140Articles
9Categories
2026-08-12Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 27[−]
12 AugMicrosoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active AttackMicrosoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escal…THEHACKERNEWS.COM
12 AugDefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gymDEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID …CYBERSECURITYTODAY.LIBSYN.COM
12 Aug KEVPatch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerabilityA currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock …CSOONLINE.COM
12 AugMetabase SQLi exploit grants attackers total accessBusiness intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-…CSOONLINE.COM
12 AugCisco Patches Firewall Zero-Day Exploited for DoS AttacksCVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugSAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary CodeSAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been des…THEHACKERNEWS.COM
12 AugShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM AccessThe security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates …THEHACKERNEWS.COM
12 Aug KEVCisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoSCisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insuf…THEHACKERNEWS.COM
12 Aug17 old software bugs that took way too long to squashIn 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one …CSOONLINE.COM
12 AugShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet PatchChaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a …SECURITYAFFAIRS.COM
12 AugAttackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessThreat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter s…THEHACKERNEWS.COM
12 AugMicrosoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-6…HELPNETSECURITY.COM
12 AugAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic FlawsAdobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below -…THEHACKERNEWS.COM
12 AugNIST Seeks Public Input on AI-Ready NVD ModernizationThe US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability researchINFOSECURITY-MAGAZINE.COM
12 AugCVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-62747 Windows Device Association Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-70348 Windows Management Services Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-68815 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50687 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-58538 Windows Bluetooth Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-62913 Microsoft Exchange Server Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-58643 Windows Admin Center Spoofing VulnerabilityCorrected Build Number in the Security Updates table. This is an informational change only.MSRC.MICROSOFT.COM
12 AugCVE-2026-50476 Windows Network Connections Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
12 AugLazarus hackers exploited Windows zero-day to target defense firmsNorth Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]BLEEPINGCOMPUTER.COM
12 AugHackers exploit critical Adobe Commerce flaw to hijack customer accountsAttempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]BLEEPINGCOMPUTER.COM
12 Aug KEVResearcher creates workaround for Microsoft Defender security patchJust weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has b…CSOONLINE.COM
⚠️ VULNERABILITY DISCLOSURE 42[−]
12 AugSandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run CommandsThe Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA…THEHACKERNEWS.COM
12 AugAI deployments are stretching enterprise security to its limitsCISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according …HELPNETSECURITY.COM
12 AugPentestGPT: Open-source automated penetration testing agentic frameworkPentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discovery,…HELPNETSECURITY.COM
12 Aug KEVMicrosoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCEMicrosoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office,…SECURITYAFFAIRS.COM
12 Aug4 gaps slowing AI in enterprise SOCsArtificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements. The issue isn’t whether…CSOONLINE.COM
12 AugThe AI harness is the new attack surfaceAsk a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted. That instinct is increasingly out of date. A growing body of security rese…CSOONLINE.COM
12 Aug KEVWindows 11 security update fixes actively exploited zero-day flawMicrosoft has released the August 2026 cumulative update for Windows 11, fixing 236 Windows vulnerabilities, including a privilege-escalation flaw that is already being exploited in attacks. The KB5121003 update was released earlier today for Windows 11 versions 24H2, 25H2, and 2…CYBERINSIDER.COM
12 AugFresh Windows Zero-Day Exploited in North Korean CyberattacksThe bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugIvanti EPM Update Patches Remotely Exploitable FlawsThe vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugCBTS brings continuous penetration testing to enterprise securityCBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud enviro…HELPNETSECURITY.COM
12 AugChrome’s anti-abuse protections block 7 billion unwanted Android notifications dailyGoogle Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) …HELPNETSECURITY.COM
12 AugDomain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - BSW #460As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company’s IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CS…YOUTUBE.COM
12 AugNew Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privilegesNightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]BLEEPINGCOMPUTER.COM
