vulnerability Multiples vulnérabilités dans HPE Aruba Networking Private 5G Core (10 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking Private 5G Core, allowing attackers to elevate privileges and bypass security policies. These vulnerabilities are present in older versions of the sof… CERT-FR · Aug 10, 2026 Medium CVE-2026-33377CVE-2026-54763vulnerabilitysecurityaruba
vulnerability Multiples vulnérabilités dans VMware Tanzu Greenplum (10 août 2026) Multiple vulnerabilities have been discovered in VMware Tanzu Greenplum. These vulnerabilities allow an attacker to cause a security issue, though the specific nature of the issue is not detailed. Users are advised to co… CERT-FR · Aug 10, 2026 Medium CVE-2018-11798CVE-2019-0205CVE-2020-13949vulnerabilitycvepatch
vulnerability Vulnérabilité dans SonicWall Global VPN Client (10 août 2026) A vulnerability in SonicWall Global VPN Client allows an attacker to cause a denial-of-service. SonicWall has released a security bulletin and a corresponding CVE to address this issue. CERT-FR · Aug 10, 2026 Medium CVE-2026-66151vpnvulnerabilitydenial-of-service
vulnerability Multiples vulnérabilités dans ClamAV (10 août 2026) Multiple vulnerabilities have been discovered in ClamAV, potentially allowing attackers to compromise data confidentiality, cause denial of service, and introduce an unspecified security issue. These vulnerabilities affe… CERT-FR · Aug 10, 2026 Medium CVE-2025-8088CVE-2026-20337CVE-2026-20338vulnerabilityantivirusclamav
threat-intel Ransomware gangs skip the CEO, head straight for the 40-something IT manager Ransomware gangs are increasingly targeting IT managers, specifically those in their 40s, bypassing traditional executive channels to gain access to sensitive data and systems. This shift suggests a change in tactics by… The Register · Aug 9, 2026 Medium ransomwarecybersecuritylinux
threat-intel Cyber actualités ZATAZ de la semaine du 3 au 9 août 2026 This week, ZATAZ reports on a significant number of cyber incidents impacting France and beyond. A staggering 1.7 billion French IDs were found on the dark web, alongside 43 ransomware demands targeting France, primarily… ZATAZ · Aug 9, 2026 High FRTAdarkwebransomwaredata breach
threat-intel Un milliard d’identifiants français sur le darkweb A massive collection of over 1.7 billion unique French email addresses and passwords has been discovered on the dark web, originating from 13 years of phishing campaigns and data breaches. The data, totaling 28GB across… ZATAZ · Aug 8, 2026 High FRcredential stuffingphishingdata breach
threat-intel Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Several security-related stories are emerging, including a focus on AI security and vulnerabilities, a Russian phishing campaign mimicking Signal support, and ongoing efforts to improve security across various Linux and… The Register · Aug 8, 2026 Medium RUIRaisecurityphishing
vulnerability Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data A critical one-click vulnerability, dubbed RovoBlast, has been discovered in Atlassian’s Rovo AI assistant, allowing attackers to inject malicious prompts and exfiltrate sensitive data from various Atlassian products and… SecurityWeek · Aug 8, 2026 Critical aiprompt injectiondata exfiltration
threat-intel Rançongiciels : 43 revendications ciblent la France Between July 1st and August 8th, 43 French organizations were targeted in cybercriminal extortion claims, with a strong concentration among several ransomware-as-a-service groups. The Gentlemen and Qilin were the most ac… ZATAZ · Aug 8, 2026 High FRransomwarecybercrimeextortion
threat-intel Des pirates revendiquent le piratage d’un miroir de Coco A mirror site for the defunct Coco discussion forum, presented as a successor to the original site shut down due to illegal activities, has been compromised by the threat actor CuteSec. The attackers gained extensive con… ZATAZ · Aug 8, 2026 High data breachpassword compromiseuser data
vulnerability Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers Atlassian’s Rovo assistant has two vulnerabilities that could allow attackers to exfiltrate data. The first, a one-click link flaw, has been patched by Atlassian. The second, a content-borne prompt injection attack, allo… The Hacker News · Aug 8, 2026 High prompt-injectiondata-exfiltrationatlassian
threat-intel Un pirate plaide coupable après 165 piratages A Canadian man, Connor Riley Moucka, has pleaded guilty to a massive cloud-based hacking and extortion scheme targeting over 165 organizations. Between February and October 2024, his group exploited stolen credentials to… ZATAZ · Aug 8, 2026 High CAUNSPcloud-securitycredential-theftextortion
threat-intel Levi Strauss signale une cyberattaque Levi Strauss & Co. disclosed a cybersecurity incident to the SEC, revealing that a third party gained unauthorized access to three employee workstations via social engineering. The attacker accessed internal files and ex… ZATAZ · Aug 8, 2026 Medium social engineeringdata exfiltrationcybersecurity
threat-intel New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens Researchers at PortSwigger have discovered several new attack vectors targeting webmail interfaces, allowing attackers to steal passwords, take over accounts, and manipulate AI tools. The vulnerabilities exploit weakness… The Hacker News · Aug 8, 2026 High webmailcsshtml
vulnerability Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A zero-day vulnerability in Metabase has been exploited in the wild, allowing unauthenticated attackers to gain administrator access to the application and steal data. The vulnerability affects versions 1.58 and above, a… The Hacker News · Aug 8, 2026 Critical CVE-2023-38646zero-daysql injectiondata breach
vulnerability N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for… The Hacker News · Aug 8, 2026 Critical CVE-2026-18577CVE-2026-18556zero-dayremote accesscloudflare
vulnerability Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts A critical command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's KEV catalog, following reports of widespread exploitation attempts. The vulnerability allows unauthenticated attackers to ex… The Hacker News · Aug 8, 2026 Critical CVE-2026-8037AUCHINcommand injectionload balancerpatching
threat-intel OpenAI pledges to add Astra security as Anthropic loosens Fable's leash OpenAI is bolstering its AI security by integrating Astra, while Anthropic is loosening restrictions on its Fable system. This shift reflects growing concerns about the potential risks associated with increasingly autono… The Register · Aug 7, 2026 Medium IRaisecurityvulnerability
threat-intel Inside the Modern SOC: The Identity Front Door A significant trend in cyberattacks is the increasing reliance on compromised identities rather than exploiting technical vulnerabilities. Nearly 90% of Unit 42 investigations involved identity weaknesses, with 65% of in… Palo Alto Unit 42 · Aug 7, 2026 High identity theftcredential abusesocial engineering