threat-intel Deux millions de données françaises mises en vente A French-language hacker is offering a database containing approximately two million French records (including identity information, contact details, addresses, and birthdates) for sale on a criminal forum. The seller’s profile indicates a history of activity, but the origin and validity of the data remain unverified,… ZATAZ · Aug 21, 2026 Medium FRdata breachidentity theftsocial engineering
vulnerability Multiples vulnérabilités dans Oracle Database Server (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, allowing attackers to potentially execute code remotely, cause denial of service, and compromise data confidentiality. These vulnerabilities affect… CERT-FR · Aug 19, 2026 High CVE-2026-59889CVE-2026-71062CVE-2026-71063oracledatabasevulnerability
threat-intel Intraverse : 16,9 millions d’entrées exposées A data broker announced the discovery of a massive, unauthenticated database linked to Intraverse/Gamifi, a casino Web3 platform. The database, allegedly exposed on August 17, 2026, contained 16.898.017 entries, includin… ZATAZ · Aug 18, 2026 High FRweb3databaseblockchain
vulnerability Multiples vulnérabilités dans PostgreSQL (14 août 2026) Multiple vulnerabilities have been discovered in PostgreSQL, impacting versions 15.x through 18.x and prior to 14.24. These vulnerabilities include potential for data confidentiality breaches, policy bypasses, denial of… CERT-FR · Aug 14, 2026 High CVE-2026-14662CVE-2026-14663CVE-2026-14664postgresqlvulnerabilitysecurity
threat-intel ArtNexus : une fuite expose le marché international de l’art A database belonging to ArtNexus, an international art specialist, has been publicly exposed, offering a detailed map of its business ecosystem. The database, accessible without authentication, contains thousands of acco… ZATAZ · Aug 13, 2026 High FRdatabasephishingsocial engineering
threat-intel Des accès superadmin exposent 27 sites français A single administrator account granting access to 27 French websites was leaked on a hacking forum, with a direct incentive for other members to collect and deliver all accessible data within 48 hours. The author is acti… ZATAZ · Aug 13, 2026 High FRhackingdatabaseadministrator
threat-intel Cars.no : une fuite revendiquée expose 148 288 automobilistes A Norwegian security researcher claims to have discovered a publicly accessible database belonging to Cars Software, an automotive software provider used by over 500 garages, dealerships, and wholesalers in Norway. The d… ZATAZ · Aug 10, 2026 High NOdatabasephishingdata breach
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
vulnerability New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated hosting customers to execute arbitrary database commands with administrative privileges, potentially leading to system-wide compromise. This flaw s… The Hacker News · Aug 4, 2026 Critical CVE-2026-58048CVE-2026-58047cvesql injectionprivilege escalation
vulnerability Critical Flaw Led to Azure Cosmos DB Pwnage A critical vulnerability, dubbed CosmosEscape, in Azure Cosmos DB allowed attackers to obtain a platform-wide key, enabling them to compromise all databases on the service. Wiz researchers exploited this flaw by bypassin… SecurityWeek · Jul 31, 2026 Critical vulnerabilitycode executiondatabase
vulnerability Vulnérabilité dans Microsoft Azure (31 juillet 2026) A critical vulnerability has been identified in Microsoft Azure's Cosmos DB, allowing attackers to execute arbitrary code remotely. This could lead to significant data compromise and system control for malicious actors. CERT-FR · Jul 31, 2026 Critical CVE-2026-66803azureremote code executiondatabase
vulnerability Multiples vulnérabilités dans MongoDB (24 juillet 2026) Multiple vulnerabilities have been discovered in MongoDB, allowing an attacker to cause a denial of service and potentially exploit a security policy bypass. These vulnerabilities affect various versions of MongoDB Compa… CERT-FR · Jul 24, 2026 High CVE-2026-13055CVE-2026-13056CVE-2026-13057mongodbvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Oracle Database Server (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, potentially leading to data integrity compromise, data confidentiality breaches, and remote denial-of-service attacks. These vulnerabilities affect… CERT-FR · Jul 23, 2026 High CVE-2025-7962CVE-2026-28387CVE-2026-28388oracledatabasevulnerability
vulnerability Multiples vulnérabilités dans Oracle MySQL (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle MySQL, allowing an attacker to cause a denial-of-service, compromise data confidentiality, and damage data integrity. These vulnerabilities are present across vario… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-46936CVE-2026-47008mysqloraclevulnerability
threat-intel The Top 10 Attack Surface Exposures in 2026 This article from The Hacker News details a study by Intruder analyzing 3,000 attack surfaces, revealing widespread vulnerabilities in organizations’ internet-facing services. A significant 60% of organizations had expos… The Hacker News · Jun 17, 2026 High attack-surfacevulnerabilitydatabase