🐛 COMMON VULNERABILITIES AND EXPOSURES 8[−]
17 AugHackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schoolsCISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 leaders with limited budgets, emphasizing MFA, device protection, tested backups, an…CYBERSECURITYTODAY.LIBSYN.COM
17 AugCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After DisclosureThe vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugMicrosoft working on Defender patch for ShieldBreak zero-dayMicrosoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]BLEEPINGCOMPUTER.COM
17 AugSuspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareCybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-travers…THEHACKERNEWS.COM
17 Aug KEVAttackers exploit patched macOS Screen Sharing flaw to deploy cryptominerA recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attacker…HELPNETSECURITY.COM
17 AugCertighost and the Privilege Hiding in Your Certificate AuthorityCVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]BLEEPINGCOMPUTER.COM
17 AugCVE-2026-62722 Microsoft Brokering File System Elevation of Privilege VulnerabilityCorrected the CVE description and title. This is an informational change only.MSRC.MICROSOFT.COM
17 AugForminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP UploadsA critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.…THEHACKERNEWS.COM
⚠️ VULNERABILITY DISCLOSURE 33[−]
17 AugSponsored: What npm 12 fixes… and what it doesn’tIn this Risky Business sponsored interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default. Attackers are already shifting payloads into package source code, and Feross explains why teams need to understand what…RISKY.BIZ
17 AugHazmat: Open-source containment for AI agentsHazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as …HELPNETSECURITY.COM
17 AugRisky Bulletin: The EU publishes its upcoming cybersecurity standardsThe EU publishes its upcoming cybersecurity standards, hackers breach France’s tax agency, threat actors exploit a GeoServer zero-day hours after disclosure, and an exploit unlocks old AMD CPUs with one instruction.RISKY.BIZ
17 AugWhat the CISO role will look like in 2029Wolfgang Goerlich has spent his career in security and has been a CISO for the past seven years. Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He’s bracing for more. “For the future I see growing the role of CISO to be the pacesett…CSOONLINE.COM
17 AugSandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the news - ESW #472Interview with Jon Hladik - ChatMate Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user’s chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim. That is exactly the ca…YOUTUBE.COM
17 AugRecent macOS Screen Sharing Vulnerability Exploited in AttacksThreat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugPolice bust cybercrime ring accused of stealing €30 million in four-day spreeGerman and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klon…HELPNETSECURITY.COM
17 Aug40,000 Impacted by SafePal Data BreachHackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information. The post 40,000 Impacted by SafePal Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugEvooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 ProxiesCybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engin…THEHACKERNEWS.COM
17 AugFrench tax authority data breach affects 678,000 individualsThe French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]BLEEPINGCOMPUTER.COM
17 AugSafePal breach affects 39,798 customers, data allegedly for saleCryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used fo…HELPNETSECURITY.COM
17 Aug KEVUpdate your Mac: Screen Sharing vulnerability exploited in the wildAttackers are exploiting a Mac Screen Sharing vulnerability to gain root access and install Monero cryptominers.MALWAREBYTES.COM
17 AugUnisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel AccessSecurity researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, i…THEHACKERNEWS.COM
17 AugZhipu says new coding AI developed advanced cyber skills faster than expectedChinese AI developer Zhipu has launched GLM-5.3, a new coding-focused AI model that the company says has developed unexpectedly strong cybersecurity capabilities, putting it close to global leading models in vulnerability discovery while remaining behind them on deeper exploitati…CSOONLINE.COM
17 AugUkraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikesUkraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.THERECORD.MEDIA
17 AugIrregular Details How a Naming Error Let AI Models Attack a Real CompanyThe AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models. The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek .SECURITYWEEK.COM
