What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,937 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 8h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 12h ago
-
Breach of Confidence — 28 August 2026
I ve started bringing a small notebook everywhere. Not because I m particularly organised, but because I ve realised the best analogies arrive whilst I m doing something completely unrelated to security. This week it happened at a…
-
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
Ugh : A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the Squidpocalypse of 26. Tha…
-
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.
-
68-year-old imprisoned after making $1.3 million by pirating IPTV services
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]
-
The Good, the Bad and the Ugly in Cybersecurity – Week 35
Authorities disrupt global cybercrime rings, attackers abuse DocuSign in NovaCookies phishing, and Spark RAT targets Cambodia with vulnerable drivers.
-
Teach Yourself to Phish | Huntress
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
-
A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
-
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. T…
-
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
-
You Need Cyber Deception for OT
The frustrating reality after an OT cyberattack: no data, no trail, and no history.
-
Huntress Employee Spotlight: Meet Ben Bernstein
Meet Ben Bernstein, cybersecurity advisor and security badass, in this employee spotlight. See how he makes a difference every day.
-
Cybercrime Statistics Worldwide: The 2026 Global Picture
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 28, 2026 – Read the full story from SWIF Cybersecurity Ventures predicted that global cybercrime damages would hit $10.5 trillion in 2025,…
-
Key Reasons Why Identity Fabric Matters in 2026
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, …
-
North Korean remote workers are broadening their job hunt beyond IT
North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession. “DPRK w…
-
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.
-
Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping
Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone. “When you visit a website or use an app, even if…
-
Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. [...]
-
How an Atlanta Suburb Ended Up Sharing Flock Data With More Than 2,000 Organizations
Alpharetta, Georgia, cops share data with thousands of Flock users, ranging from federal agencies to a fish and wildlife commission. The reasons why show how vast—and invasive—the network has become.
-
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Futur…
-
EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity
EFF, Access Now, and Data Privacy Brasil are putting forward recommendations to strengthen robust privacy and data protection safeguards in the context of Brazil's elections. The recommendations stress the close relationship betwe…
-
Advantage celebrates 40 years with $10K startup tech prize
IT and cybersecurity provider Advantage is celebrating its 40th anniversary by offering one emerging New Zealand business a year of expert technology and cybersecurity support. The Advantage Head Start prize will provide an eligib…
-
SIEM: Centralize Like You Mean It, Federate Like You Have To
(by Anton Chuvakin Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?” — an admittedly incomplete-thought blog with a scary premise: after 20+ years o…
-
Chinese Routers Sold Worldwide Contain Backdoors
An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
-
A Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her Friend
After an affair with a fellow police officer ended, a Georgia cop used Flock to track her movements—and those of a man whose vehicle often showed up near hers, internal investigation records show.
-
‘Huge’ expansion opportunity in A/NZ for Appian and its partners
The Australia and New Zealand (A/NZ) region has the potential to provide process automation platform Appian for a “huge” expansion opportunity. In turn, this provides the vendor’s partners with the chance for their own growth. Acc…
-
What’s new in Microsoft Security: August 2026
This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post …
-
Finland appeals court revives case against Eagle S Officers over cable breaks
The appeals court sent the case back to the Helsinki District Court to be heard on its merits, although the three men, who had previously been detained in Finland, have since left the country.
-
Chinese and Russian spies stepping up cyberattacks, German companies report
Foreign intelligence services, particularly those from China and Russia, are increasingly behind cyberattacks on German companies, according to a new survey of the country’s private sector.
-
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
The two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile. The post Two alleged TeamPCP members arrested and charged after months of software supply-chain…
-
How Threat Research and MDR Help SMBs Build a Defensive Edge
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human exper…
-
New Huntress Managed ITDR Dashboard: Faster Identity Investigations
Huntress’ redesigned Managed ITDR dashboard adds Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search for faster investigations.
-
Two alleged TeamPCP hackers arrested over global supply chain attacks
Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. The…
-
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs
Introduction Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity th…
-
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks. [...]
-
Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
A spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an email address.
-
Australia charges two men for TeamPCP supply-chain hacking spree
Two men in Australia were charged Wednesday over their alleged membership in TeamPCP, the cybercrime group blamed for one of the most damaging hacking campaigns of the past year.
-
Australia Arrests 2 Alleged TeamPCP Hackers
Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison. The post Australia Arrests 2 Alleged TeamPCP Hackers appeared first on SecurityWeek .
-
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
Compromised IoT devices were used in a yearslong campaign against key sectors and U.S. government agencies.
-
Women In Cybersecurity Report, Summer 2026: Black Hat(HER) Special Edition
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 27, 2026 – Watch the Video The Women in Cybersecurity Report, hosted by Cybercrime Magazine Deputy Editor Amanda Glassner, highlights the …
-
Microsoft rolls out fix for Windows 11 crashes, gaming issues
Microsoft has started rolling out a permanent fix for a known issue that causes system crashes and gaming issues on Windows 11 devices. [...]
-
Webinar: How Google Workspace breaches happen and what to do next
Google Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines real-world breaches, what happens during the critical first hours, and the…
-
Cyberattack causes network outage at Boston Scientific, disrupts global operations
Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations. Boston Scientific makes devices for minimally invasive procedures, includi…
-
Russian Hackers Phish EU Officials Over Messaging Apps
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.
-
CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader. The post CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite appeared firs…
-
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appe…
-
Cyberattack Causes Global Disruption at Boston Scientific
The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders. The post Cyberattack Causes Global Disruption at Boston Scientific appeared first on SecurityWeek .
-
JavaScript obfuscation: From party trick to phishing kit
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
-
US Navy tells sailors and their families: scrub your social media, enemies are watching
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they a…
-
US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on …
-
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-se…
Last fetch 15m ago · 0 new · 2 source error(s)