118Articles
8Categories
2026-08-10Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 8[−]
10 AugAI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackersAI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% f…CYBERSECURITYTODAY.LIBSYN.COM
10 AugN-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 su…HELPNETSECURITY.COM
10 AugCVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugCVE-2026-50309 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
10 AugVU#614868: Opencart ecommerce platform contains directory traversal vulnerabilityOverview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the inten…KB.CERT.ORG
10 AugCVE-2021-40440 Microsoft Dynamics Business Central Cross-site Scripting VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugCVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting VulnerabilityUpdated the build numbers. This is an informational update only.MSRC.MICROSOFT.COM
10 AugNATO and an AI startup can now name and track software vulnerabilitiesNATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week.  The NATO Cyber Security Centre, part o…CYBERSCOOP.COM
⚠️ VULNERABILITY DISCLOSURE 35[−]
10 AugRisky Bulletin: Two law firms pay giant ransomsTwo American law firms pay multi-million dollar ransoms, a Metabase zero-day is being used in data theft attacks, Russian hackers disrupted a second power plant in Poland, and there’s a remote code execution bug in WordPress… again!RISKY.BIZ
10 AugHow to report an AI Act violation in the EUThe EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. The AI Act is the EU’s law regulating AI, the first broad legal framework of its kind. It c…HELPNETSECURITY.COM
10 AugChainloop: Open-source evidence store and policy engine for the software supply chainChainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a sign…HELPNETSECURITY.COM
10 AugSolidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and CredentialsCybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web…THEHACKERNEWS.COM
10 Aug7 key trends defining the cybersecurity market todayAI is having a seismic impact on the cybersecurity market. Record-shattering amounts of venture capital is flowing into a new generation of startups focused on AI cybersecurity. At the same time, established cybersecurity vendors are racing to integrate AI and agentic AI features…CSOONLINE.COM
10 Aug4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofingKey takeaways OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, rotated or blank. AADSTS700016 paired with an unrecognized client ID can mean valid credentials, not a broken app registratio…CSOONLINE.COM
10 Aug KEVCritical Progress LoadMaster flaw now actively exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]BLEEPINGCOMPUTER.COM
10 AugCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityThe critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugAnthropic to put AI in charge of reviewing Claude Code actions by defaultAnthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to switch to auto mode. In a controlled experiment wi…HELPNETSECURITY.COM
10 Aug“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall ControlsTenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reportsINFOSECURITY-MAGAZINE.COM
10 AugMetabase Patches Vulnerability Exploited as Zero-DayThe security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugOne-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attackAtlassian’s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions. At DEF CON 34 , researchers from Varonis demonstrated an att…CSOONLINE.COM
10 AugOpenAI Pauses Astra Model Over Critical Cybersecurity Risk ConcernsOpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities sign…SECURITYAFFAIRS.COM
10 AugTrueConf Server Flaws Exploited to Replace Client Installers with PhantomCoreThe threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity v…THEHACKERNEWS.COM
10 AugOpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguardsOpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets. The company disclosed the assessm…CSOONLINE.COM
10 AugChina-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warnsA China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.THERECORD.MEDIA
10 Aug10th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that…RESEARCH.CHECKPOINT.COM
10 AugMetabase zero-day exploited to access Framework customer dataFramework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framewo…HELPNETSECURITY.COM
10 Aug KEVInside the Metabase SQLi: Exploited in the WildReverse engineering GHSA-vwf4-m7j8-wcjf with AI to accelerate defense.WIZ.IO
10 AugCISA: SonicWall SMA1000 flaws now exploited by ransomware gangsCISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]BLEEPINGCOMPUTER.COM
