124Articles
9Categories
2026-08-26Date
🚨 CISA KEV 2[−]
26 Aug KEVU.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-…SECURITYAFFAIRS.COM
26 Aug KEVEdge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterA joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to t…TENABLE.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 7[−]
26 AugCISA Warns of Exploited Gitea VulnerabilityCVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
26 Aug KEVCritical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like PayloadThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code executio…THEHACKERNEWS.COM
26 Aug KEVCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details about …HELPNETSECURITY.COM
26 AugNemoClaw’s AI can be poisoned through a browser tabA vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research , the flaw could give attackers unauthenticated access to the server, al…CSOONLINE.COM
26 AugVMs won't contain cyber-capable agentsAs part of Patch the Planet , we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux…TRAILOFBITS.COM
26 AugUnpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run CodeThe CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026…THEHACKERNEWS.COM
26 AugCVE-2026-62890 Windows GDI+ Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 31[−]
26 AugAI vulnerability discovery scores the highest impact of 20 emerging risksRisk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk…HELPNETSECURITY.COM
26 AugHottest cybersecurity open-source tools of the month: August 2026Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an o…HELPNETSECURITY.COM
26 AugFake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA CodesCybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat…THEHACKERNEWS.COM
26 AugMeta adds three new features to keep WhatsApp accounts secureMeta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features (Source: Meta) ̶…HELPNETSECURITY.COM
26 AugWho is accountable when your AI agent goes rogue?AI agents can go to great lengths to complete the tasks their operators assign, and as a series of recent incidents showed, this can include exploiting third-party systems, manipulating people, and distributing malicious code. But AI agents are not people who can be fired, sued, …CSOONLINE.COM
26 AugInterpol's Jackal IV Disrupts West African Crime InfrastructureThe international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe.DARKREADING.COM
26 AugConnecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - BSW #462The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasing…YOUTUBE.COM
26 AugExploits and vulnerabilities in Q2 2026This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.SECURELIST.COM
26 AugClaude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in TestsAikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was f…THEHACKERNEWS.COM
26 AugGPUThor Rowhammer attack beats ECC on NVIDIA workstation GPUsUniversity of Toronto researchers have developed a new Rowhammer technique named GPUThor that can overwhelm error-correcting memory on several NVIDIA workstation GPUs, enabling crashes and even privilege escalation to root. The attack produces up to 23,500 times more bit flips th…CYBERINSIDER.COM
26 Aug KEVMicrosoft warns patch window is collapsing, urges shift to network-level containmentMicrosoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that gap…CSOONLINE.COM
26 AugHackers now exploit critical Gitea flaw in code injection attacksAttackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]BLEEPINGCOMPUTER.COM
26 AugFour in Five AI Tools Run with No IT Oversight, New Research FindsReco report reveals growing shadow AI problem and surge in vulnerability disclosuresINFOSECURITY-MAGAZINE.COM
26 AugA recommendation from the Saskatchewan Information and Privacy Commissioner caught our eyeHere’s one we missed last week. Hannah Spray reports: The personal information of more than 2,000 people was stolen from Autism Services of Saskatoon during a data breach last year. In the aftermath, the organization properly notified the affected individuals and enhanced i…DATABREACHES.NET
26 AugUpdate Chrome before you browse againChrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them.MALWAREBYTES.COM
26 AugUbiquiti patches three max severity security vulnerabilitiesUbiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]BLEEPINGCOMPUTER.COM
26 AugNational Kidney Registry allegedly hacked by DireWolf ransomware groupSince its emergence in May 2025, DireWolf has attacked several U.S. healthcare entities, as listed among its more than 100 targets on its dedicated leak site. As early analysts reporting on the group have noted, DireWolf encrypts victims’ files as part of their double-extor…DATABREACHES.NET
26 AugNovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 SessionsCybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News a…THEHACKERNEWS.COM
26 AugGTA 6 leak hype abused to distribute Vidar infostealer malwareMalicious websites impersonating Rockstar Games are exploiting interest in Grand Theft Auto VI leaks and an upcoming official preview to distribute the Vidar information stealer. The campaign uses fake “Play Now” and “Official Download” prompts that deliver a 1.1 MB executable na…CYBERINSIDER.COM
26 AugHackers target Microsoft SharePoint RCE chain with PoC exploitAttackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
26 AugStop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series , we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you…MEDIUM.COM
26 AugUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenateThe DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.THERECORD.MEDIA
