113Articles
8Categories
2026-08-13Date
🚨 CISA KEV 2[−]
13 Aug KEVCisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US ci…HELPNETSECURITY.COM
13 Aug KEVU.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known E…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 32[−]
13 AugAttackers Exploit SharePoint Authentication Bypass After Public PoC ReleaseThreat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from w…THEHACKERNEWS.COM
13 AugSharePoint CVE-2026-55040 Comes Under Attack Following Public ExploitAttackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July, wit…SECURITYAFFAIRS.COM
13 AugCritical VMware vCenter Vulnerability in Attackers’ CrosshairsTracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugIt took $58 to break Microsoft’s SCCM, but a patch made it harderResearchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Mana…CSOONLINE.COM
13 AugAttackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updat…HELPNETSECURITY.COM
13 AugCVE-2026-49162 Microsoft Brokering File System Elevation of Privilege VulnerabilityAdded acknowledgements. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62695 Windows Storage Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-61359 Windows Storage Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-65796 Windows iSCSI Target Service Denial of Service VulnerabilityCorrected severity entries in the Affected Products table. This is an informational change only. Customers who have successfully installed the update do not need to take any further action.MSRC.MICROSOFT.COM
13 AugCVE-2026-45593 Windows SDK Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-50461 Windows NTFS Remote Code Execution VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-49798 Windows Kernel Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugCVE-2026-50387 Windows GDI Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
13 AugAdobe Commerce Bug Targeted Immediately After DisclosureThe first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugCVE-2026-62897 .NET Framework Remote Code Execution VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62902 .NET Information Disclosure VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-70354 .NET Core Remote Code Execution VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62871 .NET Elevation of Privilege VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62886 .NET Elevation of Privilege VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCVE-2026-62898 Microsoft QUIC Information Disclosure VulnerabilityRemoved Linux and macOS products from the Affected Software table. This is an informational change only.MSRC.MICROSOFT.COM
13 AugCritical VMware vCenter RCE flaw exploited for reverse SSH accessA recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]BLEEPINGCOMPUTER.COM
13 AugAdobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public DisclosureHackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The v…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 24[−]
13 AugMore Novo Nordisk data dumped by FulcrumSecFulcrumSec has dumped more data from its attack that Novo Nordisk first disclosed on June 11. FulcrumSec writes: Today we are releasing all of the Novo Nordisk data not included in our original post: their complete enterprise HuggingFace AI/ML ecosystem. 30 models, 70 datasets, a…DATABREACHES.NET
13 AugRansomware Attack Disables Canadian Hospital’s Doors, HVACMarianne Kolbasuk McGee reports: A Canadian hospital is dealing with a ransomware attack on its facility management systems that has affected the building’s doors and heating, ventilation and air conditioning equipment. Some experts said the incident underscores growing cyb…DATABREACHES.NET
13 AugA golden opportunity...for fraud.This week, while Dave is out, hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ are discussing the latest in social engineerin…THECYBERWIRE.COM
13 AugDDoS attacks hit record scale as 1 Tbps+ campaigns become more commonDDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-l…HELPNETSECURITY.COM
13 AugBelgium's eID Authentication Opens Citizen Accounts to RCEThe trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.DARKREADING.COM
13 AugNorth Korean Lazarus Group Uses Windows Zero-Day in Operation Dream JobLazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and…SECURITYAFFAIRS.COM
13 AugMicrosoft wants you to rethink your approach to cyber defenseCyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft. David Weston, group manager in the W…CSOONLINE.COM
13 AugNightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugSearchlight Cyber combines exposure and threat intelligence in new PTEM platformSearchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited. Security for the real-time era For …HELPNETSECURITY.COM
13 Aug153GB of stolen credentials surface after LiteLLM supply chain attackA massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,90…HELPNETSECURITY.COM
13 AugThe Model Is the Malware | What Four Agentic Intrusions Tell DefendersOpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.SENTINELONE.COM
13 AugWordPress 7.0.4 Patches Remote Code Execution VulnerabilityAttackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugAI agents wage near-autonomous cyberattack on Asian government networksAutonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations. The campaign unfolded over four da…CSOONLINE.COM
13 AugvCenter Flaw Exploited Just Five Days After DisclosureAttackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed itINFOSECURITY-MAGAZINE.COM
13 AugWho Vets AI’s Code? The Scale Challenge Facing Open Source IngestionAI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]BLEEPINGCOMPUTER.COM
13 AugWhat 50 open source projects taught us about security in the AI eraSee how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security. The post What 50 open source projects taught us about securit…GITHUB.BLOG
