threat-intel “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Cisco Talos researchers have discovered that threat actors are increasingly leveraging artificial intelligence (AI) to significantly enhance their malicious capabilities, bypassing traditional safeguards and exhibiting a… Cisco Talos · Aug 4, 2026 High aiartificial intelligencethreat intelligence
threat-intel Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts Unit 42 researchers discovered three attack paths within Google Password Manager in Chrome that could allow malware to hijack passkey-protected accounts without requiring a fingerprint, PIN, or any user interaction. Thes… The Hacker News · Aug 3, 2026 High passkeyssecurityauthentication
threat-intel Pass the Passkey: A Novel Attack Surface in Passwordless Authentication This report details a new attack vector, dubbed ‘Pass-ta-key,’ that allows malware running on a compromised endpoint to bypass traditional security measures and gain unauthorized access to passkey-protected accounts. Res… Palo Alto Unit 42 · Aug 3, 2026 High USpasskeyauthenticationmalware
vulnerability ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Aug 3, 2026 Critical log4jrcejndi
threat-intel Cyber’Smile : la playlist d’été de ZATAZ est de sortie ZATAZ, a French cybersecurity news platform, has released a new music playlist called ‘Cyber’Smile’ to help users relax during their summer holidays. The playlist consists of five original tracks – Bolly’Hack, Clic and P… ZATAZ · Aug 1, 2026 Info musiccybersecurityplaylist
threat-intel The most famous brand in physical security got pwned by ShinyHunters ShinyHunters, a known threat actor, has exploited vulnerabilities in Joomla extensions to compromise websites, highlighting a persistent risk for open-source CMS platforms. This incident underscores the ongoing need for… The Register · Jul 31, 2026 Medium joomlavulnerabilityshinyhunters
threat-intel Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies A Chinese company, Zhejiang Fengwo IoT Technology Co., Ltd., is behind the ‘Fuyao’ operation, which involves shipping cheap Android TV boxes with apps that mimic phones and then use them to relay internet traffic as SOCK… The Hacker News · Jul 31, 2026 High CHHOSIandroidad fraudsocks5
vulnerability Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined Google has significantly increased its pace of Chrome security updates, releasing a combined 1,442 fixes across multiple versions (149, 150, and 151). This surge is driven by a rapid increase in vulnerability discovery,… The Hacker News · Jul 31, 2026 High CVE-2026-3545vulnerabilitysecuritypatch
vulnerability Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Google has significantly increased its use of AI, specifically a Gemini-powered agent harness, to identify and patch security vulnerabilities in Chrome at a dramatically accelerated rate. This initiative led to the disco… SecurityWeek · Jul 31, 2026 High CVE-2026-3545aisecuritychrome
threat-intel Read This Before You Buy That TV Streaming Stick A security firm, Bitsight, uncovered a complex and widespread ad fraud network centered around H96 streaming devices. These devices, often sold by major retailers, are secretly used to generate revenue by masquerading as… Krebs on Security · Jul 30, 2026 High CHHOSIiotproxyad fraud
threat-intel Headteacher had the most guessable username-password combo you could imagine This article is a roundup of cybersecurity and technology news, covering a range of topics including a phishing campaign targeting Signal users, a zero-day vulnerability in on-prem SharePoint, and a report on vulnerabili… The Register · Jul 30, 2026 Medium UNphishingvulnerabilityransomware
threat-intel Excuses like 'AI did it' don't exist in the eyes of the law This article is a collection of security-related news snippets, covering a range of topics from cybersecurity incidents and vulnerabilities to acquisitions and technological developments within the open-source and Linux… The Register · Jul 30, 2026 Medium IRCHphishingzero-dayransomware
vulnerability Multiples vulnérabilités dans Google Chrome (30 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, potentially allowing an attacker to cause a security issue. These vulnerabilities are spread across various Chrome versions and are related to a range of is… CERT-FR · Jul 30, 2026 High CVE-2026-17650CVE-2026-17651CVE-2026-17652chromevulnerabilitysecurity
vulnerability Vulnérabilité dans Apache Tomcat (29 juillet 2026) A critical vulnerability has been identified in Apache Tomcat, allowing attackers to cause a denial-of-service attack. This affects older versions of the web server, requiring immediate patching to prevent exploitation. CERT-FR · Jul 29, 2026 Critical CVE-2026-66299apachetomcatvulnerability
threat-intel MCP gets an enterprise makeover This article covers a range of cybersecurity and technology news, including a vulnerability impacting Joomla extensions, a Microsoft SharePoint zero-day exploit, and a Russian phishing campaign mimicking Signal support.… The Register · Jul 28, 2026 Medium USIRRUvulnerabilityphishingransomware
threat-intel Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process A new Mirai-derived botnet, Tengu, is leveraging hardware watchdog timers and other persistence mechanisms to re-establish itself on compromised Linux devices, even after defenders attempt to kill its main process. The b… The Hacker News · Jul 28, 2026 High botnetmiraiiot
vulnerability Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root OpenWrt has released version 24.10.8 to address a critical vulnerability (CVE-2026-53921) in its DHCPv6 stack, allowing unauthenticated attackers to execute code as root on devices running the firmware. The vulnerability… The Hacker News · Jul 28, 2026 High CVE-2026-53921CVE-2026-62948CVE-2026-62947dhcpv6stack-overflowluci
threat-intel Réseaux sociaux : ce qui changera en 2026 et 2027 France is set to implement a major digital shift, prohibiting access to social media for children under 15 by September 2026, with a broader enforcement in January 2027. This follows a similar initiative in Australia, bu… ZATAZ · Jul 28, 2026 High FRAUUNsocial mediaage verificationdata privacy
threat-intel Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first The United States is actively working to maintain leadership in 6G technology and security, particularly in response to China's advancements. Recent security incidents highlight ongoing threats, including phishing attack… The Register · Jul 28, 2026 Medium IRCHphishingvulnerabilitiescybersecurity
threat-intel AutoIT Payload Injector , (Tue, Jul 28th) A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's… SANS Internet Storm Center · Jul 28, 2026 High autoitshellcodepersistence