126Articles
10Categories
2026-08-19Date
🚨 CISA KEV 2[−]
19 Aug KEVU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the followi…SECURITYAFFAIRS.COM
19 Aug KEVCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-202…THEHACKERNEWS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 14[−]
19 AugMicrosoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of itAlmost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The C…CSOONLINE.COM
19 Aug KEVCVE-2026-20349: Someone Is Crashing Cisco Firewalls. We Need to Talk About Why.An unauthenticated attacker can crash any Cisco ASA or FTD with SSL VPN exposed; it’s been confirmed exploited in the wild, and Cisco hasn’t told us who or why. Attackers Can Force Your Firewall To Reboot If you run a Cisco Adaptive Security Appliance or a Firepower T…ECLYPSIUM.COM
19 AugCVE-2026-62705 Microsoft Brokering File System Elevation of Privilege VulnerabilityCorrected the CVE title from **Windows Bind Filter Driver Elevation of Privilege Vulnerability** to **Microsoft Brokering File System Elevation of Privilege Vulnerability** and updated the acknowledgement. These are informational changes only.MSRC.MICROSOFT.COM
19 AugCVE-2026-69414 Microsoft Defender Elevation of Privilege VulnerabilityCWE added. Informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2020-1173 Microsoft Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2021-26859 Microsoft Power BI Information Disclosure VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2021-41372 Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2023-21806 Power BI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2026-58647 Microsoft PowerBI Report Server Spoofing VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 AugCVE-2026-65811 Power BI Remote Code Execution VulnerabilityCorrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.MSRC.MICROSOFT.COM
19 Aug KEVCVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayOverview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an una…RAPID7.COM
19 AugVU#874418: RDK-B WebUI contains multiple vulnerabilitiesOverview RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input validation. An attacker with network access to an affected WebUI may be able to bypass …KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 36[−]
19 AugCoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attackMicrosoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where Varonis Threat Labs says Copilot revealed an undocumented URL parameter that enab…CYBERSECURITYTODAY.LIBSYN.COM
19 AugRisky Business #849 -- Trump will unleash contractors on cybercriminalsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including: Trump’s memo authorising the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety me…RISKY.BIZ
19 AugChatGPT’s new feature could give infostealers a map of your Mac activityOpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer History does Computer History builds …HELPNETSECURITY.COM
19 AugBanks look for fraud signals in customer behaviorBanks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fra…HELPNETSECURITY.COM
19 AugRisky Bulletin: Slovakia finds Russian backdoors on its speed camerasSlovakia finds Russian backdoors on its speed cameras, French police used a public exploit to hack EncroChat, Microsoft delays Exchange updates due to a deluge of AI bugs, and a ransomware-affiliate poses as a data recovery firm.RISKY.BIZ
19 AugCyberattack forces UT San Antonio to delay start of fall semesterThe University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of…HELPNETSECURITY.COM
19 AugF5 enhances AI Gateway to control AI costs, access, and securityF5 has introduced enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control plane to govern how AI models, agents, and tools are…HELPNETSECURITY.COM
19 AugMost organizations aren’t ready for a Hugging Face-level eventThe National Security Agency (NSA) and Central Security Service recently published an advisory statement on behalf of the Five Eyes Cyber Security Agencies, warning that AI technologies are making it easier than ever for would-be malicious actors to infiltrate and compromise sens…CSOONLINE.COM
19 AugCISOs are struggling to threat-model AI. Can 15-minute sessions help?A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client. Someone at that organization had vibe-coded an app and put it to work with customer data. Now, the client wanted to know what risks the tool posed. And what it should do about them…CSOONLINE.COM
19 AugPreventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461Artificial intelligence has quickly evolved from a productivity tool into an active participant in many organizations' daily operations. As organizations give AI greater autonomy within their environment, they're also granting them access to sensitive systems and data. That creat…YOUTUBE.COM
19 AugChrome, Firefox Updates Patch Dozens of VulnerabilitiesThe bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugOpenAI puts major frontier AI training run on hold over cyber risksOpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontier RL run remains on hold while we conduct smaller-…HELPNETSECURITY.COM
19 Aug943 Patches Rolled Out With Oracle’s August 2026 Security UpdateThe fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugGoogle’s AI security agents found 100+ critical software vulnerabilities in just two daysGoogle’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories.…HELPNETSECURITY.COM
19 AugUpdate Chrome now: Two critical vulnerabilities fixedGoogle has released a Chrome desktop update fixing 15 security vulnerabilities, including 2 buffer overflow flaws rated critical.MALWAREBYTES.COM
