🐛 COMMON VULNERABILITIES AND EXPOSURES 6[−]
24 Aug KEVMicrosoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnetEntra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that …CYBERSECURITYTODAY.LIBSYN.COM
24 AugCritical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any AccountRed Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, as…THEHACKERNEWS.COM
24 AugCVE-2026-65787 Desktop Window Manager Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
24 AugCVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
24 AugMetal Gear Online 3 flaw allowed code execution on players’ PCsA vulnerability in Konami’s Metal Gear Online 3 allowed malicious multiplayer lobby hosts to remotely execute arbitrary code on the computers of players joining their sessions. The flaw, tracked as CVE-2026-19874, was silently fixed earlier this month in game version 1.1.2.9. The…CYBERINSIDER.COM
⚠️ VULNERABILITY DISCLOSURE 26[−]
24 AugRansomware attackers are zeroing in on mid-market companiesMid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 13,336 incidents with known revenue and defined mid…HELPNETSECURITY.COM
24 AugAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundClaude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugUAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux RootkitCybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bo…THEHACKERNEWS.COM
24 Aug7 ways AI can be used to enhance security operationsAI has an almost unlimited number of applications, yet none may be more important than its ability to strengthen enterprise security. AI marks a new era of business transformation in which AI autonomy and innovation converge to redefine how people, processes, and technology inter…CSOONLINE.COM
24 AugSalesforce gave every org the same free scanner. Attackers already know what it misses.A defense every attacker can rehearse against isn't a defense. It's a false sense of security.CYBERSECURITYDIVE.COM
24 AugRethinking Application Security for the AI EraAs AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugCriminal Deception in Silicon ValleyInteresting paper : Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception , employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud be…SCHNEIER.COM
24 Aug KEVCISA orders urgent patching of actively exploited Zimbra flawThe Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]BLEEPINGCOMPUTER.COM
24 AugWindows Defender’s own driver can leave systems defenselessA Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level “operation engine” capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR). The technique does not …CSOONLINE.COM
24 AugCybersecurity job ads demanding AI skills double in a yearJob postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed covering 24 months, from April 2024 to March 2026, spa…HELPNETSECURITY.COM
24 AugShinyHunters provided no real proof they hacked ReliaQuest– because they didn’t get anywhere: ReliaQuestYesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/enduser/settings. ReliaQuest did not reply to DataBreaches’ ema…DATABREACHES.NET
24 AugShipping More AI Code Than You Can Secure? Watch How to Control Remediation DebtIf your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never bui…THEHACKERNEWS.COM
24 AugPersonal Information Exposed in Apollo Global Data BreachEduard Kovacs reports: Private equity giant Apollo Global Management has disclosed a data breach that exposed sensitive personal information. According to a data breach notice sent to affected individuals, a social engineering attack enabled threat actors to access some of the co…DATABREACHES.NET
24 AugGunra ransomware: what you need to knowThe ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.FORTRA.COM
24 AugSuspected Iran-linked attack knocked UK power plant offline for daysNews that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. According to sources of …HELPNETSECURITY.COM
24 AugVU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflowOverview Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitrary code on lobby members' machines through specially crafted data. Description Meta…KB.CERT.ORG
24 Aug⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreA package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks th…THEHACKERNEWS.COM
24 AugHouse Democrats ask GAO to study CISA workforce cutsFive lawmakers serving on the Homeland Security Committee said Congress didn’t know enough about the Trump administration’s changes to the cybersecurity agency.CYBERSECURITYDIVE.COM
24 AugThe Vulnerability Gap: Why Discovery Is Outrunning RepairAI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.DARKREADING.COM