10 AugCisco Warns of High-Severity ClamAV Vulnerabilities With Public PoCRemote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugResearchers find that only a quarter of AI-generated patches are fully successful.Ransomware attacks exploit critical N-able flaw. LexisNexis disables some services following suspicious activity.THECYBERWIRE.COM
10 AugPoland uncovers second heat plant cyberattack that went hidden for monthsThe incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.THERECORD.MEDIA
10 AugUK man tied to The Com sentenced for abusing 117 victimsJustin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared …CYBERSCOOP.COM
10 AugSecure development can help turn the tables as AI alters cyber landscapeA top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.CYBERSECURITYDIVE.COM
10 AugResearchers Uncover RovoBlast Vulnerability in Atlassian AI AssistantAtlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company dataINFOSECURITY-MAGAZINE.COM
10 Aug⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router BackdoorsA lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit …THEHACKERNEWS.COM
10 AugAttack Surface Management - Matt Lea - CSP #227In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk. Matt shares lessons from his experience auditing cloud environments, including common A…YOUTUBE.COM
10 AugUnpatched HP ThinPro flaw allows bypass of disk encryption protectionsAn unpatched vulnerability in HP ThinPro 8 and 9 allows attackers with physical access to bypass the operating system’s TPM-backed full-disk encryption protections and recover the key securing the device’s root partition. The zero-day remained without a publicly available fix whe…CYBERINSIDER.COM
10 AugChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central FlawMicrosoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Micro…THEHACKERNEWS.COM
10 AugCoruna, DarkSword iOS Exploits Proliferate GloballySophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.DARKREADING.COM
10 AugOpenAI releases ChatGPT 5.6 Cyber, but it's only for approved usersOpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]BLEEPINGCOMPUTER.COM
10 AugCISA Advisory: #StopRansomware: Gunra RansomwareGunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both enc…DATABREACHES.NET
10 AugNow with extra vulnerabilities.Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following suspicious activity. US Senate confirms Adam Cassady as cyber …THECYBERWIRE.COM
10 AugMetabase SQL Zero-Day Attacks Could Have Wide Blast RadiusThe maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.DARKREADING.COM
📢 SECURITY ADVISORIES 13[−]
10 AugGitHub Dependabot malware alerts now cover eight ecosystemsGitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s…HELPNETSECURITY.COM
10 AugPython Now Has a Post-Quantum Encryption LibraryThis is good : Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature pr…SCHNEIER.COM
10 AugSenate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurityTwo Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.THERECORD.MEDIA
10 AugDon't Wait to Call InsuranceAfter confirming—or even reasonably suspecting—a cybersecurity incident, many organizations notify their cyber insurance provider early. Depending on the industry and applicable regulations, reporting timelines may begin before every detail is confirmed. Insurance providers often…YOUTUBE.COM
10 AugBdThemes plugins supply-chain hack creates rogue WordPress adminsA threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 17[−]
10 AugNewcastle University confirms data breach after ExfilSquad claims 440k recordsNewcastle University has confirmed that a configuration issue affecting a connection to one of its admissions systems allowed unauthorized access to personal information, including names, addresses, email addresses, and telephone numbers. The disclosure follows a claim by the Exf…CYBERINSIDER.COM
10 AugCorporate Data Stolen in Levi Strauss CyberattackUsing social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugThree interviews: system fragility, operational clarity, and Identity for AI agents - ESW #471Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decad…YOUTUBE.COM
10 AugValve notifies Steam hardware customers of a data breachVideo game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]BLEEPINGCOMPUTER.COM
10 AugNew Jersey, Alabama Join States Targeted in Water CyberattacksHackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugValve warns Steam users in Europe of data breach at shipping partnerValve is warning Steam customers in Europe that their personal and delivery information may have been compromised in a cyberattack targeting CEVA Logistics, the company responsible for shipping Steam hardware to European buyers. According to a security notification sent by Valve,…CYBERINSIDER.COM
10 Aug9.2 Million Israeli Records Sold as a New Breach Are 20 Years OldA seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire na…SECURITYAFFAIRS.COM