19 Aug KEVCritical RCE flaw in Windows IKE Extension now actively exploitedThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]BLEEPINGCOMPUTER.COM
19 AugCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesThe flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugSnowflake flaw slips past AI checks, gets exploited by another AIAn autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline, while GitHub Copilot had previously reviewed the code change without flagging the flaw. The vulnerable code was part of a…CSOONLINE.COM
19 AugNIST Releases Tips & Tactics for Building Automation & Control System CybersecurityRecent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersec…NIST.GOV
19 AugServer Mistake Exposes StopAndProtect’s Hacked WordPress NetworkWaqas reports: A server mistake by cybercriminals has exposed the inner workings of a global malware operation that used nearly 2,000 hacked WordPress websites to infect computers, steal files and deploy ransomware. Check Point Research identified the operation as StopAndProtect …DATABREACHES.NET
19 AugHackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2PCybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity,…THEHACKERNEWS.COM
19 AugPassword spraying attacks surge 155x as hackers exploit MFA gapsHuntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]BLEEPINGCOMPUTER.COM
19 AugDOJ secures indictment of 17 Iranians accused of ‘massive’ cyber theft campaignMax Rego reports: The Department of Justice (DOJ) on Tuesday unsealed an indictment charging 17 Iranian nationals with targeting American and foreign institutions via a cyber theft campaign on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC). The 14-count indictment char…DATABREACHES.NET
19 AugBeware the Ransomware Rescuer: Ransom BustersJustin Timothy reports: The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the th…DATABREACHES.NET
19 AugThe long tail of Clop’s PTC hack is just beginning to emergeThe data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on …CYBERSCOOP.COM
19 AugPrison for data analyst who tried to extort $2.5 million from his employerThere’s an update to a previously reported case of a disgruntled former employee who tried to extort his employer, Brightly Software. Graham Cluley reports: When Cameron Curry discovered that his contract as a data analyst wasn’t going to be renewed, he could have upd…DATABREACHES.NET
19 AugExclusive: Linux Foundation's Akrites to Go Live in SeptemberThe Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projectsINFOSECURITY-MAGAZINE.COM
19 AugFirefox 154 blocks silent WebSocket access to local network devicesMozilla has released Firefox 154 with expanded protections against websites connecting to devices on local networks, new AI-assisted tab organization, and support for NVIDIA GeForce NOW on Windows. The latest update also addresses 58 CVE entries, including multiple high-severity …CYBERINSIDER.COM
19 AugSo Is Your SOC AI-Ready? Part 3: API or Die Audit!This is Part 3 of the AI-ready SOC series ( Part 1 , Part 2 ), and it is focused on validating readiness for pillars #1 (SOC Data Foundations) and #4 (Modern SOC Technology Stack). Specifically, it is about the audit I promised in Part 2 : “The ‘API or Die’ Data Audit: You need t…MEDIUM.COM
19 AugThe AI Was the Route InSeveral recent security incidents and research demonstrations involve attackers manipulating AI assistants and connected systems that already have legitimate access to organizational data or infrastructure. The AI doesn't always have to be the target. If an assistant can read log…YOUTUBE.COM
19 AugNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyThe National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.THERECORD.MEDIA
19 AugUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureU.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]BLEEPINGCOMPUTER.COM
19 AugOpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI BehaviorOpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models…THEHACKERNEWS.COM
19 AugHackers hiding in plain sight.Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine stri…THECYBERWIRE.COM
19 AugSakura Internet hack exposes data of up to 1.36 million accountsJapanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]BLEEPINGCOMPUTER.COM
19 AugHealthtech firm CareCloud data breach impacts 3.7 million patientsU.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]BLEEPINGCOMPUTER.COM
📋 SECURITY BULLETINS 1[−]
19 AugMicrosoft fixes known issue causing Windows Defender crashesMicrosoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 11[−]
19 AugCISA: Medusa ransomware hit over 500 critical infrastructure orgsThe FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]BLEEPINGCOMPUTER.COM
19 AugBad Microsoft Defender update causes Windows crashes on scansMicrosoft Defender users are reporting widespread scan failures after a recent security intelligence update, with Quick and Full scans crashing the antivirus engine and Offline scans reportedly freezing near completion. Reports from system administrators, home users, and Microsof…CYBERINSIDER.COM
19 AugMedusa ransomware gang has hit over 500 organizations, CISA warnsMedusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI in…HELPNETSECURITY.COM
19 AugRapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin AmericaCássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expandin…RAPID7.COM
19 AugA California county wants to hire Tina Peters to help run its electionsAfter her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop .CYBERSCOOP.COM
