What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,948 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 12h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon Secure Your Co…
-
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never …
-
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
-
US charges Iranians for sprawling hacking campaign on government agencies, universities
The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.
-
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a…
-
US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek .
-
Microsoft fixes known issue causing Windows Defender crashes
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]
-
ICE Collecting DNA Samples
ICE collected nearly a million DNA samples last year.
-
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
-
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
The people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.
-
Brinqa acquires PlexTrac to bring validated remediation to exposure management
Brinqa has announced its acquisition of PlexTra, adding the ability to verify that remediation efforts have actually worked. The combined capabilities uniquely position Brinqa to identify and prioritize the exposures that matter m…
-
Windows 11 24H2 Home and Pro reach end of support in 2 months
Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]
-
Cyberattack forces UT San Antonio to delay start of fall semester
The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now st…
-
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malwar…
-
Banks look for fraud signals in customer behavior
Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requ…
-
NCSC reports 19% spike in serious cyber security incidents in Q2
The National Cyber Security Centre (NCSC) has reported a 19 per cent increase in cyber security incidents with the potential to cause national harm in the second quarter of 2026. This is according to the NCSC’s latest Cyber Securi…
-
Ninth Circuit Ruling Will Force Online Platforms That Host User Speech to Fight Lengthy and Costly Lawsuits Before They Are Dismissed Under Section 230
A federal appeals court just made it harder for online services, big and small, to get lawsuits over user speech dismissed early. In California v. Meta , a Ninth Circuit three-judge panel held that the lower court’s denial of Sect…
-
Tech NZ calls for urgent action to take local quantum and photonics tech global
Industry body Tech New Zealand has launched a manifesto, along with a local tech community, with the aim to help boost the country’s quantum and photonics sectors. According to the group, New Zealand has deep roots in quantum and …
-
Michael Johnson returns to Transaction Network Services as global lead for payments division
New Zealander Michael Johnson has rejoined US-based payment and network solutions vendor Transaction Network Services (TNS), coming into the role of global managing director for its payments market business. Described as a payment…
-
ZKP’s Aren’t Age Verification Silver Bullets
Age verification (laws and regulations requiring platforms and websites to assure or estimate that a user seeking to use an online service is of a certain age) is everywhere. At the time of writing, about half the states in the US…
-
Mojo🔥 is now open source
Mojo🔥 is now open source Mojo🔥 is now open source The Mojo programming language has been promising an open source release since May 2023 . Last week they shipped their 1.0 and today they have followed through on that original prom…
-
DOJ charges 17 people in Iran-backed hacking campaign against US
Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.
-
Comcast turns your Xfinity WiFi into a home motion detector
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
-
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated Augus…
-
CISOs Break Their Silence in 'Declassified' Docuseries
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.
-
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure throu…
-
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure throu…
-
Berlin cuts two state ministries off government network after security breach
The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as…
-
University of Texas forced to take systems offline in San Antonio after cyberattack
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in resp…
-
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.
-
Your Controls Block Known Attacks. What About the Behavior?
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral test…
-
Unconventional Thought Is the Differentiator
A rigid purple lattice of identical cells cracking and warping into warm organic curves around a single figure whose chest emits an irregular waveform/images/unconventional-thought-differentiator.webp/images/unconventional-thought…
-
NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation
NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target toward…
-
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.
-
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control inf…
-
Download: 2026 Credential Risk Report
85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where c…
-
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat und…
-
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco…
-
Microsoft tests faster Windows File Explorer, new context menu
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
-
The Cop Who Took On Flock
After Noel Pichardo called out his city's embrace of Flock surveillance cameras, he was subjected to five internal affairs investigations in less than two years.
-
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
-
Hacker claims millions of records stolen from corporate Azure tenants
A threat actor known as TheHatman claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), acc…
-
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
-
Cisco makes changes to its channel leadership ranks
Cisco has made several changes to its Australia and New Zealand (A/NZ) leadership team, with long-time channel chief Rodney Hamill moving into the role of managing director, South, covering Victoria, the ACT, and Tasmania in Austr…
-
Spark appoints former Mercury boss Vince Hawksworth as chair
Spark New Zealand has appointed non-executive director former Mercury Energy CEO Vince Hawksworth as the new chair of its board. In a statement to the NZX, Spark said Hawksworth will take over the reins from Justine Smyth, who has…
-
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
-
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
-
How to Get Started in Cybersecurity 2026
A person vaulting on a machine lever toward a glowing keyhole/images/how-to-get-started-in-cybersecurity-2026.webp/images/how-to-get-started-in-cybersecurity-2026.webp I've been writing versions of this guide since 2008. The most …
-
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity compan…
-
Poland probes MyDr healthcare software breach potentially affecting 19 million people
MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measu…
Last fetch just now · 1 new · 2 source error(s)