🚨 CISA KEV 1[−]
20 Aug KEVU.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS sc…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 11[−]
20 AugElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute CodeCybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been descr…THEHACKERNEWS.COM
20 AugCritical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityCorrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.MSRC.MICROSOFT.COM
20 AugCVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityCorrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.MSRC.MICROSOFT.COM
20 AugAttackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code ExecutionA now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of co…THEHACKERNEWS.COM
20 AugCVE-2026-62754 Windows Kerberos Elevation of Privilege VulnerabilityUpdated links to security updates. This is an informational change only.MSRC.MICROSOFT.COM
20 AugHackers Target Zimbra Servers in Active Exploitation CampaignExploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCVE-2026-54118 Microsoft SQL Server Remote Code Execution VulnerabilityThe CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.MSRC.MICROSOFT.COM
20 AugCVE-2026-54117 Microsoft SQL Server Remote Code Execution VulnerabilityThe CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.MSRC.MICROSOFT.COM
20 AugCitrix issues critical security updates for its NetScaler devicesCitrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass. Citrix said in an a…CSOONLINE.COM
20 AugRejoice In The Nostalgia - PSW #940In the security news this week: - Cursor opens your repo, the repo opens you - If you want the good model I'm going to need to see your ID - Flock's a Flocking mess - Defender was supposed to be the chosen one - Side stepping Secure boot - twice - SonicWall: a LAMP stack in a fan…YOUTUBE.COM
⚠️ VULNERABILITY DISCLOSURE 42[−]
20 AugCloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/SecondCybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstr…THEHACKERNEWS.COM
20 AugOpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention for select frontier model customersOpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering zero data retention for “eligible API customers.”…CSOONLINE.COM
20 Aug8,539 reasons to rethink how vulnerabilities get patchedThe window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report cou…HELPNETSECURITY.COM
20 AugAirlock Digital Completes Independent IRAP Assessment at the PROTECTED LevelAirlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED classification level. The assessment was conducted by an…CSOONLINE.COM
20 AugObjection! That's a scam.This week, while Dave is out, hosts Maria Varmazis and Joe Carrigan are discussing the latest in social engine…THECYBERWIRE.COM
20 AugAI is making fraud harder to spot and identity harder to proveOnline fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and ac…HELPNETSECURITY.COM
20 AugSrsly Risky Biz: Trump's private hacker memo is the right ideaTom Uren and James Wilson talk about President Donald Trump’s memo enlisting the US private sector to tackle cybercriminals. The initiative gets the big idea right: traditional law enforcement approaches have not worked against cybercriminals so the government has turned to disru…RISKY.BIZ
20 AugExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerRemote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugIdentity Abuse Through Trusted Communication ChannelsUnit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
20 Aug KEVCritical Zimbra RCE flaw now actively exploited in attacksCERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]BLEEPINGCOMPUTER.COM
20 AugUS agencies warn of AI-powered attacks on Siemens industrial controllersThreat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. PLCs are the small industr…HELPNETSECURITY.COM
20 AugICS Operators Warned of AI-Driven Attacks on Siemens PLCsA US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCsINFOSECURITY-MAGAZINE.COM
20 AugNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft CommandsSecurity researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument comman…THEHACKERNEWS.COM
20 Aug40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet SecretsA set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons tha…THEHACKERNEWS.COM
20 AugKriminal breaks out of Grok, Claude guardrails at $12.99Security researchers are warning of a criminal AI service built on Grok and Claude, among other models, that promises uncensored access to powerful AI capabilities for as little as $12.99 a month. ThreatDown researchers say “Kriminal” is largely a storefront wrapped around legiti…CSOONLINE.COM
20 AugLargest Applebee’s franchisee says hackers stole sensitive dataApple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, and biometric informatio…CYBERINSIDER.COM
20 AugAI-powered cyberattacks are targeting critical infrastructure in the USUS agencies are warning that threat actors are actively using AI-generated exploitation scripts to target Siemens S7 programmable logic controllers (PLCs) deployed across critical infrastructure. The activity focuses on Internet-exposed and poorly secured industrial systems, with…CYBERINSIDER.COM
20 AugCISA warns of hackers exploiting critical MLflow vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]BLEEPINGCOMPUTER.COM
