🚨 CISA KEV 2[−]
27 Aug KEVCISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server BugsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exp…THEHACKERNEWS.COM
27 Aug KEVCISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix ProductsCISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wildINFOSECURITY-MAGAZINE.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 9[−]
27 Aug KEVRecent Citrix NetScaler Vulnerability Exploited in the WildCISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
27 Aug KEVPreviously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August 26 and gave feder…HELPNETSECURITY.COM
27 AugCVE-2026-69550 Windows App for Mac Information Disclosure VulnerabilityUpdated CWE value. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-50435 Windows Overlay Filter Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-65779 Windows Autopilot Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-68817 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugCVE-2026-42993 Remote Desktop Client Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
27 AugNext.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCECredit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traver…THEHACKERNEWS.COM
⚠️ VULNERABILITY DISCLOSURE 39[−]
27 Aug400 episodes and we still have trust issues.This week, we’re celebrating a pretty big milestone: 400 episodes of Hacking Humans! Along the way, we’ve shared hundreds of stories, scams, lessons, and plenty of memorable Catch of the Days—and we couldn’t have made it this far without you. To everyone who has listened, written…THECYBERWIRE.COM
27 AugAI will not fix a governance problem in your camera estateCamera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials…HELPNETSECURITY.COM
27 AugNew GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root AccessAcademic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root she…THEHACKERNEWS.COM
27 AugCritical infrastructure’s long, undefended tail exposed by UK energy attackA cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed. But the incident illustrates a consequential …CSOONLINE.COM
27 AugOpenAI says AI agents formed a ‘swarm’ before breaching Hugging FaceOpenAI has published a detailed post-mortem of July’s Hugging Face breach, revealing that its AI agents did far more than escape a cybersecurity sandbox. The models created an unauthorized communication network, shared exploits and credentials, coordinated attacks across separate…CYBERINSIDER.COM
27 AugATF confirms “major incident” after recent Qilin breach claimsATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]BLEEPINGCOMPUTER.COM
27 AugLLM-Based Social Engineering ScamsOpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before i…SCHNEIER.COM
27 Aug KEVCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayCISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]BLEEPINGCOMPUTER.COM
27 AugUS Navy tells sailors and their families: scrub your social media, enemies are watchingThe US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at h…BITDEFENDER.COM
27 AugSignal flaws allowed rogue servers to decrypt users’ contact queriesSecurity researchers at V12 discovered two critical vulnerabilities in Signal’s Contact Discovery Service that could allow a malicious server operator to escape the protections of its Intel SGX enclave. The flaws enabled arbitrary reading of protected enclave memory and, in the m…CYBERINSIDER.COM
27 AugTwo Alleged ‘TeamPCP’ Hackers Arrested in AustraliaAuthorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (…KREBSONSECURITY.COM
27 AugSpark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security ToolsIndividuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These in…THEHACKERNEWS.COM
27 AugAI can be made to read an email much differently than you doSecurity researchers are claiming it is possible for users to see one email in their inbox while their AI assistant reads another. Forcepoint X-Labs has demonstrated how a few lines of invisible HTML can be planted into an email that an AI email summarizer picks up and runs as in…CSOONLINE.COM
27 AugChinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI WarnsThe FBI advisory set out QTFY’s distributed hacking ecosystem, allowing it to exploit vulnerabilities at scale and obfuscate its activitiesINFOSECURITY-MAGAZINE.COM
27 AugUnknown PaperCut NG/MF vulnerability is under active attackA yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the…HELPNETSECURITY.COM
27 AugLearn How to Build Security Operations Ready for AI-Powered AttacksSecurity teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditiona…THEHACKERNEWS.COM
27 AugAlleged TeamPCP Hackers Charged in Australia Over Major Supply Chain AttacksThe Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gatew…THEHACKERNEWS.COM
27 AugWebinar: How Google Workspace breaches happen and what to do nextGoogle Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines real-world breaches, what happens during the critical first hours, and the security controls that can make the greatest diff…BLEEPINGCOMPUTER.COM
27 AugTwo Alleged ‘TeamPCP’ Hackers Arrested in AustraliaBrian Krebs reports: Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Austra…DATABREACHES.NET
27 AugManchester Airports Group suffers data breach exposing customer dataManchester Airports Group (MAG) has disclosed a cybersecurity incident in which an unauthorized third party obtained customer information linked to airport parking, lounge, Fast Track, and Wi-Fi services. The company says payment information was not exposed and airport operations…CYBERINSIDER.COM
27 AugAmazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro PowersCybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which do…THEHACKERNEWS.COM
27 AugAustralian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and othersThe arrests come after a wave of cyberattacks earlier this year targeting tech companies that rely on high-profile and widely used open source software.TECHCRUNCH.COM
