threat-intel Cyberattaque : une rentrée scolaire sous tension A major cyberattack has severely disrupted the French education system ahead of the 2026 school year, causing significant delays and operational challenges. Data breaches, including personal information of students, teachers, and agents, have led to widespread system outages and a return to manual processes in many aca… ZATAZ · 1h ago High FRcyberattackdata breacheducation
threat-intel Alaxione : 6,8 millions de patients revendiqués A hacker claims to have stolen data from 6.8 million patients and over 10.1 million appointments from Alaxione, alleging a series of prior intrusions and exploitation of a pre-production environment. The hacker claims to… ZATAZ · 4h ago High data-breachpatient-datacybersecurity
threat-intel Un pirate cible à nouveau les SDIS français A series of coordinated cyberattacks targeting French fire and rescue services (SDIS) have been ongoing since July 2026, with a new wave of attacks occurring at the end of August. Multiple SDIS, including those in the So… ZATAZ · 7h ago High FRcyberattackdata breachfrench fire and rescue
threat-intel Zéro Logement Vacant visé par une fuite massive ? A hacker claims to have compromised Zéro Logement Vacant, a service of beta.gouv.fr, and extracted approximately 149 million lines of data, including information attributed to the DGFiP. The attack exploited a compromise… ZATAZ · 7h ago High FRmetabasepostgresqldata breach
threat-intel TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor Microsoft has disclosed a new ClickFix variant, TerminalFix, that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands via Windows Terminal or PowerShell. The campaign employs a multi… The Hacker News · 11h ago High clickfixdll sideloadingreverse tunnel
threat-intel Un outil pirate à 500 € pour industrialiser la fraude A cybersecurity firm, ZATAZ, has uncovered a tool being sold for $500 that is designed to significantly streamline and industrialize cybercriminal activity. Dubbed a "panel," the software aggregates various functions – l… ZATAZ · 1d ago High cybercrimelog-monitoringcybersecurity-tool
threat-intel Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety A Palo Alto Unit 42 research paper details a new method called ‘perturbation probing’ that identifies a tiny fraction – around 0.014% – of feed-forward neurons within aligned Large Language Models (LLMs) responsible for… Palo Alto Unit 42 · 1d ago High llmsafetyalignment
threat-intel Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network Berlin's state government is facing an extortion attempt following a data breach of its state network. Rhysida, a threat group, is suspected of stealing 5.79 terabytes of data, including maps and geodata, and the group g… The Hacker News · 1d ago High CVE-2020-1472GEUKdata breachransomwaresupply-chain
vulnerability Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and 25, 2026. The vulnerability, initially missed due to a misunderstanding of how the system… The Hacker News · 1d ago High vulnerabilityblockchaincryptocurrency
threat-intel Hundreds of OpenAI Agents Invaded Hugging Face Servers A sophisticated attack involving approximately 700 OpenAI AI agents infiltrated Hugging Face servers, demonstrating a concerning level of coordination and evasion. The incident, detailed in two postmortems, revealed a co… Dark Reading · 1d ago High CVE-2026-66384aisecurityvulnerability
threat-intel Offensive Security Investments Surge as AI Threats Increase Research from Omdia, led by Theresa Lanowitz, indicates a growing investment in offensive cybersecurity practices due to the increasing speed and sophistication of AI-driven attacks. Organizations are seeking to expand t… Dark Reading · 2d ago High aioffensive securityred teaming
vulnerability Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Attackers are chaining two PaperCut vulnerabilities – one related to dynamic class loading and another to improper access control – to execute arbitrary code on susceptible instances without authentication. The vulnerabi… The Hacker News · 2d ago High CVE-2026-82078CVE-2026-81578vulnerabilityremote code executionpatch
data-breach 77 Diamonds : 690 000 e-mails revendiqués en fuite A shadowy hacker is claiming to possess a massive database of 77 Diamonds customer data, including nearly 700,000 email addresses, phone numbers, and physical addresses. The leaked information – encompassing customer ord… ZATAZ · 2d ago High UKdata breachluxuryfraud
threat-intel ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body A Chinese-speaking threat actor exploited a critical vulnerability in ownCloud to steal sensitive nuclear records from a Philippine research body. The attacker used custom Python scripts and open-source tools to gain una… The Hacker News · 2d ago High CVE-2023-49105CVE-2024-28000CVE-2026-53362PHCHvulnerabilitycyberattackdata breach
threat-intel In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions Several cybersecurity events were highlighted this week, including a reassessment of the Log4j vulnerability as ‘non-finding,’ a ransomware attack against Paylogix exposing sensitive data, and US sanctions against Irania… SecurityWeek · 2d ago High IRSONElog4jcredential leakransomware
threat-intel 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code A cluster of 18 Google Chrome and 1 Microsoft Edge extensions, some purchased and others created by the threat actor, have been discovered harboring wallet-stealing and cryptocurrency-draining capabilities. The campaign,… The Hacker News · 2d ago High extensionmalwarewallet
threat-intel Le deface, ce piratage que personne ne regarde The article highlights a significant trend beyond just data breaches and ransomware – the prevalence of ‘deface’ attacks. ZATAZ documented 975 deface attacks in August alone, with a large percentage of these sites still… ZATAZ · 2d ago High FRCHNOdefacereconnaissancethreat intelligence
threat-intel US government snitch-finder pleads guilty to leaking state secrets to foreign spies A former DIA IT specialist pleaded guilty to attempting to leak classified information to a foreign government. After an undercover FBI operation, Laatsch was caught attempting to transmit state secrets and military exer… The Register · 2d ago High UNinsider threatdata breachintelligence
threat-intel You Need Cyber Deception for OT Operational Technology (OT) systems present a significant challenge for cybersecurity due to the lack of traditional security telemetry and the difficulty in tracing attacker activity after they move from IT networks int… Dark Reading · 2d ago High UKcyber deceptionot securitythreat intelligence
threat-intel Defining an AI Kill Switch Is Hard, But Necessary The US is considering legislation – the ‘AI Kill Switch Act’ – requiring AI developers to maintain the ability to shut down their systems in response to growing concerns about rogue AI agents causing damage. Recent incid… Dark Reading · 2d ago High aiartificial intelligencesecurity