threat-intel Attacker phished way into US defense supplier's Microsoft 365 account A US defense supplier's Microsoft 365 account was compromised after an attacker successfully phished credentials. The attacker exploited a vulnerability to gain access, highlighting a continuing issue with phishing attac… The Register · Aug 7, 2026 Medium phishingmicrosoftcredential theft
vulnerability 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers A 18-year-old vulnerability in Linux's SCTP networking code allows local users to gain root access on a host, potentially escaping containers. Tencent researchers discovered and demonstrated this flaw, which has existed… The Hacker News · Aug 7, 2026 High CVE-2026-64564CHlinuxsctpuse-after-free
threat-intel Vishing Extortion Group UNC6671 Rebrands After Making Millions UNC6671, an extortion group previously known as BlackFile, has rebranded and continued its operations under multiple names (Redact, Pink, Helix, and Falcon) while targeting sectors like financial services and private equ… SecurityWeek · Aug 7, 2026 High vishingphishingransomware
threat-intel Fuite massive de données RH A French hacker has claimed to have leaked 26GB of sensitive HR data belonging to T2MC, a French industrial cleaning and reception services company, and its subsidiaries. The data includes personal and professional infor… ZATAZ · Aug 7, 2026 High FRhr datadata breachfrench
threat-intel Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails A widespread phishing campaign, leveraging adversary-in-the-middle (AitM) techniques and residential proxies, is targeting organizations across various sectors in the U.S., Canada, and Europe. The campaign, linked to the… The Hacker News · Aug 7, 2026 High USCAEUaitmphishingmicrosoft 365
Des cibles françaises au cœur d’une plateforme cybercriminelle A ZATAZ investigation has uncovered a list of French organizations targeted by a cybercriminal group, Krybit, who are aggressively recruiting affiliates through a platform offering a lucrative 80% revenue split. The grou… ZATAZ · Aug 7, 2026 FRMXUSransomwarerecruitmentcybercrime
threat-intel ICE Is Buying Access to Credit Card Records The U.S. Department of Homeland Security’s Intelligence and Operations (I&O) division is reportedly purchasing access to credit card transaction data from a private company, effectively giving them a massive window into… Schneier on Security · Aug 7, 2026 High surveillanceprivacydata-collection
threat-intel AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day An AI-powered research tool, HTTP Terminator, developed by PortSwigger, autonomously discovered several novel HTTP desynchronization techniques, including a zero-day vulnerability in Apache Traffic Server. The tool, usin… The Hacker News · Aug 7, 2026 High CVE-2026-63078UShttpdesyncrqt
threat-intel 'Asimov was right' about rules for robots, says ex-US Cyber Director This article highlights a range of cybersecurity and technology news, including a Microsoft SharePoint vulnerability exploited in the wild, a Russian phishing campaign mimicking Signal support, and acquisitions within th… The Register · Aug 7, 2026 Medium RUvulnerabilityphishingacquisition
threat-intel Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix A 2024 safety recall for Bendix’s EC80 heavy-truck brake controller, initially issued to address memory corruption issues, has been revealed to contain a significant set of vulnerabilities, including a remotely accessibl… SecurityWeek · Aug 7, 2026 High USCAvulnerabilityremote-code-executiondenial-of-service
threat-intel New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables A new attack class, dubbed NatJack, has been disclosed that allows attackers to hijack active TCP sessions and spoof DNS responses by manipulating NAT connection state. The vulnerability exists in both Windows and Linux… The Hacker News · Aug 7, 2026 High CVE-2026-56181CVE-2026-63913nattcp hijackingdns spoofing
threat-intel Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) This article summarizes several cybersecurity vendor announcements and research findings from Black Hat 2026. Key developments include 1Password's research on AI-generated patches and new PAM offerings, Cogent's Mythos-c… SecurityWeek · Aug 7, 2026 High CVE-2026-56181CVE-2026-63913aisecuritythreat intelligence
vulnerability Microsoft, Apple Release Fresh Security Updates Microsoft and Apple released a combined set of security updates addressing dozens of vulnerabilities across their products, including critical remote code execution flaws. These updates target a wide range of products, i… SecurityWeek · Aug 7, 2026 Critical CVE-2026-63508CVE-2026-56162CVE-2026-65667vulnerabilityremote code executionpatch
threat-intel Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access Researchers have discovered a vulnerability in Windows Hello for Business that allows malware running within a signed-in session to leverage the victim's hardware-backed authentication key to gain persistent access to Mi… The Hacker News · Aug 7, 2026 High windowsentria idwebauthn
vulnerability Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed… The Hacker News · Aug 7, 2026 High CVE-2026-12537CVE-2026-54316ci/cdinput validationcommand injection
threat-intel Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th) This article details Atuin, a tool that enhances shell history tracking by storing command history in a SQLite database, providing richer context (directory, duration, exit code, hostname) and end-to-end encryption acros… SANS Internet Storm Center · Aug 7, 2026 Medium forensicsshellhistory
data-breach 3.8 Million Impacted by Unlimited Technology Systems Data Breach Unlimited Technology Systems experienced a data breach affecting over 3.8 million individuals, exposing sensitive personal and health-related information. The company is offering affected users two years of credit monito… SecurityWeek · Aug 7, 2026 High data breachhealthcarepersonal data
vulnerability Critical Vulnerabilities Patched With Chrome 151 Update Google released Chrome 151 to address 370 security vulnerabilities, primarily memory safety bugs, with 41 classified as critical. The update aims to prevent data corruption, crashes, and potential code execution exploits… SecurityWeek · Aug 7, 2026 High memory-safetychromevulnerability
threat-intel TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign The threat actor known as TeamPCP has been active since 2020, engaging in a series of campaigns targeting internet-facing infrastructure and expanding into sophisticated supply chain attacks. Their tactics have evolved s… The Hacker News · Aug 7, 2026 High IRsupply-chainkubernetesreact
threat-intel China launches mysterious probe into security of Palo Alto Networks' products Chinese authorities are investigating the security of Palo Alto Networks' products, raising concerns about potential vulnerabilities and a broader effort to monitor and control cybersecurity technology within China. This… The Register · Aug 7, 2026 Medium CNcybersecuritychinapalo alto