17 Aug⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to a…THEHACKERNEWS.COM
17 AugWhy data quality dictates security operations successAs AI takes on more security operations center (SOC) workflows to automate threat triage, indicator extraction, and incident report generation, security operations leaders face a persistent question: Does SOC performance depend more on the large language model (LLM) deployed or o…CSOONLINE.COM
17 AugOperation ASTERIX: Anatomy of a Crypto Fraud PipelineOperation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing sc…RAPID7.COM
17 AugWiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix”Wiz Red Agent independently discovered and exploited a GitHub Actions vulnerability introduced by GitHub Copilot Autofix, validated access to sensitive data in Snowflake’s internal Jira, and assessed the blast radius—all without human intervention.WIZ.IO
17 AugMore than 2 million user records from TaxAct allegedly acquired; 450k already leakedOn August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company…DATABREACHES.NET
17 AugIsrael’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customersOlivier Acuna reports: Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported. The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access t…DATABREACHES.NET
17 AugYour Backups Are Hiding ThreatsSecurity teams traditionally focus threat intelligence on sources such as identity, network, endpoint, and other parts of the standard security stack. But backup data can contain another source of security telemetry. The claim presented here is that roughly 20% of threats identif…YOUTUBE.COM
17 AugFrance’s tax authority admits hackers made off with data on 678,000 individualsFrance’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an alleged attacker using t…HELPNETSECURITY.COM
17 AugDetecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilitiesLearn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engin…TENABLE.COM
17 AugCritical flaw in SAP Commerce Cloud faces initial exploitation attemptsThe vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.CYBERSECURITYDIVE.COM
17 AugUNISOC Modem Flaw Enables Remote Code Execution via Video CallsUNISOC modem flaw enabled kernel-level code execution through video callsINFOSECURITY-MAGAZINE.COM
17 AugLinux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoSThe botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.DARKREADING.COM
17 Aug235 GB of PHI and internal documents dumped; Chaos claims it comes from Healthcare Highways“Chaos” is a Ransomware-as-a-Service (RaaS) group first found online in March, 2025. On August 5, 2026, they added Healthcare Highways to their dedicated leak site, with a 24-hour countdown clock. Healthcare Highways describes itself as a medical provider network comp…DATABREACHES.NET
17 AugSafePal Says 39,798 Customers Hit by Data BreachSafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. …SECURITYAFFAIRS.COM
17 AugApple Patches iOS and macOS, (Mon, Aug 17th)Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
ISC.SANS.EDU
17 AugPlease hold while we decide.Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged employee records for sale. ETSI begins the approval process for European cyber st…THECYBERWIRE.COM
17 AugVideo Call Exploit Chains Two Flaws in Unisoc ModemsResearchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.DARKREADING.COM
📢 SECURITY ADVISORIES 10[−]
17 AugStronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered CybersecurityWhen was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warnin…NIST.GOV
17 AugWindows Server 2022 reaches end of mainstream support in 60 daysMicrosoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]BLEEPINGCOMPUTER.COM
17 AugWordPress Plugin Flaw Exposes 40,000 Sites to Admin TakeoverCritical User Profile Builder flaw let unauthenticated attackers access administrator accountsINFOSECURITY-MAGAZINE.COM
17 Aug17th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupte…RESEARCH.CHECKPOINT.COM
🔥 INCIDENT REPORTING 19[−]
17 AugFortune 500 Companies Hit in Azure Data Theft CampaignA threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugAfrica’s Cybersecurity Challenge Is Bigger Than Access to TechnologyGopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not…RAPID7.COM
17 AugAkira Ransomware Uses Safe Mode to Bypass EDRAkira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the co…SECURITYAFFAIRS.COM
17 AugSafePal Data Breach Hits Tens of Thousands of CustomersNearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breachINFOSECURITY-MAGAZINE.COM
17 AugNew macOS malware turns stolen browsers into attacker-controlled sessionsMac users are being freshly warned of suspicious websites asking them to open Terminal and install software. Jamf Threat Labs has uncovered a multi-stage macOS infostealer, dubbed AmnesiaStealer, that uses a ClickFix-style fake GitHub download page to trick victims into executing…CSOONLINE.COM