20 AugCisco Patches Critical Crosswork, Secure Workload VulnerabilitiesThe flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugAI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian HackingAtalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network. The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugAWS limits AI agents’ data access, even when manipulatedAWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using Amazon Bedrock AgentCore can build AI agents that …HELPNETSECURITY.COM
20 AugAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesThe flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugMLflow Vulnerability Exploited for Cloud Credential TheftThe critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugCDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS AmplificationCybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x aga…THEHACKERNEWS.COM
20 AugThe push to designate AI as the next critical infrastructure sectorThe designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop .CYBERSCOOP.COM
20 AugBTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation PrimitiveResearch by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0…RESEARCH.CHECKPOINT.COM
20 Aug'Grandoreiro' Malware Resurfaces With Mexico CampaignThe banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.DARKREADING.COM
20 AugLargest Applebee’s franchisee says hackers stole sensitive dataAmar Ćemanović reports: Apple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, …DATABREACHES.NET
20 AugIsolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCECybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6r…THEHACKERNEWS.COM
20 AugCritical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA ServersCitrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect custom…THEHACKERNEWS.COM
20 AugFrequently asked questions about the active threat to Siemens S7 Series PLCsA joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiti…TENABLE.COM
20 AugChinese hackers use AI to automate attacks on 170,000 serversA Chinese-speaking cybercrime group is using AI-assisted tooling to automate attacks against vulnerable Windows and Linux web servers worldwide. Tracked as UAT-10147 by Cisco Talos, the threat group targets internet-facing servers for data theft and search engine optimization (SE…CYBERINSIDER.COM
20 AugCritical Elementor Pro bug exposes WordPress sites to RCE attacksA critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]BLEEPINGCOMPUTER.COM
20 AugNew Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat DataAdversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary we…THEHACKERNEWS.COM
20 AugCitrix urges immediate patching of two newly disclosed vulnerabilities.Federal agencies warn of an active cyber campaign targeting Siemens PLCs. Latvian road traffic agency data breach affects two-thirds of the country's population.THECYBERWIRE.COM
20 AugWhat we know so far about the hacking campaign against US water systemsSupport is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.CYBERSECURITYDIVE.COM
20 AugAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureThe U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct r…THEHACKERNEWS.COM
20 AugThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and MoreA lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hid…THEHACKERNEWS.COM
20 AugMoney and Mindset: The Two Biggest Roadblocks to Cyber PolicingLaw enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress.DARKREADING.COM
20 AugCritical flaw patched in popular JavaScript sandbox used in AI projectsA critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If exploited, the vulnerability could allow attackers to hijack the host’s control flow, which could enable remote code execution. …CSOONLINE.COM
20 AugWhy the Annual Pentest Can’t Keep Up with Chris Wallis from IntruderChris Wallis, Founder and CEO of Intruder, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. He discusses why point-in-time pentesting is struggling to keep pace as teams ship software and attackers exploit vulnerabi…THECYBERWIRE.COMHTTPS:
20 AugThe Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman . One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making …MEDIUM.COM
📢 SECURITY ADVISORIES 11[−]
20 AugWhen companies can hack back.This week, Dave and Ben discuss how the Trump administration has dramatically changed the cybersecurity landscape after signing a new memorandum, which allows private companies to hack malicious threat actors. Additionally, the two look at the concept of "AI constitutions," and w…THECYBERWIRE.COM
20 AugHackers Using AI to Target Siemens PLCs in Critical US SectorsA cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies. The post Hackers Using AI to Target Siemens PLCs in Critical US Sectors appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugNCSC Urges Stronger Controls for Agentic AI SystemsNCSC urged sandboxing, oversight and tight access controls for autonomous AI agentsINFOSECURITY-MAGAZINE.COM
20 AugGivEnergy enters administration, batteries expose home networksTL;DR Introduction In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers’ home networks, disrupt battery operation, and potentially violate UK product securi…PENTESTPARTNERS.COM