24 AugFake GTA 6 Extended Look and demo sites deliver an infostealerBogus “Play Now” sites are exploiting the GTA 6 leak hype to spread malware that steals passwords stored in browsers.MALWAREBYTES.COM
24 AugIndian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderlyA Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.THERECORD.MEDIA
24 Aug“Cognizable damage” required for data breach claims, MA appeals court says in a firstChristopher R. Deubert of Constangy, Brooks, Smith & Prophete, LLP writes: Helpful guidance for businesses, and for Massachusetts state courts. In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that in a suit for damages, “the mere risk of future harm, withou…DATABREACHES.NET
24 AugAlabama launches investigation into OpenAI’s hack of Hugging FaceWeeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s Attorney General announced an investigation into the incident.TECHCRUNCH.COM
24 AugAI Found Its Own VulnerabilityThe discussion covers a vulnerability created by AI that was later exploited by AI. After Wiz identified the issue and notified Snowflake’s security team, a patch was released the same day, followed by a JIRA token rotation. AI could accelerate both sides of the security equation…YOUTUBE.COM
24 AugHackers target WordPress sites in miniOrange auth bypass attacksHackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]BLEEPINGCOMPUTER.COM
24 AugAscent Skilled Nursing Facilities Assure Breach Victims of “Credible Evidence” Stolen Data Was DeletedA DataBreaches.net Commentary On July 31, Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation, Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation, and Asheville US Seventy NC Opco LLC d/b/a Swannanoa Valley Health and Rehabilitation…DATABREACHES.NET
📋 SECURITY BULLETINS 3[−]
24 AugMicrosoft shares temporary fix for Windows 11 gaming issuesMicrosoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
24 AugAndroid car head units infected with proxy botnet malware through built-in software updatersA newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the researchers, it’s the first documented case of mal…HELPNETSECURITY.COM
24 AugMicrosoft: August updates break printing, PDF export in WPF appsMicrosoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 8[−]
24 AugCISA’s logging guidance works beyond governmentThe US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Loggin…HELPNETSECURITY.COM
24 AugUber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver AccountsDutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts appeared first on SecurityWee…SECURITYWEEK.COM
24 AugMicrosoft Teams now lets admins block external bots from meetingsMicrosoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]BLEEPINGCOMPUTER.COM
24 AugNIST Warns of Unique Security Risks in Multi-Cloud EnvironmentsNIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutionsINFOSECURITY-MAGAZINE.COM
24 AugNew Zealand to pursue social media ban for children under 16The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information…THERECORD.MEDIA
🔥 INCIDENT REPORTING 11[−]
24 AugWeekly Update 518: IoT Doorlock Nirvana with UniFiPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all …TROYHUNT.COM
24 AugReliaQuest says claimed ShinyHunters attack was successfully blockedReliaQuest says it contained a social engineering attack that briefly gave a threat actor access to a single employee identity session but did not allow access to company applications, systems, or customer data. The attacker was not identified in the company’s report, altho…CYBERINSIDER.COM
24 AugPersonal Information Exposed in Apollo Global Data BreachThe private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugASOS credential-stuffing attack exposed data of 138,828 customersASOS is notifying US customers that attackers gained unauthorized access to accounts using credentials obtained outside the company. This access potentially exposed personal, contact, and partial payment card information. According to an investigation published by Srourian Law Fi…CYBERINSIDER.COM
24 AugWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows PasswordsCybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Ste…THEHACKERNEWS.COM
24 AugSouth Korean startup platform breach exposes key management failuresA breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]BLEEPINGCOMPUTER.COM
24 Aug24th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people …RESEARCH.CHECKPOINT.COM
24 AugUK power facility disabled for days after suspected state-linked cyberattackThe disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.CYBERSECURITYDIVE.COM
