🚨 CISA KEV 1[−]
31 Aug KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Refle…CISA.GOV
🐛 COMMON VULNERABILITIES AND EXPOSURES 7[−]
31 AugCVE-2026-49177 Windows TCP/IP Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-50344 Windows OLE Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-65775 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-65776 Windows Win32k Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-62823 Windows DHCP Server Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugCVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
31 AugSimulating legitimate Active Directory services on the network: the case of GPO exploitationSimulating legitimate Active Directory services on an internal network is a powerful and versatile capability that can be leveraged in various contexts. Many examples of exploits relying on the ability to simulate working LDAP and/or SMB services can be cited, such as Group Polic…SYNACKTIV.COM
⚠️ VULNERABILITY DISCLOSURE 29[−]
31 Aug KEVShinyHunters claims another health giant breach, PaperCut rushes second emergency patch, US bans foreign grid techShiny Hunters Claims 284M McKesson Records Stolen, PaperCut Patch Bypassed Again, and White House Bans Foreign Power Grid Tech Host David Shipley covers multiple cybersecurity headlines: Shiny Hunters claims it breached healthcare giant McKesson via voice phishing, compromised Ok…CYBERSECURITYTODAY.LIBSYN.COM
31 AugHow AI could make it harder for governments to use hacking toolsAI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices.TECHCRUNCH.COM
31 AugOpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknessesA coalition led by OpenAI is warning that AI will sharply accelerate the speed and scale of cyberattacks, leaving enterprises with a narrowing window to fix long-standing security weaknesses before they are exploited. “In the coming months, AI-enabled cyber attacks will become fa…CSOONLINE.COM
31 AugIs your cloud security strategy ready for AI’s looming threat?Cloud architectures designed to withstand human attackers are facing a new threat: AI agents that rewrite the rules on the pace and scope of attacks. The recent OpenAI incident involving Hugging Face offers an early example of what an autonomous AI attack can look like, with an a…CSOONLINE.COM
31 AugLife as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - ESW #474Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing *The Augmented Defender - What AI Actually Changes on the Front Line* with Daniel Bo…YOUTUBE.COM
31 Aug[webapps] Langflow 1.8.4 - Path Traversal to Remote Code ExecutionLangflow 1.8.4 - Path Traversal to Remote Code ExecutionEXPLOIT-DB.COM
31 AugAttackers begin exploiting critical Ruby on Rails flaw.PaperCut issues emergency patch for a second zero-day. Two Nigerians extradited to US over sextortion schemes.THECYBERWIRE.COM
31 AugSlovenian casinos reopen after cyberattack knocked gaming systems offlineOne of Slovenia’s largest gambling and tourism groups has begun reopening its casinos after a cyberattack forced them to shut down for several days.THERECORD.MEDIA
31 Aug31th August – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack …RESEARCH.CHECKPOINT.COM
31 AugCalifornia moves to exempt Linux from new age-verification lawCalifornia lawmakers have passed AB 1856, a bill that would exclude qualifying open-source software distributors from being treated as operating system providers under the state’s upcoming Digital Age Assurance Act (DAAA). The measure passed the Senate 39–0 on August 26, and the …CYBERINSIDER.COM
31 AugGrapheneOS may skip Pixel 11 over missing hardware security featureGrapheneOS says it may abandon support for Google’s Pixel 11 series after discovering that the new devices appear to lack usable support for ARM Memory Tagging Extension (MTE). MTE is a hardware security feature the privacy-focused Android project relies on extensively to mitigat…CYBERINSIDER.COM
31 AugNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product ExploitKaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugServiceNow Patches 3 Critical Code Injection VulnerabilitiesAttackers could exploit the security defects to execute arbitrary code and access or tamper with data. The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugCritical Ruby on Rails Vulnerability in Attackers’ CrosshairsNamed KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugThreat actors are posing as AI crawlers to hunt for exposed credentialsAttackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that …HELPNETSECURITY.COM
31 AugAttackers plant remote access tools on compromised PaperCut serversThe threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools …HELPNETSECURITY.COM
31 AugShinyHunters claims it stole 284 million patient records from McKessonHealthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and other healthcare products to pharmacies, hospitals …HELPNETSECURITY.COM
