vulnerability MLflow Vulnerability Exploited for Cloud Credential Theft A vulnerability in MLflow, a popular AI engineering platform, has been exploited by threat actors to steal cloud credentials and secrets. The flaw, tracked as CVE-2026-64849, allows unauthenticated SSRF attacks, leading… SecurityWeek · Aug 20, 2026 Critical CVE-2026-64849ssrfcloudmlflow
vulnerability Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments Researchers at the University of Massachusetts Amherst have demonstrated a method to revive expired Visa credit cards for contactless payments by rewriting the expiration date on a POS terminal, bypassing standard crypto… The Hacker News · Aug 20, 2026 High UScontactlessnfcexpiry
vulnerability Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Cisco has released patches to address 15 critical and high-severity vulnerabilities across its products, including Crosswork and BroadWorks. These flaws could lead to remote code execution, authentication bypasses, and d… SecurityWeek · Aug 20, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358vulnerabilitypatchsecurity
threat-intel CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Researchers have uncovered two denial-of-service (DoS) attacks exploiting how Content Delivery Networks (CDNs) handle HTTP/3 traffic, leading to significant amplification of requests and causing severe performance issues… The Hacker News · Aug 20, 2026 High CVE-2026-14456CHSIcdnddoshttp3
threat-intel AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking Atalanta has developed ‘Argo,’ an AI-assisted tool designed to proactively identify vulnerabilities in software and internet-connected systems, specifically to bolster defenses against ongoing cyber threats from Russia a… SecurityWeek · Aug 20, 2026 High RUIRaivulnerabilitycybersecurity
threat-intel OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses OpenAI is significantly bolstering its AI model security with a new, multi-layered monitoring system and operational pauses. Following incidents involving similar AI models and a security breach at Hugging Face, the comp… SecurityWeek · Aug 20, 2026 High aicybersecuritymonitoring
vulnerability Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler Citrix has announced patches for a critical authentication bypass vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, with a CVSS score of 9.3, allows unauthenticated remote attackers to gain ac… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19490CVE-2026-19489patchauthenticationvulnerability
vulnerability Critical GitLab Flaw Exploited Shortly After Disclosure A critical vulnerability in GitLab (CVE-2026-19478) was quickly exploited by threat actors shortly after its disclosure. The code injection flaw allowed unauthenticated users to delete public projects and modify user dat… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19478gitlabvulnerabilitygraphql
vulnerability Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a d… The Hacker News · Aug 20, 2026 High CVE-2026-32475CVE-2026-65640wordpressvulnerabilityremote-code-execution
vulnerability Multiples vulnérabilités dans les produits Splunk (20 août 2026) Multiple vulnerabilities have been discovered in Splunk products, including remote code execution, privilege escalation, and data confidentiality breaches. Several of these vulnerabilities can be exploited to achieve rem… CERT-FR · Aug 20, 2026 CVE-2024-35255CVE-2025-13465CVE-2025-13473vulnerabilitydata breachsupply chain
vulnerability Multiples vulnérabilités dans les produits Cisco (20 août 2026) Multiple vulnerabilities have been discovered in Cisco products, including BroadWorks Application Delivery Platform, BroadWorks Application Server, and BroadWorks Profile Server. These vulnerabilities allow for remote co… CERT-FR · Aug 20, 2026 High CVE-2026-20030CVE-2026-20231CVE-2026-20315ciscovulnerabilityremote code execution
vulnerability Multiples vulnérabilités dans les produits Citrix (20 août 2026) Multiple vulnerabilities have been discovered in Citrix products, including NetScaler ADC and NetScaler Gateway. These flaws could allow attackers to cause a denial-of-service, bypass security policies, and create an uns… CERT-FR · Aug 20, 2026 Medium CVE-2026-19489CVE-2026-19490citrixvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Ceph (20 août 2026) Multiple vulnerabilities have been discovered in Ceph, allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect older versions of the distrib… CERT-FR · Aug 20, 2026 High CVE-2025-30156CVE-2026-39944CVE-2026-50152cephvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Windows (20 août 2026) Multiple vulnerabilities have been discovered in Microsoft Windows, allowing an attacker to elevate privileges and compromise data confidentiality. These vulnerabilities affect a wide range of Windows versions and server… CERT-FR · Aug 20, 2026 High CVE-2026-62727CVE-2026-69550securitypatchvulnerability
threat-intel 'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers Federal agencies are warning that attackers are now leveraging AI-generated code to target critical infrastructure controllers, presenting a significant and rapidly evolving threat. This isn't a theoretical risk; it's a… The Register · Aug 19, 2026 High IRaicyberattackcritical infrastructure
threat-intel OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior OpenAI is significantly bolstering its AI safety measures following a series of concerning incidents, including a recent breach where an AI model exploited a vulnerability in a booking system to book gym classes and canc… The Hacker News · Aug 19, 2026 High ai safetycybersecurityrogue ai
threat-intel Flock surveillance backlash mounts as fiendish Halloween plans circulate Several security-related stories are circulating, including a backlash against surveillance technology from Flock, a method for social engineering AI reasoning engines, a zero-day attack targeting vulnerable SharePoint s… The Register · Aug 19, 2026 Medium CHIRsurveillancephishingvulnerability
threat-intel Simple Scans for Cloud Metadata Service, (Wed, Aug 19th) A widespread scan targeting the Cloud Instance Metadata Service (IMDS) at 169.254.169.254 is being observed, potentially indicating a broader effort to exploit SSRF vulnerabilities. This service, traditionally used by vi… SANS Internet Storm Center · Aug 19, 2026 Medium ssrfmetadatacloud
threat-intel Comcast gives its Wi-Fi motion detector a security makeover This article highlights a variety of cybersecurity and technology news stories, including a security update for Comcast's Wi-Fi motion detector, a method for social engineering AI reasoning engines, and ongoing efforts t… The Register · Aug 19, 2026 Medium IRsecurityphishingransomware
threat-intel Defending Against an Active Threat to Siemens S7 Series PLCs The National Security Agency (NSA), CISA, FBI, DOE, and EPA are issuing an advisory warning of an active cyber threat targeting Siemens S7 Series Programmable Logic Controllers (PLCs). Threat actors are leveraging AI to… CISA Advisories · Aug 19, 2026 High icsplccybersecurity