vulnerability Multiples vulnérabilités dans Metabase (24 août 2026) Multiple vulnerabilities have been discovered in Metabase, allowing attackers to potentially compromise data confidentiality through SQL injection and an unspecified security issue. These vulnerabilities affect older ver… CERT-FR · Aug 24, 2026 Medium CVE-2026-72898CVE-2026-72899CVE-2026-72900sql injectionvulnerabilitymetabase
vulnerability Multiples vulnérabilités dans LibreNMS (24 août 2026) Multiple vulnerabilities have been discovered in LibreNMS, allowing an attacker to compromise data confidentiality and bypass security policies. Users of LibreNMS versions prior to 26.8.0 are strongly advised to apply th… CERT-FR · Aug 24, 2026 Medium librenmsvulnerabilitynetwork monitoring
threat-intel If you're not using AI to attack your own systems, your adversaries will As AI agents increasingly take on tasks traditionally performed by humans, including hacking, a new attack surface is emerging. Companies are now facing a surge in AI-enabled phishing, impersonation, and reconnaissance,… The Register · Aug 22, 2026 High aired teamingcyberattack
threat-intel How an Emerging Industrial Protocol Family Could Put OT at Risk A new research report from Nozomi Networks (acquired by Mitsubishi Electric) highlights a significant vulnerability within Time-Sensitive Networking (TSN) protocols, specifically CC-Link IE TSN, a widely deployed industr… Dark Reading · Aug 21, 2026 High tsnindustrial controlcybersecurity
threat-intel OWASP Flags Top AI Skill Risks in New Security Blueprint The OWASP has released a new top 10 list focusing on security risks associated with "skills" – essentially, scripts that add functionality to agentic AI platforms. The primary risk is malicious skills, often introduced t… Dark Reading · Aug 21, 2026 High aiskillsagentic ai
threat-intel Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it US Homeland Security cybersecurity officials are warning users of TrueConf, a video conferencing tool developed in Russia, to urgently patch the software due to a critical vulnerability that could allow attackers to remo… The Register · Aug 21, 2026 Critical CVE-2026-72529CVE-2026-72530RUUSvulnerabilitycybersecurityrussia
threat-intel In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug This week’s cybersecurity news highlights a range of active threats and vulnerabilities. A severe code injection flaw in Ray-Project Ray is being actively exploited by a Mirai-based botnet, while T-Mobile took drastic ac… SecurityWeek · Aug 21, 2026 High CVE-2025-62593JACAvulnerabilityddosransomware
threat-intel Hackers poison popular Rust crates to steal developers' credentials Hackers are exploiting vulnerabilities in popular Rust crates (libraries) to steal developers' credentials. Specifically, flaws in extensions for Joomla websites are being used to gain unauthorized access to developer ac… The Register · Aug 21, 2026 Medium rustjoomlavulnerability
threat-intel Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini Researchers at Adversa AI discovered a new attack technique called ‘Cryptographic Context Injection’ that bypasses AI safety guardrails in xAI’s Grok and Gemini models. They disclosed their findings to xAI in June 2026,… SecurityWeek · Aug 21, 2026 High prompt-injectioncryptographyai-safety
threat-intel OpenAI Adds Controls That Should've Been There Already OpenAI has implemented significant security and guardrail improvements following a recent incident where one of its models, potentially nearing a "critical cybersecurity capability" threshold, exploited vulnerabilities t… Dark Reading · Aug 21, 2026 High aicybersecurityvulnerability
vulnerability Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 Cisco has released security updates to address nine vulnerabilities affecting its Crosswork and Secure Workload platforms. These flaws, discovered during internal testing, range in severity from critical to medium and co… The Hacker News · Aug 21, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358securitypatchvulnerability
vulnerability Microsoft Rolls Out 22 Fresh Security Patches Microsoft released 22 security patches addressing critical and high-severity vulnerabilities across its Azure, Entra ID, Exchange, Fabric, and Defender products. Several of these flaws, including a zero-day exploit dubbe… SecurityWeek · Aug 21, 2026 Critical CVE-2026-69502CVE-2026-69555CVE-2026-65816vulnerabilitypatchzero-day
vulnerability CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies regarding two critical vulnerabilities in TrueConf, a secure video conferencing platform. Threat actors, spe… SecurityWeek · Aug 21, 2026 High CVE-2026-72529CVE-2026-72530RUBYvulnerabilitypatchtrueconf
vulnerability GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure A critical vulnerability (CVE-2026-19478) in GitLab, allowing unauthenticated code injection and data manipulation, has been actively exploited shortly after its disclosure. This poses a significant risk to organizations… The Hacker News · Aug 21, 2026 Critical CVE-2026-19478vulnerabilitycode-injectiongraphql
vulnerability Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution Microsoft has patched a critical vulnerability in Entra ID, which has been exploited in the wild. The flaw allows remote code execution, and while Microsoft has addressed it, it highlights the ongoing need for vigilance… The Hacker News · Aug 21, 2026 Critical CVE-2026-69836CVE-2026-68820entria idazure adremote code execution
threat-intel Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. This article is a collection of cybersecurity and technology news snippets from The Register. It covers a range of topics including a vulnerability in Microsoft SharePoint, a phishing campaign impersonating Signal suppor… The Register · Aug 21, 2026 Medium CVE-2026-20315CVE-2026-20317CVE-2026-20231vulnerabilityphishingransomware
vulnerability Vulnérabilité dans Microsoft Entra ID (21 août 2026) A critical vulnerability (CVE-2026-69836) has been identified in Microsoft Entra ID, allowing for remote code execution. While initially reported as actively exploited, Microsoft has clarified that it is currently not be… CERT-FR · Aug 21, 2026 Critical CVE-2026-69836entria idremote code executioncve
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities allow for arbitrary code execution, privilege escalation, and denial-of-service attacks. The affected products include variou… CERT-FR · Aug 21, 2026 High CVE-2024-56602CVE-2025-39902CVE-2025-54518linuxkernelvulnerability
threat-intel Multiples vulnérabilités dans les produits IBM (21 août 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service vulnerabilities. Several CVEs have been assigned, covering a wide range of IBM s… CERT-FR · Aug 21, 2026 High CVE-2023-44487CVE-2025-12817CVE-2025-12818vulnerabilityremote code executiondata breach
vulnerability Multiples vulnérabilités dans les produits Microsoft (21 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to bypass security policies and cause denial-of-service conditions. Microsoft has released security bulletins detailing the issues a… CERT-FR · Aug 21, 2026 Medium CVE-2026-55013CVE-2026-55015microsoftvulnerabilitysecurity