135Articles
8Categories
2026-08-06Date
🚨 CISA KEV 2[−]
6 Aug KEVU.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-6307…SECURITYAFFAIRS.COM
6 Aug KEVThe exploit window is shrinking. Most security workflows are notAI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability disclosures, threat intelligence feeds, exploit chatter, and vendor advisories, all demanding imme…CSOONLINE.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 9[−]
6 AugHackers Start Exploiting Recent JetBrains TeamCity VulnerabilityTracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugCISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the WildA newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a ca…THEHACKERNEWS.COM
6 AugCritical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs s…HELPNETSECURITY.COM
6 AugAutonomy is earned, not claimedAfter more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements. The hardest problem in autonomous security isn’t teaching a machine how to attack. It’s teach…CSOONLINE.COM
6 AugChinese Zbtlink WiFi routers ship with ENDLESSDOORS malwareAt least 20 Zbtlink router models contain a preinstalled remote-access implant that connects to external command-and-control servers and can execute arbitrary commands with root privileges. The issue, tracked as CVE-2026-66747, does not require attackers to compromise the router …CYBERINSIDER.COM
6 AugTails emergency update fixes flaws that could deanonymize usersThe Tails Project has released Tails 7.10.1 as an emergency security update addressing critical vulnerabilities that could allow attackers to obtain administrator privileges, take control of the operating system, and potentially deanonymize users. Released on August 5, 2026, the …CYBERINSIDER.COM
6 AugNew Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsZapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked…THEHACKERNEWS.COM
6 AugNatJack exploits put NAT security assumptions to the test at Black HatFor decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assumption …CSOONLINE.COM
6 Aug KEVVU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitationsOverview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as…KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 48[−]
6 AugOpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud SchemesOpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of C…THEHACKERNEWS.COM
6 AugSuppliers, logins, and AI tools are all becoming attack pathsCybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike’s 2026 Threat Hunting Report. Intrusion activity increased by about 4% over …HELPNETSECURITY.COM
6 AugCloudflare OS goes open source with a record of everything its agents readCloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output the platform checks them ag…HELPNETSECURITY.COM
6 AugSrsly Risky Biz: Being a North Korean hacker is about to be less funTom Uren and James Wilson talk about North Korea losing control over some of its hacker workforce. Expect some tightening of controls and oversight, and perhaps even a reduction in the country’s ransomware operations. They also discuss escalating attacks on American water infrast…RISKY.BIZ
6 AugOWASP 2026 LLM Top 10: “The model will be fooled”The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant,…HELPNETSECURITY.COM
6 AugBrowser security is where software, data, and AI meetIn this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party co…HELPNETSECURITY.COM
6 AugCisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesPatches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code. The post Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugChinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root ShellsCybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more th…THEHACKERNEWS.COM
6 AugPractical lessons from deploying AI securely at scaleWhen I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities. I was wrong — or at least …CSOONLINE.COM
6 AugEvidence points to cybercriminals stepping up their AI gameMore evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research. Drawing on recovered prompt logs, attack tooling, and threat actor conversat…CSOONLINE.COM
6 AugPhotos: Black Hat USA 2026 ArsenalThis week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings. If you’ve never been, it’s the corner of Black Hat that feels least like a conference and most like a workshop: a room full of stations where the people who wrote the…HELPNETSECURITY.COM
6 AugAttackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM AccessAttackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored s…THEHACKERNEWS.COM
6 AugAWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the ModelSecurity flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts…THEHACKERNEWS.COM
6 Aug KEVWhy the ‘rogue AI’ problem will lead to an era of headaches for security practitionersShortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours…CSOONLINE.COM
6 AugToken Jacking: Cybercriminals Could Be Stealing Your AI ResourcesDiscover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
6 AugMeta AI Model Hacked a Company During Testing, Marking Third AI Lab IncidentMeta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed that one of its AI models breached an unidentified company during cybersecurity testing, after its independent testing partne…SECURITYAFFAIRS.COM
6 AugApple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploitsApple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. Read more in my article on the Hot for …BITDEFENDER.COM
6 AugVerification closes the loopMost organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved. The pr…CSOONLINE.COM
6 AugAI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project GlasswingWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing.…TENABLE.COM
6 AugApple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy BypassesCybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic thr…THEHACKERNEWS.COM
