IntelFreed A CYBERSECURITY INTELLIGENCE FEED

NEWS

Cybersecurity reportings, advisories, and research. 309 matching records.
Last update // 2026-08-22 04:55 UTC
CYBER INTEL TEMPERATURE
For today's cybersecurity intelligence
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
RESET
2026-08-18 12:49 UTC
Vendor Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…

APT / Nation-StateCloud SecurityCybercrimeDFIRICS / OTMicrosoftPhishingRansomwareVulnerabilities
P15
2026-08-18 08:44 UTC
Other

GitLab Patches Critical Unauthenticated GraphQL Vulnerability

Security Affairs · Pierluigi Paganini · indexed 2026-08-18 09:00 UTC

GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user […]

VulnerabilitiesCVE-2026-19478
P15
2026-08-18 08:02 UTC
Other

U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-18 09:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9.4), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray, […]

VulnerabilitiesCVE-2025-62593
P50
2026-08-18 06:34 UTC
Security Journalism

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 07:15 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

AI SecurityVulnerabilities
P80
2026-08-17 21:03 UTC
Security Journalism

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 21:20 UTC

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on

VulnerabilitiesCVE-2026-19478
P15
2026-08-17 20:26 UTC
Community

Apple Patches iOS and macOS, (Mon, Aug 17th)

SANS Internet Storm Center · indexed 2026-08-17 20:35 UTC

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.

AppleVulnerabilities
P0
2026-08-17 18:44 UTC
Security Journalism

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 19:35 UTC

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a

Security ResearchVulnerabilities
P0
2026-08-17 18:22 UTC
Security Journalism

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 19:35 UTC

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

Security ResearchVulnerabilitiesCVE-2026-15748
P20
2026-08-17 17:54 UTC
Other

SafePal Says 39,798 Customers Hit by Data Breach

Security Affairs · Pierluigi Paganini · indexed 2026-08-17 18:35 UTC

SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026, […]

Data BreachesVulnerabilities
P0
2026-08-17 13:23 UTC
Security Journalism

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 14:05 UTC

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a

MicrosoftVulnerabilities
P25
2026-08-17 10:52 UTC
Security Journalism

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 12:35 UTC

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the

LinuxMobile SecuritySecurity ResearchVulnerabilities
P15
2026-08-17 07:36 UTC
Security Journalism

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

RansomwareSecurity ResearchVulnerabilitiesCVE-2026-59310
P20
2026-08-16 08:31 UTC
Other

Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware SAP Commerce Cloud CVE-2026-58231 Exploited […]

MalwareVulnerabilitiesCVE-2026-58231
P5
2026-08-15 17:14 UTC
Other

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. […]

VulnerabilitiesCVE-2026-58231
P25
2026-08-15 08:38 UTC
Security Journalism

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit

VulnerabilitiesCVE-2026-58231
P5
2026-08-15 08:34 UTC
Other

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS score of 9.8), less than two weeks after Apple shipped the fix. The […]

AppleVulnerabilitiesCVE-2026-65400
P5
2026-08-15 07:24 UTC
Security Journalism

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to

AppleVulnerabilitiesCVE-2026-65400
P25
2026-08-15 07:18 UTC
Other

GeoServer Zero-Day Is Already Being Probed. That’s the Problem

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded the vulnerability […]

Security ResearchVulnerabilities
P25
2026-08-15 01:36 UTC
Vendor Research

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…

AI SecurityAPT / Nation-StateCloud SecurityNetwork SecurityThreat ActorsVulnerabilitiesCVE-2025-3248
P30
2026-08-14 21:27 UTC
Vendor Research

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Rapid7 · Rapid7 Labs · indexed 2026-08-15 18:55 UTC

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (mo…

LinuxMicrosoftVulnerabilitiesCVE-2025-49132CVE-2026-15409CVE-2026-27760CVE-2026-29053CVE-2026-3891CVE-2026-46300CVE-2026-48907CVE-2026-60137CVE-2026-63030
P20
2026-08-14 17:32 UTC
Security Journalism

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Dark Reading · Robert Lemos · indexed 2026-08-15 18:55 UTC

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.

Vulnerabilities
P0
2026-08-13 20:11 UTC
Vendor Research

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The Securi…

LinuxMicrosoftVulnerabilitiesCVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345CVE-2026-20346CVE-2026-20347CVE-2026-20348
P5
2026-08-13 18:45 UTC
Security Journalism

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

Vulnerabilities
P40
3 4 5 6 7