What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,936 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 7h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 11h ago
-
Cybersecurity jobs available right now: September 1, 2026
Security Engineer, PSO Google USA On-site View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Se…
-
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT
Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.
-
RMM Tools for MSPs: Features, Risks & How to Stay Secure
Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.
-
Introducing wrapture
Introducing wrapture New from Graham Dumpleton (of wrapt , mod_wsgi, and New Relic's Python agent fame), who describes Wrapture as taking the monkeypatching ideas from wrapt and extending them to apply to testing and tracing at th…
-
EFF to Governor Newsom: Veto California’s AB 1709
The California legislature passed Assembly Bill 1709 (A.B. 1709) today, which functions as a sweeping ban on social media use for young people under the age of 16. This well-intentioned, but deeply flawed piece of legislation, cut…
-
AoFrio hires for APAC SaaS growth
NZX-listed smart refrigeration tech company AoFrio has appointed Peg Tsai to the role of commercial and customer success manager to help drive customer growth across the Asia Pacific (APAC) and East Asia region Based in Auckland, …
-
Quoting Andrew Digby
325 #kakapo! The chicks from this year's record breeding season are now juveniles and so have been added to the population. In 1995 there were just 51 kākāpō left. Recovery of critically endangered species is possible with sustain…
-
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.
-
Five plead guilty in latest federal ATM jackpotting case
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
-
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
-
The Guardrails Debate: Security Researcher Changes His Mind
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
-
Fraudsters steal $6 million from Tectonic crypto platform after inflating token price
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.
-
Doxxing Safety Part II: Incident Response
Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, t…
-
Doxxing Safety Pt I: Prevention and Footprint Management
Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use …
-
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
-
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.” The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity h…
-
Is Someone Hacking DoD Refrigerators?
It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force …
-
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying susp…
-
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. [...]
-
Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections
Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should m…
-
Who’s the fairest, most Patagonian, and most contemplative of them all?
It s time to move on to fuller accounts of our July-August adventures in Kyrgyzstan and the Sayan Mountains, and I figure that their telling should go in chronological order: first, the Karavshin trek in the Pamir Mountains, and t…
-
Think twice before installing this device promising free movies
In exchange for free stuff, devices make home connections part of a proxy network.
-
Onyxia Expands Cross-Industry Benchmarks To Five Sectors
Starting today, industry benchmarks in Onyxia’s Operational Resilience Platform cover five sectors: IT & Tech, Financial Services, Healthcare, Critical Infrastructure, and Retail & eCommerce – expanded from IT and Finance.
-
LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?
This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch! EFF answers all the queer digital rights questions you submit to us through our LGBT Q A . You asked us: What…
-
State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
-
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
-
File servers are here to stay. Here’s how to manage them securely
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and m…
-
Huntress API Update: New Endpoints, Webhooks, and Automation
The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the nam…
-
31th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and Ea…
-
Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.
-
Slovenian casinos reopen after cyberattack knocked gaming systems offline
One of Slovenia’s largest gambling and tourism groups has begun reopening its casinos after a cyberattack forced them to shut down for several days.
-
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to t…
-
AWS Console Private Access can block sign-ins to personal accounts
The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, …
-
Boston Scientific Still Recovering From Cyberattack
The company has called in CrowdStrike and others to investigate the attack that caused global network disruption. The post Boston Scientific Still Recovering From Cyberattack appeared first on SecurityWeek .
-
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]
-
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared …
-
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
-
Nigerians extradited to US for sextortion, deaths of two teens
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]
-
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linu…
-
Microsoft asks users to ignore 'Antivirus is turned off' errors
Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]
-
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among …
-
The Link Between Your Workplace Situation and Your Mental Health
A large purple hand holds a pendulum swinging one man between standing arms-wide on a ship's prow in warm sienna and collapsed head-in-hands in a purple office chair/images/workplace-situation-mental-health.webp/images/workplace-s…
-
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclo…
-
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
-
Cybersecurity Has a Design Problem. And We’re Blaming the Users for It.
I ve stood in a car park more times than I can count, phone in hand, running late for a train, only to find a machine that takes cards but not cash, and is out of order anyway. And, a app I have to download, with a location code t…
-
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to th…
-
Brave browser adds email aliases to help users evade tracking
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]
-
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tu…
-
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tu…
Last fetch 16m ago · 0 new · 2 source error(s)