17 AugPhilips and GE investigating Clop ransomware data theft claimsTech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]BLEEPINGCOMPUTER.COM
17 Aug680,000 Impacted by French Tax Authority Data BreachHackers used compromised credentials to access enterprise and personal tax-related data. The post 680,000 Impacted by French Tax Authority Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugSogang University data breach exposes information of 180,000 peopleSogang University in Seoul has suffered a cyberattack that exposed personal information belonging to roughly 180,000 students, alumni, faculty members, and staff. The university said an unidentified external party gained unauthorized access to its integrated login system, resulti…CYBERINSIDER.COM
17 AugGeneral Electric, Philips, and Shell investigate alleged breaches.ShinyHunters leaks alleged RingCentral data. Police arrest seven suspects in connection with 2023 bank hack.THECYBERWIRE.COM
17 AugMajor genetic-testing firm says hack compromised sensitive patient dataThe June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector.CYBERSECURITYDIVE.COM
17 AugSafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impactedThe crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.THERECORD.MEDIA
17 AugIrregular faces criticism over ‘spin’ in AI hacking postmortemThe company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.THERECORD.MEDIA
17 AugPoland probes MyDr healthcare software breach potentially affecting 19 million peopleMyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.THERECORD.MEDIA
17 AugWill Cyber Insurance Stop Covering Fraud?Financial fraud is described as a leading category of cyber insurance claims, with Adrian Sanabria noting that it can exceed ransomware in claims paid by insurers. At the same time, insurers are changing what they consider covered cyber risk. Social engineering, “click fix,” and …YOUTUBE.COM
17 AugHacker claims 3.6 million Azure account records stolen from major companiesA threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]BLEEPINGCOMPUTER.COM
17 AugPokémon Center data breach exposes customer info, cancels some ordersPokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]BLEEPINGCOMPUTER.COM
17 AugNearly 750k had financial info, SSNs leaked in South Carolina loan company breachThe breach affected anyone who received a loan through the company or inquired about a loan product through a third party.THERECORD.MEDIA
17 AugDetails emerge on BlackFile’s recent attacks on financial companiesBlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. The post Details emerge on BlackFile’s recent attacks on financial companies a…CYBERSCOOP.COM
17 AugIrregular says ‘human oversight’ responsible for AI sandbox escape incidentsIn a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop .CYBERSCOOP.COM
🕵️ THREAT INTELLIGENCE 12[−]
17 AugISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
17 AugWhen companies get specific about AI, revenue growth looks differentCompanies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on …HELPNETSECURITY.COM
17 AugProduct showcase: ScamNet looks for warning signs in suspicious calls and shady linksScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform.…HELPNETSECURITY.COM
17 AugWindows 11’s strongest security defenses can be bypassed without a screwdriverResearchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to th…HELPNETSECURITY.COM
17 AugHacking Public Wi-Fi DNS to Steal CredentialsCriminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.SCHNEIER.COM
17 AugProton’s AI Paper Trail reveals how much ChatGPT and Claude know about usersProton has launched a free tool that shows users how much personal information ChatGPT and Claude may reveal through their conversation histories, highlighting the privacy risks of repeatedly sharing sensitive information with AI chatbots. Called AI Paper Trail, the tool analyzes…CYBERINSIDER.COM
17 AugConflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating MalwareAnthropic has been conducting tests to identify issues in how AI agents interact with each other. The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek .SECURITYWEEK.COM
17 AugFortinet expands AI security portfolio with Virtue AI acquisitionFortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiGate Hyperscale Firewall. As organizations deploy A…HELPNETSECURITY.COM
17 AugApple Screen Sharing Security, (Mon, Aug 17th)About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used…ISC.SANS.EDU