19 AugAI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warnHackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.CYBERSECURITYDIVE.COM
🔥 INCIDENT REPORTING 21[−]
19 AugOz Hair and Beauty - 1,988,331 breached accountsIn August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack . The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations…HAVEIBEENPWNED.COM
19 AugFanlore - 144,520 breached accountsIn August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-s…HAVEIBEENPWNED.COM
19 AugCareCloud Data Breach Impact Grows to 3.7 Million IndividualsThe data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugOver 500 Critical Infrastructure Organizations Hit by Medusa RansomwareThe FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counterINFOSECURITY-MAGAZINE.COM
19 AugStopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal DataCybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the a…THEHACKERNEWS.COM
19 AugOpenAI Tightens AI Safeguards Following Hugging Face IncidentOpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilitiesINFOSECURITY-MAGAZINE.COM
19 AugCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignThe cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugUS charges Iranians for sprawling hacking campaign on government agencies, universitiesThe Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.THERECORD.MEDIA
19 AugCareCloud confirms 3.7M patients had their medical records stolen in data breachThe cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.TECHCRUNCH.COM
19 AugLatvian officials resign after cyberattack exposes data on 1.2 million peopleLatvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.THERECORD.MEDIA
19 AugBackup Software Can Exfiltrate DataBackup software is designed to move and store large amounts of organizational data. If the destination or purpose changes, that same capability can potentially be used for data exfiltration. Because backup activity is expected and can generate substantial data movement, malicious…YOUTUBE.COM
19 AugMedusa ransomware affiliates have breached hundreds of critical infrastructure entities.US accuses 17 Iranians of hacking for Iran's IRGC. Business news: Fortinet acquires AI security firm Virtue AI.THECYBERWIRE.COM
19 AugRansomware disproportionately targets medium-sized firms, straining customer relationshipsThese companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.CYBERSECURITYDIVE.COM
19 Aug2,000 WordPress sites hijacked by StopAndProtect malware operationA large-scale malware operation dubbed StopAndProtect uses thousands of compromised WordPress websites to distribute malware, issue commands, and store data stolen from infected computers. The campaign combines ransomware, credential theft, surveillance, lateral movement, and han…CYBERINSIDER.COM
19 AugT-Mobile ‘chopped a cable’ to expel Chinese hackers from its networkThe U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on.TECHCRUNCH.COM
19 AugInside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua CamerasAn exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between Ju…SECURITYAFFAIRS.COM
19 AugElectronic health record company CareCloud says 3.7 million people affected by breachHealthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.THERECORD.MEDIA
19 AugHackers compromise 14,500 Dahua web cameras in 35-day campaignIn a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]BLEEPINGCOMPUTER.COM
19 AugRogue ransomware affiliate poses as data recovery firm to steal paymentsA suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]BLEEPINGCOMPUTER.COM
19 AugCybersecurity Needs Its Stop Drop RollCybersecurity is complex, but emergency response doesn't always have to be. The discussion compares cybersecurity's response problem with familiar basics like CPR and “stop, drop and roll.” A simple, memorable response playbook could help people act faster during an incident inst…YOUTUBE.COM
19 AugRogue ransomware affiliate poses as recovery firm to steal paymentsA suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 14[−]
19 AugChina-Linked Hacker Shows AI Capabilities in APAC AttackIn the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.DARKREADING.COM
19 AugISC Stormcast For Wednesday, August 19th, 2026 https://isc.sans.edu/podcastdetail/10058, (Wed, Aug 19th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
19 AugBrinqa acquires PlexTrac to bring validated remediation to exposure managementBrinqa has announced its acquisition of PlexTra, adding the ability to verify that remediation efforts have actually worked. The combined capabilities uniquely position Brinqa to identify and prioritize the exposures that matter most, drive remediation, and validate that fixes ho…HELPNETSECURITY.COM
19 AugICE Collecting DNA SamplesICE collected nearly a million DNA samples last year.SCHNEIER.COM
19 AugEurope is creating a common security standard for VPN servicesEuropean standards body ETSI has begun the approval process for a new cybersecurity standard for VPN products, part of a wider package of 17 standards designed to support the EU Cyber Resilience Act (CRA). The VPN standard, EN 304 620, introduces defined technical and privacy req…CYBERINSIDER.COM
19 AugPrevalent AI Raises $22 Million to Expand Data Fabric PlatformThe previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemThe 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek .SECURITYWEEK.COM
19 AugSilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATsA previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETa…THEHACKERNEWS.COM
19 AugVirtual Event Today: CodeSecCon – Secure Your Code and ApplicationsCodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on Secu…SECURITYWEEK.COM
