18Articles
7Categories
2026-08-22Date
🚨 CISA KEV 1[−]
22 Aug KEVU.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 …SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 6[−]
22 AugAI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoningHow AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—former U.S. Marine with experience at Cyber Command, NSA, and the intelligence commun…CYBERSECURITYTODAY.LIBSYN.COM
22 AugCitrix urges immediate patching of two newly disclosed vulnerabilities.Supply chain attack compromises popular Rust library. US states sue Meta over claims that it deliberately addicts young users.THECYBERWIRE.COM
22 AugGolf Canada - 568,972 breached accountsIn mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postco…HAVEIBEENPWNED.COM
22 AugCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionA critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, n…SECURITYAFFAIRS.COM
22 AugYour Expired Visa Card Could Be ‘Zombified’ to Make Contactless PaymentsPlus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.WIRED.COM
22 AugConnecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this yearWSFB reports: State officials say a data breach involving the Connecticut Medicaid program’s provider portal exposed payment and claims information tied to roughly 41,000 HUSKY Health members. The Connecticut Department of Social Services said Gainwell Technologies, which serves …DATABREACHES.NET
📢 SECURITY ADVISORIES 1[−]
22 AugPostal Service moves to finalize mail ballot regs before SCOTUS rulingThe rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 1[−]
22 AugHackers infect Android car head units with proxy botnet malwareA supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 3[−]
22 AugA RAT in the spreadsheet.Today we are joined by ⁠Aaron Beardslee⁠, Manager of Threat Research at ⁠Securonix⁠, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using …THECYBERWIRE.COM
22 AugBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightThe spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek .SECURITYWEEK.COM
22 AugWe Hate Surveillance Until We Need ItModern life is surrounded by cameras and sensors, from dash cams and traffic cameras to phones and home security systems. People often dislike being surveilled, but that attitude can change quickly when footage could identify someone responsible for an accident or crime. Surveill…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
22 Aug14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates …THEHACKERNEWS.COM
22 AugMalware Hijacks Android Car Head UnitsMalware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any …SECURITYAFFAIRS.COM
📡 INFOSEC NEWS 4[−]
22 AugNamed Pipes Under Attack: Securing Windows Interprocess CommunicationWindows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help se…BLEEPINGCOMPUTER.COM
22 AugTikTok Agrees to $400 Million Settlement in U.S. Child Privacy LawsuitThe U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million imme…THEHACKERNEWS.COM
22 AugFrontier AI labs still won’t say how they’d contain a rogue modelA new study finds leading AI labs have few publicly documented plans for containing rogue models, raising questions about preparedness as AI systems increasingly demonstrate unexpected and potentially dangerous behavior.TECHCRUNCH.COM
22 AugToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 CountriesToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team jus…SECURITYAFFAIRS.COM