6 AugAI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM MemoryA new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embeddi…THEHACKERNEWS.COM
6 AugYou’re only as secure as your last evaluationThe updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly h…CSOONLINE.COM
6 AugCybersecurity needs a new operating modelFor decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure. Deploy patches. Verify that critical systems remained protected. That assumption shaped how organizations built security programs, how vendors…CSOONLINE.COM
6 AugCTEM isn’t failing. It’s not being operationalizedCybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now Continuous Threat Exposure Management (CTEM) all provide valuable guidance and describe desired outcomes. The ch…CSOONLINE.COM
6 AugAttackers hid malware inside Oracle Database after SQL injection breachHuntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploited a SQL injection vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database usin…CSOONLINE.COM
6 AugZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsZenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugThree in four AI-generated vulnerability patches leave something brokenAsk a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Password graded 6,080 patches f…HELPNETSECURITY.COM
6 AugBelarusian Ransom Cartel Mastermind Gets 16 Years in PrisonThere is an update to the case of Maksim Silnikau, who was extradited from Poland to the U.S. in August 2024 to stand trial here. Ionut Arghire reports: The Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison in the US. Maksim …DATABREACHES.NET
6 AugDutch retailer Bol follows De Bijenkorf in warning of data breach as leaked data appears on dark webThe NL Times reports: Online retailer Bol has warned customers about a data breach involving one of its logistics partners. The company said unauthorized parties accessed the partner’s systems, but emphasized that Bol’s own systems were not affected. Even so, some cus…DATABREACHES.NET
6 AugHow a software provider closed unknown paths to cloud compromiseA healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative ac…CSOONLINE.COM
6 AugHow a global investment firm reduced security surprisesMost security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matte…CSOONLINE.COM
6 AugMeta joins OpenAI, Anthropic in latest AI test breachMeta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center of a series of disclo…CSOONLINE.COM
6 AugMeta Joins OpenAI and Anthropic in Reporting AI Exploit IncidentOne of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systemsINFOSECURITY-MAGAZINE.COM
6 AugPhotos: Black Hat USA 2026Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) …HELPNETSECURITY.COM
6 AugNovel-reading apps used users’ phones to generate fake ad trafficA new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab) While a person taps through chapters of a romance or …HELPNETSECURITY.COM
6 AugThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More StoriesApparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tool…THEHACKERNEWS.COM
6 AugToolkit Hidden Inside Oracle Database Evades Endpoint ToolsAttackers used SQL injection to compile a post-exploitation toolkit inside an Oracle databaseINFOSECURITY-MAGAZINE.COM
6 AugNew TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashesResearchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]BLEEPINGCOMPUTER.COM
6 AugSwiss government SharePoint breach compromised 200 accountsSwitzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]BLEEPINGCOMPUTER.COM
6 AugCardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.There have been approximately 4 dozen new threat actor groups targeting U.S. medical entities in the first half of 2026. One of them calls itself “Orova.” They have no “About” page or information about themselves on their dark web leak site, so seeing that…DATABREACHES.NET
6 AugWhen AI Commits Felonies - PSW #938This week: - When you are not at summer camp you can't read about it - The Fettle continues - Using the CFAA against AI - Social contracts are not security models - VSCode extentions, again - Bugtraq is back! - NVIDA, LVFS, and unraveling AI infrastructure - More routers that com…YOUTUBE.COM
6 AugAI without adult supervision.Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce new GitHub risks. ENISA expands its CVE role. A critical Paperclip flaw enables co…THECYBERWIRE.COM
6 AugCapitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scamsA Senate Foreign Relations Committee hearing explored how 13 federal agencies and myriad foreign governments are wrestling with the problem. The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop .CYBERSCOOP.COM
6 AugMeta says AI model hacked third-party company during cyber testingMeta has disclosed that one of its AI models compromised another company’s systems during an internal cybersecurity evaluation after a misconfiguration inadvertently granted the model access to the public internet, marking the latest in a series of real-world AI testing inc…CYBERINSIDER.COM
6 AugResearcher Claims Control of ChatGPT Secure SandboxA researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.DARKREADING.COM
6 AugWhy exposure management is replacing vulnerability managementVulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becomi…CSOONLINE.COM
6 AugThe Coordination Gap: How Attackers Are Outpacing Law EnforcementThe fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.DARKREADING.COM
6 AugCyberRisk TV Live Coverage from Black Hat 2026 - Day 2CyberRisk TV is broadcasting live from Black Hat 2026 in Las Vegas! Tune into our coverage featuring interviews with cybersecurity leaders, practitioners, researchers, and technology innovators from one of the industry’s most influential security events. Throughout the day, we’ll…YOUTUBE.COM
📢 SECURITY ADVISORIES 11[−]