12 AugChipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities CombinedIntel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution. The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugFake CCleaner downloads turn Chrome into a credential-stealing surveillance toolA convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance. Researchers from Malwarebytes found the campaign distributing a malicious Chrome extens…CSOONLINE.COM
12 AugSignal adds new security feature to thwart man-in-the-middle attacks​Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]BLEEPINGCOMPUTER.COM
12 AugLazarus hackers pair fake job offers with Windows zero-day exploitThe North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which attack…HELPNETSECURITY.COM
12 AugCloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new waveFrom Cloudflare’s new report: Key insights The 1 Tbps club grew. Cloudflare mitigated a combined 935 network-layer DDoS attacks exceeding 1 Tbps in the first half of 2026 and a +519% quarter-over-quarter surge between Q1 and Q2. The attack-vector center of gravity shifted f…DATABREACHES.NET
12 AugA serious incident occurred at MyDr, a Polish healthcare system providerAdam Haertle reports: MyDr has just announced that it is investigating a serious security incident on its network. The alleged perpetrators of this incident contacted us earlier and claimed to have access to patient data from numerous Polish clinics. According to the hackers, the…DATABREACHES.NET
12 AugMicrosoft’s massive Patch Tuesday releases continue as AI reshapes bug discoveryThis month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.THERECORD.MEDIA
12 AugCISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaignResearchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.THERECORD.MEDIA
12 AugHackers leverage new Microsoft SharePoint exploit in attacksHackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]BLEEPINGCOMPUTER.COM
12 AugOpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' ReasoningA newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the …THEHACKERNEWS.COM
12 AugThree intrusions at UK criminal records office went undetected for two yearsUnread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.THERECORD.MEDIA
12 AugLazarus Used Post-Quantum Key Exchange to Deliver Zero-DayLazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploitINFOSECURITY-MAGAZINE.COM
12 AugGunra Ransomware Exploits Fortinet Flaws to Target Critical InfrastructureGunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warnedINFOSECURITY-MAGAZINE.COM
12 AugThe Threat Hiding in Your Hiring Process: How Fake Remote Workers Get InFake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receivin…BLEEPINGCOMPUTER.COM
12 AugStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetResearchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugA stranger has been reading Salesforce and ServiceNow portals worldwide for 17 monthsMost security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a …HELPNETSECURITY.COM
12 Aug737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have OneA massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrom…THEHACKERNEWS.COM
12 AugPatch Tuesday: Update now to fix 421 flaws, including three zero-daysMicrosoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.MALWAREBYTES.COM
12 Aug KEVSharePoint Vulnerability Exploited Shortly After PoC ReleaseThe vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugRESOURCE: Introducing the Cyber Incident RegistryOver on DysruptionHub, Joseph Topping has introduced a new resource for exploring cyber disruptions, following incidents over time, and uncovering the connections between them: The registry is a research resource focused specifically on cyber disruptions. Each incident profile br…DATABREACHES.NET
12 AugAfter Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bugThis is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.TECHCRUNCH.COM
12 AugPatch Tuesday notes: Microsoft fixes three zero-days.Attackers target SharePoint vulnerability following PoC release. Business news: Visa and Deel both acquire identity verification companies.THECYBERWIRE.COM
12 AugCisco says software vulnerability could let hackers crash firewallsThreat actors already have begun exploiting the flaw, according to the U.S. government.CYBERSECURITYDIVE.COM
12 AugPlug and Pwn attack uses fake USB devices for Windows SYSTEM accessSecurity researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]BLEEPINGCOMPUTER.COM
12 AugCA: Snoopers Beware; NL’s Privacy Commissioner Recommends Naming Individuals in Snooping-Related BreachesVOCM reports: The province’s Privacy Commissioner is recommending that public bodies consider providing the name of anyone involved in snooping-related privacy breaches to affected individuals. The recommendation comes after an employee of NL Health Services had a peek at a perso…DATABREACHES.NET
12 AugLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy BackdoorThe North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and…THEHACKERNEWS.COM
12 AugA flurry of fixes.We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. Ca…THECYBERWIRE.COM
12 AugLong-running Data Theft Campaign Targeting Salesforce, ServiceNowThe "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.DARKREADING.COM
12 Aug"City-Forum" data-theft attacks target Salesforce, ServiceNow portalsAn ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]BLEEPINGCOMPUTER.COM
📋 SECURITY BULLETINS 2[−]
12 AugICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix ContactCISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugMicrosoft Fixes 400 Flaws on August Patch TuesdayMicrosoft has issued another massive batch of security updates with 400 fixed in the August Patch TuesdayINFOSECURITY-MAGAZINE.COM
📢 SECURITY ADVISORIES 13[−]
12 AugCrytica’s RDAi detects OT device tampering from withinCrytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disruptin…HELPNETSECURITY.COM