31 AugRussian hackers plant nuclear weapon prompt in malware to trip AI safety guardrailsRussian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group prev…HELPNETSECURITY.COM
31 AugThe OpenClaw 2.0 release moves your sessions into SQLiteOpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor advisories and pings you on Telegram when one names a product you run. OpenClaw 2.0 is the largest update in the project’…HELPNETSECURITY.COM
31 Aug KEVWhat vulnerability prioritization looks like when KEV, EPSS, and CVSS disagreeIn this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, with adjustments fo…HELPNETSECURITY.COM
31 AugHalo-record: Open-source audit trails for AI agentsBrian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, and every line carries a hash of the line…HELPNETSECURITY.COM
31 AugA rough day at the extortion office and a botched attack on Blossom Health.A tip about Click2Mail was not the only interesting tip DataBreaches received on Thursday. We also received an email from someone who identified themself as a patient at Blossom Health, a US-based telehealth and psychiatry platform. “An extortionist appears to have compromi…DATABREACHES.NET
31 AugTime’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.On August 6, DataBreaches reported that Cardiology Associates of Port Huron (CAPH), a Michigan medical practice with 9 locations, appeared to have been breached by a group called Orova. As reported at the time, the listing included screenshots with personally identifiable and pro…DATABREACHES.NET
31 AugCritical GiveWP Flaw Lets Attackers Run Commands on WordPress ServersA critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated…SECURITYAFFAIRS.COM
31 AugAutomate IAM Identity Center governance with continuous discovery and reportingAWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS ser…AWS.AMAZON.COM
31 AugIs Someone Hacking DoD Refrigerators?It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force Base , Calif., according to announcements made onl…SCHNEIER.COM
31 AugWindows bug incorrectly tells users that Microsoft Defender Antivirus is turned offMicrosoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in that it w…CSOONLINE.COM
31 AugFive plead guilty in latest federal ATM jackpotting caseFederal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.THERECORD.MEDIA
31 AugCronos blockchain restarts after $74 million Tectonic exploitThe Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]BLEEPINGCOMPUTER.COM
📋 SECURITY BULLETINS 1[−]
31 AugTrusted Chrome, Edge extensions weaponized in supply chain campaignAttackers have turned previously legitimate browser extensions into malware after acquiring them from legitimate publishers, potentially allowing malicious updates to reach users who had installed the software when it was still safe, researchers at Socket have found. The campaign…CSOONLINE.COM
📢 SECURITY ADVISORIES 15[−]
31 AugSecuring Claude Code: The New Compliance API, Local Visibility, and Identity GovernanceClaude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activi…THEHACKERNEWS.COM
31 AugDoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not VictimsThe U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the Nation…THEHACKERNEWS.COM
31 AugFile servers are here to stay. Here’s how to manage them securelyFile servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]BLEEPINGCOMPUTER.COM
31 AugBerlin confirms data theft after Rhysida ransomware attack claimsBerlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]BLEEPINGCOMPUTER.COM
31 AugLet’s kill the kill switch.Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastructure. Claude Code gets tricked into running attacker-controlled code. MyChart p…THECYBERWIRE.COM
🔥 INCIDENT REPORTING 13[−]
31 AugAurora Ransomware Operators Use Cursor AI in Attacks Against 10 TargetsThreat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are bas…THEHACKERNEWS.COM
31 AugChina-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security LogsA China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, an…THEHACKERNEWS.COM
31 AugMcKesson confirms cyber incident after ShinyHunters claims patient-data theftHealthcare company McKesson acknowledged a data breach. ShinyHunters claims to have stolen hundred of millions of recordsMALWAREBYTES.COM
31 AugBerlin says it won’t pay ransom after hackers steal government dataGoverning Mayor Kai Wegner said that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.THERECORD.MEDIA
31 AugPharmaceutical giant McKesson warns of 'service degradation' following cyberattackThe pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.THERECORD.MEDIA