26 AugDoes Exploitation Status Actually Matter?Phishing-resistant authentication can significantly reduce credential theft, but attackers can target the authentication session itself. An adversary-in-the-middle attack can relay authentication and obtain a live session. Once inside, attackers may access Microsoft 365 or Okta r…YOUTUBE.COM
26 AugDetecting multi-stage attacks on AWS: A guide to cross-service signal correlationA single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetC…AWS.AMAZON.COM
26 AugUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenateJonathan Greig reports; Chinese government hackers used tools known as “QScan” and “QTRouter” to breach multiple federal agencies since 2018, the Department of Justice said in announcing the takedown of the platforms on Wednesday. The tools were run by China-based Nanjing Xinjiuw…DATABREACHES.NET
26 AugThree 10.0 security flaws fixed across Ubiquiti’s UniFi lineThe communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher. The post Three 10.0 security flaws fixed across Ubiquiti’s UniFi line appeared first on CyberScoop .CYBERSCOOP.COM
26 AugNew GPUThor attack defeats NVIDIA ECC protection for root accessA newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]BLEEPINGCOMPUTER.COM
26 AugWhen AI infrastructure becomes the target: Securing gateways and control pointsMicrosoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first o…MICROSOFT.COM
26 AugThe feds flip the script.The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens.…THECYBERWIRE.COM
26 AugCritical Avada WordPress theme flaw enables zero-click RCEA critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]BLEEPINGCOMPUTER.COM
26 AugNSA to host a hacker reunion in bid to rebuild secretive unitMartin Matishak reports: A top U.S. spy agency will resemble a college for a while on Friday, as it hosts a first-of-its-kind reunion for alumni of its most secretive hacking unit. The National Security Agency will welcome back to campus potentially hundreds of former members of …DATABREACHES.NET
📢 SECURITY ADVISORIES 14[−]
26 AugRisky Business #850 -- Widespread AI-enabled attacks target Siemens PLCsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Ollie Whitehouse, the CTO of the UK’s NCSC, to talk through the week’s news, including: Iranian hackers take down a small-scale power generator in the UK Siemens PLCs in critical US sectors are also bei…RISKY.BIZ
26 AugLinux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agentsThe Linux Foundation announced the contribution of TRACE (Trust, Runtime Attestation and Compliance Evidence), from OPAQUE. Collaboratively developed by AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute (TII), TRACE creates a standard, open evidence layer that…HELPNETSECURITY.COM
26 AugLinux Foundation Introduces TRACE Standard for AI Runtime EvidenceThis new open standard offers hardware-attested runtime and compliance evidence for AI agentsINFOSECURITY-MAGAZINE.COM
26 AugCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksThe agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugCISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected NothingThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different de…THEHACKERNEWS.COM
26 AugCISA confirms hackers targeted over 100 US water systems during JulyThe federal cyber agency's warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States.TECHCRUNCH.COM
26 AugWho Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"&#;x26;#;x3f;&#;x26;#;xc2;&#;x26;#;xa0; Who can delete or change key things, or mo…ISC.SANS.EDU
26 AugCyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructureThe order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop .CYBERSCOOP.COM
26 AugCISA Red Team Fully Compromised Two Critical Infrastructure OrgsCISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organ…SECURITYAFFAIRS.COM
🔥 INCIDENT REPORTING 15[−]
26 AugIranian hackers darken UK power plant, ShinyHunters breaches the threat hunters, Zombie Visa cardsIran-Linked Cyberattack Hits UK Power Facility, ShinyHunters Phish ReliaQuest, LockBit Claims US Bancorp, Teams Blocks Bots, Expired Visa Card Flaw Cyber Security Today host David Shipley reports a UK power facility was taken offline for four days in July by a cyberattack linked …CYBERSECURITYTODAY.LIBSYN.COM
26 AugJADEPUFFER: An End-to-End Agentic-Led Ransomware AttackIn this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss ⁠JADEPUFFER⁠, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direc…THECYBERWIRE.COM
26 AugSensitive Information Exposed in Nutex Health Data BreachNutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration. The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
26 Aug88 ID Verification Breaches Show the Cost of Collecting Identity Data88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s ide…SECURITYAFFAIRS.COM
26 AugChoose your fighter: Balancing competing requirements to select models for your AI SOCSelecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.TALOSINTELLIGENCE.COM
26 AugWhat If Ransomware Never Encrypts Anything?Ransomware is no longer just about encrypting files and demanding payment for decryption keys. Attackers may instead focus on disrupting a critical service because they know the victim has strong incentives to restore operations quickly. Service disruption can create consequences…YOUTUBE.COM
26 AugBoston Scientific says cyberattack disrupted order processing, shippingThe medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week.CYBERSECURITYDIVE.COM
26 AugUS disrupts Chinese hacking campaign that breached NASA, the DOJ, the DOE, the Senate, and others.Meta settles children's safety lawsuits for $16.68 billion. Business news: AI security firm Alice raises $140 million.THECYBERWIRE.COM
