threat-intel Researcher shows how Claude Code can be tricked simply by asking it to summarize a website A researcher demonstrated a vulnerability in the Claude Code AI model, showing that it can be tricked into generating malicious code simply by asking it to summarize a website. This highlights a potential risk in using AI models for code generation and underscores the need for robust safeguards against prompt injection… The Register · 2d ago Medium IRCHaiprompt injectioncybersecurity
threat-intel Silent Patches Don’t Stop Attackers—They Blind Defenders Broadcom’s new program offering early access to CVE-only patches for Spring Framework users is exacerbating the problem of silent patching. While Broadcom continues to issue CVEs, the program effectively provides pre-ale… SecurityWeek · 5d ago High silent patchingvulnerability disclosureai-driven vulnerability
vulnerability 91 Vulnerabilities Patched in Spring Application Framework Broadcom released a massive update addressing 91 vulnerabilities within the Spring application framework. Many of these flaws, including a critical Remote Code Execution (RCE) vulnerability, could be exploited for variou… SecurityWeek · 6d ago High CVE-2026-59270CVE-2026-59285CVE-2026-59318springvulnerabilityrce
threat-intel Cyber actualités ZATAZ de la semaine du 17 au 23 août 2026 This week’s cybersecurity news is dominated by data breaches, ransomware attacks, and widespread data exposures. ShinyHunters is targeting Logitech and Streamlabs, while RingCentral has experienced a massive 1.6 million… ZATAZ · Aug 22, 2026 High FRBESOransomwaredata breachvpn
vulnerability Multiples vulnérabilités dans Oracle Systems (19 août 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality and integrity. These vulnerabilities affect several Oracle products and require immed… CERT-FR · Aug 19, 2026 High CVE-2026-60822CVE-2026-70737CVE-2026-70829oraclevulnerabilitypatch
vulnerability Recent macOS Screen Sharing Vulnerability Exploited in Attacks A recently patched macOS Screen Sharing vulnerability is being actively exploited in the wild by threat actors to gain root access and deploy cryptominers. The flaw allows attackers to authenticate without credentials si… SecurityWeek · Aug 17, 2026 High CVE-2026-65400macosscreen sharingroot access
vulnerability Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner A critical vulnerability in Apple's macOS Screen Sharing component has been actively exploited in the wild to install a cryptocurrency miner. Researchers have discovered a pre-authentication vulnerability (CVE-2026-65400… The Hacker News · Aug 15, 2026 Critical CVE-2026-65400CVE-2026-43779CVE-2026-43777USmacosscreen sharingvulnerability
data-breach 1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack Approximately 1.6 million RingCentral accounts have been exposed after a ShinyHunters extortion attack. Attackers gained access to sensitive data, including customer information, and are now demanding ransom for its retu… The Register · Aug 14, 2026 High credential stuffingdata breachransomware
data-breach 1.6 Million Likely Impacted by RingCentral Data Breach A data breach at RingCentral has potentially exposed the personal information of 1.6 million individuals, including email addresses, names, and phone numbers. The breach was orchestrated by the ShinyHunters extortion gro… SecurityWeek · Aug 14, 2026 Medium data breachsocial engineeringtor
threat-intel Are AI tutors safe for your kids? The market for AI tutoring tools is booming, driven by potential cost savings and improved educational outcomes, particularly for disadvantaged students. However, concerns are rising about the potential negative impacts… WeLiveSecurity · Aug 10, 2026 Medium UKaieducationprivacy
threat-intel Token Jacking: Cybercriminals Could Be Stealing Your AI Resources Cybercriminals are exploiting a growing trend of AI token jacking to generate significant financial losses. As AI adoption increases and costs for accessing powerful models rise, attackers are stealing API keys – known a… Palo Alto Unit 42 · Aug 6, 2026 High CHaitoken jackingtransfer station
threat-intel Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Cyberattacks targeting over 30 water systems in Minnesota are under investigation, with authorities suspecting Iranian hackers are responsible. The attacks involved disrupting remote monitoring and control systems, leadi… SecurityWeek · Jul 31, 2026 High IRcritical infrastructurecyberattackiran
threat-intel Cyber extortionists steal data from UK Department for Education Cybercriminals, identifying as ExfilSquad, have stolen data from the UK Department for Education and the Police National Legal Database, potentially exposing names, email addresses, and contact details of over 600,000 in… The Record · Jul 30, 2026 High UKransomwaredata breachcybercrime
threat-intel When AppSec Scanners Become a Supply Chain Attack Vector Security scanners used in the software supply chain can be exploited to introduce vulnerabilities and compromise downstream systems. Researchers at ZeroPath discovered that attackers can craft malicious code repositories… Dark Reading · Jul 29, 2026 High supply-chainvulnerabilitysecurity
vulnerability Java Spring Boot "heapdump" scans, (Mon, Jul 27th) A vulnerability in Spring Boot applications exposes a heapdump endpoint that, by default, contains sensitive data like API keys and database passwords. Attackers are leveraging a weak default username/password combinatio… SANS Internet Storm Center · Jul 27, 2026 High springheapdumpsecurity
vulnerability Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available A critical Remote Code Execution (RCE) vulnerability in Fastjson 1.x, a Java JSON library by Alibaba, is being actively exploited. Attackers are leveraging a type-resolution path to execute arbitrary code in Spring Boot… The Hacker News · Jul 25, 2026 High CVE-2026-16723USSGCArcejsonjava
threat-intel Oracle drops 1,449 security patches like it's the new normal This article is a collection of security-related news snippets from The Register. It covers a range of topics including security patches from Oracle, advancements in AI hardware (AMD vs Nvidia), phishing attacks targetin… The Register · Jul 23, 2026 Medium CVE-2026-47056CVE-2026-60217CVE-2026-61211securityvulnerabilitiesphishing
threat-intel Russian Global Webmail Espionage A persistent cyberespionage campaign, tracked as CL-STA-1114, originating from Russian threat actors (Void Blizzard and LAUNDRY BEAR) is targeting Zimbra webmail instances across various sectors, including governments, d… Palo Alto Unit 42 · Jul 23, 2026 High CVE-2025-66376NAUKCIcyberespionagephishingvulnerability
vulnerability Multiples vulnérabilités dans Oracle Systems (23 juillet 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality, integrity, and cause denial of service. These vulnerabilities affect various Oracle… CERT-FR · Jul 23, 2026 High CVE-2026-60659CVE-2026-60661CVE-2026-60833oraclevulnerabilitypatch
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai