vulnerability Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Fortinet has released patches for eight security vulnerabilities across its products, including critical authentication flaws in FortiWeb and FortiManager. These vulnerabilities could allow attackers to gain unauthorized… SecurityWeek · Aug 13, 2026 Critical CVE-2026-26035CVE-2026-70468CVE-2026-70465vulnerabilityauthenticationpatch
threat-intel Passwords stored in public Google Doc then showed up in search results A security incident occurred where passwords were stored in a publicly accessible Google Doc, leading to those passwords appearing in search results. This highlights a significant risk of credential exposure and undersco… The Register · Aug 13, 2026 High IRcredentialspasswordsecurity
threat-intel Chinese Loongson processors have leaky caches, researchers find Researchers have discovered a significant security vulnerability in Chinese Loongson processors, specifically related to their cache memory. This allows attackers to potentially extract sensitive data from the processors… The Register · Aug 13, 2026 Medium CNvulnerabilitycachechina
vulnerability Vulnérabilité dans WordPress (13 août 2026) A remote code execution vulnerability has been identified in older versions of WordPress, allowing attackers to execute arbitrary code. This affects WordPress versions prior to 7.0.4, and requires immediate patching to p… CERT-FR · Aug 13, 2026 Critical CVE-2026-65640wordpressrcevulnerability
threat-intel Multiples vulnérabilités dans les produits Palo Alto Networks (13 août 2026) Multiple vulnerabilities have been discovered in Palo Alto Networks products, including remote code execution, privilege escalation, and denial-of-service attacks. Several CVEs have been identified, impacting various pro… CERT-FR · Aug 13, 2026 High CVE-2026-0291CVE-2026-0292CVE-2026-0293vulnerabilitythreatsecurity
vulnerability Vulnérabilité dans les produits Foxit (13 août 2026) A vulnerability has been identified in Foxit PDF Editor and Reader software, allowing an attacker to compromise data integrity. Users of older versions of these products are at risk of exploitation. The vendor has releas… CERT-FR · Aug 13, 2026 Medium CVE-2026-18622pdfvulnerabilitydata integrity
vulnerability Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible Researchers have discovered that some RISC-V chips are vulnerable to Spectre, a hardware-level security flaw that can be exploited to steal sensitive data. This represents a resurgence of Spectre concerns, highlighting t… The Register · Aug 12, 2026 Medium spectrerisc-vhardware
threat-intel Linux Kernel Process Accounting, (Wed, Aug 12th) This article details the Linux kernel process accounting feature, a tool for logging process activity on Linux systems. It’s a relatively simple-to-implement feature that doesn’t require kernel recompilation and can be u… SANS Internet Storm Center · Aug 12, 2026 Medium linuxprocess-monitoringlogging
vulnerability Exposed: Woeful security at UK criminal records office that led to sensitive data leak A security vulnerability in Joomla extensions has been exploited to compromise numerous websites, highlighting a broader issue of security weaknesses within open-source CMS platforms. This incident underscores the ongoin… The Register · Aug 12, 2026 Medium joomlavulnerabilityopen-source
threat-intel Mindgard Raises $30 Million to Protect AI Systems AI security startup Mindgard secured $30 million in Series A funding to bolster its platform for identifying and mitigating vulnerabilities in AI systems. The company’s platform proactively tests AI models and applicatio… SecurityWeek · Aug 12, 2026 Medium aisecurityvulnerability
threat-intel OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning Researchers have discovered a significant vulnerability in OpenAI, Anthropic, and Google's AI APIs that allows weaker AI models to decode the reasoning processes of stronger models by replaying encrypted reasoning blocks… The Hacker News · Aug 12, 2026 High encryptionapiprompt injection
vulnerability Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws Adobe has released critical security patches to address multiple vulnerabilities in ColdFusion, Commerce, and Campaign Classic. These flaws could lead to arbitrary code execution and privilege escalation, and while no ex… The Hacker News · Aug 12, 2026 Critical CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined Intel and AMD released patches addressing over 80 vulnerabilities across their products, including fixes for privilege escalation, denial-of-service attacks, and information disclosure. The updates cover a wide range of… SecurityWeek · Aug 12, 2026 High patch tuesdayvulnerabilitiessecurity
threat-intel Prompt Injections for Defense Researchers discovered a method called ‘context bombing’ where strategically placing prompt injections alongside sensitive data (like passwords and keys) can effectively disable AI hacking agents. This works by forcing t… Schneier on Security · Aug 12, 2026 Medium prompt-injectionai-securityguardrails
vulnerability ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Several major industrial automation vendors – Siemens, Schneider Electric, and Phoenix Contact – released security patches to address critical vulnerabilities in their ICS products. These flaws could allow attackers to e… SecurityWeek · Aug 12, 2026 High icsindustrial control systemspatch tuesday
vulnerability SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a critical security flaw in its Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability stems from insufficient autho… The Hacker News · Aug 12, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-34265securitypatcharbitrary code execution
vulnerability Multiples vulnérabilités dans Microsoft Edge (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing an attacker to trigger arbitrary code execution and a security issue not specified by the vendor. These vulnerabilities are part of a larger set o… CERT-FR · Aug 12, 2026 High CVE-2026-19137CVE-2026-19138CVE-2026-19139vulnerabilitysecuritymicrosoft
vulnerability Multiples vulnérabilités dans les produits Ivanti (12 août 2026) Multiple vulnerabilities have been discovered in Ivanti products, including Endpoint Manager and Neurons for MDM. These flaws could lead to data integrity compromise, data confidentiality breaches, and denial-of-service… CERT-FR · Aug 12, 2026 Medium CVE-2026-18125CVE-2026-18127CVE-2026-18129ivantivulnerabilityendpoint
vulnerability Multiples vulnérabilités dans Microsoft Azure (12 août 2026) Multiple vulnerabilities have been discovered within Microsoft Azure, potentially allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect va… CERT-FR · Aug 12, 2026 High CVE-2026-47299CVE-2026-57104CVE-2026-65806azurevulnerabilitysecurity
threat-intel Multiples vulnérabilités dans les produits Microsoft (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, some of which allow an attacker to cause arbitrary code execution, privilege escalation, and a denial-of-service attack. These vulnerabilities span a w… CERT-FR · Aug 12, 2026 High CVE-2026-40375CVE-2026-47285CVE-2026-54123vulnerabilitysecuritymicrosoft