vulnerability Multiples vulnérabilités dans les produits Nextcloud (06 août 2026) Multiple vulnerabilities have been discovered in Nextcloud products, allowing an attacker to compromise data confidentiality and bypass security policies. These vulnerabilities affect various versions of Mail and Server,… CERT-FR · Aug 6, 2026 Medium CVE-2026-61527CVE-2026-61545vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans KeyCloak (06 août 2026) Multiple vulnerabilities have been discovered in Keycloak, potentially allowing for privilege escalation, denial of service attacks, and data compromise. These vulnerabilities affect versions 26.6.x through 26.6.5, 26.7.… CERT-FR · Aug 6, 2026 High CVE-2026-15572CVE-2026-15573CVE-2026-16071keycloakvulnerabilitysecurity
threat-intel AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking A new vulnerability, dubbed 'PleaseFix,' is exposing AI browsers like Claude, Gemini, and Perplexity Comet to zero-click exploits. Attackers can inject malicious instructions into seemingly harmless content – such as ema… Dark Reading · Aug 5, 2026 High aiagentic browserzero-click
threat-intel Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Graham Cluley recounts a bizarre experience where he was contacted by someone posing as a police detective investigating a cybercrime. The individual claimed to have evidence suggesting they possessed a 24-word seed key… Graham Cluley · Aug 5, 2026 High cryptocurrencyhardware walletphishing
threat-intel No Perfect Fix for AI Browser Prompt Injection Flaws Research presented at Black Hat USA 2026 revealed that despite numerous security guardrails, AI-powered web browsers remain vulnerable to prompt injection attacks. Artem Chaikin demonstrated how attackers can bypass thes… Dark Reading · Aug 5, 2026 High prompt injectionai securityweb browser
threat-intel Prompt injection isn't the bug, AI agent frameworks are This article discusses the increasing risk of prompt injection attacks within AI agent frameworks, rather than the models themselves. The rise of open-source AI models, particularly from China, is prompting a reaction fr… The Register · Aug 5, 2026 Medium CHIRUSprompt injectionaillm
threat-intel Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says A House Committee investigation, spurred by the Salt Typhoon hack, revealed that Chinese telecommunications giants – China Mobile, China Unicom, and China Telecom – maintain a significant and deeply embedded presence in… The Record · Aug 5, 2026 High CHcybersecuritytelecomstate-sponsored
threat-intel Canadian man pleads guilty to Snowflake hacks that led to 165 breaches A Canadian man, Connor Riley Moucka, has pleaded guilty to hacking Snowflake and orchestrating data breaches affecting over 165 companies, including major names like AT&T and Ticketmaster. He and his co-conspirators stol… The Record · Aug 5, 2026 High CATUUNdata breachcybercrimelogin credentials
threat-intel CSS: The Hidden Threat Lurking in Your Inbox Researchers have discovered that Cascading Style Sheets (CSS), traditionally used for website design, can be weaponized to steal sensitive data from webmail platforms. While not a new threat, the potential for CSS-based… Dark Reading · Aug 5, 2026 Medium csswebmailsecurity
vulnerability How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Two security researchers, Dimitrios Valsamaras and Ken Gannon, demonstrated a complex exploit chain targeting Samsung phones, leveraging vulnerabilities in the Samsung Members and Samsung Account apps to gain remote code… SecurityWeek · Aug 5, 2026 High CVE-2025-21079CVE-2025-58486CVE-2025-58487androidbixbyexploit
threat-intel 15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning Researchers at Forescout discovered 15 vulnerabilities within TP-Link's ZTP (Zero-Touch Provisioning) ecosystem, primarily within their Omada networking devices. These vulnerabilities expose organizations to significant… Dark Reading · Aug 5, 2026 High ztpzero-touch provisioningvulnerabilities
threat-intel Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A macOS ClickFix operation is using browser fingerprinting to deliver malware lures to a targeted subset of Mac users. The operation, involving over 250 domains and distributing malware like MacSync and AMOS, hides the m… The Hacker News · Aug 5, 2026 High browser fingerprintingmacosclickfix
threat-intel OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes OpenAI disrupted a large-scale scam network originating from Cambodia, utilizing its ChatGPT AI chatbot to facilitate a wide range of fraudulent schemes, including investment scams, romance scams, and impersonating law e… The Hacker News · Aug 5, 2026 High KHaiscamcybercrime
threat-intel Flaws in Google APK for Python Unlock Agent-to-Agent Attack Researchers at Pillar Security discovered a critical vulnerability in Google's Agent Development Kit (ADK) for Python, allowing a low-privileged AI agent to trigger actions by a more privileged agent via prompt injection… Dark Reading · Aug 5, 2026 High prompt injectionai agentssupply chain
threat-intel AI Sends Global Crime Syndicates Into Fraud Nirvana AI is dramatically accelerating and industrializing fraud operations globally, enabling organized crime syndicates to bypass traditional security measures and create highly convincing synthetic identities and impersonati… Dark Reading · Aug 5, 2026 High AUNICAaifraudkyc
supply-chain Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th) A sophisticated supply-chain attack leveraging compromised npm packages (keyv and cacheable) has been active since August 4th, 2026. Attackers exploited a vulnerability to inject malicious code into widely used libraries… SANS Internet Storm Center · Aug 5, 2026 High supply-chainnpmcredential theft
threat-intel IBM's agentic AI platform is under active attack - patch now IBM's agentic AI platform is currently under active attack, with vulnerabilities exploited to gain control of systems. Attackers are leveraging prompt injection techniques to manipulate other AI agents, highlighting a gr… The Register · Aug 5, 2026 High CVE-2026-9198CHIRprompt injectionai securityvulnerability
threat-intel Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Cybersecurity researchers have uncovered a network of underground services, including ‘Poison Claude,’ offering discounted access to Anthropic’s AI models (like Claude Opus) to users in China and elsewhere. These service… The Hacker News · Aug 5, 2026 High CHaisynthetic identityproxy
supply-chain Dutch retailer De Bijenkorf warns customer data may be exposed after cyber incident De Bijenkorf, a Dutch luxury department store chain, is investigating a cyber incident that may have exposed customer data after a logistics provider was compromised. While payment details were not affected, customer inf… The Record · Aug 5, 2026 Medium NLPLDEsupply chaincyber incidentretail
vulnerability Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports Two critical vulnerabilities in Paperclip, an AI agent control plane, allow attackers to execute commands on a server or a developer's computer. The first vulnerability (CVE-2026-41679) requires no prior account or inter… The Hacker News · Aug 5, 2026 Critical CVE-2026-41679agentauthenticationdns