20 AugNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsNSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic contr…SECURITYAFFAIRS.COM
20 AugAWS Network Firewall now supports rule hit countAs firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and complianc…AWS.AMAZON.COM
20 AugThe robots have gone bananas.Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassi…THECYBERWIRE.COM
🔥 INCIDENT REPORTING 14[−]
20 AugStopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal NetworkStopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites in…SECURITYAFFAIRS.COM
20 AugNew Manic Android malware can exfiltrate data through nearby devicesA new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]BLEEPINGCOMPUTER.COM
20 AugOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesThe action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugFake Gemini installer delivers Vidar infostealer via Google Colab lureA malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search res…HELPNETSECURITY.COM
20 AugAI data giant Alation confirms cyberattackThe data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.TECHCRUNCH.COM
20 AugWhy "Shady AI" is Security's Next Big Governance ProblemIn March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer…THEHACKERNEWS.COM
20 AugManic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected DevicesA new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused commun…THEHACKERNEWS.COM
20 AugOne Programmer Can Break EverythingA critical system becomes vulnerable when only one person knows how to restore or debug it. Matt Lea calls these people “lone wolf programmers” and connects the problem to the idea of a bus factor. The risk isn't just that someone leaves. People get sick, take vacation, burn out,…YOUTUBE.COM
20 AugPakistan's Transparent Tribe Refreshes Toolset for Afghan CyberattacksA nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.DARKREADING.COM
20 AugFitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacksResilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.CYBERSECURITYDIVE.COM
20 AugDetailed Timeline of OpenAI’s Cyberattack on Hugging FaceOpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.SCHNEIER.COM
20 AugHackers poison arrayref Rust crate to push infostealer malwareHackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]BLEEPINGCOMPUTER.COM
20 AugManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineManic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least…SECURITYAFFAIRS.COM
20 AugChina Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt TyphoonWIRED.COM
🕵️ THREAT INTELLIGENCE 17[−]
20 AugISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
20 AugResearchers find a loophole that lets expired credit cards make unauthorized paymentsA team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. The …HELPNETSECURITY.COM
20 AugTufin expands Unified Control Plane with AI intelligence and multi-vendor automationTufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain consistent control across increasingly complex multi-vendor, hybrid environments. As enterprise security environments continue to exp…HELPNETSECURITY.COM
20 AugUS charges 17 Iranian hackers over 31-terabyte academic data theftThe U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American universities, companies, and government agencies. The post US charges 17 Iranian hackers over 31-terabyte academi…HELPNETSECURITY.COM
20 AugUS Indicts 17 Iranians Over Years-Long Cyber Espionage CampaignThe US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Departmen…SECURITYAFFAIRS.COM
20 AugPolice Are Hiding Their Use of Flock Surveillance CamerasA usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells p…SCHNEIER.COM
20 AugOpenAI previews privacy-focused system for detecting AI misuseOpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the…HELPNETSECURITY.COM
20 Aug40 malicious Firefox extensions caught stealing crypto wallet dataSocket researchers have uncovered a network of 77 Firefox extensions tied to cryptocurrency wallet theft, credential harvesting, and deceptive software distribution. Of those, 40 were confirmed malicious, while another 37 disguised sports-score applications as unrelated browser u…CYBERINSIDER.COM
20 AugCorero brings cloud-based AI threat analysis to SmartWall ONECorero Network Security has announced AI-Augmented Cloud-Assist for SmartWall ONE, extending its automated DDoS protection with cloud-delivered AI analysis, threat intelligence, and policy optimization. As cybercriminals increasingly leverage AI to develop and evolve attack campa…HELPNETSECURITY.COM
20 AugThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiaOperation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugSurveillance – Everything You Wanted to Know, But Were Afraid to AskWe all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it. The post Surveillance – Everything You Wanted to Know, But Were Afraid to Ask appeared first on SecurityWeek .SECURITYWEEK.COM
20 AugRetail theft bill spurs ‘very large and very dangerous’ surveillance fearsThe Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop .CYBERSCOOP.COM
