vulnerability Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs Cisco has released patches to address multiple critical security vulnerabilities affecting its SD-WAN and IOS XE software. These flaws, including several with a CVSS score of 9.8 and 9.9, cover issues like improper input… The Hacker News · Aug 6, 2026 High CVE-2026-20303CVE-2026-20304CVE-2026-20310sd-wanios xevulnerability
threat-intel Canadian Man Pleads Guilty in Snowflake Extortions A 26-year-old Canadian man, known online as ‘Judische’ and ‘Waifu,’ has pleaded guilty to computer fraud and conspiracy to hack and extort over 165 Snowflake customers, including major companies like TicketMaster and Nei… Krebs on Security · Aug 6, 2026 High CASOTUcybercrimedata breachextortion
threat-intel Humans in the loop miss a third of dangerous AI coding agent requests A recent report highlights that human reviewers are consistently missing a significant portion of dangerous requests made to large language models (LLMs). This means that even when LLMs are generating potentially harmful… The Register · Aug 6, 2026 Medium llmaisecurity
vulnerability New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs Researchers at MIT have discovered a new vulnerability, dubbed INTERRUPT INJECTION, that allows an unprivileged Linux program to bypass Spectre v2 defenses on Intel and AMD CPUs. By precisely timing a hardware interrupt,… The Hacker News · Aug 6, 2026 High CVE-2023-20569spectreinterruptkernel
threat-intel ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories This week's 'ThreatsDay' bulletin highlights a diverse range of security threats, including a China-linked telecom risk, a multi-stage phishing attack leveraging ClickOnce files, a supply chain attack involving 846 softw… The Hacker News · Aug 6, 2026 High CVE-2025-21079CVE-2025-58486CVE-2026-25177CHUSsupply-chainmalwarephishing
threat-intel Snowflake Hacker Pleads Guilty in US Court A 26-year-old man, Connor Riley Moucka, has pleaded guilty to his role in a coordinated cybercrime campaign targeting Snowflake accounts and stealing sensitive data from over 165 organizations. The campaign, linked to th… SecurityWeek · Aug 6, 2026 Critical snowflakescybercrimedata breach
threat-intel Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence A Belarusian cybercriminal, Maksim Silnikau, the alleged leader of the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison. He was responsible for developing and administering Ransom Cartel, a ra… The Record · Aug 6, 2026 High BEUKRUransomwarecybercrimeexploit kit
threat-intel Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Zenity researchers have uncovered two zero-click hacking techniques targeting AI browser agents, ChatGPT Atlas and Claude in Chrome. These attacks allow attackers to hijack user sessions, conduct phishing campaigns (incl… SecurityWeek · Aug 6, 2026 High zero-clickprompt injectionagentic browser
threat-intel Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities A significant number of internet-facing Rockwell PLCs (over 4,400 globally, with 22 located in cities experiencing recent US water utility cyberattacks) are exposed online. While not all have been confirmed as compromise… The Hacker News · Aug 6, 2026 High CVE-2017-16740USplccybersecurityindustrial control systems
vulnerability Johnson Controls Inc. TL280 A critical vulnerability (CWE-327) exists in Johnson Controls Inc.'s TL280 firmware, allowing attackers to access sensitive information on the device. The vulnerability stems from hardcoded credentials embedded directly… CISA Advisories · Aug 6, 2026 Critical CVE-2026-27871cwe-327firmwareics
vulnerability ABB Ability Zenon ABB has issued a security advisory regarding multiple vulnerabilities in its Ability Zenon industrial automation platform. These vulnerabilities, primarily related to MongoDB, could allow attackers to bypass security, cr… CISA Advisories · Aug 6, 2026 High CVE-2025-14847CVE-2020-7928CVE-2020-7921WOvulnerabilitydata-breachmalware
threat-intel Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway This SecurityWeek podcast episode, featuring Edna Conway, delves into the evolving landscape of cybersecurity risk, emphasizing the need to move beyond traditional compliance and embrace proactive resilience strategies.… SecurityWeek · Aug 6, 2026 Info cybersecurityrisk managementgovernance
threat-intel IT department put sticky notes on the laptops to help employees log in This article is a collection of security-related news snippets from The Register. It covers a range of topics including a phishing campaign mimicking Signal support, a zero-day exploit targeting on-prem SharePoint, and a… The Register · Aug 6, 2026 Medium CHIRSWphishingzero-dayransomware
vulnerability Medixant RadiAnt DICOM A vulnerability in Medixant RadiAnt DICOM versions older than 2025.2 allows an attacker to crash the application by opening a maliciously crafted DICOM file, potentially leading to remote code execution. CISA recommends… CISA Advisories · Aug 6, 2026 High CVE-2026-17264PLdicomcwe-787heap overflow
threat-intel CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps A vulnerability in the CryptoJS library's random number generator has led to approximately $5.7 million in cryptocurrency drains affecting five wallet applications. Coinspect discovered that the weak random number genera… The Hacker News · Aug 6, 2026 High cryptowalletvulnerability
vulnerability Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Researchers have discovered a vulnerability in Apple's iCloud Private Relay tool that allows users' real IP addresses to be exposed, even when the tool is active. The issue stems from three WebKit features – DNS prefetch… The Hacker News · Aug 6, 2026 High webkitprivacyip leak
threat-intel AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory A new attack vector, dubbed "AI Recommendation Poisoning," is spreading across websites, leveraging "Ask AI" buttons to silently manipulate Large Language Model (LLM) memory. Attackers embed hidden prompts within these b… The Hacker News · Aug 6, 2026 High prompt injectionllmmemory poisoning
vulnerability Critical Paperclip Flaw Allowed Admin Access, Code Execution A critical vulnerability (CVE-2026-41679) in Paperclip, an AI management platform, allowed remote attackers to gain administrative access and execute code on the server, potentially exposing sensitive data and internal s… SecurityWeek · Aug 6, 2026 Critical CVE-2026-41679aivulnerabilitycode-execution
threat-intel Adversarial Clothing Designed to Fool Facial Recognition Systems Researchers are creating clothing designed to disrupt facial recognition systems, primarily as a form of protest against surveillance. While the technology is still unproven and susceptible to future updates, the act of… Schneier on Security · Aug 6, 2026 Info facial recognitionsurveillanceprivacy
threat-intel Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple has implemented strict limits on its bug bounty program to combat a surge of low-quality, AI-generated vulnerability reports. The issue stems from amateur bug hunters using AI to create plausible-but-nonexistent se… Graham Cluley · Aug 6, 2026 High aivulnerabilitybug bounty