🚨 CISA KEV 1[−]
21 Aug KEVU.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 16[−]
21 Aug KEVMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionMicrosoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting t…THEHACKERNEWS.COM
21 AugGitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of DisclosureA newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or …THEHACKERNEWS.COM
21 AugCitrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review…HELPNETSECURITY.COM
21 AugGitLab Warns of Active Exploitation of Critical GraphQL FlawGitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS score of 9.4). This week, GitLab pushed out an emerg…SECURITYAFFAIRS.COM
21 AugPoland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawCERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a cr…SECURITYAFFAIRS.COM
21 AugCVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-49183 Windows Clipboard Server Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-55134 Microsoft Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-68801 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-64903 Microsoft Office Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-64899 Microsoft Office Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugCVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 Aug KEVCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, A…HELPNETSECURITY.COM
21 AugCVE-2026-50466 Microsoft Brokering File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 AugVU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerabilityOverview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. Description Calix GS7 XGS GS5239XG is a residential gateway…KB.CERT.ORG
21 Aug KEVCVE-2026-69836 Microsoft Entra ID Remote Code Execution VulnerabilityCorrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only.MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 27[−]
21 Aug KEVNSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spotNSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA and FBI warn of an active campaign using AI-generated exploit tools to probe US …CYBERSECURITYTODAY.LIBSYN.COM
21 AugRisky Bulletin: US warns of AI-assisted attacks against Siemens PLCsThe US warns of AI-aided attacks against Siemens PLCs, hackers breach Latvia’s road traffic agency, a new hacking tool enrolls an attacker’s passkey to your account, and academics find source code overlaps between Geedge devices and China’s Great FirewallRISKY.BIZ
21 AugNew infosec products of the week: August 21, 2026Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP…HELPNETSECURITY.COM
21 AugA $25 template helped scammers build hundreds of phantom bank domainsA phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial se…HELPNETSECURITY.COM
21 AugNearly half of enterprises have no one leading PQC migrationEnterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source:…HELPNETSECURITY.COM
21 AugCybersecurity Job Ads Requiring AI Skills DoubleAn analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AIINFOSECURITY-MAGAZINE.COM
21 AugCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesThe Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugCl0p Targets 40+ Organizations Through PTC Windchill FlawCl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The gro…SECURITYAFFAIRS.COM
21 AugAI threats are everywhere. A risk-first CISO decides what to prioritizeThe good news? AI gives cyber defenders some of the best discovery tooling they’ve ever had. The bad news? It gives attackers the same capability. This duality has left CISOs managing AI on two simultaneous fronts. Outside the organization, attackers are using AI to make phishing…CSOONLINE.COM
21 AugRansomware takes aim at enterprise resilienceRansomware remains one of the most disruptive cyber threats organizations face. Companies have strengthened their cyber defenses over the years, but attackers in 2026 have become faster, more targeted, and increasingly reliant on AI , forcing the need for a change in how organiza…CSOONLINE.COM
21 AugMicrosoft Rolls Out 22 Fresh Security PatchesMost of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugMore Incidents of AIs Going Rogue in Cybersecurity ChallengesThe AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior —while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents…SCHNEIER.COM
21 AugBackdoored Rust packages hit crates.io, exposing developers to malware at build timeMalicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled. Security researchers at Wiz said the attack also shares infr…CSOONLINE.COM
21 AugMicrosoft warns of max severity Entra ID flaw exploited in attacksMicrosoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]BLEEPINGCOMPUTER.COM
21 AugAttackers impersonate popular AI brands to spread malwareAttackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Overview of MDR cases with AI involvement (Source: Sophos) Sophos X-Ops rev…HELPNETSECURITY.COM
21 Aug KEVCISA orders feds to patch actively exploited TrueConf Server flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]BLEEPINGCOMPUTER.COM
21 AugCritical Isolated-vm Vulnerability Leads to RCE on HostThe type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugScammers Pose as NYPD Officers in “Well-Done” Video-Call Impersonation ScamThe phone rang, and when “Eddie” (not his real name) picked up, the caller identified herself as being from American Express. Even though Eddie didn’t have any American Express account, he wasn’t initially suspicious. According to the caller, Eddie’s…DATABREACHES.NET