20 Aug‘Unprecedented’ Number of Apple Users Received Recent Spyware AlertApple customers in 110 countries received threat notifications recently alerting them to suspected spyware attacks targeting their devices. The post ‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert appeared first on The Citizen Lab .CITIZENLAB.CA
20 AugEarly 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremistKyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremis…CYBERSCOOP.COM
20 AugRussian hackers abuse WhatsApp device linking to spy on high-value targetsThree suspected Russian cyber-espionage clusters are abusing legitimate authentication features across WhatsApp, Google, and Microsoft to compromise academics, diplomats, defense personnel, researchers, and government-linked individuals. One cluster, tracked as UNC7005, has gone …CYBERINSIDER.COM
20 AugChina’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malwareSuspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.THERECORD.MEDIA
20 AugWhen Security Benchmarks Break SystemsSecurity benchmarks such as CIS Benchmarks and STIGs provide detailed recommendations for configuring systems securely. But applying every control literally can create problems, especially when those settings conflict with how a particular environment needs to operate. A benchmar…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 8[−]
20 AugUpdated ToxicPanda Variant Targets 140+ Banking and Crypto AppsZimperium lifts the lid on the ToxicPanda 2.0 Android banking TrojanINFOSECURITY-MAGAZINE.COM
20 AugToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device FraudCybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android ma…THEHACKERNEWS.COM
20 AugUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiesThe newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.TALOSINTELLIGENCE.COM
20 AugUAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsCisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromi…TALOSINTELLIGENCE.COM
20 AugYour Mac already has a built-in firewall. Here’s how to get more from itMalwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall.MALWAREBYTES.COM
20 AugJFrog Artifactory Flaws Enable Software Supply Chain AttacksTwo Artifactory flaws allowed attackers to poison package metadata across software repositoriesINFOSECURITY-MAGAZINE.COM
20 AugRust Supply Chain Attack on arrayref: Significant Overlap with DPRK CampaignsMalicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.WIZ.IO
20 AugSomeone targeted security researchers using a fake crypto conference as a lureA hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware.TECHCRUNCH.COM
📡 INFOSEC NEWS 19[−]
20 AugMicrosoft says August Windows updates may cause gaming issuesMicrosoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]BLEEPINGCOMPUTER.COM
20 AugDef Con Attendees Targeted by Persistent Phishing CampaignHuntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def ConINFOSECURITY-MAGAZINE.COM
20 AugUsing Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that …ISC.SANS.EDU
20 Aug9 million images of people’s faces exposed by reverse lookup serviceA researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.MALWAREBYTES.COM
20 AugUS says hackers are targeting vulnerable water systems with the help of AIHackers are targeting internet-connected Siemens controllers used in water facilities around the United States.TECHCRUNCH.COM
20 AugUS Defense Contractors Admit Their Rising CMMC Scores May Not Be AccurateDefense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time highINFOSECURITY-MAGAZINE.COM
20 AugCitrix urges admins to patch new NetScaler flaws as soon as possibleCitrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]BLEEPINGCOMPUTER.COM
20 AugZombie Card Attack Can Revive Expired Visa Cards for Contactless PaymentsResearchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without bre…THEHACKERNEWS.COM
20 AugUsing Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at "Risky" logins.
ISC.SANS.EDU
20 AugTwitch wants your content for Amazon AI training. Here’s how to opt outTwitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.MALWAREBYTES.COM
20 AugChatGPT for Teens tackles risky chats and homework shortcutsOpenAI has strengthened ChatGPT's protections for teens, but some of its strongest parental controls still depend on linked accounts.MALWAREBYTES.COM
20 AugHow MSPs can catch phishing attacks email filters missAI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]BLEEPINGCOMPUTER.COM
20 AugSenators press TikTok over withholding of safety features for some usersIn a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users."THERECORD.MEDIA
20 AugN-able Bug Exposes Password Vault Master KeysThe popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?DARKREADING.COM
20 AugIs Cyber missing the Marque?In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.TALOSINTELLIGENCE.COM
20 AugPresident Trump allows for private companies to hack cybercriminals.States start lawsuit against Meta.THECYBERWIRE.COM
20 AugWhat We Missed: Delta Flight Disrupted With Wi-Fi HackIn this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.DARKREADING.COM
20 AugIntelligence Insights: August 2026Debuts, departures, and danger on the blockchain in this month’s edition of Intelligence Insights.REDCANARY.COM
20 AugNew CUSTODY Framework Constrains AI Agents Inside the NetworkEnterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.DARKREADING.COM