6 AugBelarusian Ransom Cartel Mastermind Gets 16 Years in PrisonMaksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution. The post Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugWiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.WIZ.IO
6 AugPodcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field. The post Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway appeared first on Se…SECURITYWEEK.COM
6 AugHow we took malware advisories beyond npmGitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malware advisories beyond npm appeared first on The GitHub Blog .GITHUB.BLOG
🔥 INCIDENT REPORTING 17[−]
6 AugShai-Hulud strikes again: CHAINDROP worm hits 400+ npm packagesElastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.ELASTIC.CO
6 AugOpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking SpreeAt the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.WIRED.COM
6 AugTracking people, training AI.This week, Ben and Ethan discuss two major stories. The first involves an incident where a police officer was abusing his access to Flock camera databases to track a former partner's movement. The second looks at recent research that found that Chinese military research units hav…THECYBERWIRE.COM
6 AugSnowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million PeopleConnor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records …THEHACKERNEWS.COM
6 AugSnowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of RecordsSnowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, …SECURITYAFFAIRS.COM
6 AugRansom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-ServiceA federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies…THEHACKERNEWS.COM
6 AugThe water sector just got it’s wake-up call. Again.The attack on water systems across seven states was preventable. Utilities had the playbook. They didn't use it. The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop .CYBERSCOOP.COM
6 AugMeta AI Hacked External Systems During Cybersecurity TestingThe incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugOver 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack CitiesForescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, includin…THEHACKERNEWS.COM
6 AugBelarusian cybercriminal behind Ransom Cartel gets 16-year prison sentenceA Belarusian national active in the cybercriminal world for decades was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation.THERECORD.MEDIA
6 AugMeta's AI escaped sandbox and hacked external systems.Researchers identify backdoor in Chinese-made routers. Snowflake hacker pleads guilty.THECYBERWIRE.COM
6 AugRansom Cartel Leader Sentenced to 16 Years in U.S.A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a c…SECURITYAFFAIRS.COM
6 AugMeta AI model hacked a company during misconfigured cyber testMeta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. [...]BLEEPINGCOMPUTER.COM
6 AugCyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigateNorth Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.THERECORD.MEDIA
6 AugRoute Amazon Bedrock Guardrails interventions to Amazon Security LakeSecurity teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongsid…AWS.AMAZON.COM
6 AugChina researchers using US AI models for defense systems.US water system cyberattacks continue to grow.THECYBERWIRE.COM
6 AugHedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion groupA recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 22[−]
6 AugOver 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware LuresA macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malic…THEHACKERNEWS.COM
6 Aug22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program] ISC.SANS.EDU
6 AugISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
6 AugNon-human identities are 91% of everything active in productionA backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one…HELPNETSECURITY.COM
6 AugLOW - TrailerAfter 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in the dark, the silences we carry, and what remains when we stop…THISISLOW.COM
6 AugNVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel SharingThe Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)INFOSECURITY-MAGAZINE.COM
6 AugSignal broadens device linking support on Android and iOSSignal has introduced broader linked-device support, allowing users to connect additional Android phones, Android tablets, and iPhones to an existing Signal account. The changes are rolling out with Signal Android version 8.20 and Signal iOS version 8.22. Signal developer Jim Lun…CYBERINSIDER.COM
6 AugMicrosoft extends zero trust deeper into enterprise AIMicrosoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles to AI agents and AI-assisted software de…HELPNETSECURITY.COM
6 AugDiscounted Claude access bought on the gray market may expose every prompt you sendMore than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI models, were discovered by Okta. Okta believes the trend is likely driven by Chinese users seeking access to AI mod…HELPNETSECURITY.COM
6 AugAdversarial Clothing Designed to Fool Facial Recognition SystemsThere are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I worry that it’s mostly security theater: “Our patterns play with that chaos, confuse algorithms and make it way harder to pin you …SCHNEIER.COM
6 AugCritical Paperclip Flaw Allowed Admin Access, Code ExecutionAn attacker could self-register, sign in for board-level API access, and import a new company for code execution. The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugGrapheneOS says Revolut is blocking its users over Google Play checksGrapheneOS says Revolut has begun blocking customers who use its privacy-focused Android operating system, alleging that the fintech company is presenting the restriction as a security measure while actually enforcing Google Play licensing and device-certification requirements. T…CYBERINSIDER.COM
