vulnerability Vulnérabilité dans Apereo CAS (19 août 2026) A security vulnerability has been identified in Apereo CAS, allowing attackers to bypass security policies. This affects older versions of the CAS system, requiring immediate patching to prevent exploitation. CERT-FR · Aug 19, 2026 Medium casvulnerabilitysecurity
vulnerability Critical GitLab Zero-Click Flaw Poses Mitigation Challenges GitLab has released an out-of-band security update addressing two critical vulnerabilities, CVE-2026-19478 and CVE-2062-19650, that could allow unauthenticated attackers to manipulate or delete data. The vulnerabilities… Dark Reading · Aug 18, 2026 Critical CVE-2026-19478CVE-2026-19650graphqlcvezero-click
threat-intel Expired credit cards revived by researchers to make unauthorized payments Researchers have discovered a method to revive expired credit cards and use them for unauthorized payments. This vulnerability stems from a flaw in how Stripe handles AI token sales, allowing attackers to manipulate the… The Register · Aug 18, 2026 High credit-cardsaitokenization
threat-intel 'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture Researchers discovered a novel 'meta-hacking' technique that tricked Microsoft Copilot Personal into revealing its own security vulnerabilities, allowing attackers to map out its architecture and subsequently steal enter… Dark Reading · Aug 18, 2026 High CVE-2026-24301prompt-injectionmeta-hackingdata-exfiltration
threat-intel CISOs Break Their Silence in 'Declassified' Docuseries Red Mirror Studios, led by Danielle Lewan and Clint Howard II, is releasing an 11-episode docuseries titled "Declassified" featuring 11 cybersecurity CISOs sharing their real-world breach-response stories and personal st… Dark Reading · Aug 18, 2026 High cybersecuritycisosburnout
threat-intel Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets Two critical vulnerabilities are being actively exploited to steal cloud credentials and secrets. MLflow (versions < 3.15.0) is experiencing SSRF attacks, allowing attackers to access cloud metadata and exfiltrate sensit… The Hacker News · Aug 18, 2026 Critical CVE-2026-64849CVE-2026-25895CVE-2026-25939ssrfpath traversalremote code execution
threat-intel Berlin cuts two state ministries off government network after security breach Berlin authorities have isolated two state ministries from the city's government network following a suspected security breach. The exact details of the attack, including the perpetrators and stolen data, remain unknown,… The Record · Aug 18, 2026 Medium DEsecurity breachnetwork isolationgovernment systems
vulnerability CISA gives feds 3 days to fix actively exploited Ray RCE bug The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency advisory to federal agencies, demanding they address a rapidly exploited Remote Code Execution (RCE) vulnerability in Ray Ray, a widely… The Register · Aug 18, 2026 High CVE-2025-62593ray rayrcevulnerability
threat-intel Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks The rapid advancement of AI is drastically shortening the time between vulnerability discovery and exploitation, forcing a fundamental shift in cybersecurity strategies. This webinar explores how AI is empowering attacke… SecurityWeek · Aug 18, 2026 Medium aicybersecuritythreat intelligence
threat-intel Apple plugs image-processing hole ripe for spyware abuse Apple has patched a security vulnerability in its image processing system that could have been exploited to install spyware. The flaw allowed attackers to trick an AI system into revealing instructions on how to self-hac… The Register · Aug 18, 2026 High CVE-2026-65346CVE-2026-65329aispywarevulnerability
threat-intel CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Nico Waisman’s cybersecurity journey is a remarkable and almost accidental one, beginning with a childhood fascination with hacking in Argentina and culminating in his current role as CISO at XBOW, a company specializing… SecurityWeek · Aug 18, 2026 High ARcybersecurityoffensive-securityai
threat-intel Copilot tricked into telling reseachers how to hack itself Researchers successfully tricked Microsoft's Copilot AI assistant into revealing instructions on how to exploit vulnerabilities within itself, highlighting a significant weakness in AI reasoning and a potential avenue fo… The Register · Aug 18, 2026 High aivulnerabilityprompt-injection
vulnerability CISA Malcolm Several vulnerabilities in CISA Malcolm allow for denial-of-service attacks and arbitrary code execution. Versions prior to 26.06.1 and 26.07.1 are affected. The vulnerabilities stem from issues related to unbounded file… CISA Advisories · Aug 18, 2026 High CVE-2026-55676CVE-2026-63133CVE-2026-63134vulnerabilitynginxlua
vulnerability Siemens Simcenter Nastran A stack overflow vulnerability exists in Siemens Simcenter Nastran and Femap versions prior to V2606, potentially allowing remote code execution. Siemens has released updates to address the issue. Organizations are advis… CISA Advisories · Aug 18, 2026 High CVE-2026-59086stack-overflowremote-code-executionindustrial-control-systems
vulnerability 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw A critical vulnerability in the Forminator Forms plugin for WordPress is exposing over 300,000 websites to potential remote code execution attacks. The flaw stems from inadequate file type validation, allowing attackers… SecurityWeek · Aug 18, 2026 Critical CVE-2026-15748wordpressvulnerabilityrce
vulnerability GitLab Patches Critical Code Injection Vulnerability GitLab has released patches to address two critical vulnerabilities, including a code injection flaw that could allow unauthorized data modification and deletion. These vulnerabilities affected multiple versions of GitLa… SecurityWeek · Aug 18, 2026 Critical CVE-2026-19478CVE-2026-19650vulnerabilitygraphqlcve
vulnerability Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates Apple released security updates for macOS, iOS, and iPadOS addressing dozens of vulnerabilities primarily within the WebKit browser engine. These updates fix issues ranging from crashes and data exposure to potential sys… SecurityWeek · Aug 18, 2026 Medium webkitsecuritypatch
vulnerability ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a log message. This vulnerability, alongside related exp… SANS Internet Storm Center · Aug 18, 2026 Critical log4jlog4j2apache
vulnerability Multiples vulnérabilités dans GitLab (18 août 2026) Multiple vulnerabilities have been discovered in GitLab, including one that could allow attackers to compromise data integrity and another through Cross-Site Request Forgery (CSRF). GitLab versions 19.0.x through 19.0.8,… CERT-FR · Aug 18, 2026 Medium CVE-2026-19478CVE-2026-19650gitlabvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Zabbix (18 août 2026) Multiple vulnerabilities have been discovered in Zabbix, potentially allowing attackers to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect various Zabbi… CERT-FR · Aug 18, 2026 High CVE-2026-1199CVE-2026-23922CVE-2026-23929zabbixvulnerabilitypatch