Cybersecurity News | Daily Recap [10 Aug 2026]

Cybersecurity News | Daily Recap [10 Aug 2026]

Daily Recap, AI security risks are rising as OpenAI’s upcoming Astra model and security gaps in AI accelerators/neo-clouds raise concerns about autonomous abuse and infrastructure blind spots, while new guidance calls for an interaction-aware layer over CASB and DLP to better control prompts and agent behavior. Separately, Cisco warned of high-severity ClamAV issues with a public PoC, Metabase and Progress LoadMaster faced actively exploited flaws, Belgium’s eID software was found to contain critical vulnerabilities affecting 2 million users, and enterprise impact included LexisNexis shutting down services amid suspicious activity. #Astra #ClamAV #Metabase #ProgressLoadMaster #BelgianEID #eID #LexisNexis

AI Security

  • AI security concerns are rising as OpenAI’s upcoming Astra model and security gaps in AI accelerators/neo-clouds highlight risks of autonomous abuse and blind spots in modern AI infrastructure – Astra Risks, AI Blind Spots
  • AI governance is also driving new defense guidance, with calls for an interaction-aware layer on top of CASB and DLP to better control prompts, data flows, and agent behavior – AI Controls

Vulnerabilities

  • Cisco warned of high-severity ClamAV vulnerabilities with a public PoC, increasing the risk of real-world exploitation if systems are not patched quickly – ClamAV Flaws
  • Metabase had a zero-day exploited in the wild that allows admin access without authentication, while Progress LoadMaster contains a critical flaw now being actively abused in attacks – Metabase Zero-Day, LoadMaster Exploit
  • Belgium’s eID software used by 2 million people was found to have critical flaws, creating potential exposure for national identity services – Belgian eID

Enterprise Incidents

  • LexisNexis shut down services after detecting suspicious activity on its servers, signaling a possible security incident affecting enterprise users – LexisNexis Incident
  • Coldcard bitcoin hardware wallet maker destroyed inventory after a cyberattack linked to more than $88 million stolen, underscoring the financial impact of supply-chain and theft campaigns – Coldcard Theft

Threat Research

  • Weekly research highlighted npm supply-chain abuse, including ChainDrop/Shai-Hulud, compromised keyv/cacheable packages, and additional worm activity, alongside phishing, vishing, and AI-enabled abuse trends – Weekly Recap
  • The same recap also covered malware and intrusion activity such as APT37/NarwhalRAT, BINDCLOAK, FakeCaptcha infrastructure, and fileless XMRig cryptojacking in cloud/container environments – Threat Research

Sector Attacks

  • Water sector operators were warned again about cyberattacks, reinforcing the need for stronger defenses around critical infrastructure and utility networks – Water Sector

Crime & Extortion

  • A member of The Com was sentenced to prison for blackmail and sextortion, reflecting ongoing law-enforcement pressure on cybercrime crews – Com Sentencing

Cybersecurity News | Daily Recap – hendryadrian.com