecybercrimeextortion
threat-intel Des pirates revendiquent le piratage d’un miroir de Coco A mirror site for the defunct Coco discussion forum, presented as a successor to the original site shut down due to illegal activities, has been compromised by the threat actor CuteSec. The attackers gained extensive con… ZATAZ · Aug 8, 2026 High data breachpassword compromiseuser data
vulnerability Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers Atlassian’s Rovo assistant has two vulnerabilities that could allow attackers to exfiltrate data. The first, a one-click link flaw, has been patched by Atlassian. The second, a content-borne prompt injection attack, allo… The Hacker News · Aug 8, 2026 High prompt-injectiondata-exfiltrationatlassian
threat-intel Un pirate plaide coupable après 165 piratages A Canadian man, Connor Riley Moucka, has pleaded guilty to a massive cloud-based hacking and extortion scheme targeting over 165 organizations. Between February and October 2024, his group exploited stolen credentials to… ZATAZ · Aug 8, 2026 High CAUNSPcloud-securitycredential-theftextortion
threat-intel Levi Strauss signale une cyberattaque Levi Strauss & Co. disclosed a cybersecurity incident to the SEC, revealing that a third party gained unauthorized access to three employee workstations via social engineering. The attacker accessed internal files and ex… ZATAZ · Aug 8, 2026 Medium social engineeringdata exfiltrationcybersecurity
threat-intel New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens Researchers at PortSwigger have discovered several new attack vectors targeting webmail interfaces, allowing attackers to steal passwords, take over accounts, and manipulate AI tools. The vulnerabilities exploit weakness… The Hacker News · Aug 8, 2026 High webmailcsshtml
vulnerability Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A zero-day vulnerability in Metabase has been exploited in the wild, allowing unauthenticated attackers to gain administrator access to the application and steal data. The vulnerability affects versions 1.58 and above, a… The Hacker News · Aug 8, 2026 Critical CVE-2023-38646zero-daysql injectiondata breach
vulnerability N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for… The Hacker News · Aug 8, 2026 Critical CVE-2026-18577CVE-2026-18556zero-dayremote accesscloudflare
vulnerability Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts A critical command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's KEV catalog, following reports of widespread exploitation attempts. The vulnerability allows unauthenticated attackers to ex… The Hacker News · Aug 8, 2026 Critical CVE-2026-8037AUCHINcommand injectionload balancerpatching
threat-intel OpenAI pledges to add Astra security as Anthropic loosens Fable's leash OpenAI is bolstering its AI security by integrating Astra, while Anthropic is loosening restrictions on its Fable system. This shift reflects growing concerns about the potential risks associated with increasingly autono… The Register · Aug 7, 2026 Medium IRaisecurityvulnerability
threat-intel Inside the Modern SOC: The Identity Front Door A significant trend in cyberattacks is the increasing reliance on compromised identities rather than exploiting technical vulnerabilities. Nearly 90% of Unit 42 investigations involved identity weaknesses, with 65% of in… Palo Alto Unit 42 · Aug 7, 2026 High identity theftcredential abusesocial engineering
other Friday Squid Blogging: Arctic Bobtail Squid Video This article is a link to a video showcasing the Arctic bobtail squid. It’s a non-security related piece and doesn’t contain any information about security vulnerabilities, breaches, or threats. Schneier on Security · Aug 7, 2026 Info
threat-intel Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks An ex-NSA chief is warning that water system controllers, which are increasingly connected to the internet, are vulnerable to attacks, particularly from Iran. He believes these devices represent a significant security ri… The Register · Aug 7, 2026 Medium IRcybersecurityinfrastructureiran
threat-intel Water utilities group partners with DEF CON offshoot for Water Watch Center The National Rural Water Association (NRWA) has partnered with DEF CON Franklin to establish the Water Watch Center (WWC), a program designed to provide cybersecurity services to underfunded water and wastewater systems… The Record · Aug 7, 2026 High IRUNcybersecuritywater systemsoperational technology
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ClickFix-style attacks are being used to deliver a Go-based macOS stealer that can drain cryptocurrency wallets and steal browser-stored passwords and Apple iCloud Keychain data. The malware, developed by the Aeza Group… The Hacker News · Aug 7, 2026 High USUKAUmacoscryptocurrencystealer
threat-intel UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data UNC6671, a data extortion group linked to ShinyHunters and potentially SLH, is leveraging sophisticated vishing tactics to steal SaaS data from organizations across multiple sectors. They impersonate IT help desks, direc… The Hacker News · Aug 7, 2026 High NOAUU.vishingphishingdata-breach
threat-intel US cyber ambassador nominee Cassady confirmed in Senate The Senate confirmed Adam Cassady as the next U.S. ambassador for cyber and digital policy. This appointment follows a reorganization within the State Department, leading to a restructuring of the Bureau of Cyberspace an… The Record · Aug 7, 2026 Info CHHOUScybersecuritytechnology exportschina