What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,037 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, regi…
-
BreachLock: CISO Conversations Revealed At Black Hat USA 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 14, 2026 – Watch the YouTube video One thing is really clear in all the CISO conversations I ve had is that everybody is worried about the…
-
Cyera's Oasis Security Buy is All About AI Agent Control
The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.
-
In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: R…
-
Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
-
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek .
-
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and t…
-
New Android malware relays bank cards to fraudsters while victims still hold them
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote acces…
-
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, sav…
-
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . OpenAI, and then Anthropic , were each formed by AI developers who feared unrestrained corporate AI development specifically, that companies …
-
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on Security…
-
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, …
-
OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode
OpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up to 14 times faster than Standard processing and ge…
-
RingCentral data breach exposed info of 1.6 million accounts
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]
-
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number…
-
1.6 Million Likely Impacted by RingCentral Data Breach
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek .
-
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilitie…
-
Over 1,000 Charities Hit by Beacon CRM Data Breach
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on Securit…
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
-
Data analyst sent to prison for stealing data, extorting employer
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]
-
AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. T…
-
Weekly Cyber Update: 14 August 2026
The ICO reprimands ACRO for a historic CMS breach; US authorities investigate a mid-air Wi-Fi incident; the Polish CERT releases details on an energy plant attack; hackers scrape data from Salesforce and ServiceNow customers; and …
-
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek .
-
Ukrainian police raid 94 fraudulent call centers, seize $2 million
Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent …
-
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered…
-
Hackers Exploiting Unpatched GeoServer Zero-Day
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek .
-
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on Secu…
-
The hardest part of agentic AI may be rebuilding the business
Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits,…
-
Weak IAM affects up to 98% of cloud environments
Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now m…
-
17 draft Cyber Resilience Act standards are open for comment
A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the…
-
Ingram Micro reports growing uptake of Xvantage Integration Hub
Ingram Micro has found that its global channel partners are increasingly using AI when it can be securely connected to their existing business systems, data sources and workflows. The distributor is seeing growing adoption of its …
-
New infosec products of the week: August 14, 2026
Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub. ScienceLogic delivers secure AI deployment and smarter IT operations with Sky…
-
10 Hacker Summer Camp Standouts at Black Hat and DEF CON
From the panels to the villages, Huntress researchers and SOC analysts were all over Hacker Summer Camp this year. Here’s what stood out at Black Hat and DEF CON.
-
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]
-
Finalists revealed for Reseller News Innovation Awards 2026
Reseller News is proud to reveal the finalists for the Innovation Awards 2026, recognising excellence across the New Zealand channel, including start-ups, partners, distributors, marketplaces, vendors and personal achievement. Set…
-
Industry-led strategy calls for NZ to become trusted, sustainable data centre and AI hub
New Zealand has the opportunity to build the digital infrastructure needed to lift productivity, strengthen national resilience, create thousands of jobs and develop a sustainable new export industry. This is according to a strate…
-
sqlite-utils 4.2.1
Release: sqlite-utils 4.2.1 Fixes a crashing bug in sqlite-utils 4.2 . I'd introduced code that looks like this: from typing_extensions import Self It turned out the typing-extensions package was not listed as a dependency for sql…
-
The Ancient Art of SIEM: Why 2003 Problems Look So Familiar in 2026
Lately, I’ve been reading a lot of insightful posts related to best practices in SIEM, detection, and logs (written in 2026). The interesting bit is that a lot of these best practices looked good to me and made sense — and yet, th…
-
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say. The post A bold new strategy or a dangerous precedent? Experts are divided on Trump s memo. appeared first on CyberScoop …
-
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92. The post Tech contractor for Brigh…
-
Ukraine shuts down 94 fraudulent call centers, seize millions in cash
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
-
Too Little, Too Late: Flock Admits Their Technology Needs Reforms
Flock Safety, the embattled vendor of mass surveillance technology, has rolled out a handful of new reforms intended to appease the justified nationwide anger that has seen scores of towns cancel or suspend their contracts with th…
-
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
-
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
-
sqlite-utils 4.2
Release: sqlite-utils 4.2 Lots of improvements in this one relating to the table.transform() feature , which adds support for complex alter table operations by creating a fresh table, copying across the data and then dropping and …
-
White House recruits security firms to hack overseas cybercriminals
Trump memo is first time gov't has authorized private sector to perform cyber attacks.
-
llm-gemini 0.33
Release: llm-gemini 0.33 It's been a while since the last llm-gemini release. This version of the plugin adds support for today's Gemini 3.7 Flash release, plus gemini-3.6-flash , gemini-3.5-flash-lite and two embedding models gem…
-
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform tha…
-
ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack metho…
-
Hackers breach govt webmail while running parallel crypto fraud
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
Last fetch 5m ago · 0 new · 2 source error(s)