🚨 CISA KEV 1[−]
25 Aug KEVU.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 14[−]
25 AugAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin AccessBad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by…THEHACKERNEWS.COM
25 Aug KEVActively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilit…THEHACKERNEWS.COM
25 AugCISA Warns of Exploited Oracle WebLogic VulnerabilityThe vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugUnpatched Zimbra servers are falling to CVE-2026-73570 attacksAt least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organization…HELPNETSECURITY.COM
25 AugNucleus wants to get ahead of scanners on new vulnerabilitiesThere usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it. Nucleus Security says it wants to close that gap. The cybersecurity outfit focused on unified exposure management is expanding its plat…CSOONLINE.COM
25 AugCVE-2026-55137 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-50448 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-61939 Winlogon Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugWordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesCVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugCVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 AugCVE-2026-70337 Microsoft PowerShell Remote Code Execution VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
25 AugCVE-2026-59127 Windows Installer Elevation of Privilege VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
25 AugVU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura ServersOverview The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v…KB.CERT.ORG
25 AugTwo CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableTwo CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both …SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 29[−]
25 AugHow Equifax is using AI to elevate its cybersecurityFor nearly a decade, Equifax has been dealing with the aftermath of one of the worst cybersecurity breaches in US history, racking up $1.4 billion on cleanup costs. Among the mistakes that led to the breach were a mismanaged patching process, an expired public-key certificate, an…CSOONLINE.COM
25 AugApplying Zero Trust Principles to Agents - Kieran Human - ASW #397Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of t…YOUTUBE.COM
25 AugSilent Patches Don’t Stop Attackers—They Blind DefendersSilent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugAI supply chain risk is showing up in developer workflows firstIn this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mo…HELPNETSECURITY.COM
25 AugHOL Guard: Open-source antivirus for AI agentsHOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 millis…HELPNETSECURITY.COM
25 AugCybersecurity jobs available right now: August 25, 2026Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency r…HELPNETSECURITY.COM
25 AugPeter Ortiz: The WWII Marine Who Foreshadowed Modern-Day Special ForcesIn 2017, journalist Katie Sanders discovered an episode of a radio program called This Is Your Life. It was a scratchy recording from 1949, and she heard the voice of 2nd Lt. Murray Simon, her grandfather, for the first time. In the episode, Murray was reunited with a man named P…THECYBERWIRE.COM
25 Aug KEVAustralia Warns of Active Exploitation of Critical TeamCity Server FlawAustralian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US governmentINFOSECURITY-MAGAZINE.COM
25 AugPolice arrests dozens of suspects in global cybercrime crackdownLaw enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]BLEEPINGCOMPUTER.COM
25 AugNew attack lets hackers plant hidden instructions in AI memory with a single promptA newly demonstrated attack technique allows hackers to plant hidden instructions inside an AI agent’s memory with a single prompt, enabling them to influence how the system responds to future queries. The technique, called InjecMEM, is described in a research paper as a “targete…CSOONLINE.COM
25 AugAI helps Chinese-speaking hackers speed up attacks on exposed serversA Chinese-speaking cybercrime group is using AI-driven tools to help compromise internet-facing Windows and Linux web servers, according to Cisco Talos, Cisco’s threat intelligence research unit. Talos said the activity points to increasingly automated offensive operations. Talos…CSOONLINE.COM
25 AugState divergence enables unauthorized accessWe found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK , that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of financial services, including on-chain tok…TRAILOFBITS.COM
25 Aug24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA PagesCybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downlo…THEHACKERNEWS.COM
25 AugFrontier AI: Vulnerability Management's Systemic RevolutionVulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. Wh…THEHACKERNEWS.COM
25 AugAnonyMousKIT service uses AI calls to unlock stolen Apple devicesA Phishing-as-a-Service (PhaaS) ecosystem dubbed AnonyMousKIT helps criminals steal Apple credentials and disable Activation Lock on stolen devices. The platform combines phishing emails, SMS, WhatsApp messages, recorded calls, and AI-powered voice agents in a credit-based servic…CYBERINSIDER.COM
25 AugHackers breached over 270 Zimbra servers in ongoing attacksThreat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]BLEEPINGCOMPUTER.COM
