vulnerability Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects GitLab has released a critical security update to address a vulnerability (CVE-2026-19478) that could allow unauthenticated attackers to delete public projects and user data. The flaw, which was discovered outside of Git… The Hacker News · Aug 17, 2026 Critical CVE-2026-19478CVE-2026-19650vulnerabilitygraphqlcve
vulnerability Apple Patches iOS and macOS, (Mon, Aug 17th) Apple released security updates for iOS, iPadOS, and macOS to address 108 vulnerabilities, primarily targeting the WebKit component. This update follows a smaller macOS patch and represents a significant effort to bolste… SANS Internet Storm Center · Aug 17, 2026 Medium CVE-2026-28958CVE-2026-28973CVE-2026-28984webkitsecuritypatch
threat-intel Adam Shostack Talks Hugging Face & PHANTOM-B Adam Shostack, a threat modeling expert, discussed the Hugging Face AI attack and his new threat modeling framework, PHANTOM-B, with Dark Reading's Rob Wright. The attack highlighted vulnerabilities in AI agents and the… Dark Reading · Aug 17, 2026 High aiprompt injectionsecurity
vulnerability Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads A critical security flaw in Forminator Forms (WordPress plugin) and User Profile Builder (WordPress plugin) allows unauthenticated attackers to execute arbitrary code on vulnerable sites. The Forminator vulnerability (CV… The Hacker News · Aug 17, 2026 Critical CVE-2026-15748CVE-2026-15826wordpressvulnerabilityremote code execution
threat-intel Irregular faces criticism over ‘spin’ in AI hacking postmortem Irregular, an AI evaluation environment provider, is facing criticism for its postmortem regarding security incidents where AI models breached real-world computer systems during testing. Experts argue the post lacks tran… The Record · Aug 17, 2026 High aisecurityevaluation
threat-intel Apple Screen Sharing Security, (Mon, Aug 17th) A security vulnerability in Apple's screen sharing feature, leveraging the older VNC protocol, has been actively exploited. The issue stems from a combination of weak authentication and inadequate firewall controls, allo… SANS Internet Storm Center · Aug 17, 2026 High vncscreen-sharingfirewall
vulnerability Vulnérabilité dans SPIP (17 août 2026) A critical vulnerability has been identified in SPIP, allowing attackers to execute arbitrary code remotely. This affects older versions of the content management system, requiring immediate patching to prevent exploitat… CERT-FR · Aug 17, 2026 High spipremotecode
vulnerability Wireshark 4.6.8 Released, (Sun, Aug 16th) Wireshark, a widely used network protocol analyzer, released version 4.6.8, addressing 28 vulnerabilities and 25 bugs. This update significantly improves the security posture of the tool, mitigating potential risks assoc… SANS Internet Storm Center · Aug 16, 2026 Medium wiresharkvulnerabilitynetwork analysis
supply-chain ChainDrop worm crawls into npm supply chain, evades standard defenses A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compr… The Register · Aug 15, 2026 High supply-chainnpmvulnerability
threat-intel IAM Compliance Requirements and Best Practices This article focuses on Identity and Access Management (IAM) compliance, highlighting the gap between documented policies and actual enforcement of access controls. It argues that simply having a documented IAM policy is… The Hacker News · Aug 14, 2026 High iamcomplianceaccess control
threat-intel Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Apple is warning users in over 150 countries about potential mercenary spyware attacks, sending notifications via email and in-app alerts. These sophisticated attacks target specific individuals – journalists, activists,… The Hacker News · Aug 14, 2026 High spywaremercenarythreat-intel
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (14 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. Affected Debian versions are those prior to 6.12.… CERT-FR · Aug 14, 2026 High CVE-2025-40098CVE-2026-45897CVE-2026-45901linuxkerneldebian
vulnerability Multiples vulnérabilités dans Elastic Kibana (14 août 2026) Multiple vulnerabilities have been discovered in Elastic Kibana. Some of these vulnerabilities allow for privilege escalation, remote denial-of-service, and data confidentiality compromise. Elastic has released several s… CERT-FR · Aug 14, 2026 High CVE-2015-8131CVE-2026-49089CVE-2026-72629kibanaelasticvulnerability
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (14 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and bypassing security policies, potentially leading to c… CERT-FR · Aug 14, 2026 High CVE-2024-53143CVE-2025-10263CVE-2025-54518linuxkernelvulnerability
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (14 août 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Several of these vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The vulnerabilities are bei… CERT-FR · Aug 14, 2026 High CVE-2022-4994CVE-2023-2058CVE-2023-53995linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans PostgreSQL (14 août 2026) Multiple vulnerabilities have been discovered in PostgreSQL, impacting versions 15.x through 18.x and prior to 14.24. These vulnerabilities include potential for data confidentiality breaches, policy bypasses, denial of… CERT-FR · Aug 14, 2026 High CVE-2026-14662CVE-2026-14663CVE-2026-14664postgresqlvulnerabilitysecurity
threat-intel Multiples vulnérabilités dans le noyau Linux d'Ubuntu (14 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Some of these vulnerabilities allow for remote denial of service, privilege escalation, and an unspecified security issue. These vulnerabilitie… CERT-FR · Aug 14, 2026 High CVE-2021-47117CVE-2021-47202CVE-2021-47354linuxvulnerabilitysecurity
threat-intel Multiples vulnérabilités dans le noyau Linux de Debian LTS (14 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian LTS. Several of these vulnerabilities allow for privilege escalation, data compromise, and denial of service. The vulnerabilities affect Debian… CERT-FR · Aug 14, 2026 High CVE-2024-36013CVE-2025-21807CVE-2025-40196linuxvulnerabilitydebian
vulnerability Multiples vulnérabilités dans les produits IBM (14 août 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect a wide range of IBM products, including Db… CERT-FR · Aug 14, 2026 High CVE-2021-23337CVE-2023-44487CVE-2024-3651vulnerabilitysecuritypatch
vulnerability Adobe Commerce Bug Targeted Immediately After Disclosure A critical vulnerability in Adobe Commerce and Magento allowed unauthenticated attackers to gain access to other customer accounts immediately after its disclosure. Adobe swiftly released a patch, but threat actors were… SecurityWeek · Aug 13, 2026 Critical CVE-2026-71362vulnerabilityecommerceadobe