26 AugBoston Scientific says cyberattack disrupted operations globallyMedical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]BLEEPINGCOMPUTER.COM
26 AugUS seizes domains of Chinese botnet used to hack NASA, Justice Department, and the SenateThe FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments.TECHCRUNCH.COM
26 AugFBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical InfrastructureFBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical i…SECURITYAFFAIRS.COM
26 AugMedical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operationsThe company won't say if medical devices are affected or if any customer data was exfiltrated.TECHCRUNCH.COM
26 AugOpenAI: Agent behavior that led to Hugging Face intrusion formed in MayThe company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first o…CYBERSCOOP.COM
26 AugMedical device firm Boston Scientific says cyberattack has disrupted shipment processesThe company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.THERECORD.MEDIA
26 AugWhat If Your Vendor Goes Down?Third-party risk depends on more than the likelihood that a vendor experiences an incident. Organizations also need to understand their exposure: the data involved, the number of records affected, and the potential business impact. A major technology provider can create consequen…YOUTUBE.COM
🕵️ THREAT INTELLIGENCE 23[−]
26 AugISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
26 AugProduction data in testing is still common, and Tricentis’ CISO wants it goneIn this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for …HELPNETSECURITY.COM
26 AugChrome 152 Patches Over 300 VulnerabilitiesMost of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugRightCrowd Pass unifies mobile, physical, and biometric credentialsRightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometr…HELPNETSECURITY.COM
26 AugBogus recruiters go after high-value corporate credentials on mobileScammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on rec…HELPNETSECURITY.COM
26 AugEstate planning of credentialsA sad start Last year one of my colleagues, Ken, received the sad news that a father of a friend had passed away. He was a tech-savvy gentleman and had invested in smart tech to make his and his family’s life easier and, just as we recommen…PENTESTPARTNERS.COM
26 AugTutaCrypt post-quantum email encryption passes security analysisResearchers at the University of Wuppertal have analyzed TutaCrypt, the hybrid encryption protocol used by Tuta Mail to protect email against both conventional and future quantum-computing attacks. Their paper concludes that the protocol provides meaningful post-quantum confident…CYBERINSIDER.COM
26 AugThe MFA Identity Trap: When Authentication Creates a False Sense of SecurityOrganizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. The post The MFA Identity Trap: When Authentication Creates a False Sense of Security appeared first on SecurityWe…SECURITYWEEK.COM
26 AugSpyware for BabiesThe New York Times has a long article ( alt link ) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the b…SCHNEIER.COM
26 AugTreasury to help financial firms transition to quantum-resistant encryptionThe government is concerned that hackers someday will be able to decrypt financial information and other secrets using code-breaking quantum computers.CYBERSECURITYDIVE.COM
26 AugAdobe and Nvidia Patch Dozens of VulnerabilitiesAdobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesA phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a…HELPNETSECURITY.COM
26 AugElection official says Tina Peters would be consultant, won’t have access to election systemsShasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction. The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first …CYBERSCOOP.COM
26 AugFBI disrupts proxy network enabling Chinese espionage operationsThe FBI has disrupted infrastructure associated with a technical "quartermaster" that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. [...]BLEEPINGCOMPUTER.COM
26 AugAI Infra Summit 2026The post AI Infra Summit 2026 appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
26 AugMeta agrees to $17.1 billion settlement over alleged harms to childrenMeta has agreed to pay up to $17.1 billion and make sweeping changes to Facebook and Instagram under a proposed multistate settlement resolving claims that its platforms harmed children and teenagers and misled the public about those risks. The agreement, announced today by a bip…CYBERINSIDER.COM
26 AugAI Speeds Up Malware Development, Not Its Success Rate: AnalysisPalo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek .SECURITYWEEK.COM
26 AugFBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. OrganizationsThe U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chin…THEHACKERNEWS.COM
26 AugNimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH TunnelerCybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published t…THEHACKERNEWS.COM
26 AugAndroid Malware Hijacks Update System for Car Head UnitsThreat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.DARKREADING.COM
26 AugOfficials disrupt Chinese espionage operation that hit multiple federal agenciesThe full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years. The post Officials disrupt Chinese espionage operation that hit multiple federal agencies appeared first on CyberS…CYBERSCOOP.COM
26 AugRed Flags That Expose Fake North Korean IT WorkersNorth Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.DARKREADING.COM
26 AugDark Caracal Adds New Malware to Cyber Espionage ArsenalGoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.DARKREADING.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