25 AugMarimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit ModeMarimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record…THEHACKERNEWS.COM
25 AugINTERPOL crackdown on West African crime rings uncovers troubling new trendPolice across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) Operation Jackal IV ran from …HELPNETSECURITY.COM
25 AugSeoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000This is one of those headlines where our first thought was “Uh oh!” but then we read more and thought “Hmmm…” Ko Jae-woo reports: Seoul National University Hospital has not filed a mandatory cybersecurity disclosure for years, an investigation has fo…DATABREACHES.NET
25 AugA Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawOasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker N…THEHACKERNEWS.COM
25 AugCISA orders agencies to fix exploited Zimbra vulnerabilityThe collaboration software’s developer took almost a full month to patch the flaw after disclosing it.CYBERSECURITYDIVE.COM
25 AugInside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police UnitHudson Rock’s InfoStealers has an interesting story. From their Executive Summary: In May 2023, an infostealer infected a computer belonging to the Military Police Investigation Section in Suluk, northern Syria – a unit of the Turkish-backed Syrian National Army (SNA). The …DATABREACHES.NET
25 AugHealth systems warn of coordinated phishing targeting Epic’s patient portalChad Van Alstin reports: Numerous health systems across the country have issued alerts, warning patients to ignore scam messages that are attempting to phish passwords from patients, allowing hackers to gain access to Epic Systems’ MyChart patient portal. The effort appears to be…DATABREACHES.NET
25 AugResearchers warn about chained SharePoint sequenceAn authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks. CYBERSECURITYDIVE.COM
25 AugNew Utah law protects student privacy after BYU research found K-12 apps were collecting and sharing dataSharman Gill reports: … BYU research finds that EdTech vendors don’t always meet their student privacy obligations; that research has led to new Utah legislation that tightens up the privacy issues. In an August 2025 investigation report prepared for the Utah State Board of…DATABREACHES.NET
25 AugFinding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClawAttackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.DARKREADING.COM
25 Aug2 weeks after JPS Health Network outage, patients still dealing with falloutGiles Bruce reports: Patients at Fort Worth, Texas-based JPS Health Network are facing lasting consequences from a network outage that stretched nearly two weeks, the Fort Worth Star-Telegram reported. JPS Health Network operated under a “controlled network downtime” starting Aug…DATABREACHES.NET
25 Aug‘Close Enough’ Data Breach Notifications Create ExposureVaughn Stupart, Matthew W. Van Hise, and Craig A. Hoffman of BakerHostetler write: One ruling is not a trend. And there can be unique factors at play in regulatory investigations related to large incidents. But a summary judgment ruling in favor of a state in a lawsuit against a …DATABREACHES.NET
25 AugWhat If Nobody Has Exploited It Yet?A vulnerability's current exploitation status can provide an important urgency signal, but it doesn't necessarily determine the risk it poses to an organization. Attack complexity may also be becoming a less reliable measure of practical risk as AI and nation-state capabilities b…YOUTUBE.COM
📋 SECURITY BULLETINS 2[−]
25 AugWhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security UpdateWhen Android users get a call from a non-contact, they will see more information about the caller, including their country. The post WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugMicrosoft PowerToys adds Alt+Tab-style switching for an app's windowsMicrosoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 5[−]
25 AugUS lawmakers seek investigation into impact of CISA cuts.Zimbra servers targeted in ongoing attack campaign. US Treasury Department levies sanctions on alleged Iranian hackers.THECYBERWIRE.COM
25 AugWater sector passes, government sector fails attempts to spot and halt simulated CISA attackAgency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 14[−]
25 AugReliaQuest Rejects Compromise Claims After ShinyHunters IncidentReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systemsINFOSECURITY-MAGAZINE.COM
25 AugShinyHunters taunts ReliaQuest after its own employee falls for social engineering attackCybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group ShinyHunters posted screenshot…HELPNETSECURITY.COM
25 AugThe cybercrime supply chain has five stages, each with a priceIn this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run infostealer malware, brokers wh…HELPNETSECURITY.COM
25 AugThe safety penalty: Reclaiming operational sovereignty in the age of AIAs frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.TALOSINTELLIGENCE.COM
25 AugMirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login FlowsThousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targ…THEHACKERNEWS.COM
25 AugHands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity ConferenceHands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugHospital operator Nutex Health says data stolen in cyberattackHealthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]BLEEPINGCOMPUTER.COM
