threat-intel Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026 focused heavily on the accelerating role of AI in cybersecurity, both as a threat and a tool. Experts highlighted the rapid discovery of vulnerabilities by AI systems and the need for robust oversight… WeLiveSecurity · Aug 12, 2026 Medium aicybersecurityvulnerabilities
threat-intel Three intrusions at UK criminal records office went undetected for two years The UK criminal records office, ACRO, suffered three undetected intrusions over two years due to severe security failings, including unaddressed vulnerabilities in its public-facing website and ignored cybersecurity aler… The Record · Aug 12, 2026 High security breachdata breachransomware
vulnerability Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-59310) in Broadcom VMware vCenter to gain persistent remote access. QUIRSO discovered a campaign involving 361 unique victim IP ad… The Hacker News · Aug 12, 2026 High CVE-2026-59310CVE-2026-59309GEUNTUvulnerabilityexploitreverse_ssh
vulnerability ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access A security researcher, Chaotic Eclipse, has released a proof-of-concept (PoC) demonstrating a patch bypass for a Microsoft Defender zero-day vulnerability, dubbed ShieldBreak. This vulnerability, CVE-2026-50656 (RoguePla… The Hacker News · Aug 12, 2026 High CVE-2026-50656CVE-2026-62832CVE-2026-68820zero-daypatch-bypassprivilege escalation
vulnerability Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS A critical vulnerability (CVE-2026-20349, CVSS: 8.6) in Cisco ASA and FTD software has been actively exploited in the wild. This flaw, triggered by a crafted HTTP request, can lead to a denial-of-service condition and is… The Hacker News · Aug 12, 2026 Critical CVE-2026-20349cveasaftd
threat-intel Multiples vulnérabilités dans Microsoft Windows (12 août 2026) Multiple vulnerabilities have been discovered in Microsoft Windows, including remote code execution, privilege escalation, and denial-of-service attacks. Microsoft indicates that vulnerability CVE-2026-42976 is actively… CERT-FR · Aug 12, 2026 High CVE-2026-68820CVE-2026-42976CVE-2026-49179vulnerabilityremote code executionprivilege escalation
vulnerability Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688… The Hacker News · Aug 11, 2026 High CVE-2026-68820CVE-2026-62878CVE-2026-62893zero-dayrceexploit
threat-intel NSA installs DHS lawyer as new general counsel The National Security Agency (NSA) has appointed Kerianne Tobitsch, a former Homeland Security lawyer and Jones Day partner, as its new general counsel. This appointment follows a series of high-level departures within t… The Record · Aug 11, 2026 Medium fisansasurveillance
vulnerability August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Microsoft released a substantial update addressing 421 vulnerabilities, including a critical zero-day exploit in a kernel-mode driver (afd.sys). Threat actors, potentially including nation-state actors like those linked… SecurityWeek · Aug 11, 2026 High CVE-2026-68820CVE-2025-32709CVE-2025-21418zero-daykernel-modeprivilege escalation
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
threat-intel Two wars and a World Cup lead to epic DDoS attacks on publishers This article covers a range of cybersecurity and technology news, including a phishing campaign targeting Signal users, a zero-day exploit affecting on-prem SharePoint, and a vulnerability impacting Joomla extensions. It… The Register · Aug 11, 2026 Medium IRphishingvulnerabilitycybersecurity
threat-intel Google suspend son IA d’images dans Google Earth Google has temporarily suspended a new AI feature in Google Earth that allowed users to generate fictional satellite images based on text prompts. The feature, dubbed Nano Banana 2, was quickly shut down after journalist… ZATAZ · Aug 11, 2026 Medium aidisinformationsatellite imagery
threat-intel US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ The US is bolstering its defenses against cyberattacks targeting water infrastructure through a combination of new legislation and a grassroots initiative. The Water Cyber Shield Act will expand federal oversight, while… SecurityWeek · Aug 11, 2026 Medium cybersecuritywater systemsdigital twins
threat-intel Local governments in four states dealing with cyberattacks that have shut down services Local governments across four states – California, Oklahoma, South Dakota, Texas, and Wisconsin – are experiencing a surge in cyberattacks, leading to service disruptions and shutdowns. These attacks have impacted critic… The Record · Aug 11, 2026 High UScyberattacklocal governmentransomware
threat-intel Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G This article discusses a security vulnerability where malicious actors are exploiting SIM cards to disable phones, steal data, and potentially downgrade connections to 2G, enabling more sophisticated phishing attacks. Th… The Register · Aug 11, 2026 High CVE-2025-48618CHRUsim cardphishingtelecom security
vulnerability ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Aug 11, 2026 Critical log4jrcevulnerability
threat-intel DEF CON hackers add new muscle to water utility protection DEF CON hackers are focusing on bolstering water utility protection by leveraging their skills to identify and address vulnerabilities in critical infrastructure. This initiative follows successful 'Voting Village' proje… The Register · Aug 10, 2026 Medium cybersecurityinfrastructurevulnerabilities
threat-intel FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure The FBI and South Korea’s government have issued a cybersecurity advisory warning of the Gunra ransomware gang, which is exploiting vulnerabilities in Fortinet firewalls to target critical infrastructure organizations gl… The Record · Aug 10, 2026 High CVE-2024-55591CVE-2025-24472SONOransomwarevulnerabilitysupply-chain
threat-intel North Korean spies are running local LLMs to cause AI mischief North Korean intelligence operatives are leveraging locally hosted Large Language Models (LLMs) to conduct sophisticated disinformation campaigns and potentially cause broader AI-related mischief. This indicates a growin… The Register · Aug 10, 2026 Medium NOaillmcyberespionage
threat-intel Coruna, DarkSword iOS Exploits Proliferate Globally Sophisticated iPhone exploit chains, DarkSword and Coruna, are rapidly spreading beyond nation-state actors and into the hands of organized cybercrime groups. These advanced tools, initially developed for surveillance an… Dark Reading · Aug 10, 2026 High CVE-2025-31277CVE-2025-43529CVE-2026-20700CHMASAexploitioscybercrime