vulnerability SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities SAP released 28 security notes on August 2026 Patch Day to address a range of critical vulnerabilities across its products, including SAP Commerce Cloud, NetWeaver Application Server ABAP, and ABAP Platform. These flaws… SecurityWeek · Aug 11, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-44758vulnerabilitypatchcode injection
threat-intel US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ The US is bolstering its defenses against cyberattacks targeting water infrastructure through a combination of new legislation and a grassroots initiative. The Water Cyber Shield Act will expand federal oversight, while… SecurityWeek · Aug 11, 2026 Medium cybersecuritywater systemsdigital twins
threat-intel Corma Raises $60 Million for Defensive Cybersecurity AI Model Corma, a new cybersecurity firm, has secured $60 million in funding to develop an AI-powered defensive cybersecurity model. Unlike general AI models, Corma’s system is specifically designed to analyze security telemetry… SecurityWeek · Aug 11, 2026 Medium aicybersecuritydefense
threat-intel Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities A Chrome extension, initially banned for stealing AI chat conversations, has returned to the Chrome Web Store and is now targeting enterprise browsers through Google's CDN. The extension employs a sophisticated affiliate… SecurityWeek · Aug 11, 2026 High chromeextensionaffiliate
threat-intel Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption Marcus Hutchins, a cybersecurity professional, rose to prominence in 2017 for his role in stopping the WannaCry ransomware attack. Initially involved in a cybercrime forum and creating a blog (MalwareTech) that inadverte… SecurityWeek · Aug 11, 2026 High USUKneurodiversitywannacrymalwaretech
threat-intel OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber OpenAI has released GPT-5.6-Cyber, a new AI model specifically designed for advanced cybersecurity tasks, including finding zero-days and creating exploit chains. This model addresses limitations of its predecessor, GPT-… SecurityWeek · Aug 11, 2026 High aicybersecurityvulnerability
supply-chain Mozilla Issues New Firefox GPG Key Following Exposure Mozilla has revoked a compromised GPG signing key used for Firefox and Thunderbird, following its accidental exposure in a GitHub repository. While the immediate risk was mitigated due to limited access, the incident hig… SecurityWeek · Aug 11, 2026 Medium gpgsupply-chainkey-rotation
threat-intel OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns OpenAI is suspending development of its upcoming AI model, Astra, due to concerns that it could autonomously develop zero-day exploits and execute complex cyberattacks. The company has implemented strict security control… SecurityWeek · Aug 10, 2026 High aicybersecurityai agents
threat-intel Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds Stealthium is a new cybersecurity firm addressing a critical security blind spot in the rapidly growing neo-cloud market, which utilizes specialized AI accelerators. Because traditional security tools aren't designed for… SecurityWeek · Aug 10, 2026 High neo-cloudacceleratorsupply chain
vulnerability Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Cisco has warned of seven high-severity vulnerabilities in its Secure Endpoint Connector software, stemming from flaws within the ClamAV antivirus engine. These vulnerabilities could lead to denial-of-service conditions… SecurityWeek · Aug 10, 2026 High CVE-2026-20337CVE-2026-20339CVE-2026-20345clamavvulnerabilitypatch
threat-intel ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad Tenet security researchers have demonstrated a novel ‘Ghostjacking’ attack that leverages poisoned logs to manipulate AI agents, effectively turning them into malicious tools. The attack exploits trust in AI agents by in… SecurityWeek · Aug 10, 2026 High aiartificial intelligencelog poisoning
threat-intel New Jersey, Alabama Join States Targeted in Water Cyberattacks A coordinated cyberattack targeting water and wastewater facilities in the United States is expanding, with New Jersey and Alabama becoming the latest states to report incidents. The attacks, linked to Iranian hackers, a… SecurityWeek · Aug 10, 2026 High IRUScyberattackwater systemsics
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
threat-intel Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Polish CERT has revealed a second, parallel cyberattack targeting a smaller CHP plant supplying heat to 50,000 residents, utilizing a novel private APN attack vector. The attack, attributed to Russian APT group Sandworm,… SecurityWeek · Aug 10, 2026 High PLicsindustrial control systemsprivate apn
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
threat-intel Corporate Data Stolen in Levi Strauss Cyberattack Levi Strauss & Co. suffered a cyberattack resulting from social engineering, leading to unauthorized access to employee computers and potential corporate data theft. While initial investigations suggest no customer data… SecurityWeek · Aug 10, 2026 Medium social engineeringcyberattackdata breach
vulnerability Critical Flaws Discovered in Belgian eID Software Used by 2 Million People A critical vulnerability in Nitro Software Belgium’s Connective digital identity system, used by over two million people in Belgium, allowed attackers to steal sensitive data and forge electronic signatures. The flaw was… SecurityWeek · Aug 10, 2026 High BEdigital identityeidbrowser extension
vulnerability Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data A critical one-click vulnerability, dubbed RovoBlast, has been discovered in Atlassian’s Rovo AI assistant, allowing attackers to inject malicious prompts and exfiltrate sensitive data from various Atlassian products and… SecurityWeek · Aug 8, 2026 Critical aiprompt injectiondata exfiltration
threat-intel In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Several significant cybersecurity events are unfolding this week, including a coordinated AI-powered scam network originating in Cambodia, a data breach at Amgen, a supply chain attack targeting QuickFox VPN, and a serie… SecurityWeek · Aug 7, 2026 High CHCAUSsupply-chainphishingransomware
threat-intel Vishing Extortion Group UNC6671 Rebrands After Making Millions UNC6671, an extortion group previously known as BlackFile, has rebranded and continued its operations under multiple names (Redact, Pink, Helix, and Falcon) while targeting sectors like financial services and private equ… SecurityWeek · Aug 7, 2026 High vishingphishingransomware