19 AugIntezer adds native response automation without separate SOARIntezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly inside the Intezer platform. Workflows brings response into the same platform where alerts are triaged and investigated, allow…HELPNETSECURITY.COM
19 AugUS charges Iranian hackers over $3.4 billion intellectual property theftThe U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]BLEEPINGCOMPUTER.COM
19 AugSilkParasite Threatens Central Asian Orgs With Flurry of RATsA spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.DARKREADING.COM
19 AugAI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warnThe agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop .CYBERSCOOP.COM
19 AugMicrosoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appea…MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 1[−]
19 AugMaaS Campaign Combines ClickFix, ErrTraffic and CruciferraeSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and CruciferraINFOSECURITY-MAGAZINE.COM
🎙️ PODCASTS 1[−]
19 AugSmashing Security podcast #481: Never say this to a robot dogAt Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room …GRAHAMCLULEY.COM
📡 INFOSEC NEWS 25[−]
19 AugWeekly Threat Bulletin – August 19th, 2026These are the top threats you should know about this week.F5.COM
19 AugBehind the Cyber Creator: An AMA with Infosec Pat (Patrick Gorman)Patrick Gorman started making YouTube videos during COVID to study for a certification with friends. He now has over 100,000 subscribers and runs a pentesting firm called ISP Security. This is a replay of our Behind the Cyber Creator AMA series. Patrick and Gianna talk about how …THECYBERWIRE.COM
19 AugPrison for data analyst who tried to extort $2.5 million from his employerWhen Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion. Read…BITDEFENDER.COM
19 AugFlock Has a Powerful New AI Tool for Police. We Got Its CodeFlock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates.WIRED.COM
19 AugUK Fraud Cases Hit Record High in 2026Cifas data finds account takeover and identity fraud are driving a surge in fraud casesINFOSECURITY-MAGAZINE.COM
19 Aug50,000 Stripe Secrets Leaked in Public CodeOver 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misc…SECURITYAFFAIRS.COM
19 AugYour polite reply to that text is worth $2 on the dark webA polite reply to a wrong-number text may seem harmless. But scammers use it to profile their victims and fuel a multibillion-dollar fraud industry.MALWAREBYTES.COM
19 AugReverse-Lookup Service Exposed Millions of Photos of People’s FacesThe people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.WIRED.COM
19 AugICO Urges Police to Improve Data Governance in Facial Recognition RolloutsThe UK’s privacy watchdog has called on police using facial recognition to follow its recommendationsINFOSECURITY-MAGAZINE.COM
19 AugWindows 11 24H2 Home and Pro reach end of support in 2 monthsMicrosoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]BLEEPINGCOMPUTER.COM
19 AugMicrosoft Tracks MacSync Stealer by Its Behavior, Not Its DomainsMicrosoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it…SECURITYAFFAIRS.COM
19 AugScammers are using fake crypto AML checkers to drain your walletWe found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers.MALWAREBYTES.COM
19 AugDescribing attacks with crime script analysisMartin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.TALOSINTELLIGENCE.COM
19 Aug3 Lessons for Securing Large-Scale Events: Inside FIFA World Cup 2026Lessons learned for securing large scale events and CIS's critical role as a partner supporting event security operations at the 2026 FIFA World CupCISECURITY.ORG
19 AugPhishing 3.0: The Fight Moves to Agent Versus AgentMost email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing…THEHACKERNEWS.COM
19 AugGrandoreiro Resurfaces in Mexico With New DLL Sideloading CampaignGrandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detectionsINFOSECURITY-MAGAZINE.COM
19 AugSimple Scans for Cloud Metadata Service, (Wed, Aug 19th)Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service…ISC.SANS.EDU
19 AugSideloading on Android: What it is, why it’s risky, and how to do it more safelyWith the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.MALWAREBYTES.COM
19 AugWiz Penetration Test Findings is now GATransform point-in-time pen-tests into continuous exposure management with unified platform combining pen-test findings and real-time cloud contextWIZ.IO
19 AugPropagate user authorization context in AI agents with Amazon Bedrock AgentCoreMany teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who…AWS.AMAZON.COM
19 AugResearchers say OpenAI revoked their access to limited cyber programMultiple cybersecurity researchers said they suddenly lost access to OpenAI’s Trusted Access for Cyber (TAC) program, which offers models with fewer guardrails for vetted users.TECHCRUNCH.COM
19 Aug41 deceptive download sites show a real link, then send you somewhere elseA legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.MALWAREBYTES.COM
19 AugFortinet has acquired San Francisco-based AI security company Virtue AI.Dynatrace has agreed to acquire San Francisco-based AI observability platform Arize for $915 million. Cribl has acquired technology assets from Radiant Security's AI SOC product.THECYBERWIRE.COM
19 AugNo-Filter 'Kriminal' AI Platform Raises Cybercrime ConcernsThe AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.DARKREADING.COM
19 AugOpenAI confirms ChatGPT is down as logins and signups failChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]BLEEPINGCOMPUTER.COM