27 AugHow to build an exposure management program the business trusts: Lessons from Tenable’s CSODiscover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that t…TENABLE.COM
27 AugTwo alleged TeamPCP hackers arrested over global supply chain attacksTwo men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. The Australian Federal Police (AFP), working with the…HELPNETSECURITY.COM
27 AugIdentity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNsIntroduction Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and impos…RAPID7.COM
27 AugAustralian Police Charge Two Over TeamPCP Credential TheftAustralian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious cod…SECURITYAFFAIRS.COM
27 AugOpenClaw went viral. Meet the maintainers building and securing it.OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog .GITHUB.BLOG
27 AugManchester Airports Group confirms cyber attack exposed customer emails, phone numbers and vehicle detailsGabriel Higgins reports: Manchester Airports Group (MAG) has confirmed that it has been the target of a cybersecurity incident carried out by an unauthorised third party, resulting in the exposure of a quantity of customer data. The group operates Manchester, London Stansted and …DATABREACHES.NET
27 AugThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New StoriesA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting…THEHACKERNEWS.COM
27 AugPaperCut warns of NG, MF flaw exploited in zero-day attacksPaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
27 AugManchester Airports Group says hackers stole travelers' dataThe Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]BLEEPINGCOMPUTER.COM
27 AugQilin claimed they attacked the ATF. Here’s what the ATF says.As many people have heard by now, the Qilin ransomware group claimed to have attacked the ATF. As is their regular practice, they provided no proof of their claims. Today, the ATF has issued a statement that sheds light on the incident and what ATF has found so far: WASHINGTON …DATABREACHES.NET
27 AugSwarm of 700 AI bots went rogue in hacking attackJames Titcomb reports: A swarm of 700 OpenAI bots conspired in a cyber attack last month, an investigation has revealed, in what the AI giant called a “warning shot” to the world. Independent researchers found that hundreds of AI bots worked together to attack the technology comp…DATABREACHES.NET
27 AugInside 90 days of attacks on AI infrastructureWiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.WIZ.IO
27 Aug“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friendIn his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.TALOSINTELLIGENCE.COM
27 AugAgentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.DARKREADING.COM
27 AugWhite House bans foreign-made equipment for power generation over cyber backdoor concernsThe Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.THERECORD.MEDIA
27 AugHacking All The Devices, with AI? - Rob Allen - PSW #941Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about …YOUTUBE.COM
27 AugSIEM: Centralize Like You Mean It, Federate Like You Have To(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?” — an admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earli…MEDIUM.COM
📢 SECURITY ADVISORIES 7[−]
27 AugFBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. SenateThe Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years. The tools, known as QScan and QTRouter, were developed by a …HELPNETSECURITY.COM
27 AugCISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers DoCISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July 2026, and CISA’s r…SECURITYAFFAIRS.COM
27 AugTrump Order Aims to Block Foreign Backdoors in US Power Grid GearThe White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns. The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugAustralian police arrest two suspected TeamPCP members.CISA says more than 100 water and wastewater systems were targeted in cyberattacks in July. UK airports disclose breach.THECYBERWIRE.COM
🔥 INCIDENT REPORTING 20[−]
27 AugProton suffers major data center outage, says no user data was lostProton experienced a global service outage earlier today after a critical cooling failure hit one of its data centers in Frankfurt, disrupting access to Proton Mail and other services. The company says services have since been restored and that no user data was lost during the in…CYBERINSIDER.COM
27 AugBoston Scientific Reveals Global Disruption After Cyber IncidentMedTech giant Boston Scientific has revealed IT outages following a cyber incidentINFOSECURITY-MAGAZINE.COM
27 AugOpenAI: Hugging Face Incident a “Warning Shot” to the WorldOpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breachINFOSECURITY-MAGAZINE.COM
27 AugPro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital ServicesThe pro-Russian hacker group Server Killers claimed responsibility for the attack. The post Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugThreat landscape for industrial automation systems. Q2 2026The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.SECURELIST.COM
27 AugCyberattack Causes Global Disruption at Boston ScientificThe cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders. The post Cyberattack Causes Global Disruption at Boston Scientific appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugCarhartt data breach exposes information of 12.9 million accountsThe ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]BLEEPINGCOMPUTER.COM
27 AugCyberattack causes network outage at Boston Scientific, disrupts global operationsMedical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations. Boston Scientific makes devices for minimally invasive procedures, including stents, catheters, pacemakers and defibrillator…HELPNETSECURITY.COM
27 AugVersion Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOpsA practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.WIZ.IO
