threat-intel Agentic Browsers Rewind Web Security by 20 years Researchers at Zenity have discovered a significant vulnerability class – "PleaseFix" – that allows attackers to socially engineer AI agentic browsers to perform malicious actions, including account takeover and remote c… Dark Reading · Jul 27, 2026 High agentic browserssocial engineeringzero-click
vulnerability Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities are detailed in a series of security… CERT-FR · Jul 27, 2026 Medium CVE-2026-57978CVE-2026-57989CVE-2026-57990vulnerabilitymicrosoftedge
threat-intel Europol flags 4,340 'horrific' URLs linked to The Com This article is a collection of security-related news snippets from The Register. It highlights a phishing campaign targeting Signal users by Russian actors, a zero-day vulnerability in on-prem SharePoint, and a signific… The Register · Jul 24, 2026 Medium RUCHphishingvulnerabilitycybersecurity
threat-intel Uncle Sam tells overseas cybercrooks their visas are canceled This article covers a range of cybersecurity and technology news, including a US government action targeting Iranian propaganda sites, a security acquisition by EQT, and vulnerabilities impacting Joomla extensions. It al… The Register · Jul 24, 2026 Medium IRSWcybersecuritythreat intelligencevulnerability
vulnerability Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Bing Image Search had two critical vulnerabilities allowing attackers to execute commands as SYSTEM on Microsoft's servers by submitting crafted SVGs. The issue stemmed from a helper component that treated SVG files as c… The Hacker News · Jul 24, 2026 High CVE-2026-32194CVE-2026-32191CVE-2016-3714svgcommand-injectionimagemagick
threat-intel Motherless : les serveurs saisis au cœur de l’enquête Dutch police have seized servers associated with Motherless, a controversial online platform hosting potentially illegal content, including images of child sexual abuse and videos of women appearing to be drugged and ass… ZATAZ · Jul 24, 2026 High NLchild sexual abuseonline exploitationdigital evidence
vulnerability NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats NodeBB has patched eight security flaws, including vulnerabilities allowing unauthorized admin access and the ability to read private chats, discovered by AI penetration testing. The flaws, some of which stem from the fo… The Hacker News · Jul 24, 2026 High CVE-2026-58593securityvulnerabilityadmin access
vulnerability Multiples vulnérabilités dans Microsoft Edge (24 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, impacting versions prior to 150.0.4078.96. The exact nature of the vulnerabilities and the resulting security issue are not specified by the publisher. Use… CERT-FR · Jul 24, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415vulnerabilitypatchsecurity
threat-intel OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be This article covers a range of cybersecurity and technology news, including a competitive landscape in AI hardware between AMD and Nvidia, a security incident involving Joomla extensions, and a general overview of variou… The Register · Jul 23, 2026 Medium IRSWcybersecurityj2eex11
threat-intel Researchers replace downloaded macOS apps with evil twins, Apple shrugs Researchers have discovered a method to replace downloaded macOS applications with malicious 'evil twin' versions, while Apple has not responded to the issue. This highlights a significant vulnerability in how users obta… The Register · Jul 23, 2026 Medium IRUSmacosmalwarephishing
threat-intel Year-long Russian attacks infect users as soon as they look at an email Russian actors are leveraging phishing attacks, impersonating Signal support, to compromise users. This follows a broader trend of Russian state-sponsored actors targeting various systems and platforms, including exploit… The Register · Jul 23, 2026 High CVE-2025-66376RUphishingthreat-intelrussian
vulnerability Millions of California-bought cars can be hijacked via Bluetooth A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited to compromise websites running the CMS. Attackers are leveraging these flaws to gain unauthorized access to vulnerable sit… The Register · Jul 23, 2026 Medium joomlavulnerabilityextension
threat-intel Oracle drops 1,449 security patches like it's the new normal This article is a collection of security-related news snippets from The Register. It covers a range of topics including security patches from Oracle, advancements in AI hardware (AMD vs Nvidia), phishing attacks targetin… The Register · Jul 23, 2026 Medium CVE-2026-47056CVE-2026-60217CVE-2026-61211securityvulnerabilitiesphishing
threat-intel Iran-linked crews are probing more flavors of US industrial kit Iranian-linked actors are actively probing and exploiting vulnerabilities in various US-based industrial hardware and software, including AMD systems and Joomla extensions. This activity highlights a broader trend of sta… The Register · Jul 23, 2026 High IRstate-sponsoredvulnerabilitycyberattack
threat-intel One ChatGPT link could smuggle a rogue AI agent into your company This article is a collection of security and technology news snippets from The Register. It highlights a vulnerability impacting Joomla extensions, a Russian phishing campaign mimicking Signal support, and a general over… The Register · Jul 23, 2026 Medium IRvulnerabilityphishingransomware
threat-intel Swiss train maker tells ransomware crooks to get off at the next stop This article is a collection of security-related news snippets from The Register. It covers a range of topics including a Swiss train maker’s response to ransomware attacks, a security acquisition, ransomware trends, vul… The Register · Jul 23, 2026 Medium ISIRransomwarevulnerabilityjoomla
threat-intel Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts Google has introduced a new selfie video verification method to help users regain access to their accounts if they are locked out or unable to use traditional recovery options like email or phone number. This feature is… The Hacker News · Jul 23, 2026 Medium livenessfacial-recognitionauthentication
threat-intel Talking smack about a doctor got him access to private medical files This article is a collection of security and technology news snippets. It highlights a vulnerability impacting Joomla websites due to extension bugs, a Russian phishing campaign mimicking Signal support, and Microsoft's… The Register · Jul 23, 2026 Medium RUIRvulnerabilityphishingransomware
vulnerability Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026) Mozilla Thunderbird contains multiple vulnerabilities that could lead to data compromise, security policy bypass, denial of service, remote code execution, and privilege escalation. These vulnerabilities are present in v… CERT-FR · Jul 23, 2026 High CVE-2026-14899CVE-2026-15718CVE-2026-15719vulnerabilitysecurityfirefox
vulnerability Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A vulnerability in the Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294) allows attackers to silently steal WhatsApp Web data by tricking users into visiting a malicious website. The flaw requires only user… The Hacker News · Jul 22, 2026 High CVE-2026-48294chromeextensionwhatsapp