31 AugMcKesson Confirms Data Breach as Attacker Deadline LoomsThe ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems. The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugWhat the Hugging Face Incident Teaches Security Leaders About AI Agent AccessSecurity teams must treat autonomous agents as highly privileged identities. The post What the Hugging Face Incident Teaches Security Leaders About AI Agent Access appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugBoston Scientific Still Recovering From CyberattackThe company has called in CrowdStrike and others to investigate the attack that caused global network disruption. The post Boston Scientific Still Recovering From Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugExtortion Group Claims Manchester Airports Group Data BreachFulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online. The post Extortion Group Claims Manchester Airports Group Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugBerlin Won’t Pay Extortion Group Claiming Data TheftThe Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials. The post Berlin Won’t Pay Extortion Group Claiming Data Theft appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugAnthropic locks out Claude users after infostealers hijack login sessionsAnthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. “The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomi…HELPNETSECURITY.COM
31 AugHackers claim millions of patient records stolen during data breach at healthcare giant McKessonThe company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation.TECHCRUNCH.COM
31 AugMicrosoft warns of TerminalFix attacks deploying reverse tunnelsA new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 22[−]
31 AugHiding Prompt Injection in Legal FilingSomeone hid AI instructions into a legal filing. Alternate link .SCHNEIER.COM
31 AugValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus ExclusionsThe threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity v…THEHACKERNEWS.COM
31 AugISC Stormcast For Monday, August 31st, 2026 https://isc.sans.edu/podcastdetail/10074, (Mon, Aug 31st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
31 AugAI Creates an Accountability GapAgentic AI can investigate and combine information from different parts of an organization. A financial agent could encounter relevant information through email or security systems that changes how it approaches a task. The technical ability to connect information can move faster…YOUTUBE.COM
31 AugValleyRAT masquerading as adwareThreat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.SECURELIST.COM
31 AugThe AI Kill Switch Act is repeating the Clipper Chip’s mistakesMandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act. The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberS…CYBERSCOOP.COM
31 AugPaperCut issues emergency patches as threat actors target chained vulnerabilitiesThe print management software maker faced a wave of attacks in 2023 aimed at higher education customers.CYBERSECURITYDIVE.COM
31 AugState-linked actor targets Cisco routers for espionageAn actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.CYBERSECURITYDIVE.COM
31 AugBreaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 BytecodeResearch by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign…RESEARCH.CHECKPOINT.COM
31 AugSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft TeamsLearn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
31 AugEU puts ChatGPT, Reddit, and Roblox under stricter DSA rulesThe European Commission has designated ChatGPT, Reddit, and Roblox as services subject to the strictest requirements of the EU’s Digital Services Act (DSA) after each reported reaching at least 45 million monthly users in the European Union. Under the designations announced today…CYBERINSIDER.COM
31 AugAnthropic Warns Claude Users of Infostealer Malware InfectionsThe AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek .SECURITYWEEK.COM
31 AugJudge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year. The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ appeared first on Securit…SECURITYWEEK.COM
31 AugAWS Console Private Access can block sign-ins to personal accountsThe AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, that have no internet connectivity at all. Authent…HELPNETSECURITY.COM
31 AugDebian developers rejected an LLM ban and left disclosure voluntaryA maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: the winning option encourages contributors to …HELPNETSECURITY.COM
31 AugChina-linked Fire Ant Hides Inside Trusted InfrastructureFire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking…SECURITYAFFAIRS.COM
31 AugNorth Korean Job Fraud Expands Beyond IT Into Healthcare and SalesThreat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and …THEHACKERNEWS.COM
