What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,945 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 32m ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 11h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
New infosec products of the week: August 21, 2026
Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced…
-
Spark trims headcount ahead of split into two units
Spark has reduced its headcount by over 600 people in the past year as it prepares to split into two divisions. In its annual report, released alongside its 2026 financial year results , Spark reported overall headcount of 3,416 e…
-
Intermediary Liability in Brazil: The Intricate Path Ahead
Brazil's new internet intermediary liability regime is underway. The implementation of changes established by the Supreme Court includes notice and takedown mechanisms and duty of care obligations. Caution is crucial as these meas…
-
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and execu…
-
Intelligence Insights: August 2026
Debuts, departures, and danger on the blockchain in this month’s edition of Intelligence Insights.
-
China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?
This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon
-
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks acro…
-
What We Missed: Delta Flight Disrupted With Wi-Fi Hack
In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest hack back strategy.
-
Red Teaming vs. Pentesting: What's the Difference?
Penetration testing and red teaming are not the same engagement. They don't answer the same question, they don't run on the same timeline, and picking the wrong one at the wrong stage of your program doesn't just waste your budget…
-
Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist
Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest pri…
-
Is Cyber missing the Marque?
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensiv…
-
I Only Do Anything Once
A figure carrying a crate around a deep circular rut worn by dozens of layered footprints, with an angular slot at the rut's edge and one clean line departing from it/images/i-only-do-anything-once.webp/images/i-only-do-anything-o…
-
N-able Bug Exposes Password Vault Master Keys
The popular Passportal password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?
-
Senators press TikTok over withholding of safety features for some users
In a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users."
-
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress.
-
A shot-scraper-style JSON API on Bun 1.4's new Bun.WebView
Research: A shot-scraper-style JSON API on Bun 1.4 s new Bun.WebView Today saw the long awaited release of Bun 1.4 , the first stable version since the infamous Rust rewrite a few months ago . Interestingly, the Rust rewrite was d…
-
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ s…
-
Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks
Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.
-
Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it. The post Surveillance – Everything You Wanted to Know, But Were Afraid to Ask appeared first on SecurityWeek .
-
What we know so far about the hacking campaign against US water systems
Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.
-
'Grandoreiro' Malware Resurfaces With Mexico Campaign
The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.
-
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek .
-
Editorial Style Videos Are The Cutting Edge Of Cybersecurity Journalism
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 20, 2026 – Read the Full Story An editorial style video uses journalistic narration and storytelling, changing scenes and angles, and b-ro…
-
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal read…
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cr…
-
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands …
-
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium…
-
New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]
-
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detec…
-
Police Are Hiding Their Use of Flock Surveillance Cameras
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don t want them to know. A usage policy for the automated licens…
-
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions a…
-
Microsoft says August Windows updates may cause gaming issues
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]
-
Researchers find a loophole that lets expired credit cards make unauthorized payments
A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and pr…
-
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
A nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.
-
Codex Curl Test Blog Post 20260820150831
Codex curl lifecycle test content.
-
Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.
In a handful of known cases, large social media companies have privately pushed back against Immigration and Customs Enforcement (ICE) subpoenas when the agency tried to unmask anonymous users who tracked immigration activities or…
-
Mobile service revenue up, IT services down for Spark in FY26
Spark New Zealand has seen a return to revenue growth for its mobile services in its 2026 financial year, along with a boost to its cash flow and balance sheet following the sale in its data centre business. However, revenues were…
-
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 time…
-
Electronic health record company CareCloud says 3.7 million people affected by breach
Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health…
-
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]
-
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar…
-
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar…
-
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.
-
📍 The Sneaky Code Tracking App Users | EFFector 38.15
Your location isn't just a pin on a map—it can expose some of the most intimate details about your life. The value of this information to advertisers and others has turned the location data business into a multi-billion dollar ind…
-
YouTube Is The New Powerhouse For Marketing To CISOs And MSSPs
The top b2b focused cybersecurity media and event channels listed by number of subscribers and views per video – Steve Morgan, Editor-in-Chief Sausalito, Calif. – Aug. 19, 2026 As one of the world’s largest social media platforms …
-
A California county wants to hire Tina Peters to help run its elections
After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its elections appear…
-
US charges Iranian hackers over $3.4 billion intellectual property theft
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]
-
Intezer adds native response automation without separate SOAR
Intezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly inside the Intezer platform. Workflows brings response into the same platfor…
-
Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.
-
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon Secure Your Co…
Last fetch 14m ago · 2 new · 2 source error(s)