10 AugA data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyondCompanies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack.TECHCRUNCH.COM
10 AugWordPress Plugins Compromised Without a Single File ChangePoisoned JSON feed let attackers backdoor WordPress sites without changing any plugin filesINFOSECURITY-MAGAZINE.COM
10 AugOpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack ConcernsThe current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugCyberattack on Steam hardware shipper leaks names, addresses, and order dataVideo game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. R…HELPNETSECURITY.COM
10 AugDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructureMicrosoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pre…MICROSOFT.COM
10 AugHackers Cross From IT to OT Through a Private APN in PolandAttackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an…SECURITYAFFAIRS.COM
10 AugNew StormEncryptor ransomware used by former Medusa affiliateA financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]BLEEPINGCOMPUTER.COM
10 AugFBI, South Korea warn of Gunra ransomware gang targeting critical infrastructureThe Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.THERECORD.MEDIA
10 AugU.S., South Korean government agencies caution to be on lookout for Gunra ransomware gangThe ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop .CYBERSCOOP.COM
10 AugGym Booking Task Turns Into Real-World AI CyberattackAn AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to book him into a gym class. He didn’t ask it to hack the booking software, and he definitely didnR…SECURITYAFFAIRS.COM
🕵️ THREAT INTELLIGENCE 20[−]
10 AugISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 AugCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleThe vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugProduct showcase: Enpass Password Manager breaks away from the proprietary cloud modelEnpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user. Users who work across mul…HELPNETSECURITY.COM
10 Aug71% of CISOs spend 10+ hours on board reportsBoards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who are calling for simpler data …HELPNETSECURITY.COM
10 AugOpenAI locks down Astra over potential critical cyber capabilitiesOpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Frame…HELPNETSECURITY.COM
10 AugNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilityCERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugNew Zealand sanctions Russian hackers, propaganda groups over Ukraine warNew Zealand announced new sanctions on Russian hackers, technology companies and Kremlin-linked organizations over their roles in supporting Moscow’s war against Ukraine.THERECORD.MEDIA
10 Aug‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents BadAn AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugMicrosoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO usersMicrosoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting early October 2026, with completion expected by late November. Microsoft sa…HELPNETSECURITY.COM
10 AugKimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware DevelopmentNorth Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collectin…THEHACKERNEWS.COM
10 AugWhen Technology Stops WorkingTechnology has gradually become part of almost every daily activity. Many people now rely on smartphones and digital systems for shopping, payments, communication, and routine tasks without thinking about it. The concern isn't that technology is bad—it's that dependence can becom…YOUTUBE.COM
10 AugWhy transparent AI agents matter more than you thinkThe difference between a prompt injection attack you'll catch and one you won't might just be whether your AI agent can explain itself. The post Why transparent AI agents matter more than you think appeared first on CyberScoop .CYBERSCOOP.COM
10 AugStealthium Targets Security Blind Spots in AI Accelerators and Neo-CloudsThe startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek .SECURITYWEEK.COM
10 AugRussian military hackers pose as recruiters to target Ukrainian IT workersUkraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.THERECORD.MEDIA
10 AugCivil-society initiative will pay cybersecurity vendors to protect rural water systemsThe group is seeking philanthropic grants, but its founder said the federal government ultimately needs to step in.CYBERSECURITYDIVE.COM
10 AugFirewallFalcon VPN management tool caught backdooring serversFirewallFalcon, a free Linux server management tool promoted to VPN resellers and “free internet” operators, has been found secretly hijacking network traffic and giving its developer control over systems that install it. Researchers say FirewallFalcon Manager combines legitimate…CYBERINSIDER.COM
10 AugMicrosoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the EnterpriseMicrosoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared firs…MICROSOFT.COM