27 AugDOJ firearms agency says hackers breached system containing investigation targetsThe Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried out the breach.THERECORD.MEDIA
27 AugManchester Airports Group Hit by Cyber IncidentCustomer data linked to bookings and airport Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorized third partyINFOSECURITY-MAGAZINE.COM
27 AugHere’s all the times AI has gone rogue and hacked other companiesA recap of all the incidents involving LLMs made by Anthropic, Meta, and OpenAI, which went rogue and attacked real companies and individuals on the internet.TECHCRUNCH.COM
27 AugCyberattack on Manchester Airports Group exposes data of 8.7 million customersA spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an email address.THERECORD.MEDIA
27 AugChinese and Russian spies stepping up cyberattacks, German companies reportForeign intelligence services, particularly those from China and Russia, are increasingly behind cyberattacks on German companies, according to a new survey of the country’s private sector.THERECORD.MEDIA
27 AugFederal authorities disrupt China-backed hacking operation targeting US critical infrastructureCompromised IoT devices were used in a yearslong campaign against key sectors and U.S. government agencies.CYBERSECURITYDIVE.COM
27 AugFlock wants privacy to meet surveillance halfwayFlock’s CEO wants a compromise between privacy and public safety, but the public has already compromised enough.MALWAREBYTES.COM
27 AugHundreds of agents went rogue in lead up to Hugging Face breachOpenAI released a technical breakdown of the historic incident and plans changes to prevent such an occurrence from happening again. CYBERSECURITYDIVE.COM
27 AugATF declares ‘major incident’ as ransomware gang claims hackThe ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity.TECHCRUNCH.COM
27 AugMeta gets a Meta-sized bill.Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock down social media. The FBI warns of a prolific Chinese hacking operation. Bill Gat…THECYBERWIRE.COM
27 AugLegitimate Tools Became Attack ToolsA ransomware attack against a hospital was stopped after attackers attempted to install three legitimate remote-access tools. The tools themselves weren't malware, but they were being used as part of the attack chain. Stopping the ransomware payload wasn't what prevented the atta…YOUTUBE.COM
🕵️ THREAT INTELLIGENCE 21[−]
27 AugISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
27 AugThe best human hacking team still out-solved the best AI teamBring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed up in 17 of the Top 25 finishers. The people who least needed help were the ones who brought it. The peop…HELPNETSECURITY.COM
27 AugSrsly Risky Biz: China's AI-Enabled APT Operations Are Getting InterestingTom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arsenal. This will make it harder for threat intel firms to cluster activity for attribution. They also discuss the US disrupting Iranian hackers …RISKY.BIZ
27 AugAbnormal AI expands email security from detection to data protection and phishing-simulation trainingAbnormal AI announced an expansion of its email security platform with three new capabilities: Control Center, Email DLP Rules, and AI Phishing Coach upgrades. Together, the launch extends Abnormal’s behavioral AI across all three surfaces of email risk: what comes into the inbox…HELPNETSECURITY.COM
27 AugUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksThe operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugGoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 AddressThreat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell…THEHACKERNEWS.COM
27 AugThe Future of AI-Driven Security Depends on Complete DataFor twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. The post The Future of AI-Driven Security Depends on Complete Data appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackNew training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels. The post OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityThe identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities. The post Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security appeared first on Secur…SECURITYWEEK.COM
27 AugCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteSecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader. The post CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugRussian Hackers Phish EU Officials Over Messaging AppsEU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.DARKREADING.COM
27 AugRing adds rotating video keys and 24-hour deletion with new TAKE systemRing has announced a new video encryption system called Throw Away the Key Encryption (TAKE) that will eventually become the default for all customers worldwide. The system limits how long Ring retains the encryption keys needed to process recordings while preserving cloud-based …CYBERINSIDER.COM
27 AugAustralia Arrests 2 Alleged TeamPCP HackersAustralian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison. The post Australia Arrests 2 Alleged TeamPCP Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
27 AugHow Threat Research and MDR Help SMBs Build a Defensive EdgeThreat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses. [...…BLEEPINGCOMPUTER.COM
27 AugCybercrime Just Got Much FasterInternet-based crime can operate across borders at enormous speed and scale. Matt Lea says major clients are seeing unprecedented levels of bot traffic. The challenge isn't simply blocking malicious traffic. Defenders have to determine whether massive volumes of requests are legi…YOUTUBE.COM
27 AugTwo alleged TeamPCP members arrested and charged after months of software supply-chain chaosThe two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile. The post Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos appeared first on CyberScoop .CYBERSCOOP.COM