25 AugThat fake Grand Theft Auto VI demo is actually just malwareGrand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.TECHCRUNCH.COM
25 AugIs Cyber Facing an Affordability Crisis?As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.DARKREADING.COM
25 AugNorway ’s Digital Government Infrastructure Hit by a new DDoS AttackNorway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupte…SECURITYAFFAIRS.COM
25 AugU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesThe U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial con…THEHACKERNEWS.COM
25 AugLACMA data breach last year exposed social security and medical dataThe Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]BLEEPINGCOMPUTER.COM
25 AugA Cautionary Tale About Data Breach Claims, Verification and CarharttPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that …TROYHUNT.COM
25 AugCarhartt - 12,933,413 breached accountsIn August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The publis…HAVEIBEENPWNED.COM
🕵️ THREAT INTELLIGENCE 27[−]
25 AugISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
25 AugThe State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic ExecutionExplore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
25 AugTaiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro StaffAI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China. The post Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugTruffleHog AWS Analyze reduces remediation time on leaked AWS credentialsTruffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise …HELPNETSECURITY.COM
25 AugNew TCG guidance gives buyers a way to test PQC-ready TPM claimsThe Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has…HELPNETSECURITY.COM
25 AugBlack Hat State of Security VendorsAndy Ellis has a roundup of the security vendors at Black Hat this year. Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, A…SCHNEIER.COM
25 AugFake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure TakedownA threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in JulyINFOSECURITY-MAGAZINE.COM
25 AugFirst Malware Built Specifically for Car Head Units Fuels BotnetKaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugE4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware CommandsCybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to p…THEHACKERNEWS.COM
25 AugFirefox moves to adopt JPEG XL with safer Rust-based decoderMozilla is preparing to enable JPEG XL support in Firefox, bringing the modern image format closer to broad browser adoption alongside AVIF. The company says its implementation relies on a new Rust-based decoder designed to reduce security risks while supporting features such as …CYBERINSIDER.COM
25 AugDuckDuckGo finds one-third of AI users share secrets they hide from peopleA DuckDuckGo survey of nearly 2,000 US adults found that 32% of people who use AI chatbots have shared information they withheld from friends, relatives, colleagues, or medical professionals. The figure rises to 56% among respondents who describe themselves as AI enthusiasts. Duc…CYBERINSIDER.COM
25 AugFake OpenAI Codex download tricks macOS users into installing malwareA malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular social engineering technique that persuades …HELPNETSECURITY.COM
25 AugCitrix UniconOS dual boot turns Windows endpoints into their own recovery deviceCitrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Available now as part of Citrix UniconOS Release 7 2607, d…HELPNETSECURITY.COM
25 AugFideo Lens reveals connections across identities, accounts and devicesFideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships among identities, accounts, devices and behaviors. Starting with a single identity signal, investigators can use Fideo Lens to…HELPNETSECURITY.COM
25 AugAI Agents Don't Respect Every BoundaryTraditional automation generally stops when a permission or policy blocks an action. An agentic system may instead interpret that restriction as an obstacle and search for another way forward. That changes the security model. An agent pursuing a legitimate goal could discover an …YOUTUBE.COM
25 AugInterpol targets Black Axe’s illicit financial web in latest international stingThe multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents. The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoo…CYBERSCOOP.COM
25 AugWhatsApp adds multiple passkeys and stronger two-step verificationWhatsApp is rolling out support for multiple passkeys, stronger two-step verification passwords, and additional information for calls from unknown numbers. The changes, announced today, are intended to make account authentication harder to compromise while giving users more conte…CYBERINSIDER.COM
25 AugAlice Raises $140M to Expand AI Model Defenses and Enterprise GuardrailsThe company, previously known as ActiveFence, has raised a total of $280 million from investors. The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugApple quietly fixes iCloud Private Relay IP leak in SafariApple has quietly fixed an iCloud Private Relay IP address leak in the public releases of iOS 26.6.1 and macOS 26.6.2. The fix appears limited to Safari, while other WebKit-based browsers using Apple’s proxy configuration APIs remain affected. Apple has not mentioned the ch…CYBERINSIDER.COM
25 AugMicrosoft Paint embeds hidden IDs in locally generated AI imagesMicrosoft Paint and Photos appear to embed an invisible, server-issued identifier into AI-generated images, including pictures created locally on Copilot+ PCs. Reverse engineering shows that while image generation can happen on-device, prompts are still sent to Microsoft for mode…CYBERINSIDER.COM
