What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,037 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek .
-
Download: 2026 Credential Risk Report
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where c…
-
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government s promises about the Gold Eagle coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.
-
Google’s $10,000 refund test shows why AI agents need zero trust
Google’s open-source autonomous Customer Support Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive…
-
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat und…
-
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (…
-
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco…
-
Microsoft tests faster Windows File Explorer, new context menu
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
-
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on Securi…
-
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs : Abstr…
-
CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
-
Can AI Coexist With Privacy? Proton’s Andy Yen Says It Will Have To
Proton’s CEO is a champion of encryption for everyone. So why is he going all in on un-encryptable AI?
-
The Cop Who Took On Flock
After Noel Pichardo called out his city's embrace of Flock surveillance cameras, he was subjected to five internal affairs investigations in less than two years.
-
OpenAI tightens defenses after AI agents breach research environment
Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI b…
-
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
-
Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform. The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on Securit…
-
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker…
-
Hacker claims millions of records stolen from corporate Azure tenants
A threat actor known as TheHatman claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), acc…
-
GitLab Patches Critical Code Injection Vulnerability
The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek .
-
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
-
Synthesized builds Test Data Agent to validate AI agents with production-like data
Synthesized has announced its Test Data Agent, a new agentic infrastructure capability being developed to create and provision the realistic data, business context, and system states enterprises need to validate AI agents safely b…
-
Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data. The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on …
-
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Py…
-
Google’s open-source HEIR lets AI work with data it can’t see
Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre…
-
A hollowed out data layer is making CISOs fly blind into AI attacks
The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are a…
-
Attackers turn to AI for help identifying files worth stealing
AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands d…
-
Cybersecurity jobs available right now: August 18, 2026
CISO ADI Global Distribution USA Hybrid View job details As a CISO, you will develop and lead ADI’s global security strategy to protect information assets, digital platforms, critical operations, and AI-enabled environments. Advis…
-
Weekly Update 517: Cyber Ransoms
The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn t even involve ware , it s just extortion) is carried out by kids who successfully make a truckload of money but can t spe…
-
Dell CTO John Roese: Partners, culture, and governance are all layers of AI transformation
AI success depends on disciplined execution, governance, culture change, startup innovation, and human relationships, said Dell global chief technology officer (CTO) John Roese. For Dell, this means partners are not an optional ro…
-
Cisco makes changes to its channel leadership ranks
Cisco has made several changes to its Australia and New Zealand (A/NZ) leadership team, with long-time channel chief Rodney Hamill moving into the role of managing director, South, covering Victoria, the ACT, and Tasmania in Austr…
-
CVE-2025-62593: Ray-Project Ray — Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
-
CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
-
CVE-2026-59310: Broadcom VMware vCenter — Broadcom VMware vCenter Path Traversal Vulnerability
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
-
CVE-2026-55040: Microsoft SharePoint — Microsoft SharePoint Weak Authentication Vulnerability
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
-
CVE-2026-65400: Apple macOS — Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
-
Qwen 3.8 27B scores 52 on the Artificial Analysis Intelligence Index
Qwen 3.8 27B scores 52 on the Artificial Analysis Intelligence Index That's the same score as GPT-5.6 Luna (max), and just one point behind GLM-5.2 (max) and DeepSeek V4 Pro 0813 (max) - that GLM is 753B and that DeepSeek is 1.6B …
-
Spark appoints former Mercury boss Vince Hawksworth as chair
Spark New Zealand has appointed non-executive director former Mercury Energy CEO Vince Hawksworth as the new chair of its board. In a statement to the NZX, Spark said Hawksworth will take over the reins from Justine Smyth, who has…
-
Ukrainian software developer faces 12 years in Swiss ransomware trial
The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation.
-
Video Call Exploit Chains Two Flaws in Unisoc Modems
Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.
-
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely…
-
Details emerge on BlackFile’s recent attacks on financial companies
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. The post Details emerge on BlackFi…
-
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape inciden…
-
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
Three testing models with the same goal but different directives engaged in increasingly aggressive territorial attacks on one another, according to Anthropic.
-
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
-
If you are an expert witness, do not use ChatGPT to write the report you are charging $475/hour for. All of yo…
If you are an expert witness, do not use ChatGPT to write the report you are charging $475/hour for. All of your chat prompts are subpoenable and we are all going to laugh so hard. https://www. 404media.co/show-how-3m-is-0-a t-fau…
-
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
-
Adam Shostack Talks Hugging Face & PHANTOM-B
World-class threat modeler Adam Shostack shared he was blown away by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both lightweight yet still usable.
-
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [..…
-
How to Get Started in Cybersecurity 2026
A person vaulting on a machine lever toward a glowing keyhole/images/how-to-get-started-in-cybersecurity-2026.webp/images/how-to-get-started-in-cybersecurity-2026.webp I've been writing versions of this guide since 2008. The most …
-
This Friday, I'm teaching a one-day seminar on assessing the security of MCP with @ Antisy_Training . It's goi…
This Friday, I'm teaching a one-day seminar on assessing the security of MCP with @ Antisy_Training . It's going to be a fun time where we'll evaluate three custom MCP servers for vulnerabilities through the day. https:// learning…
Last fetch 7m ago · 0 new · 2 source error(s)