6 AugSnowflake hacker pleads guilty, faces up to 32 years in prisonA Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165 organizations. Connor Riley Moucka, also known as “Waifu” and “Judische,” 26, of Kitchener, Ontario, pleaded g…HELPNETSECURITY.COM
6 AugDon't Chase Every Shiny TechnologyTechnology evolves quickly, and new tools, trends, and innovations constantly compete for attention. Throughout a career in cybersecurity, staying focused on core principles can be more valuable than chasing every new development. Governance and security provide a framework for e…YOUTUBE.COM
6 AugSnowflake Hacker Pleads Guilty in US CourtConnor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek .SECURITYWEEK.COM
6 AugCanadian Man Pleads Guilty in Snowflake ExtortionsA 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka,…KREBSONSECURITY.COM
6 AugPhotos: Black Hat USA 2026, part twoRound two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing cro…HELPNETSECURITY.COM
6 AugRansom Cartel creator sentenced to 16 years in prisonMaksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023. The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop .CYBERSCOOP.COM
6 AugDespite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed onlineA scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks. The post Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online appeared first on …CYBERSCOOP.COM
6 AugHackers grow more willing to destroy, not just disrupt OT systemsExperts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics.CYBERSECURITYDIVE.COM
6 AugComputers Inside Your ComputersAI infrastructure contains multiple layers of hardware and software working together, including components like BMCs, UEFI, memory systems, and DPUs. As AI systems become more advanced, understanding the underlying architecture becomes harder. Complexity creates new challenges fo…YOUTUBE.COM
6 AugChainDrop: Inside a Self-Propagating npm WormAnalysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
🌐 CYBER THREAT LANDSCAPE 3[−]
6 AugChina-linked LightSpy spyware caught targeting victims in 13 countries, including the USResearchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address.TECHCRUNCH.COM
6 AugHackers Stalked Me by Hijacking a Smartwatch for KidsSecurity researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.WIRED.COM
6 AugClickFix attack pushes macOS infostealer for crypto theft attacksA Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]BLEEPINGCOMPUTER.COM
📡 INFOSEC NEWS 23[−]
6 AugCanadian Hacker Pleads Guilty Over Snowflake Extortion CampaignA Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victimsINFOSECURITY-MAGAZINE.COM
6 AugScammers target OnlyFans users with deepfakesCriminals are impersonating OnlyFans creators using AI tools in order to scam followers.MALWAREBYTES.COM
6 AugAmazon and Apple impersonated in “$149.99 unauthorized charge” scamDifferent logos, different color schemes, same scam.MALWAREBYTES.COM
6 AugAnthropic’s Mythos AI used social engineering to target real peopleTesters found that Anthropic's AI agent Mythos attempted to social engineer Github developers into accepting malicious code.MALWAREBYTES.COM
6 AugViolent Physical Crypto Thefts Surge to $30m in LossesSo-called “wrench attacks” have resulted in $30m in losses so far in 2026, says ChainalysisINFOSECURITY-MAGAZINE.COM
6 AugCryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet AppsCoinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery …THEHACKERNEWS.COM
6 AugHow AI Exposed a Browser Security Gap that Enterprises Cannot IgnoreAI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. [...]BLEEPINGCOMPUTER.COM
6 AugApple WebKit vulnerabilities reveal your IP address, despite Private RelayResearchers have found three methods to bypass Apple's Private Relay which is supposed to shield users' IP addresses and location.MALWAREBYTES.COM
6 AugTeamPCP Traced Back to 2020 Cryptojacking OperationOligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020INFOSECURITY-MAGAZINE.COM
6 AugCloud Threat Highlights: H1 2026Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026WIZ.IO
6 AugNew Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUsAn unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the techni…THEHACKERNEWS.COM
6 AugHacker pleads guilty to stealing data from more than 165 Snowflake customersConnor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments.TECHCRUNCH.COM
6 AugCaching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scaleThis post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-…AWS.AMAZON.COM
6 AugExposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance RecordsAn exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Informa…SECURITYAFFAIRS.COM
6 AugCisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score BugsCisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and…THEHACKERNEWS.COM
6 AugGoogle says hackers are calling financial firm employees to hack and extort victimsGroups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.TECHCRUNCH.COM
6 AugWhy metaphor may dictate your security strategyIn this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.TALOSINTELLIGENCE.COM
6 AugFrom Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First CultureFormer chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.DARKREADING.COM
6 AugSecurity StagflationWhat's security stagflation look like? The cost of finding bugs is down, but the cost of fixing them is the same. Here's what CISOs need to know.CISECURITY.ORG
6 AugStrengthening Cyber Resilience Through Education via Essential Cyber Hygiene BootcampEssential Cyber Hygiene Fundamentals Bootcamp helps cyber practitioners implement CIS IG1 Safeguards, reduce risk and strengthen organizational resilience.CISECURITY.ORG
6 AugAutomate certificates with ACME support in AWS Certificate ManagerCustomers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum…AWS.AMAZON.COM
6 AugOpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for itOpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]BLEEPINGCOMPUTER.COM