26 AugRisky Bulletin: Russia starts blocking DoH and DoTRussia begins blocking the DoH and DoT protocols, Russian hacktivists leak Spanish police and military personnel data, China and South Korea detain a vishing gang, and AI malware is not that common.RISKY.BIZ
26 AugNewly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own BytecodeAn independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.…THEHACKERNEWS.COM
26 AugBeware of fake Indeed interview apps used to install spywareScammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.MALWAREBYTES.COM
26 AugTortoiseshell Expands Malware Toolset With New Backdoor, SSH TunnelGroup-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling toolINFOSECURITY-MAGAZINE.COM
26 AugThe Hidden Attack Surface Inside Data CentersStephen Hilt, Senior Threat Researcher at TrendAI, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices recorded at Black Hat USA 2026. Drawing on research presented at DEF CON, he discusses thousands of internet-exposed industrial control systems ass…THECYBERWIRE.COMHTTPS:
🎙️ PODCASTS 1[−]
26 AugSmashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrencyA hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a …GRAHAMCLULEY.COM
📡 INFOSEC NEWS 26[−]
26 AugWeekly Threat Bulletin – August 26th, 2026These are the top threats you should know about this week.F5.COM
26 AugHow Check Point Built a Cybersecurity Arcade Game in Under a Month with Gemma GoldsteinGemma Goldstein had a quiet Thursday in the office, a domain someone spotted for sale, and an idea. A few short weeks later, Check Point's Exposure Management team had a browser-based arcade game live at exposuremanagement.ai with 11,000 players and a leaderboard. The game launch…THECYBERWIRE.COM
26 AugNigeria Looks to Sovereign Cloud for Cyber, National SecurityThe West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.DARKREADING.COM
26 AugOperation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global ScamsINTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African o…SECURITYAFFAIRS.COM
26 AugINTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud CrackdownAn eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by …THEHACKERNEWS.COM
26 AugWhatsApp Adds Stronger Security as Passkeys Hit 1 BillionWhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. …SECURITYAFFAIRS.COM
26 AugDDoS Attack Hits Norwegian Government ServicesA coordinated DDoS campaign has caused disruption among Norwegian government servicesINFOSECURITY-MAGAZINE.COM
26 AugOpenAI Bans Russian ChatGPT Accounts Used to Run Influence OperationOpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Tele…THEHACKERNEWS.COM
26 AugImagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis EngineThe SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity s…THEHACKERNEWS.COM
26 AugAverage Cyber Insurance Losses Increase Despite Fewer ClaimsChubb reported that growing privacy litigation has contributed to surging cyber claim costs in the USINFOSECURITY-MAGAZINE.COM
26 AugPopular school apps may be sharing student data with advertisersA Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.MALWAREBYTES.COM
26 AugMicrosoft tests new privacy controls for Windows 11 desktop appsMicrosoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. [...]BLEEPINGCOMPUTER.COM
26 AugInterpol Operation Jackal IV Identifies 263 Cybercrime SuspectsInterpol operation leads to 58 arrests and identifies 263 suspects across 22 countriesINFOSECURITY-MAGAZINE.COM
26 Aug'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a MonthThe adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.DARKREADING.COM
26 AugSnowflake ends service-account passwords. Now comes the hard partSnowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. [...]BLEEPINGCOMPUTER.COM
26 AugIran-linked hackers expand infrastructure across Europe and Middle East, report saysResearchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group.THERECORD.MEDIA
26 AugThe State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker OpportunitiesWiz Research telemetry reveals why the majority of high-severity findings lack a path to compromiseWIZ.IO
26 AugMeta agrees to $18 billion settlement over teen social media harmsMeta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]BLEEPINGCOMPUTER.COM
26 AugFBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and InfrastructureChina’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.WIRED.COM
26 AugDemocratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service CatalogHow the Wiz Cloud Cost automates cost allocation to power developer-led cost optimization and connect cost to business value.WIZ.IO
26 AugMeta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media caseA multibillion-dollar settlement with attorneys general from nearly every U.S. state and territory will mean new privacy and safety protections in Meta products.THERECORD.MEDIA
26 AugICYMI: July 2026 @AWS SecurityIf you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blo…AWS.AMAZON.COM
26 AugAI safety and security company Alice raises $140 million.Munich Re Group has agreed to acquire San Francisco-based At-Bay for $575 millionTHECYBERWIRE.COM
26 AugOpenAI’s Hugging Face Hack Debrief Raises More Questions Than It AnswersThe AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.WIRED.COM
26 AugCIS and SANS: A Longstanding Partnership Built to Advance CybersecurityCIS and SANS extend decades of partnership with a new AWS Marketplace offering that combines secure cloud infrastructure and expert training.CISECURITY.ORG
26 AugExclusive: NSA to host a hacker reunion in bid to rebuild secretive unitThe National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding.THERECORD.MEDIA