27 AugWhat’s new in Microsoft Security: August 2026This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post What’s new in Microsoft Security: August 2026 a…MICROSOFT.COM
27 AugFormer sexual abuse victims say Grok used their images, videos to train deepfake capabilitiesElon Musk claimed he was aware of “literally zero” CSAM content created through Grok. A new lawsuit from thousands of real victims say the model was trained on their child abuse. The post Former sexual abuse victims say Grok used their images, videos to train deepfake capabilitie…CYBERSCOOP.COM
27 AugUnit 42 warns AI has shifted balance of power from defenders to attackersPalo Alto Networks’ threat intelligence team said the early waves of threats riding on agentic AI models have broken in the wild, and organizations are unprepared for what’s coming next. The post Unit 42 warns AI has shifted balance of power from defenders to attackers appeared f…CYBERSCOOP.COM
27 Aug100-plus companies call for ‘global surge’ in AI-powered cyber defenseOpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophisticated. The post 100-plus companies call for ‘global surge’ in AI-powered cyber defense appeared first on CyberScoop .CYBERSCOOP.COM
27 AugDark Caracal Deploys New Go Malware With Ethereum-Based C2 FallbackDark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communication…SECURITYAFFAIRS.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
27 AugBoardroom Battles 2026: ASD’s Cyber Priorities & AI RiskThe Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.HUNTRESS.COM
27 AugJavaScript obfuscation: From party trick to phishing kitLearn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.TALOSINTELLIGENCE.COM
27 AugWhat the Data Says About AI in Security Operations in 2026AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4…THEHACKERNEWS.COM
27 AugAustralia arrests alleged TeamPCP hackers behind supply-chain attacksAustralian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks. [...]BLEEPINGCOMPUTER.COM
27 AugChinese Routers Sold Worldwide Contain BackdoorsAn untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.DARKREADING.COM
📡 INFOSEC NEWS 18[−]
27 AugWhat does hospital downtime teach us about building AI-native organizations?Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it. Zach Evans, Chief Technology Officer at Xsolis, has a simple test for telling the difference: strip…THECYBERWIRE.COM
27 AugBreaking big tech's hold.This week, Dave and Ben look at California's latest effort to restrict social media companies further by banning design features that are considered harmful to minors. Additionally, the two discuss recent calls on the Maryland government to investigate data brokers which could be…THECYBERWIRE.COM
27 AugOpenAI banned Russian ChatGPT accounts backing covert influence operationOpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro‑Russia narratives. OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were used to support a covert influ…SECURITYAFFAIRS.COM
27 AugMeta to Pay Up to $18B Over Teen Social Media UseMeta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that…SECURITYAFFAIRS.COM
27 AugA polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
ISC.SANS.EDU
27 AugNew Instagram and Facebook rules set a default two-hour limit for teensMeta will pay up to $17 billion and introduce new protections for US teens to settle a landmark child safety case.MALWAREBYTES.COM
27 AugBack to the Future: Why Agentic AI Needs a Strong Identity FoundationAs AI matures, enterprises and customers are rapidly deploying agents seeking to unlock the next level of automation and productivity. Agentic AI shows potential to handle a multitude of use cases, from buying personal items on Amazon to customer service applications to enterpris…NIST.GOV
27 AugFake Apple Pay charge brings the classic tech support scam to your phoneBuilt for mobile users, this tech support scam uses a fake Apple Pay alert and browser tricks to pressure victims into calling a scam number.MALWAREBYTES.COM
27 AugAustralia charges two men for TeamPCP supply-chain hacking spreeTwo men in Australia were charged Wednesday over their alleged membership in TeamPCP, the cybercrime group blamed for one of the most damaging hacking campaigns of the past year.THERECORD.MEDIA
27 AugMicrosoft rolls out fix for Windows 11 crashes, gaming issuesMicrosoft has started rolling out a permanent fix for a known issue that causes system crashes and gaming issues on Windows 11 devices. [...]BLEEPINGCOMPUTER.COM
27 AugAndroid 17 adds ECH support to make web browsing harder to trackGoogle is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks. [...]BLEEPINGCOMPUTER.COM
27 AugFake listings can turn trusted platforms into scam springboardsA trusted name on a trusted platform does not guarantee a trustworthy listing. It could still lead to a tech support scammer.MALWAREBYTES.COM
27 AugFinland appeals court revives case against Eagle S Officers over cable breaksThe appeals court sent the case back to the Helsinki District Court to be heard on its merits, although the three men, who had previously been detained in Finland, have since left the country.THERECORD.MEDIA
27 AugFrom Concept to Context Engine: How Wiz Built AI-Powered Data DiscoveryInside the multi-agent pipeline and feedback loops that turned a bucket scanner into a context engine.WIZ.IO
27 AugExtend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDKIf you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You …AWS.AMAZON.COM
27 AugA Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her FriendAfter an affair with a fellow police officer ended, a Georgia cop used Flock to track her movements—and those of a man whose vehicle often showed up near hers, internal investigation records show.WIRED.COM
27 AugUK and Ukraine sign landmark AI deal.Taiwan cracks down on illegal AI server smuggling.THECYBERWIRE.COM
27 AugNearly 700 rogue AI agents coordinated in the Hugging Face attackNew details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]BLEEPINGCOMPUTER.COM