17 AugCall for Applications: Information Controls Research Program 2026The Information Controls Research Program (ICRP) (formerly known as the “Information Controls Fellowship Program) from the Open Technology Fund (OTF) supports applied research into how authoritarian governments in the most repressive information environments are restricting the f…CITIZENLAB.CA
17 AugCavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate TrafficCybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the thr…THEHACKERNEWS.COM
17 AugThe EU CRA Clock is Ticking:Are You Compliant?The post The EU CRA Clock is Ticking:Are You Compliant? appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
17 AugA week in security (August 10 – August 16)A list of topics we covered in the week of August 10 to August 16 of 2026MALWAREBYTES.COM
17 AugInfostealers Harvest 1.7 Billion Credentials in Six MonthsFlashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026INFOSECURITY-MAGAZINE.COM
17 AugLiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most AffectedThe SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code reposit…SECURITYAFFAIRS.COM
17 Aug‘Unprecedented’ number of Apple users received recent spyware alert, say investigatorsCybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.TECHCRUNCH.COM
17 Aug'Turf War' Between Claude Agents Leads to Self-Replicating MalwareThree testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.DARKREADING.COM
🎙️ PODCASTS 1[−]
17 AugWhen AI Sprawl Becomes a Security Problem with Nick Warner from NeoNick Warner, CEO of Neo, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. He discusses how the rapid adoption of AI tools and agentic software is reshaping enterprise security, why CISOs need greater visibility and …THECYBERWIRE.COMHTTPS:
📡 INFOSEC NEWS 15[−]
17 AugWhy more security data has blurred companies’ view of riskMore security data can create blind spots. Here’s how to regain visibility.CYBERSECURITYDIVE.COM
17 AugInvisible AI Prompts Trigger Court SanctionsA litigant hid AI prompt injections in a court filing to influence a ruling. The judge caught it and banned him from electronic filing. A man suing the New York Bariatric Group reportedly hid AI prompt in a court filing, instructing any AI system that read it to rule in his favor…SECURITYAFFAIRS.COM
17 AugMcDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records StolenA seller claims 1.7M McDonald’s employee records were stolen from Azure. An 8,000-row sample appears genuine, but its age and full size remain unconfirmed. A seller on a data-trading forum posted an 8,000-row sample this week claiming it came from McDonald’s own Azure tenan…SECURITYAFFAIRS.COM
17 AugWhy Facebook’s war on ad blockers could help scammersOne ad blocker is giving up the fight against Facebook ads. The consequences could go beyond annoying advertising.MALWAREBYTES.COM
17 AugFake TikTok rewards promise cash you’ll never getTikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.MALWAREBYTES.COM
17 AugETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience ActThe European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience ActINFOSECURITY-MAGAZINE.COM
17 AugHow MCP Servers Can Expose Enterprise SecretsMCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become…THEHACKERNEWS.COM
17 AugCrypto hardware wallet owners face fresh security risks after recent spate of personal data theftsThe hacks at shipping companies used to mail out hardware wallets puts crypto owners at greater risk of real-world attacks.TECHCRUNCH.COM
17 AugThe Closed Loop Remediation Playbook with WizStart your path to a self-healing cloud today, with Wiz Workflows now GA and Remediation and Response in public preview.WIZ.IO
17 AugShieldBreak bypasses Microsoft’s patch for earlier Defender flawThe researcher who found RoguePlanet has discovered ShieldBreak, a new way to bypass Microsoft’s fix and gain SYSTEM privileges.MALWAREBYTES.COM
17 AugAn “invisible” car? Researcher uses machine learning to hide vehicles from Flock camerasA cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming increasingly common on American streets. Read more in…BITDEFENDER.COM
17 AugMicrosoft confirms GitHub is down worldwideGitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]BLEEPINGCOMPUTER.COM
17 AugUpdates to your AWS Sign-In experienceAmazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These update…AWS.AMAZON.COM
17 AugVishing: An Evolving Threat to SLTT OrganizationsThe CIS CTI team assesses vishing will continue to pose a risk to U.S. SLTT organizations. Read the team's analysis and recommendations.CISECURITY.ORG
17 AugAdam Shostack Talks Hugging Face & PHANTOM-BWorld-class threat modeler Adam Shostack shared he was "blown away" by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both "lightweight yet still usable."DARKREADING.COM