31 AugNew RevStealer malware spreads as fake Claude Opus 5 desktop appRevStealer malware is being distributed through trojanized Electron applications, including a GitHub project masquerading as a free desktop version of Anthropic’s Claude Opus 5. The malware steals browser data, password-manager files, cryptocurrency wallets, credentials, and docu…CYBERINSIDER.COM
31 AugAI Security Tools Need to TalkSecurity investigations often depend on connecting activity from different systems. File activity might matter in combination with email activity, for example, but that context can be fragmented across separate security tools. AI agents could perform more of that correlation auto…YOUTUBE.COM
31 Aug‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity helpThe six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.” The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop .CYBERSCOOP.COM
31 AugMcKesson copes with fallout from data theft extortion attackThe major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop .CYBERSCOOP.COM
31 AugAnthropic Users Hit by Infostealer Attacks, Session TheftsA threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.DARKREADING.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
31 Aug⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task wa…THEHACKERNEWS.COM
31 AugA week in security (August 24 – August 30)A list of topics we covered in the week of August 24 to August 30 of 2026MALWAREBYTES.COM
31 AugATM Flaws Reveal Key Weaknesses in the Software Supply ChainA security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.WIRED.COM
31 AugInfostealers Are Hijacking Claude Sessions and Draining SubscriptionsInfostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usag…SECURITYAFFAIRS.COM
31 AugValleyRAT: When Legitimate Software Becomes a Malware Delivery ToolValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something muc…SECURITYAFFAIRS.COM
🎙️ PODCASTS 1[−]
31 AugSponsored: Attackers need to be right more than onceIn this Risky Business sponsored interview, James Wilson chats with Dropzone AI’s founder and CEO Edward Wu to debunk the adage, “an attacker only has to be right once”. Modern intruders need to be successful across multiple steps before actually reaching an organisation’s “crown…RISKY.BIZ
📡 INFOSEC NEWS 22[−]
31 Aug[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)C-MOR 6.0104 - Cross-Site Scripting (XSS)EXPLOIT-DB.COM
31 Aug[webapps] CubeCart 6.7.4 - Cross-Site ScriptingCubeCart 6.7.4 - Cross-Site ScriptingEXPLOIT-DB.COM
31 Aug[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command InjectionLinksys E1200_2.0.04 - Unauthenticated OS Command InjectionEXPLOIT-DB.COM
31 AugMicrosoft Exchange Online outage causes email failures, auth issuesMicrosoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. [...]BLEEPINGCOMPUTER.COM
31 AugOpenAI confirms ChatGPT outage as users report errorsChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]BLEEPINGCOMPUTER.COM
31 AugChinese Fire Ant hackers turn Cisco routers into spying platformsThe researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]BLEEPINGCOMPUTER.COM
31 AugMicrosoft says Windows 11 KB5120998 update resets mouse settingsMicrosoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]BLEEPINGCOMPUTER.COM
31 AugNigerians extradited to US for sextortion, deaths of two teensTwo Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]BLEEPINGCOMPUTER.COM
31 AugMicrosoft asks users to ignore 'Antivirus is turned off' errorsMicrosoft asked customers this week to ignore alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]BLEEPINGCOMPUTER.COM
31 Aug[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIDARKREADING.COM
31 AugGreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOARToday we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR. The expanded integration includes a purpose-built Falcon Next-Gen SIEM dashboard, …GREYNOISE.IO
31 AugRisky Bulletin: New powers for Dutch intelligence servicesDutch intelligence services will get new powers, a security expert has been arrested in Israel for hacking, the BTS hacker gets a 20 year sentence in South Korea, and an AfD politician in Germany has been linked to a Russian cybercrime hosting service.RISKY.BIZ
31 AugAI Model Rules Are Not Security ControlsOpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.DARKREADING.COM
31 AugWe invited a direct competitor into Security Hub Extended. Here’s why.When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for …AWS.AMAZON.COM
31 AugFraudsters steal $6 million from Tectonic crypto platform after inflating token priceAt least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.THERECORD.MEDIA
31 AugThe Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#;x26;#;xe2;&…ISC.SANS.EDU
31 Aug'TerminalFix' Campaign Weaponizes PowerShell for Enterprise AttacksThe ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.DARKREADING.COM