What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,036 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
📍 The Sneaky Code Tracking App Users | EFFector 38.15
Your location isn't just a pin on a map—it can expose some of the most intimate details about your life. The value of this information to advertisers and others has turned the location data business into a multi-billion dollar ind…
-
YouTube Is The New Powerhouse For Marketing To CISOs And MSSPs
The top b2b focused cybersecurity media and event channels listed by number of subscribers and views per video – Steve Morgan, Editor-in-Chief Sausalito, Calif. – Aug. 19, 2026 As one of the world’s largest social media platforms …
-
A California county wants to hire Tina Peters to help run its elections
After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its elections appear…
-
US charges Iranian hackers over $3.4 billion intellectual property theft
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]
-
Ransomware disproportionately targets medium-sized firms, straining customer relationships
These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.
-
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC h…
-
Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies …
-
Intezer adds native response automation without separate SOAR
Intezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly inside the Intezer platform. Workflows brings response into the same platfor…
-
Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.
-
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon Secure Your Co…
-
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never …
-
In today's episode of Breach Please, me and @ Secitup talk through OpenAI's pacing model development blog, whe…
In today's episode of Breach Please, me and @ Secitup talk through OpenAI's pacing model development blog, where they apparently hope we won't notice that they're recommending security basics. We do think they set a new bar for ag…
-
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
-
Binary Defense Launches NightBeacon, An AI-Driven SOC Platform Built For The Speed Of Modern Cyberattacks
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 19, 2026 – Watch the Video Binary Defense, a trusted Managed Detection and Response (MDR) and enterprise defense provider, earlier this ye…
-
US charges Iranians for sprawling hacking campaign on government agencies, universities
The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.
-
Prevalent AI Raises $22 Million to Expand Data Fabric Platform
The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek .
-
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Cássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, …
-
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a…
-
US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek .
-
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger …
-
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and …
-
Microsoft fixes known issue causing Windows Defender crashes
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]
-
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appeared first on SecurityWeek .
-
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings a…
-
ICE Collecting DNA Samples
ICE collected nearly a million DNA samples last year.
-
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .
-
Medusa ransomware gang has hit over 500 organizations, CISA warns
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advis…
-
Critical RCE flaw in Windows IKE Extension now actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...…
-
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
-
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
The people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.
-
Brinqa acquires PlexTrac to bring validated remediation to exposure management
Brinqa has announced its acquisition of PlexTra, adding the ability to verify that remediation efforts have actually worked. The combined capabilities uniquely position Brinqa to identify and prioritize the exposures that matter m…
-
943 Patches Rolled Out With Oracle’s August 2026 Security Update
The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle s August 2026 Security Update appeared first on SecurityWeek .
-
Windows 11 24H2 Home and Pro reach end of support in 2 months
Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]
-
Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live inves…
-
Flock Has a Powerful New AI Tool for Police. We Got Its Code
Flock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates.
-
OpenAI puts major frontier AI training run on hold over cyber risks
OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontie…
-
Chrome, Firefox Updates Patch Dozens of Vulnerabilities
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .
-
CISA: Medusa ransomware hit over 500 critical infrastructure orgs
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
-
Cyberattack forces UT San Antonio to delay start of fall semester
The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now st…
-
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North…
-
F5 enhances AI Gateway to control AI costs, access, and security
F5 has introduced enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control pl…
-
CareCloud Data Breach Impact Grows to 3.7 Million Individuals
The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek .
-
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malwar…
-
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, accor…
-
Inside EDGE 2026: From the modern seller’s playbook to marketplaces, networking fun and dedicated tracks
The third day of EDGE 2026 brought together channel leaders, vendors and MSPs for a packed morning of insights focused on the future of selling, scaling and succeeding in an AI-driven market, before attendees headed out for networ…
-
I'm Worried About a Prompt Injection Worm
A honeycomb of small cells, one person at a screen in each, a purple filament threading cell to cell and turning each one cold while bundles are drawn out the bottom/images/prompt-injection-worm.webp/images/prompt-injection-worm.w…
-
Banks look for fraud signals in customer behavior
Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requ…
-
ChatGPT’s new feature could give infostealers a map of your Mac activity
OpenAI s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer…
-
A Detection Engineer's Guide for Delegating Work to AI
Before delegating work to AI, ask one question: can you check the output? A detection engineer on why verification, not trust, decides what tasks you hand over.
-
Oz Hair and Beauty: 1,988,331 accounts breached
Data exposed: Email addresses, Geographic locations, Names, Phone numbers, Purchases. In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack . The group subsequently published …
Last fetch · 0 new