10 AugOpenAI says Daybreak will expand to offer specialized cyber servicesThe company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors. The post OpenAI says Daybreak will expand to offer specialized cyber services appeared first on CyberScoop .CYBERSCOOP.COM
10 AugThe FTC wants to regulate AI for ideological biasThe commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. The post The FTC wants to regulate AI for ideological bias appeared first on CyberScoop .CYBERSCOOP.COM
10 AugThe Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and CommunicationsAnalysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 4…UNIT42.PALOALTONETWORKS.COM
🌐 CYBER THREAT LANDSCAPE 6[−]
10 AugA week in security (August 3 – August 9)A list of topics we covered in the week of August 3 to August 9 of 2026MALWAREBYTES.COM
10 AugIT threat evolution in Q2 2026. Non-mobile statisticsThe report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.SECURELIST.COM
10 AugIT threat evolution in Q2 2026. Mobile statisticsThis report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.SECURELIST.COM
10 AugGo-Based macOS Malware Steals Crypto and SecretsA macOS malware variant has been detected stealing crypto, passwords and moreINFOSECURITY-MAGAZINE.COM
10 AugNew Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFAThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Window…THEHACKERNEWS.COM
10 AugSherlock Holmes was the “OG” Social EngineerThe crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers.DARKREADING.COM
🎙️ PODCASTS 2[−]
10 AugSponsored: Island's expansion to SASE and enterprise AIIn this Risky Business sponsored interview, Catalin Cimpanu talks with Michael Leland, Field CTO at Island, about the company’s seamless expansion into SASE and enterprise AI.RISKY.BIZ
10 AugHow to fake a data trail (and maybe lower prices) (Lock and Code S07E16)This week on the Lock and Code podcast, we speak with Chris Parr about his inventive and all-too-funny stress-test of surveillance pricing.MALWAREBYTES.COM
📡 INFOSEC NEWS 17[−]
10 AugOpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger PauseOpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upst…THEHACKERNEWS.COM
10 AugUS Sanctions Iranian $6bn Crypto “Exchange” ShelbitTRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchangeINFOSECURITY-MAGAZINE.COM
10 AugA GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity BenchmarkKimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s es…SECURITYAFFAIRS.COM
10 AugShipping 10–50× More Code? Watch This Webinar on Securing AI-Speed DevelopmentAI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vul…THEHACKERNEWS.COM
10 AugEdge is dropping older extensions, affecting popular privacy toolsMicrosoft is retiring Manifest V2, the technology behind older Edge extensions. Some popular privacy tools will lose features or stop working.MALWAREBYTES.COM
10 AugMember of The Com sent to prison for blackmail, sextortionA member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. [...]BLEEPINGCOMPUTER.COM
10 AugLexisNexis shuts down services after suspicious activity on serversLexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]BLEEPINGCOMPUTER.COM
10 AugBritish ‘Com’ member who abused more than 100 girls worldwide jailed for two yearsJustin Swaddle, of Leeds in northern England, targeted 117 female victims aged 13 to 17, according to the National Crime Agency.THERECORD.MEDIA
10 AugWhen Credentials Are No Longer Enough: Device Trust in the AI EraAI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to th…BLEEPINGCOMPUTER.COM
10 AugSigned up for Klaviyo? Dozens of advertisers may have seen your passwordA bug in the tech giant's website mistakenly shared users' sign-up information, including personal data and their password, to third-party companies.TECHCRUNCH.COM
10 AugNew turnkey kit makes it easy for anyone to become a scammerWe discovered a kit that gave us an insight into how modern online scams are built, promoted, and potentially used to target everyday consumers.MALWAREBYTES.COM
10 AugScans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for d…ISC.SANS.EDU
10 AugOutdated Cybercrime Laws Put Security Researchers at RiskA public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.DARKREADING.COM
10 Aug2026 AWS CyberVadis report now available for due diligence on third-party suppliersWe’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service provider…AWS.AMAZON.COM
10 AugThe Patch Gap: Why Defenders Need to Think in Chains, Not ChecklistsIt's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.DARKREADING.COM
10 AugAWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the …AWS.AMAZON.COM
10 AugMultistate Water System Attacks Widen, Iran SuspectedAttacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.DARKREADING.COM