24 AugReliaQuest confirms failed data-theft attack after ShinyHunters breachCybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]BLEEPINGCOMPUTER.COM
24 AugTricky 'SynkLoader' Multitool May Herald RansomwareAn advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.DARKREADING.COM
24 AugSlovakia finds Russian backdoors on traffic speed cameras.Canada's Hospital for Sick Children discloses breach. TikTok will pay $400 million to settle children's privacy case.THECYBERWIRE.COM
🕵️ THREAT INTELLIGENCE 20[−]
24 AugISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
24 AugAWS makes it easier to spot firewall rules that have gone quietAWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability covers stateful…HELPNETSECURITY.COM
24 AugFake bank websites play dead to evade security scannersA phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. The company’s threat intelligence unit, Fortra Intelligence and Resea…HELPNETSECURITY.COM
24 AugRisky Bulletin: Expired credit cards can be used for malicious transactionsExpired credit cards can be used for malicious transactions, Iranian hackers shut down a UK power plant, the Lazarus Group hacks South Korea’s Presidential Office, and an Android malware strain is infecting smart cars.RISKY.BIZ
24 AugProduct showcase: AI Paper Trail shows the privacy cost of talking to AIProton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or Claude conversation data and produces a personal privacy report showing what can be inferred from those conversations. Proton…HELPNETSECURITY.COM
24 AugDOUBLECUP's PNG Payload, (Mon, Aug 24th)New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up . It doesn&#;x26;#;39;t use real steganography:
ISC.SANS.EDU
24 AugCan employees safely use AI agents? AI pentesting agent liabilities, and the news - ESW #473Interview with Rob Allen from Threatlocker Safely enabling agentic AI for Businesses OpenClaw was the wakeup call and businesses wanted to know how to block it. “Easy,” Rob Allen said, “it’s already blocked if you’re using Threatlocker.” Now that things have settled down a bit, t…YOUTUBE.COM
24 AugIran-Linked Hackers Shut Down UK Power Plant for Four DaysThe attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks. The post Iran-Linked Hackers Shut Down UK Power Plant for Four Days appeared first on SecurityWeek…SECURITYWEEK.COM
24 AugTikTok Reaches $400 Million Settlement With US Justice Department Over Children’s PrivacyTikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. The post TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy appeared first …SECURITYWEEK.COM
24 AugVenezuelan Gets Record Federal Prison Term for ATM JackpottingJuan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek .SECURITYWEEK.COM
24 Aug91 Vulnerabilities Patched in Spring Application FrameworkMore than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugOperation QUICSILVER Targets Myanmar Government and IT with QUICAgent BackdoorCybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technolo…THEHACKERNEWS.COM
24 AugHired for One Job, Judged on Another: The CISO’s Real ProblemThe skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. The post Hired for One Job, Judged on Another: The CISO’s Real Problem appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugOne SSID To Rule Them AllTL;DR How we ended up here My colleague Adam Bromiley and I recently tripped over one of those ‘What!?’ findings. We could completely break an IT-OT segmentation without having to do … anything. We were on an OT-focused engagement, working out of a control ro…PENTESTPARTNERS.COM
24 AugWhat Happens When AI Polices AI?AI systems can potentially be used to monitor other AI systems, but that approach assumes the monitoring system will correctly identify problematic behavior. The argument here is that AI will inevitably make mistakes when making judgments about what is good, bad, or acceptable. B…YOUTUBE.COM
24 AugTikTok and ByteDance to pay $400 million to settle children’s privacy lawsuitTikTok, ByteDance, and affiliated companies have agreed to pay $400 million to settle a US Justice Department lawsuit alleging violations of federal children’s privacy law. The agreement resolves litigation brought in 2024 over TikTok’s handling of data belonging to users under 1…CYBERINSIDER.COM
24 AugMullvad overhauls Multihop with new automatic routing modesMullvad VPN has redesigned its Multihop feature with three operating modes intended to make multi-server VPN routing easier to use while avoiding connection failures caused by incompatible server settings. Announced today, the new system introduces When needed, Always, and Never …CYBERINSIDER.COM