13 AugTrezor says ShipMonk breach exposed data of 13,700 customersA data breach at Trezor logistics partner ShipMonk exposed the personal information of 13,689 hardware wallet customers. Trezor says its own systems and devices were not compromised, but warned affected customers to expect more convincing phishing attempts. Trezor disclosed the i…CYBERINSIDER.COM
13 AugQuestel confirms Microsoft 365 breach after ShinyHunters leaks dataFrench intellectual property services provider Questel has confirmed that attackers gained unauthorized access to part of its Microsoft 365 environment following a voice phishing attack, and that some of the stolen data was subsequently published online. The company disclosed the…CYBERINSIDER.COM
13 AugTrezor discloses data breach affecting nearly 14,000 customersHardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...]BLEEPINGCOMPUTER.COM
13 AugIn a first, US will allow some private firms to carry out cyberattacksZack Whittaker reports: The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday. In a newly published presidential memorandum, the Trump adm…DATABREACHES.NET
13 AugQuincy Valley Medical Center notifies patients of Aesto breachAs Seen on Facebook: To our Patients, Some of you have or will receive a letter from Grant County Public Hospital District 2 describing a security incident involving one of our third-party vendors. It is important to us that you understand some facts regardin this incident. First…DATABREACHES.NET
13 AugAI’s ‘middle class’ has gotten dramatically better at hackingAs frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models. The post AI’s ‘middle class’ has gotten dramatically better at hacking appeared first on CyberScoop .CYBERSCOOP.COM
13 AugMicrosoft patches LegacyHive Windows zero-day vulnerabilityMicrosoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
13 AugAI 'watermark removers' flood the web. Almost none can prove they work.Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be …BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 8[−]
13 AugSrsly Risky Biz: Data extortion is booming. Hooray!Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it. For organisations whose reputation is very important to them, data leaks are a bigger threat…RISKY.BIZ
13 AugTrump turns to private sector in offensive hacking operations memoOne expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense. The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberS…CYBERSCOOP.COM
13 AugTrump administration opens door to private-sector cyber offensivesThe Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime. A presidential memorandum issued…CSOONLINE.COM
13 AugGermany moves to give spy agencies hacking and sabotage powersGermany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era.THERECORD.MEDIA
13 AugTrump taps cyber firms to go on offensive against criminalsThe Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.THERECORD.MEDIA
🔥 INCIDENT REPORTING 9[−]
13 AugWhat do AI-driven ‘bank heist’ attacks mean for defenders?Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI…THECYBERWIRE.COM
13 AugICO Reprimands Criminal Records Office After 2023 BreachThe ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breachINFOSECURITY-MAGAZINE.COM
13 AugStorm-1175 Replaces Medusa With New StormEncryptor RansomwareMicrosoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group prev…SECURITYAFFAIRS.COM
13 AugAkira Affiliate Crashes Ransomware After Attempting EDR EvasionHuntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effortINFOSECURITY-MAGAZINE.COM
13 AugThe State of Ransomware Q2 2026For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Rese…RESEARCH.CHECKPOINT.COM
13 AugRingCentral - 1,596,490 breached accountsIn July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with …HAVEIBEENPWNED.COM
13 AugIn a first, US will allow some private firms to carry out cyberattacksThe new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.TECHCRUNCH.COM
13 AugExposed AWS Access Key Linked to Data Breach Affecting 1500+ UK CharitiesCRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ dataINFOSECURITY-MAGAZINE.COM
13 AugHackers breach govt webmail while running parallel crypto fraudThe Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 23[−]
13 AugISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
13 AugUsing Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity…ISC.SANS.EDU
13 AugProduct showcase: Is this image real? Slop or Not investigatesSlop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of people say they struggle to di…HELPNETSECURITY.COM
13 AugWireshark 4.6.8 patches 28 security bugs, nine in file parsersWireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Cat…HELPNETSECURITY.COM
13 AugFour corporate investigation mistakes organizations make under pressureIn this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decision…HELPNETSECURITY.COM
13 AugArmored Likho expands its cyber-espionage toolkitKaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.SECURELIST.COM
13 AugWhite House Mobilizes Security Firms for Operations Against Foreign Cybercrime GangsContracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek .SECURITYWEEK.COM
13 Aug'Jewelbug' APT Balances State Espionage & Cryptocurrency TheftResearchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.DARKREADING.COM
13 AugProton VPN is replacing wireguard-go with a new Rust VPN coreProton VPN has developed a new Rust-based client architecture, internally called ProTUN, to provide a common WireGuard implementation across its desktop and mobile applications and give its engineers greater control over anti-censorship features. Proton engineer Antonio Cesarano …CYBERINSIDER.COM
