What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,939 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 8h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 12h ago
-
New CUSTODY Framework Constrains AI Agents Inside the Network
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.
-
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.
-
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
OpenAI presented details of its AI s model s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It s really interesting to read through and really impressive cyberoffense work.
-
Apple to OpenAI: Go to your room
Apple’s latest filing in its ongoing fight with OpenAI makes it sound as if Apple legal is so frustrated at the arguments the AI firm is making that it’s begun swatting them away like a parent might dismiss a child. Apple v. OpenA…
-
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 Series…
-
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server …
-
How MSPs can catch phishing attacks email filters miss
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that mak…
-
The push to designate AI as the next critical infrastructure sector
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical in…
-
Grok exfiltrates user data when malicious instructions are encrypted
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.
-
Why "Shady AI" is Security's Next Big Governance Problem
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technica…
-
Corero brings cloud-based AI threat analysis to SmartWall ONE
Corero Network Security has announced AI-Augmented Cloud-Assist for SmartWall ONE, extending its automated DDoS protection with cloud-delivered AI analysis, threat intelligence, and policy optimization. As cybercriminals increasin…
-
AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using …
-
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network. The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on Se…
-
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses a…
-
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadI…
-
OpenAI previews privacy-focused system for detecting AI misuse
OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions whi…
-
Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation
Tufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain consistent control across increasingly complex multi-vendor, hybrid environments. A…
-
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies. The post Hackers Using AI to Target Siemens PLCs in Critical US Sectors appeared first on SecurityWeek .
-
AI is making fraud harder to spot and identity harder to prove
Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity Fraud Report describes a market where scams extend across messages,…
-
When AI explains its decision, humans may stop thinking independently
AI is known to be confidently wrong, and now it’s influencing humans to be that way, too. In a new study, researchers tested AI’s influence on humans reviewing innovation proposals, and found that AI recommender tools were persuas…
-
OpenAI confirms ChatGPT is down as logins and signups fail
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]
-
OpenAI ‘temporarily’ slows scaling efforts, promises zero data retention for select customers
OpenAI this week announced multiple moves designed to counter negative perceptions of its security and privacy, saying it had slowed its pace of scaling, implemented a two-week pause in reinforcement learning, and will be offering…
-
smolmachines / smolvm as a sandbox for untrusted Python & JavaScript
Research: smolmachines / smolvm as a sandbox for untrusted Python JavaScript I tasked Claude Fable 5 running in Claude Code for web with the following research task: Put https://smolmachines.com through its paces as a fast secure …
-
Smashing Security podcast #481: Never say this to a robot dog
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved…
-
Quoting Jeremy Morrell
My hypothesis is that there is a new opportunity for Extensible Software on the web . LLMs radically lower the cost of authoring extensions, and modern sandbox primitives lower the deployment cost and provide good security boundar…
-
Conceptual integrity and counting lines of code
Last week I recorded an episode of the Talking Postgres podcast with Claire Giordano on the subject of "How AI is changing software development". We had a really great conversation. Here are a couple of my highlights from a lightl…
-
No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.
-
Agentic AI Presents New Insider Threat Model for Orgs
Katie Moussouris of Luta Security talks with the Dark Reading News Desk about how enterprises will now need to monitor risks posed by their own agents in the wake of the recent Hugging Face attack.
-
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.
-
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first …
-
IAM Protects the Identity. ITDR Protects the Moment.
IAM Locks the Door. ITDR Catches the Intruders? – Christophe Briguet, Sr. Director of Product Management – AI Security Analytics, Stellar Cyber San Jose, Calif. – Aug. 19, 2026 Your employee successfully authenticates. The account…
-
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to av…
-
So Is Your SOC AI-Ready? Part 3: API or Die Audit!
This is Part 3 of the AI-ready SOC series ( Part 1 , Part 2 ), and it is focused on validating readiness for pillars #1 (SOC Data Foundations) and #4 (Modern SOC Technology Stack). Specifically, it is about the audit I promised in…
-
Flock makes a point of saying that their system can't track individuals. Wired continues to do the Lord's work…
Flock makes a point of saying that their system can't track individuals. Wired continues to do the Lord's work, taking Flock software apart and demonstrating its new AI tool comes preloaded with prompts like find me witness and fi…
-
In today's episode of Breach Please, me and @ Secitup talk through OpenAI's pacing model development blog, whe…
In today's episode of Breach Please, me and @ Secitup talk through OpenAI's pacing model development blog, where they apparently hope we won't notice that they're recommending security basics. We do think they set a new bar for ag…
-
Binary Defense Launches NightBeacon, An AI-Driven SOC Platform Built For The Speed Of Modern Cyberattacks
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 19, 2026 – Watch the Video Binary Defense, a trusted Managed Detection and Response (MDR) and enterprise defense provider, earlier this ye…
-
Prevalent AI Raises $22 Million to Expand Data Fabric Platform
The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek .
-
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Cássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, …
-
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger …
-
Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live inves…
-
Flock Has a Powerful New AI Tool for Police. We Got Its Code
Flock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates.
-
OpenAI puts major frontier AI training run on hold over cyber risks
OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontie…
-
F5 enhances AI Gateway to control AI costs, access, and security
F5 has introduced enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control pl…
-
Inside EDGE 2026: From the modern seller’s playbook to marketplaces, networking fun and dedicated tracks
The third day of EDGE 2026 brought together channel leaders, vendors and MSPs for a packed morning of insights focused on the future of selling, scaling and succeeding in an AI-driven market, before attendees headed out for networ…
-
I'm Worried About a Prompt Injection Worm
A honeycomb of small cells, one person at a screen in each, a purple filament threading cell to cell and turning each one cold while bundles are drawn out the bottom/images/prompt-injection-worm.webp/images/prompt-injection-worm.w…
-
ChatGPT’s new feature could give infostealers a map of your Mac activity
OpenAI s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer…
-
A Detection Engineer's Guide for Delegating Work to AI
Before delegating work to AI, ask one question: can you check the output? A detection engineer on why verification, not trust, decides what tasks you hand over.
-
AI agents aren’t cheap, even with falling model costs: Gartner
While token economics are improving, this alone won’t prevent overall AI costs from rising as organisations move from chatbots to agentic systems. Analyst firm Gartner predicts AI inference costs per agentic workflow will increase…
-
China-Linked Hacker Shows AI Capabilities in APAC Attack
In the first purported near-autonomous attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.
-
Oracle’s partner co-innovation initiative leads to success
Oracle’s focus on collaborating earlier with partners in joint engagements is working in the vendor’s favour as it uses AI to open up more opportunities. In 2025, the vendor’s group vice president and head of alliances and channel…
Last fetch 5m ago · 2 new · 2 source error(s)