vulnerability Multiples vulnérabilités dans Google Chrome (12 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser on Windows, Linux, and macOS. The exact nature of the security issue is not specified by the publisher, but users ar… CERT-FR · Aug 12, 2026 Medium CVE-2026-19556CVE-2026-19557CVE-2026-19558chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Office (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Office, some of which allow an attacker to trigger arbitrary code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities are p… CERT-FR · Aug 12, 2026 High CVE-2026-58651CVE-2026-62842CVE-2026-62882vulnerabilitysecuritymicrosoft
vulnerability Multiples vulnérabilités dans les produits Intel (12 août 2026) Multiple vulnerabilities have been discovered in Intel products, impacting a range of their processors. These vulnerabilities could lead to privilege escalation, data confidentiality breaches, and denial of service attac… CERT-FR · Aug 12, 2026 High intelvulnerabilitysecurity
threat-intel Signal adds an extra layer of security to make sure you're actually chatting with the right person A phishing campaign is underway where attackers are impersonating Signal support to trick users into revealing their information. This follows a broader trend of security vulnerabilities being exploited in open-source so… The Register · Aug 11, 2026 Medium phishingjoomlavulnerability
vulnerability Microsoft Plugs Nearly 400 Security Holes Microsoft released a massive update bundle addressing 398 security vulnerabilities, including one actively exploited and two previously disclosed flaws. Despite the sheer volume of fixes, only one of these vulnerabilitie… Krebs on Security · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-72971patch tuesdayvulnerabilityai
vulnerability Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Adobe has released critical patches to address over 50 vulnerabilities across its products, including significant flaws in ColdFusion and Campaign Classic. These vulnerabilities could lead to code execution and denial-of… SecurityWeek · Aug 11, 2026 High CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability Zoom Patches Zero-Click Code Execution Vulnerability Zoom has released patches to address four critical vulnerabilities, including a zero-click remote code execution flaw that could allow an attacker to take control of any participant’s machine without any user interaction… SecurityWeek · Aug 11, 2026 Critical CVE-2026-53413CVE-2026-53414CVE-2026-53415vulnerabilityremote code executionzero-click
threat-intel Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Mozilla has revoked a signing key for Firefox after an unencrypted copy of the key was accidentally uploaded to GitHub. This significantly increases the risk of malicious actors creating fake Firefox installations. The i… The Register · Aug 11, 2026 High key-managementfirefoxvulnerability
threat-intel Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets A malicious tool server leveraging the Model Context Protocol (MCP) can silently exfiltrate sensitive data – including SSH keys, source code, and customer data – from AI coding assistants. The attack works by splitting r… The Hacker News · Aug 11, 2026 High aimodel context protocolghostsplice
vulnerability Vulnérabilité dans Docker (11 août 2026) A vulnerability has been identified in Docker Desktop, allowing an attacker to compromise data integrity. Users of versions prior to 4.86.0 should immediately update to mitigate the risk. CERT-FR · Aug 11, 2026 Medium CVE-2026-17106dockervulnerabilitysecurity
vulnerability Multiples vulnérabilités dans OpenSSH (11 août 2026) Multiple vulnerabilities have been discovered in OpenSSH, impacting versions prior to 10.5. The exact nature of the security issue is not specified by the publisher, but users are advised to consult the vendor's security… CERT-FR · Aug 11, 2026 Medium sshvulnerabilitysecurity
vulnerability Vulnérabilité dans CPython (11 août 2026) A denial-of-service vulnerability has been identified in CPython, allowing an attacker to disrupt remote systems. The vulnerability stems from a lack of recent security updates and requires immediate patching to prevent… CERT-FR · Aug 11, 2026 Medium CVE-2026-18503pythondenial-of-servicevulnerability
vulnerability Multiples vulnérabilités dans Postfix (11 août 2026) Multiple vulnerabilities have been discovered in Postfix, potentially allowing attackers to cause a denial-of-service, bypass security policies, and create an unspecified security issue. Users of Postfix versions prior t… CERT-FR · Aug 11, 2026 Medium vulnerabilitymail serversecurity
threat-intel Multiples vulnérabilités dans les produits SAP (11 août 2026) Multiple vulnerabilities have been discovered in SAP products, including remote code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities can be exploited to cause significant damage.… CERT-FR · Aug 11, 2026 High CVE-2025-42947CVE-2025-58057CVE-2026-33871vulnerabilitysapsecurity
threat-intel Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list A user exploited a waitlist API for a gym class booking service by prompting an AI agent to bypass the normal process, demonstrating a vulnerability in how AI systems can be manipulated to access and abuse online service… The Register · Aug 10, 2026 Medium aiautomationsecurity
threat-intel Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development As AI accelerates software development, security teams are struggling to keep pace, leading to a massive backlog of vulnerabilities and an expanded attack surface. This webinar explores how to adapt security practices to… The Hacker News · Aug 10, 2026 Medium aisecuritydevelopment
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
threat-intel Python Now Has a Post-Quantum Encryption Library Python’s popular cryptography library, pyca/cryptography, has gained post-quantum encryption support thanks to funding from the Sovereign Tech Agency. This means developers can now integrate algorithms designed to withst… Schneier on Security · Aug 10, 2026 Medium post-quantumcryptographypython
threat-intel Claude Code puts auto mode in the driver's seat Several security incidents and developments are highlighted, including a vulnerability in Joomla extensions, a Microsoft SharePoint issue leading to a zero-day attack, and ongoing efforts to combat Iranian propaganda and… The Register · Aug 10, 2026 Medium IRUSvulnerabilityphishingransomware