13 AugWhatsApp adds on-device scam detection without sending chats to MetaMeta has unveiled an early version of Scam Alert, an optional WhatsApp security feature that uses an on-device machine learning model to identify messages that may be part of a scam. The company says message content remains on the user’s phone during classification and is n…CYBERINSIDER.COM
13 AugFortinet Patches Authentication Flaws in FortiWeb and FortiManagerThe vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugSeparating AI’s Technological Problems from Its Capitalism ProblemsThis essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press . AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technolo…SCHNEIER.COM
13 AugVenture Firm Team8 Secures Additional $365 MillionThe Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugDataGrout helps enterprises control AI usage, governance and LLM costsSelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout’s mission is to drive token reduction for agentic workflows, chatbots and AI tools, while equi…HELPNETSECURITY.COM
13 AugA10 Networks introduces AI Gateway to secure and manage enterprise AIA10 Networks has announced the general availability of the A10 AI Gateway, a centralized, intelligent control plane that gives organizations unified routing, cost management, and governance across every AI agent, application and large language model (LLM) they use. As AI adoption…HELPNETSECURITY.COM
13 AugTemporary AWS Holes Become PermanentOpening an AWS security group for convenience can create unintended exposure. A common example is allowing access to a database without going through a bastion host, or temporarily opening access while working remotely. The word “temporary” doesn't make an overly broad rule safe.…YOUTUBE.COM
13 AugCybersecurity M&A Roundup: 21 Deals Announced in July 2026Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
13 AugWhite House authorizes private US companies to hack foreign criminal networksPresident Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government. The post White House authorizes private US comp…HELPNETSECURITY.COM
13 AugResearchers find AI-powered hacking tools for sale in underground forumsA report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.CYBERSECURITYDIVE.COM
13 AugUS government will let private companies hack criminal gangsThe new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.CYBERSECURITYDIVE.COM
13 AugBTS #80 - Exploring BMC VulnerabilitiesIn episode 80 of Below the Surface, Paul Asadoorian is joined by Chase Snyder and Vlad Babkin for a wide-ranging conversation about the infrastructure risks that remain easy to overlook until attackers start using them. The episode begins with a brief reflection on Black Hat USA …ECLYPSIUM.COM
13 AugAnthropic set AI agents loose on the same task. They started a turf war.Anthropic researchers found AI agents can clash, collude and coordinate in unexpected ways, raising new questions about whether today’s safety tests capture the risks of multi-agent systems.TECHCRUNCH.COM
13 AugBrave browser adds new defenses against GPU fingerprintingBrave is rolling out new protections to reduce browser fingerprinting through WebGL and WebGPU, two APIs that can expose detailed information about a device’s graphics hardware and drivers. The protections are enabled by default on desktop and Android and are being introduc…CYBERINSIDER.COM
🌐 CYBER THREAT LANDSCAPE 3[−]
13 AugNew Android malware lets criminals use your bank card in real timeSocial engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It's no joke. Together, they can empty your bank account.MALWAREBYTES.COM
13 AugNew Mirai variant adds stealth capabilities to notorious botnet codeBeyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.THERECORD.MEDIA
13 AugClosing the Blind Spot: Securing Personal Repositories in the Software Supply ChainPersonal repositories are where corporate secrets quietly escape. Wiz correlates them to your developers, validates the real risk, and drives the fix.WIZ.IO
📡 INFOSEC NEWS 12[−]
13 AugSurveillance Rulings and Social Media Scrutiny.This week, Ben and Ethan discuss two major stories. The first looks deeper into the Supreme Court's recent ruling on the Chatrie case and the long-term impacts this decision could have on privacy within the nation. The second dives into another court case decision, which exposes …THECYBERWIRE.COM
13 AugParents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuitsIt's the biggest legal challenge yet to addictive social media design and its impact on children.MALWAREBYTES.COM
13 AugCBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and ColleaguesRecords obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.WIRED.COM
13 AugDissecting the JWR phishing frameworkCisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.TALOSINTELLIGENCE.COM
13 AugWhatsApp rolls out new feature that flags potential scam messagesWhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]BLEEPINGCOMPUTER.COM
13 AugTrump Authorizes Private Sector Participation in Offensive Cyber OperationsThe White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attribution risksINFOSECURITY-MAGAZINE.COM
13 AugBrazil orders Discord to suspend livestreaming after teen suicideDiscord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.THERECORD.MEDIA
13 AugWhite House taps security firms for offensive hack-back operationsA new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]BLEEPINGCOMPUTER.COM
13 AugGoogle Cloud Targets 2027 for First Major Post-Quantum Security MilestoneGoogle Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028INFOSECURITY-MAGAZINE.COM
13 AugFlock tightens privacy controls amid scandals over officer abuseAll Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.THERECORD.MEDIA
13 AugHow to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization CampaignA practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.WIZ.IO
13 AugUS private equity firms targeted by hackers.More jurisdictions continue to cut ties with Flock.THECYBERWIRE.COM