21 AugAI, Data Breaches, and an Old Lesson from the Law of BailmentSo I didn’t know what the doctrine of bailment is. If you don’t either, you may want to read this post by Jake L. Ramsey of Offit Kurman. It starts by noting the presentation at BlackHat by two OpenAI engineers about the Hugging Face incident and notes two of their st…DATABREACHES.NET
21 AugSix Maximum-Severity Flaws Found in Cisco ProductsCisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing int…SECURITYAFFAIRS.COM
21 AugAWS EKS forensics: data sources and investigation toolingInvestigating a compromise in Amazon EKS means piecing together evidence spread across three layers: the managed Kubernetes control plane, the worker nodes, and the surrounding AWS services. This article maps the data sources an EKS cluster exposes for digital forensics and threa…SYNACKTIV.COM
21 Aug KEVCISA warns of actively exploited TrueConf vulnerabilities.Supply chain attack compromises popular Rust library. Data giant Alation discloses a cyberattack.THECYBERWIRE.COM
21 AugMicrosoft confirms maximum severity flaw in Entra ID targeted for exploitationThe company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.CYBERSECURITYDIVE.COM
21 AugMicrosoft Defender's Own Driver Can Be Weaponized to Delete Security Software at BootCheck Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software fl…THEHACKERNEWS.COM
21 AugTroutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNsIn April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG says a recent attack was actually its second on one law firm…DATABREACHES.NET
21 AugYour Shredded Visa Card May Still Work at the CheckoutUMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa co…SECURITYAFFAIRS.COM
21 AugThe guest nobody invited.CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agent Tesla v4 campaign introduces enhanced evasion techniques. A novel malware deli…THECYBERWIRE.COM
📋 SECURITY BULLETINS 2[−]
21 AugBadBox-linked Android malware has now infected car head unitsAndroid malware is spreading through the built-in firmware update mechanism of automotive head units, turning the devices into nodes for ad fraud and a residential proxy botnet. Kaspersky reports this is the first documented malware campaign with an infection chain specifically d…CYBERINSIDER.COM
21 AugCisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswor…THEHACKERNEWS.COM
📢 SECURITY ADVISORIES 9[−]
21 AugOpenAI adds an AI safety layer to detect misuse without retaining enterprise dataOpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments. “OpenAI does not retain…pr…CSOONLINE.COM
21 AugIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused BugOther noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first …SECURITYWEEK.COM
21 AugFormer NSA Director Paul Nakasone Launches National Security Advisory FirmThe newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm a…SECURITYWEEK.COM
21 AugLawmakers call for investigation into impact of CISA staffing cutsLawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.THERECORD.MEDIA
🔥 INCIDENT REPORTING 11[−]
21 AugRust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million DownloadsThe Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affec…THEHACKERNEWS.COM
21 AugSickKids data breach exposes employee and job applicant infoToronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...…BLEEPINGCOMPUTER.COM
21 AugMedical records, SSNs, and bank details exposed in CareCloud data breachHealthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.MALWAREBYTES.COM
21 AugNorth Korean Hackers Tied to Rust Supply Chain AttackCybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacksINFOSECURITY-MAGAZINE.COM
21 AugPrivate equity firm Apollo confirms data breach amid hacking wave targeting financial giantsThe private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies.TECHCRUNCH.COM
21 AugRussian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackersThe statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform.THERECORD.MEDIA
21 AugOpenAI Adds Controls That Should've Been There AlreadyThe new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.DARKREADING.COM
21 AugCanada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolenThe Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.THERECORD.MEDIA
21 AugIs Online Privacy Possible? How Digital Identities Can HelpUsing the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity thef…BLEEPINGCOMPUTER.COM
21 AugU.S. Bank says breach claims related to fourth-party incidentThe bank said there is no evidence that its own systems, networks or data repositories were compromised.THERECORD.MEDIA
21 AugApollo discloses data breach from ongoing wave of attacks hitting financial sectorThe private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop .CYBERSCOOP.COM
🕵️ THREAT INTELLIGENCE 20[−]
21 AugSuspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack AccountsThree distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks wit…THEHACKERNEWS.COM
21 AugISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 AugGitLab 19.3 helps enterprises scale agentic development securelyGitLab has announced updates that give enterprises more control as they scale agentic software development. GitLab Dedicated customers, who already run their most sensitive software delivery workloads on GitLab, can now run GitLab Duo Agent Platform inside that same single tenant…HELPNETSECURITY.COM
21 AugContractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindTwo industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugNew SynkLoader malware uses fake Windows lock screen to steal passwordsA new malware family dubbed SynkLoader uses a fake Windows lock screen to steal users’ login passwords before giving attackers remote access to corporate networks. The modular malware combines Python, PowerShell, C#, and C++ components, with many payloads executed only in memory …CYBERINSIDER.COM