24 AugReliaQuest Confirms ShinyHunters Hack, but Says Impact Was LimitedA ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek .SECURITYWEEK.COM
24 AugBipartisan Senate bill aims to prepare energy sector for Q-DayUnder the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector. The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop .CYBERSCOOP.COM
24 AugTreasury sanctions alleged Iranian hackers as part of ‘economic D-Day’It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 9[−]
24 AugA week in security (August 17 – August 23)A list of topics we covered in the week of August 17 to August 23 of 2026MALWAREBYTES.COM
24 AugSlovakia Warns of Cyber Risks in Road Speed CamerasSlovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a signifi…SECURITYAFFAIRS.COM
24 AugTracking PavinLoader across ClickFix and fake download campaignsWe found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware.MALWAREBYTES.COM
24 AugHackers infecting Android car systems to build proxy botnetA new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet.THERECORD.MEDIA
24 AugToxicPanda 2.0 can take over your Android phone and banking appsA new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services.MALWAREBYTES.COM
24 AugFake Codex Download Uses Google Sites to Deliver macOS MalwareFake Codex pages used Google Sites, sponsored search and ClickFix to target Mac usersINFOSECURITY-MAGAZINE.COM
24 AugToxicPanda Banking Trojan Matures into Enterprise ThreatThe latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.DARKREADING.COM
24 AugSLTT Traffic Directing to S3 Buckets Hosting KrustyLoaderThe CIS CTI team identified several MS-ISAC members directing DNS traffic to AWS S3 buckets hosting Krustyloader malware. Read its analysis.CISECURITY.ORG
24 AugCybercriminals Turn GTA VI Leaks Into Malware BaitA fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to ̶…SECURITYAFFAIRS.COM
🎙️ PODCASTS 2[−]
24 AugSponsored: Passkeys won’t stop authorisation phishingIn this Risky Business sponsored interview, James Wilson chats with Luke Jennings, Push Security’s VP of Research, about how stronger authentication is pushing attackers towards the authorisation layer. Device code phishing is on the rise. Luke explains how these attacks can surv…RISKY.BIZ
24 AugWhat happens to your data when you die? (Lock and Code S07E17)This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.MALWAREBYTES.COM
📡 INFOSEC NEWS 12[−]
24 AugResearchers Uncover Thousands of Leaked AWS KeysTruffle Security says it found over 9000 publicly accessible and active AWS key pairsINFOSECURITY-MAGAZINE.COM
24 AugTikTok Settles U.S. Child Privacy Case for $400 MillionTikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department…SECURITYAFFAIRS.COM
24 AugiAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password ResetiAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000…SECURITYAFFAIRS.COM
24 AugWake-Up Call for CNI After Iranian Attack Shuts Down UK Power PlantExperts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructureINFOSECURITY-MAGAZINE.COM
24 AugThe Outsized Shadow: Why 5% of AI Users Are Your Biggest Security RiskBig security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools…THEHACKERNEWS.COM
24 AugDoubloon Dredger Abuses Notion to Harvest Authentication TokensDoubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokensINFOSECURITY-MAGAZINE.COM
24 AugAliExpress caught using silent audio to fingerprint visitors’ browsersSilent audio processing on the AliExpress website was found helping to fingerprint visitors’ browsers without relying on cookies.MALWAREBYTES.COM
24 AugMalicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentialsEvery time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access t…BITDEFENDER.COM
24 AugFake Microsoft security scans trick victims into uninstalling their antivirusWe found fake Microsoft-branded scanners that invent security problems, tell victims to uninstall AV, and then steer them into a refund scam.MALWAREBYTES.COM
24 AugNew Guidance Helps Businesses Verify Quantum-Safe Hardware ClaimsTCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirementsINFOSECURITY-MAGAZINE.COM
24 AugTikTok reaches $400M settlement with US over COPPA violationsThe U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]BLEEPINGCOMPUTER.COM
24 AugInstinct’s powerful AI assistant is raising privacy and security concernsEarly testers are raving about what Instinct can do, but some say the AI assistant’s sweeping access, broad terms and ability to act on users’ behalf come with uncomfortable trade-offs.TECHCRUNCH.COM