vulnerability Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering A vulnerability in Google’s Agent Development Kit (ADK) for Python allowed an attacker to manipulate low-privileged agents to gain access to high-privilege capabilities, potentially leading to pull request poisoning and… SecurityWeek · Aug 4, 2026 High agent-to-agentpull request poisoningremote code execution
vulnerability New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated hosting customers to execute arbitrary database commands with administrative privileges, potentially leading to system-wide compromise. This flaw s… The Hacker News · Aug 4, 2026 Critical CVE-2026-58048CVE-2026-58047cvesql injectionprivilege escalation
threat-intel Some Claude Chats Are Searchable on Google A vulnerability in Anthropic's Claude chatbot system has led to users' private conversations, including cryptocurrency wallet keys and personal data, becoming searchable on Google. This stems from a user-controlled data… Schneier on Security · Aug 4, 2026 Medium privacyaidata-sharing
threat-intel “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Cisco Talos researchers have discovered that threat actors are increasingly leveraging artificial intelligence (AI) to significantly enhance their malicious capabilities, bypassing traditional safeguards and exhibiting a… Cisco Talos · Aug 4, 2026 High aiartificial intelligencethreat intelligence
vulnerability Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks A 22-year-old vulnerability in BMC management processors is exposing thousands of data centers to attack. The flaw allows attackers to retrieve password hashes and crack them offline, potentially gaining unauthorized acc… SecurityWeek · Aug 4, 2026 High CVE-2013-4786bmcipmipassword cracking
threat-intel DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution… The Hacker News · Aug 4, 2026 High RUsteganographyclickfixransomware
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
data-breach 150,000 Impacted by Madera Community Hospital Data Breach Madera Community Hospital in California experienced a data breach affecting over 150,000 individuals, exposing sensitive personal and financial information. The attackers initially demanded a ransom, which they subsequen… SecurityWeek · Aug 4, 2026 High USdata breachhealthcarecybersecurity
threat-intel CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its KEV catalog due to active exploitation. This flaw, stemming from incomplete patching of… The Hacker News · Aug 4, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875GEICSWvulnerabilityremote monitoringremote management
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers Microsoft significantly increased its bug bounty payouts, reaching over $20 million in the past year and rewarding 562 researchers across 64 countries. The company’s programs saw a substantial rise in submissions, partly… SecurityWeek · Aug 4, 2026 Medium bug bountyvulnerabilityresearch
threat-intel Cloudflare has mostly ditched third party security tools, suggests not trying that at home This article is a collection of security-related news snippets from The Register. It covers a range of topics including AI model releases from China, vulnerabilities in Joomla extensions, acquisitions in the cybersecurit… The Register · Aug 4, 2026 Medium CHSWvulnerabilityransomwarecybersecurity
vulnerability ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Aug 4, 2026 Critical activemqrcevulnerability
threat-intel New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems New York is investing $9 million to bolster cybersecurity at 153 water and wastewater systems, following a coordinated cyberattack targeting over 30 community water systems in Minnesota and subsequent incidents in at lea… SecurityWeek · Aug 4, 2026 Medium IRSOUNcyberattackindustrial control systemswater infrastructure
vulnerability Vulnérabilité dans les produits Check Point (04 août 2026) A vulnerability has been identified in Check Point’s security products, allowing attackers to execute arbitrary code remotely and bypass security policies. This affects older versions of their Multi-Domain Security Manag… CERT-FR · Aug 4, 2026 High CVE-2026-18574vulnerabilityremote code executionsecurity policy
vulnerability Multiples vulnérabilités dans les produits Tenable (04 août 2026) Multiple vulnerabilities have been discovered in Tenable products, including vulnerabilities that could lead to arbitrary code execution, data integrity compromise, and SQL injection attacks. These vulnerabilities span a… CERT-FR · Aug 4, 2026 High CVE-2025-11187CVE-2025-14179CVE-2025-15467vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans LibreNMS (04 août 2026) Multiple vulnerabilities have been discovered in LibreNMS, allowing attackers to execute arbitrary code remotely, perform server-side request forgery (SSRF), and inject code remotely via XSS. These vulnerabilities affect… CERT-FR · Aug 4, 2026 High CVE-2026-45694librenmsvulnerabilitycve
vulnerability Multiples vulnérabilités dans Microsoft Edge (04 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing an attacker to trigger an unspecified security issue. These vulnerabilities are part of a series of CVEs released on July 31, 2026. Us… CERT-FR · Aug 4, 2026 CVE-2026-17871CVE-2026-17872CVE-2026-17873
vulnerability Multiples vulnérabilités dans Traefik (04 août 2026) Multiple vulnerabilities have been discovered in Traefik, allowing an attacker to bypass security policies. Users of Traefik versions 3.7.x prior to 3.7.10, 3.6.25, and 2.11.54 are at risk. The CERT-FR is advising users… CERT-FR · Aug 4, 2026 Medium traefikvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Google Android (04 août 2026) Google Android is experiencing multiple vulnerabilities, as reported by CERT-FR. The exact nature of these vulnerabilities is not specified, but users are urged to apply the security patch released on August 3, 2026, to… CERT-FR · Aug 4, 2026 Medium androidvulnerabilitysecurity