What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,037 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Curiouser and Curiouser
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
-
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]
-
AI 'watermark removers' flood the web. Almost none can prove they work.
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools'…
-
AI’s ‘middle class’ has gotten dramatically better at hacking
As frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models. The post AI’s ‘middle class’ has gotten dramatically better at hacking …
-
Flock tightens privacy controls amid scandals over officer abuse
All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.
-
Critical VMware vCenter RCE flaw exploited for reverse SSH access
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
-
New Mirai variant adds stealth capabilities to notorious botnet code
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
-
Researchers find AI-powered hacking tools for sale in underground forums
A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.
-
Trezor discloses data breach affecting nearly 14,000 customers
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]
-
US government will let private companies hack criminal gangs
The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.
-
New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Res…
-
Education Under Attack: The Pattern Behind Recent University Breaches
Four university breaches, one root cause: misconfiguration. See the pattern behind 2026's higher ed cyberattacks and how to fix the gap.
-
Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks
AI agents are driving demand for cybersecurity tools as companies confront increasingly sophisticated threats, CEO Chuck Robbins said.
-
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
Significant cybersecurity M A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek .
-
White House authorizes private US companies to hack foreign criminal networks
President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US governmen…
-
Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .
-
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, befor…
-
DataGrout helps enterprises control AI usage, governance and LLM costs
SelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout’s mission is to drive token reduction for ag…
-
AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spr…
-
Brazil orders Discord to suspend livestreaming after teen suicide
Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.
-
White House taps security firms for offensive hack-back operations
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime orga…
-
Trump taps cyber firms to go on offensive against criminals
The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.
-
A10 Networks introduces AI Gateway to secure and manage enterprise AI
A10 Networks has announced the general availability of the A10 AI Gateway, a centralized, intelligent control plane that gives organizations unified routing, cost management, and governance across every AI agent, application and l…
-
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Micr…
-
Fake Refund Scam Hits Shopify Shop App Users
A Shopify fake refund scam has been making the rounds over the past few months, targeting Shopify’s Shop app users directly within the app. Here’s what to know.
-
The State of Ransomware Q2 2026
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State …
-
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek .
-
Kai: The Agentic AI Platform Built To Fight AI-Enabled Attacks
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 13, 2026 – Watch the YouTube video Kai was founded on a simple and radical conviction: you cannot win a machine-speed war with human-speed…
-
Germany moves to give spy agencies hacking and sabotage powers
Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the coun…
-
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme…
-
WhatsApp rolls out new feature that flags potential scam messages
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]
-
Trump turns to private sector in offensive hacking operations memo
One expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense. The post Trump turns to private sector in offensiv…
-
North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems …
-
Venture Firm Team8 Secures Additional $365 Million
The Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek .
-
Separating AI’s Technological Problems from Its Capitalism Problems
This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press . AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early yea…
-
RingCentral: 1,596,490 accounts breached
Data exposed: Email addresses, Names, Phone numbers, Physical addresses. In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subs…
-
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on Security…
-
Searchlight Cyber combines exposure and threat intelligence in new PTEM platform
Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to…
-
153GB of stolen credentials surface after LiteLLM supply chain attack
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtain…
-
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
-
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
-
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared fi…
-
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.
-
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers Crosshairs appeared first on SecurityWeek .
-
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ShieldBreak appeared first on SecurityWeek .
-
Armored Likho expands its cyber-espionage toolkit
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
-
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA s Known Exploited Vulnerabilities…
-
Belgium's eID Authentication Opens Citizen Accounts to RCE
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
-
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a …
-
Four corporate investigation mistakes organizations make under pressure
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Acce…
Last fetch 8m ago · 0 new · 2 source error(s)