What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,026 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-se…
-
Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
The pro-Russian hacker group Server Killers claimed responsibility for the attack. The post Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services appeared first on SecurityWeek .
-
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years. The tools,…
-
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC an…
-
Abnormal AI expands email security from detection to data protection and phishing-simulation training
Abnormal AI announced an expansion of its email security platform with three new capabilities: Control Center, Email DLP Rules, and AI Phishing Coach upgrades. Together, the launch extends Abnormal’s behavioral AI across all three…
-
AI will not fix a governance problem in your camera estate
Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentati…
-
Recent Citrix NetScaler Vulnerability Exploited in the Wild
CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek .
-
The best human hacking team still out-solved the best AI team
Bring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed up in 17 of the Top 25 finishers. The people who least …
-
The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms
Threat actors are targeting the AI attack surface to deliver malware and steal data. See how trusted AI tools are being exploited today.
-
2degrees satellite services in sight as it opens AST SpaceMobile ground station
2degrees has taken a step closer to launching direct-to-device satellite services with the opening a satellite ground station with partner AST SpaceMobile this week. The facility in Marton in the central North Island is one of the…
-
Rivals 2degrees and One NZ to cozy up on proposed radio access network joint venture
Telecommunications rivals 2degrees and One New Zealand have revealed a proposed plan to combine their respective radio access networks (RAN) into a joint venture. Under the proposal, the companies will combine their respective RAN…
-
Headline: AI writes lots of code. Buried under the headline: that doesn't always translate into features reach…
Headline: AI writes lots of code. Buried under the headline: that doesn't always translate into features reaching users. Oh, and even when that code does reach users, it doesn't work reliably. And when it doesn't, it takes longer …
-
CVE-2023-49105: ownCloud ownCloud — ownCloud Improper Authentication Vulnerability
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
-
CVE-2026-53362: Linux Kernel — Linux Kernel Unspecified Vulnerability
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other produ…
-
CVE-2026-66384: JFrog Artifactory — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository co…
-
Qwen3.8-Flash-Next
Qwen3.8-Flash-Next Another open weights model from Qwen. This one is "a multimodal MoE model that also serves as an early preview of the architecture used in Qwen4". It's pretty big: 125B tokens, but only 6B active which means it …
-
Dicker Data brings Huddly AI camera systems to New Zealand
Dicker Data New Zealand has secured a new distribution partnership with Norwegian AI-powered video technology provider Huddly. The agreement will see Dicker Data distribute Huddly’s full range of intelligent camera systems to part…
-
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, …
-
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure ap…
-
Critical Avada WordPress theme flaw enables zero-click RCE
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]
-
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.
-
A List of ICE Subpoenas to Tech Companies
Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and internationa…
-
Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit
The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding.
-
Charlie McGonigal Is in Prison. Almost No One Else Is.
The woman who gave the fullest public account of the corruption of the man who ran FBI counterintelligence in New York during the 2016 election now says she invented much of it.
-
'HTTP Terminator' Hunts for Novel Desync Attacks
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.
-
Officials disrupt Chinese espionage operation that hit multiple federal agencies
The full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years. The post Officials disrupt Chinese espionage operation that hit …
-
Red Flags That Expose Fake North Korean IT Workers
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.
-
OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.
-
Medical device firm Boston Scientific says cyberattack has disrupted shipment processes
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
-
OpenAI: Agent behavior that led to Hugging Face intrusion formed in May
The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. The post OpenAI: Agent behavior that led to Hug…
-
New GPUThor attack defeats NVIDIA ECC protection for root access
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]
-
Three 10.0 security flaws fixed across Ubiquiti’s UniFi line
The communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher. The post Three 10.0 security flaws fixed across Ubiquiti’s UniFi line appeared first on CyberScoop .
-
Meta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case
A multibillion-dollar settlement with attorneys general from nearly every U.S. state and territory will mean new privacy and safety protections in Meta products.
-
The Top CISO Stories from Around the Web: August 2026
From critical infrastructure attacks to severe gaps in manufacturing leadership, today's CISOs must navigate autonomous agent risks, secure vulnerable OT systems, and orchestrate complex defenses. This month’s roundup explores how…
-
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.
-
EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms
Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to tra…
-
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.
-
Sometimes I hear non-technical people speculating that this is a thing that could happen and I am posting it h…
Sometimes I hear non-technical people speculating that this is a thing that could happen and I am posting it here to let them know that yes, this is a thing that happens. https://www. theguardian.com/world/2026/aug /26/fake-thinkt…
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series , we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI age…
-
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Sec…
-
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Sec…
-
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the c…
-
Meta agrees to $18 billion settlement over teen social media harms
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use …
-
EFF Statement on Meta Settlement
Under this settlement , young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settleme…
-
US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.
-
Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Researchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group.
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Cor…
-
There is not enough popcorn in the world to talk to address the fact that OpenAI has been notified by 15 state…
There is not enough popcorn in the world to talk to address the fact that OpenAI has been notified by 15 state AGs to retain records for its Hugging Face incident (and any others it might have caused that aren't reported). Me and …
-
AI Speeds Up Malware Development, Not Its Success Rate: Analysis
Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek .
-
Boston Scientific says cyberattack disrupted operations globally
Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]
Last fetch 1m ago · 2 new · 2 source error(s)