What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,030 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
I Know What I Did This Summer.
Ladies and gents, boys and girls – greetings! It s been a while. But of course it has: there was a vacation-heavy summer to get through! And now, finally, the time has come to begin my traditional tales from the summer-holiday sid…
-
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
-
UK power facility disabled for days after suspected state-linked cyberattack
The disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors.
-
Tricky 'SynkLoader' Multitool May Herald Ransomware
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
-
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that…
-
House Democrats ask GAO to study CISA workforce cuts
The five lawmakers, who serve on the Homeland Security Committee, said Congress didn t know enough about the Trump administration s changes to the cybersecurity agency.
-
ToxicPanda Banking Trojan Matures into Enterprise Threat
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
-
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit wor…
-
24th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting …
-
Microsoft Teams now lets admins block external bots from meetings
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
-
South Korean startup platform breach exposes key management failures
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate fr…
-
Hired for One Job, Judged on Another: The CISO’s Real Problem
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. The post Hired for One Job, Judged on Another: The CISO’s Real Problem appea…
-
The Vulnerability Gap: Why Discovery Is Outrunning Repair
AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.
-
New Partner View for Security Incident Investigations
See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.
-
Suspected Iran-linked attack knocked UK power plant offline for days
News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK s power grid and, indeed, the country s critical infrastructure can fend off destructive c…
-
Who’s Who In Cyberinsurance For Small Businesses
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 24, 2026 – Read the Full Story Many small business owners operate under the dangerous misconception that they’re too small to be a target.…
-
Gunra ransomware: what you need to know
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the For…
-
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspension…
-
Microsoft: August updates break printing, PDF export in WPF apps
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
-
Source article: https://www. bleepingcomputer.com/news/micr osoft/microsoft-warns-of-max-severity-entra-id-fla…
Source article: https://www. bleepingcomputer.com/news/micr osoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/
-
In today's episode of Breach Please, me and @ Secitup talk about how you should respond to vulnerabilities in …
In today's episode of Breach Please, me and @ Secitup talk about how you should respond to vulnerabilities in cloud platforms. This was the chosen topic because of multiple CVSS 10.0 vulns in Entra and Azure products disclosed wit…
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, W…
-
Hackers infecting Android car systems to build proxy botnet
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet.
-
91 Vulnerabilities Patched in Spring Application Framework
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek .
-
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source p…
-
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account …
-
Cybersecurity job ads demanding AI skills double in a year
Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed cove…
-
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been f…
-
Your executable is a SQLite database
Your executable is a SQLite database Farid Zakaria describes a neat Linux pattern for creating a SQLite database file that can be directly used as an executable binary. The trick sets the SQLite file format's 4-byte application ID…
-
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-…
-
Venezuelan Gets Record Federal Prison Term for ATM Jackpotting
Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first …
-
CISA’s logging guidance works beyond government
The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you ve collected to catch it and rec…
-
CISA orders urgent patching of actively exploited Zimbra flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
-
Criminal Deception in Silicon Valley
Interesting paper : Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception , employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley v…
-
Personal Information Exposed in Apollo Global Data Breach
The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek .
-
Rethinking Application Security for the AI Era
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on Securi…
-
Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the …
-
Microsoft shares temporary fix for Windows 11 gaming issues
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
-
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks. The post Iran-Linked Hackers Shut Down UK Power …
-
TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. The post TikTok Reaches $400 Million Settlement With US Justice Depart…
-
Salesforce gave every org the same free scanner. Attackers already know what it misses.
A defense every attacker can rehearse against isn't a defense. It's a false sense of security.
-
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast…
-
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first on Security…
-
Product showcase: AI Paper Trail shows the privacy cost of talking to AI
Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or Claude conversation data and produces a personal privacy report showing wha…
-
Fake bank websites play dead to evade security scanners
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. The company s threat inte…
-
Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 1…
-
Weekly Update 518: IoT Doorlock Nirvana with UniFi
I genuinely think I ve nailed the IoT door lock situation! Well, Ubiquiti has, but I think I ve worked out how to put it all into a residential house and have it make sense. There are a few basic tenets: Main power (never have to …
-
AWS makes it easier to spot firewall rules that have gone quiet
AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are w…
-
CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access…
-
Dicker Data adds Sophos to boost cyber security offering
Dicker Data is set to expand its cyber security portfolio and providing partners across Australia and New Zealand with Sophos solutions. The agreement will see Dicker Data distribute the vendor’s cyber security portfolio across en…
Last fetch 13m ago · 1 new · 2 source error(s)