vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
threat-intel Claude Code puts auto mode in the driver's seat Several security incidents and developments are highlighted, including a vulnerability in Joomla extensions, a Microsoft SharePoint issue leading to a zero-day attack, and ongoing efforts to combat Iranian propaganda and… The Register · Aug 10, 2026 Medium IRUSvulnerabilityphishingransomware
vulnerability Critical Flaws Discovered in Belgian eID Software Used by 2 Million People A critical vulnerability in Nitro Software Belgium’s Connective digital identity system, used by over two million people in Belgium, allowed attackers to steal sensitive data and forge electronic signatures. The flaw was… SecurityWeek · Aug 10, 2026 High BEdigital identityeidbrowser extension
threat-intel Ransomware gangs skip the CEO, head straight for the 40-something IT manager Ransomware gangs are increasingly targeting IT managers, specifically those in their 40s, bypassing traditional executive channels to gain access to sensitive data and systems. This shift suggests a change in tactics by… The Register · Aug 9, 2026 Medium ransomwarecybersecuritylinux
threat-intel Un milliard d’identifiants français sur le darkweb A massive collection of over 1.7 billion unique French email addresses and passwords has been discovered on the dark web, originating from 13 years of phishing campaigns and data breaches. The data, totaling 28GB across… ZATAZ · Aug 8, 2026 High FRcredential stuffingphishingdata breach
threat-intel Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Several security-related stories are emerging, including a focus on AI security and vulnerabilities, a Russian phishing campaign mimicking Signal support, and ongoing efforts to improve security across various Linux and… The Register · Aug 8, 2026 Medium RUIRaisecurityphishing
threat-intel OpenAI pledges to add Astra security as Anthropic loosens Fable's leash OpenAI is bolstering its AI security by integrating Astra, while Anthropic is loosening restrictions on its Fable system. This shift reflects growing concerns about the potential risks associated with increasingly autono… The Register · Aug 7, 2026 Medium IRaisecurityvulnerability
threat-intel UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data UNC6671, a data extortion group linked to ShinyHunters and potentially SLH, is leveraging sophisticated vishing tactics to steal SaaS data from organizations across multiple sectors. They impersonate IT help desks, direc… The Hacker News · Aug 7, 2026 High NOAUU.vishingphishingdata-breach
threat-intel Military device manufacturer discloses cyber incident to SEC IEH Corporation, a military device manufacturer, suffered a cyberattack after an employee fell victim to a phishing scheme, gaining unauthorized access to their email account. The attackers accessed sensitive data includ… The Record · Aug 7, 2026 Medium INUSphishingcyberattackdata-breach
threat-intel Ransomware attacks spike as world distracted by AI Ransomware attacks are increasing, potentially coinciding with a global focus on AI. This article highlights a range of security incidents, including a zero-day exploit targeting on-prem SharePoint, phishing attacks mimi… The Register · Aug 7, 2026 Medium IRransomwarephishingvulnerability
threat-intel In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Several significant cybersecurity events are unfolding this week, including a coordinated AI-powered scam network originating in Cambodia, a data breach at Amgen, a supply chain attack targeting QuickFox VPN, and a serie… SecurityWeek · Aug 7, 2026 High CHCAUSsupply-chainphishingransomware
vulnerability MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs This article discusses a vulnerability related to Spectre defenses on Intel and AMD CPUs, where an AI-powered attack, dubbed TONTOU, successfully bypassed existing security measures. The vulnerability stems from AI's str… The Register · Aug 7, 2026 Medium CHIRspectrevulnerabilityai
threat-intel Attacker phished way into US defense supplier's Microsoft 365 account A US defense supplier's Microsoft 365 account was compromised after an attacker successfully phished credentials. The attacker exploited a vulnerability to gain access, highlighting a continuing issue with phishing attac… The Register · Aug 7, 2026 Medium phishingmicrosoftcredential theft
threat-intel Vishing Extortion Group UNC6671 Rebrands After Making Millions UNC6671, an extortion group previously known as BlackFile, has rebranded and continued its operations under multiple names (Redact, Pink, Helix, and Falcon) while targeting sectors like financial services and private equ… SecurityWeek · Aug 7, 2026 High vishingphishingransomware
threat-intel Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails A widespread phishing campaign, leveraging adversary-in-the-middle (AitM) techniques and residential proxies, is targeting organizations across various sectors in the U.S., Canada, and Europe. The campaign, linked to the… The Hacker News · Aug 7, 2026 High USCAEUaitmphishingmicrosoft 365
threat-intel 'Asimov was right' about rules for robots, says ex-US Cyber Director This article highlights a range of cybersecurity and technology news, including a Microsoft SharePoint vulnerability exploited in the wild, a Russian phishing campaign mimicking Signal support, and acquisitions within th… The Register · Aug 7, 2026 Medium RUvulnerabilityphishingacquisition
threat-intel Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access Researchers have discovered a vulnerability in Windows Hello for Business that allows malware running within a signed-in session to leverage the victim's hardware-backed authentication key to gain persistent access to Mi… The Hacker News · Aug 7, 2026 High windowsentria idwebauthn
threat-intel How the famed USENIX Security conf is managing a flood of papers in the AI era The USENIX Security conference is grappling with a surge in research papers, particularly those leveraging AI and machine learning. While AI usage is increasing, concerns are being raised about the potential for autonomo… The Register · Aug 6, 2026 Medium USCHRUaimachine learningvulnerability
threat-intel ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories This week's 'ThreatsDay' bulletin highlights a diverse range of security threats, including a China-linked telecom risk, a multi-stage phishing attack leveraging ClickOnce files, a supply chain attack involving 846 softw… The Hacker News · Aug 6, 2026 High CVE-2025-21079CVE-2025-58486CVE-2026-25177CHUSsupply-chainmalwarephishing
threat-intel Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Zenity researchers have uncovered two zero-click hacking techniques targeting AI browser agents, ChatGPT Atlas and Claude in Chrome. These attacks allow attackers to hijack user sessions, conduct phishing campaigns (incl… SecurityWeek · Aug 6, 2026 High zero-clickprompt injectionagentic browser