threat-intel ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · 5d ago Medium phishingvulnerabilitycredential theft
vulnerability Multiples vulnérabilités dans OpenSSL (26 août 2026) Multiple vulnerabilities have been discovered in OpenSSL, allowing for denial of service attacks and policy bypasses. These vulnerabilities affect various OpenSSL versions and could be exploited by attackers. Users are a… CERT-FR · 5d ago Medium CVE-2026-14457CVE-2026-18798CVE-2026-54874vulnerabilityopensslsecurity
vulnerability Multiples vulnérabilités dans les produits Veeam (26 août 2026) Multiple vulnerabilities have been discovered in Veeam products, allowing an attacker to compromise data confidentiality and bypass security policies. Veeam has released security bulletins with patches to address these i… CERT-FR · 5d ago Medium CVE-2026-58070CVE-2026-65641vulnerabilitypatchsecurity
threat-intel Hidden Prompts Trick AI Into False Email Summaries Researchers at Forcepoint X-Labs demonstrated how attackers can manipulate AI-powered email summarizers by embedding malicious prompts within seemingly normal emails. The AI then generated false and altered summaries, hi… Dark Reading · 5d ago High prompt injectionai securityhtml injection
threat-intel 58 arrested in international cybercrime crackdown Interpol and law enforcement agencies across 22 countries concluded Operation Jackal IV, resulting in the arrest of 58 individuals involved in a coordinated cybercrime operation. The operation targeted a crime-as-a-servi… The Record · 5d ago High ARITROcybercrimeromance scamsmoney laundering
vulnerability Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw A vulnerability in NVIDIA's NemoClaw tool, used for deploying AI agents with OpenClaw, allows unauthenticated attackers to poison a large language model's chat template and corrupt the AI agents using it. The issue stems… Dark Reading · 5d ago High aiagentdns rebinding
threat-intel Employee benefits platform Paylogix says hackers stole financial and health data Paylogix, a benefits administration platform, suffered a cyberattack that exposed sensitive data for tens of thousands of users, including Social Security numbers, health insurance details, and passport information. The… The Record · 5d ago Critical USransomwaredata breachcyberattack
threat-intel U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches The U.S. Treasury has imposed fresh sanctions on nearly 60 Iran-linked entities, including individuals and vessels, as part of "Operation Economic Outcast." These sanctions target a cyber group affiliated with Iran's Min… The Hacker News · 5d ago High IRUKsanctionscyber espionagecritical infrastructure
threat-intel Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation The Linux Foundation will manage TRACE, a new open standard for verifying the behavior of AI agents and confidential workloads. Developed collaboratively by AMD, Intel, Microsoft, and the Technology Innovation Institute,… SecurityWeek · 5d ago Medium aiconfidential computingtrust
vulnerability You could've applied all 1,449 Oracle patches and still been hit by this attack A zero-day vulnerability in on-prem SharePoint, stemming from improperly applied patches, is being exploited by attackers. Despite applying 1,449 Oracle patches, attackers successfully leveraged this flaw to gain unautho… The Register · 5d ago High UNzero-dayvulnerabilitysharepoint
threat-intel Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th) Attackers are increasingly using hostname-based IP address obfuscation, specifically leveraging services like 1u.ms to bypass security measures. This tactic is used to exploit vulnerabilities like Server Side Request For… SANS Internet Storm Center · 5d ago Medium ssrfdnsobfuscation
threat-intel Is Cyber Facing an Affordability Crisis? The cybersecurity industry is facing an ‘affordability crisis’ driven by rapidly rising breach costs and defense spending, disproportionately impacting small and medium-sized businesses (SMBs) who often lack the resource… Dark Reading · 5d ago High cybersecurityaffordabilitysmb
threat-intel Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails Alice, a cybersecurity firm specializing in AI safety, has raised $140 million to bolster its defenses against vulnerabilities and attacks targeting generative AI models. The company uses a decade-long database of harmfu… SecurityWeek · 5d ago Medium ISUNaicybersecurityprompt injection
vulnerability A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw A vulnerability in NVIDIA NemoClaw allows an attacker to poison an AI model by serving a malicious webpage that can inject hidden instructions into every conversation. The vulnerability stems from a misconfigured Ollama… The Hacker News · 5d ago High CVE-2024-28224aimodel poisoningdns rebinding
threat-intel Ukraine to give Britain access to battlefield data to train AI Ukraine is sharing a massive dataset of battlefield imagery and video with the United Kingdom to train AI systems for defense purposes. This partnership, part of a broader effort to utilize war-generated data, will allow… The Record · 5d ago Medium UKUNRUaibattlefield dataukraine
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
threat-intel WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android WhatsApp is bolstering its security by introducing passkeys and enhanced two-step verification to combat phishing attacks and improve account protection for users on both iOS and Android. This move aims to make it signif… The Hacker News · 5d ago Medium passkeysphishingsecurity
threat-intel WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update WhatsApp has significantly boosted its account security by introducing multi-passkey support, upgrading two-step verification to stronger passwords, and providing caller information to combat scams. These changes aim to… SecurityWeek · 5d ago Medium passkeystwo-factorsecurity
threat-intel Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference SecurityWeek and MTSI are offering a hands-on training course, Cyber Attack Methods (CAM), as part of the 25th Anniversary Industrial Control Systems (ICS) Cybersecurity Conference. The course teaches participants to thi… SecurityWeek · 5d ago Medium cyber-physicalicscybersecurity
threat-intel UK government seeks powers to secretly block risky tech suppliers The UK government is seeking new powers to secretly block technology suppliers deemed to pose a national security risk, particularly to critical sectors like energy, water, and transport. These powers, modeled after thos… The Record · 5d ago High UKnational securitycybersecurityvendor risk