12 AugRansomware Hits Colombian Justice Ministry Days Before Presidential TransitionAttackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.DARKREADING.COM
12 AugScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations.…HELPNETSECURITY.COM
12 AugDeloitte strengthens AI governance to support trusted enterprise adoptionDeloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support acros…HELPNETSECURITY.COM
12 AugAndroid malware combo takes out loans and relays victims' credit cardsA new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 10[−]
12 AugWeekly Update 516: Live From VietnamPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back …TROYHUNT.COM
12 Aug‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI HardwareExperts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.WIRED.COM
12 AugOver 2,500 Organizations Impacted by LiteLLM Supply Chain AttackLiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugCeva Logistics Operations Disrupted by CyberattackAffecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugUber Freight reportedly investigating after hacking group claims data breachAn extortion gang known for targeting transportation companies and private equity firms has taken credit for a breach at Uber Freight.TECHCRUNCH.COM
12 AugYour AI Can Be Hacked Through TextThis clip describes an AI hijacking technique in which an external attacker places instructions into text that an AI agent is already processing, such as logs, alerts, or email. The danger is that the agent may interpret untrusted content as an instruction. That creates a new sec…YOUTUBE.COM
12 AugFBI: Hackers using social engineering to breach accounts and steal explicit contentLeaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.THERECORD.MEDIA
12 AugLiteLLM breach data shows supply chain attack impacted 2,488 firmsA new analysis of data allegedly stolen during the March 2026 LiteLLM supply chain attack has linked nearly 2,500 corporate domains to exposed CI/CD environments, including those of major technology, industrial, financial, and telecommunications firms. Cybersecurity firm Hudson R…CYBERINSIDER.COM
12 AugChina-Linked Hackers Use AI Agents in Autonomous Attack on TaiwanChina-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a …SECURITYAFFAIRS.COM
12 AugCEVA Logistics Cyberattack Disrupts European Warehouses and ShipmentsCEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted impacted eight ware…SECURITYAFFAIRS.COM
🕵️ THREAT INTELLIGENCE 22[−]
12 AugKimwolf botnet rebuilt to survive takedowns, researchers sayMonths after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from the Ethereum blockchain. The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared…CYBERSCOOP.COM
12 AugISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
12 AugRisky Bulletin: Russian hackers jump on the fake job interview trainRussian state hackers adopt fake job interview tactics, a Portuguese man will face trial for developing a malicious AI chatbot, an AI assistant hacks an Australian gym, and OpenAI releases cyber models for blue teams.RISKY.BIZ
12 Aug338 million attack simulations reveal the state of enterprise defenseFirst, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from th…HELPNETSECURITY.COM
12 AugReady-made $500 kit puts a crypto scam within anyone’s reachA seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found. Researchers discovered the scam project on…HELPNETSECURITY.COM
12 AugPost-quantum migration gets harder when every user holds a keyIn this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assu…HELPNETSECURITY.COM
12 AugShifts We Are Seeing Across Social Engineering, Post-Disruption Impact ReportIn this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director⁠ Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They d…THECYBERWIRE.COM
12 AugSonicWall Patches Critical Vulnerabilities in Discontinued GMS PlatformThe security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugSplit-second deepfake glitch blows digital certificate fraudster’s coverSpanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made 38 attempts using this …HELPNETSECURITY.COM
12 AugMalicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ OrganizationsTwo malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now …THEHACKERNEWS.COM
12 AugConnectSecure helps MSPs automate Microsoft 365 security remediationConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, support…HELPNETSECURITY.COM
12 AugPrompt Injections for DefenseThis seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts …SCHNEIER.COM
12 AugSignal adds auto key verification to detect encryption key tamperingSignal has introduced automatic key verification, a new security feature designed to detect attempts to secretly replace the encryption keys associated with users’ accounts. The system, which has been under limited user testing since earlier this year, uses key transparency, cont…CYBERINSIDER.COM
12 AugWhatsApp Unveils New Scam Alert FeatureSignal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugMindgard Raises $30 Million to Protect AI SystemsThe cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams. The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek .SECURITYWEEK.COM
12 AugSignal’s new security feature checks if your encrypted chats were tampered withSignal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to c…HELPNETSECURITY.COM
12 AugAI is Working in the SOC. So Why are Security Executives More Worried Than Ever?Something shifted in security operations over the last two years: AI stopped being a pilot program and became the plan. And if you survey 500 security professionals on whether that's going well – as Omdia did, commissioned by Rapid7 – you get a remarkable level of consensus: 97% …RAPID7.COM