21 AugAlibaba spotted using WebAudio fingerprinting for user trackingAlibaba is facing scrutiny over its use of WebAudio fingerprinting, a browser-tracking technique that can help distinguish users by measuring subtle differences in how their devices process audio. The technique attracted attention after fingerprinting code running on Alibaba repo…CYBERINSIDER.COM
21 AugRust Supply Chain Attack Linked to North Korean HackersHackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugHackers abuse FTP server banners to deliver new Windows malwareThreat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]BLEEPINGCOMPUTER.COM
21 AugDEFCON 34: Planes, PLCs and 6am runsTL;DR A perfectly normal amount of luggage On Tuesday 4th August, 5 brave souls set off to the faraway climes of Nevada, bound for DEF CON 34. We had 9 cases of tech with us, a motley assortment of flight simulators, industrial control CTFs and plenty more.&…PENTESTPARTNERS.COM
21 AugFake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage TacticsGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three …SECURITYAFFAIRS.COM
21 AugPagers Can Still Leak Patient DataPagers are still used in healthcare, and the clip describes patient information being transmitted over a pager network. The network was described as unencrypted and operating as a broadcast medium. Legacy technology can create security exposure when organizations assume that some…YOUTUBE.COM
21 AugEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiResearchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugNew Phishing Toolkit Uses Passkeys to Maintain Access After Password ResetsResearchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek .SECURITYWEEK.COM
21 AugLawmakers seek watchdog review of federal hacking of AmericansSen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities. The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop .CYBERSCOOP.COM
21 AugDefense contractors’ CMMC confidence lags, even as self-assessments improveA “confidence disconnect” is plaguing the industry, a consulting firm said.CYBERSECURITYDIVE.COM
21 AugAI Is Learning to Write Genetic CodeThis sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacter…SCHNEIER.COM
21 AugFriday Squid Blogging: Neon Flying SquidThe neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing,…SCHNEIER.COM
21 AugSurveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able and More - SWN #609Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able, Robo-Tips, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-609YOUTUBE.COM
21 AugWhen AI Attacks Critical InfrastructureAI-assisted automated attacks can be fast and effective, creating new challenges for infrastructure operators. Much of the critical infrastructure people depend on may also operate with limited budgets, aging technology, and significant operational constraints. The danger isn't j…YOUTUBE.COM
21 AugConnecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainAttackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared f…UNIT42.PALOALTONETWORKS.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
21 AugThe invisible passenger in your carKaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.SECURELIST.COM
21 AugNew Agent Tesla Malware Variant Boosts Evasion CapabilitiesAn Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealedINFOSECURITY-MAGAZINE.COM
21 AugSenator asks US government watchdog to review how feds use hacking toolsSenator Ron Wyden sent a letter to the U.S. federal watchdog requesting a comprehensive review of how the FBI, DEA, ICE's HSI, and the Secret Service use hacking tools and spyware against Americans.TECHCRUNCH.COM
21 AugAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetCybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage download…THEHACKERNEWS.COM
21 AugNew SynkLoader malware pushed in Microsoft Teams phishing campaignA previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]BLEEPINGCOMPUTER.COM
📡 INFOSEC NEWS 10[−]
21 AugCalling on Cyber Pros to Help Defend City HallGovernment agencies with smaller budgets need support — and here's how you can help.DARKREADING.COM
21 AugEven MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
One log that really bears looking at is the log of successful and failed logins. the call for that is:
ISC.SANS.EDU
21 AugWho Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... &…ISC.SANS.EDU
21 AugWazuh and AI For Enhanced SOC WorkflowsArtificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster de…THEHACKERNEWS.COM
21 AugMicrosoft rolls out Classic Outlook theme for New Outlook usersMicrosoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]BLEEPINGCOMPUTER.COM
21 AugCalling on Cyber Pros to Help Defend City HallGovernment agencies with smaller budgets need support — and here's how you can help.DARKREADING.COM
21 AugZombie Card: An expired Visa credit card can be used for purchasesScientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.MALWAREBYTES.COM
21 AugMicrosoft blames Windows gaming issues on RGB lighting devicesMicrosoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]BLEEPINGCOMPUTER.COM
21 AugHundreds of leaked AWS keys give full control over corporate accountsMore than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]BLEEPINGCOMPUTER.COM
21 AugOWASP Flags Top AI Skill Risks in New Security BlueprintThe Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.DARKREADING.COM