25 AugLinux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationTRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek .SECURITYWEEK.COM
25 AugThe patch window is collapsing: Why security needs a new control planeOrganizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog .AZURE.MICROSOFT.COM
25 AugArrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justiceJoshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop .CYBERSCOOP.COM
25 AugWhat Regex Can't Catch in AI SkillsAgentic skills can be packaged as Markdown files containing natural-language instructions. Traditional software-supply-chain controls such as signing, provenance, and scanning can still apply. The harder problem is understanding intent. A conventional code scanner can search for …YOUTUBE.COM
25 AugThe GTA VI leaks are breaking the internet. Security researchers have seen this before.A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop .CYBERSCOOP.COM
25 AugFibonacci, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's, Aaran Leyland - SWN #610Fibonacci and the Unhappy Number, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's battery, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-610YOUTUBE.COM
25 AugHackers abuse npm mirrors to host phishing redirect pagesThreat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]BLEEPINGCOMPUTER.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
25 AugBetween Two Nerds: Attribution is dead, long live attributionIn this edition of Between Two Nerds Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack. This episode is also available on YouTube.RISKY.BIZ
25 AugFake Minecraft Sites Are Still Spreading WeedHack After C2 TakedownWeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites an…SECURITYAFFAIRS.COM
📡 INFOSEC NEWS 23[−]
25 AugTikTok phishing: How to spot fake login and verification pagesScammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.MALWAREBYTES.COM
25 AugUS Sanctions Mabna Institute Hackers for Iranian Cyber-AttacksThe US has sanctioned individuals connected to hacking-for-hire group the Mabna InstituteINFOSECURITY-MAGAZINE.COM
25 AugGTA 6 leak hunt could expose data belonging to thousands of Discord usersTake-Two is demanding IP addresses, phone numbers, device IDs, and other data as it tries to identify whoever leaked GTA 6 footage.MALWAREBYTES.COM
25 AugThe County Prosecutors Who Became ICE InformantsIllinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.WIRED.COM
25 AugEncrypted instructions can fool AI assistants like Grok and GeminiResearchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.MALWAREBYTES.COM
25 AugLarge DDoS attack knocks Norwegian public services offlineThe Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.THERECORD.MEDIA
25 AugWhatsApp tightens account security with stronger two-step verification and moreWhatsApp’s two-step verification previously relied on a six-digit PIN, but now users can choose a longer, alphanumeric password with special characters.TECHCRUNCH.COM
25 AugUK government seeks powers to secretly block risky tech suppliersThe British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.THERECORD.MEDIA
25 AugFake Recruiter Scams Target Corporate Credentials on MobileRecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentialsINFOSECURITY-MAGAZINE.COM
25 AugWhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and AndroidMeta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion…THEHACKERNEWS.COM
25 AugFrom Fake Workers to Account Recovery: The Growing Identity Verification RiskAttackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate …BLEEPINGCOMPUTER.COM
25 AugWhatsApp adds stronger two-step verification, multiple passkeysWhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]BLEEPINGCOMPUTER.COM
25 AugApple rescues Hide My Email feature from the privacy scrap heapApple says it will no longer ditch using its icloud.com domain for hiding people's email addresses.TECHCRUNCH.COM
25 AugUkraine to give Britain access to battlefield data to train AIUkraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.THERECORD.MEDIA
25 AugZeroTokens Phishing Platform Steers Attacks in Real TimeZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brandsINFOSECURITY-MAGAZINE.COM
25 AugMassive DDoS attack disrupts Norway’s government digital servicesA large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]BLEEPINGCOMPUTER.COM
25 AugWhen the Algorithm Fires You: Uber Faces €825M FineUber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie…SECURITYAFFAIRS.COM
25 AugEmployee benefits platform Paylogix says hackers stole financial and health dataThe benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.THERECORD.MEDIA
25 Aug58 arrested in international cybercrime crackdownInterpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.THERECORD.MEDIA
25 AugAnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodesA newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]BLEEPINGCOMPUTER.COM
25 AugFast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWSThis post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Securi…AWS.AMAZON.COM
25 AugHidden Prompts Trick AI Into False Email SummariesWith some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.DARKREADING.COM