12 AugA Lookalike Domain Can Fool UsersCyber criminals can purchase and monitor domain names while watching their targets. When an opportunity appears, they can create lookalike domains that resemble a legitimate company. The deception can be subtle. A domain such as example-1.com may look close enough to a trusted do…YOUTUBE.COM
12 AugRecord-breaking Kimwolf DDoS botnet released new, stealthier versionPalo Alto Networks’ Unit 42 has uncovered a new version of the Kimwolf Android and IoT botnet that adds stealth to its DDoS attacks and multiple backup mechanisms designed to keep infected devices connected when command-and-control (C2) servers are disrupted. The variant, d…CYBERINSIDER.COM
12 Aug737 Chrome VPN extensions impersonate brands to hijack browser trafficSocket researchers have uncovered a sprawling network of 737 Chrome VPN extensions that impersonated legitimate privacy brands, redirected browser traffic through shared SOCKS5 infrastructure, and accumulated more than 75,000 installs. The campaign primarily targeted Russian-spea…CYBERINSIDER.COM
12 AugResearchers observe first ‘near-autonomous’ AI attack on government target in TaiwanIsraeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along. The post Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan appeared first on CyberScoop .CYBERSCOOP.COM
12 AugAutomate 90%, But Not the Last 10%Some companies claim to automate the entire takedown process. The speaker argues that much of this automation is really workflow automation, such as filling out takedown forms. A complete takedown process also requires monitoring, verification, and confirmation that the action wa…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
12 AugKimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate BrowsingCybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, trac…THEHACKERNEWS.COM
12 AugKimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and EthereumKimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats following public disclosures of the botnet’s earlier activity. The new version su…SECURITYAFFAIRS.COM
12 AugWindRelay Malware Pairs With SpyNote RAT in Live-Call ScamNew WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-callINFOSECURITY-MAGAZINE.COM
12 AugUK Cyber Resilience: Closing the Execution GapA UK survey reveals cyber risk is growing, but cyber resilience is not keeping pace. Learn how CIS SecureSuite can help UK organizations move from awareness to execution.CISECURITY.ORG
12 AugThe AI Supply Chain Has a Trust Problem with Michael Leland from IslandMichael Leland, Field CTO at Island joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices at Black Hat USA 2026. He discusses the emerging risks in the AI supply chain, why AI agents introduce new challenges around trust and governance, and what organi…THECYBERWIRE.COMHTTPS:
🎙️ PODCASTS 2[−]
12 AugRisky Business #848 -- OpenAI comes cleanOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including: The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI’s legal te…RISKY.BIZ
12 AugSmashing Security podcast #480: This is the AI service you should never sign up toWould you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has c…GRAHAMCLULEY.COM
📡 INFOSEC NEWS 17[−]
12 AugWeekly Threat Bulletin – August 12th, 2026These are the top threats you should know about this week.F5.COM
12 AugZoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's ClientAnyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked n…THEHACKERNEWS.COM
12 AugCapability Is Closing the Open-Closed Gap; Security Is NotA competitive open-weight model, Claude Fable, and Jade Puffer.F5.COM
12 AugWhen to Pay for Analyst Relations and When Not To with Kelly O'Dwyer ManuelKelly O'Dwyer Manuel has been building analyst relations (AR) programs for a long time, and her first question is always the same when starting from scratch: what are you actually trying to accomplish? She joins Gianna and Andy T to talk through what AR looks like for a small tea…THECYBERWIRE.COM
12 AugRussian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PLThe Polish CERT has released details of another 2025 attack on a combined heat and power plant in the countryINFOSECURITY-MAGAZINE.COM
12 AugThis Coin-Sized Device Can Hack a Boeing 737Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan.WIRED.COM
12 AugWalmart Leaders Transform Security Operations Without Going BananasThe big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency and team spirit are key factors.DARKREADING.COM
12 AugEnterprise Defenses Recovered at the Edge and Collapsed InsideEnterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in…THEHACKERNEWS.COM
12 AugLinux Kernel Process Accounting, (Wed, Aug 12th)A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#;x26;#;x5f;history"&#;x26;#;xc2;&#;x26…ISC.SANS.EDU
12 AugFBI: Hackers target online accounts to steal nude photosThe FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]BLEEPINGCOMPUTER.COM
12 AugHackers abuse AI models to find new entry pathsNetwork defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.CYBERSECURITYDIVE.COM
12 Aug“Zoomsday” flaws could let one Zoom participant attack anotherUpdate Zoom now to protect against critical vulnerabilities that could allow an attacker in the same meeting to run malicious code on your device.MALWAREBYTES.COM
12 AugWalmart's "Trusted Agent" Approach to Purple TeamingWalmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercisesDARKREADING.COM
12 AugHundreds of fake Chrome VPN extensions route traffic through a proxyMore than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]BLEEPINGCOMPUTER.COM
12 AugCorma raises $60 million in seed funding.Visa and Deel both acquire identity verification companies.THECYBERWIRE.COM
12 AugHow AWS IAM role manager rethinks the starting point for IAM rolesWhen you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an ide…AWS.AMAZON.COM