The Hacker News Aug 22, 2026, 02:32 PM (UTC)
Read
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will p…
BleepingComputer Aug 22, 2026, 02:14 PM (UTC)
Read
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
BleepingComputer Aug 22, 2026, 01:00 PM (UTC)
Read
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped pr…
SecurityWeek Aug 22, 2026, 08:30 AM (UTC)
Read
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.
The Hacker News Aug 21, 2026, 06:53 PM (UTC)
Read
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the modul…
BleepingComputer Aug 21, 2026, 06:01 PM (UTC)
Read
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
SecurityWeek Aug 21, 2026, 04:27 PM (UTC)
Read
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Secu…
BleepingComputer Aug 21, 2026, 03:55 PM (UTC)
Read
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
The Hacker News Aug 21, 2026, 03:52 PM (UTC)
Read
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2,…
The Hacker News Aug 21, 2026, 03:41 PM (UTC)
Read
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a…
SecurityWeek Aug 21, 2026, 03:11 PM (UTC)
Read
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused…
BleepingComputer Aug 21, 2026, 02:54 PM (UTC)
Read
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
SecurityWeek Aug 21, 2026, 02:34 PM (UTC)
Read
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on Sec…
SecurityWeek Aug 21, 2026, 02:22 PM (UTC)
Read
Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared fir…
BleepingComputer Aug 21, 2026, 02:00 PM (UTC)
Read
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spa…
BleepingComputer Aug 21, 2026, 01:39 PM (UTC)
Read
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
Cybersecurity Ventures Aug 21, 2026, 01:15 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 21, 2026 – Read the full Irish Times Story A special report from The Irish Times declares cyber fraud is big business. According to Cybersecurity Ventures, global cyber…
Infosecurity Magazine Aug 21, 2026, 12:40 PM (UTC)
Read
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks
SecurityWeek Aug 21, 2026, 12:26 PM (UTC)
Read
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.
BleepingComputer Aug 21, 2026, 12:25 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]
Infosecurity Magazine Aug 21, 2026, 12:00 PM (UTC)
Read
An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed
The Hacker News Aug 21, 2026, 11:21 AM (UTC)
Read
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, a…
BleepingComputer Aug 21, 2026, 11:04 AM (UTC)
Read
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]
BleepingComputer Aug 21, 2026, 11:00 AM (UTC)
Read
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
BleepingComputer Aug 21, 2026, 10:10 AM (UTC)
Read
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not…
The Hacker News Aug 21, 2026, 10:03 AM (UTC)
Read
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Cont…
SecurityWeek Aug 21, 2026, 09:23 AM (UTC)
Read
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
SecurityWeek Aug 21, 2026, 08:41 AM (UTC)
Read
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek.
SecurityWeek Aug 21, 2026, 08:12 AM (UTC)
Read
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Patches Exploited Entra ID Vulnerability appeared first on SecurityWeek.
Infosecurity Magazine Aug 21, 2026, 08:00 AM (UTC)
Read
An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI
SecurityWeek Aug 21, 2026, 07:25 AM (UTC)
Read
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.
The Hacker News Aug 21, 2026, 07:04 AM (UTC)
Read
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated at…
The Hacker News Aug 21, 2026, 06:06 AM (UTC)
Read
Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corr…
The Hacker News Aug 20, 2026, 08:22 PM (UTC)
Read
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during co…
The Hacker News Aug 20, 2026, 07:59 PM (UTC)
Read
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia…
BleepingComputer Aug 20, 2026, 05:53 PM (UTC)
Read
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]
The Hacker News Aug 20, 2026, 05:23 PM (UTC)
Read
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed system…
The Hacker News Aug 20, 2026, 04:59 PM (UTC)
Read
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers…
BleepingComputer Aug 20, 2026, 02:39 PM (UTC)
Read
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]
The Hacker News Aug 20, 2026, 02:36 PM (UTC)
Read
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summ…
BleepingComputer Aug 20, 2026, 02:01 PM (UTC)
Read
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]
The Hacker News Aug 20, 2026, 01:48 PM (UTC)
Read
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability…
The Hacker News Aug 20, 2026, 01:35 PM (UTC)
Read
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the…
The Hacker News Aug 20, 2026, 01:24 PM (UTC)
Read
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which re…
Cybersecurity Ventures Aug 20, 2026, 12:58 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 20, 2026 – Read the Full Story An editorial style video uses journalistic narration and storytelling, changing scenes and angles, and b-roll, over plain, unedited or mi…
Infosecurity Magazine Aug 20, 2026, 12:45 PM (UTC)
Read
NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents
Infosecurity Magazine Aug 20, 2026, 12:40 PM (UTC)
Read
Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high
BleepingComputer Aug 20, 2026, 12:14 PM (UTC)
Read
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]
The Hacker News Aug 20, 2026, 12:01 PM (UTC)
Read
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communicatio…
The Hacker News Aug 20, 2026, 11:45 AM (UTC)
Read
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal foru…
The Hacker News Aug 20, 2026, 11:39 AM (UTC)
Read
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stre…
The Hacker News Aug 20, 2026, 11:26 AM (UTC)
Read
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and mil…
The Hacker News Aug 20, 2026, 11:05 AM (UTC)
Read
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft a…
Infosecurity Magazine Aug 20, 2026, 11:00 AM (UTC)
Read
A US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCs
The Hacker News Aug 20, 2026, 10:38 AM (UTC)
Read
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report,…
Infosecurity Magazine Aug 20, 2026, 10:00 AM (UTC)
Read
Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan
Infosecurity Magazine Aug 20, 2026, 09:30 AM (UTC)
Read
Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con
The Hacker News Aug 20, 2026, 08:42 AM (UTC)
Read
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77…
The Hacker News Aug 20, 2026, 06:04 AM (UTC)
Read
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.…
The Hacker News Aug 19, 2026, 07:02 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attac…
Cybersecurity Ventures Aug 19, 2026, 06:27 PM (UTC)
Read
IAM Locks the Door. ITDR Catches the Intruders? – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Aug. 19, 2026 Your employee successfully authenticates. The account is valid. The permissions a…
The Hacker News Aug 19, 2026, 06:06 PM (UTC)
Read
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like…
Cybersecurity Ventures Aug 19, 2026, 04:15 PM (UTC)
Read
The top b2b focused cybersecurity media and event channels listed by number of subscribers and views per video – Steve Morgan, Editor-in-Chief Sausalito, Calif. – Aug. 19, 2026 As one of the world’s largest social media platforms with more than 2.7 billion mon…
Infosecurity Magazine Aug 19, 2026, 03:30 PM (UTC)
Read
The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects
Infosecurity Magazine Aug 19, 2026, 03:00 PM (UTC)
Read
eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra
Infosecurity Magazine Aug 19, 2026, 02:00 PM (UTC)
Read
Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections
The Hacker News Aug 19, 2026, 01:12 PM (UTC)
Read
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: Dr…
Cybersecurity Ventures Aug 19, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 19, 2026 – Watch the Video Binary Defense, a trusted Managed Detection and Response (MDR) and enterprise defense provider, earlier this year announced the launch of Nig…
Infosecurity Magazine Aug 19, 2026, 12:00 PM (UTC)
Read
OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities
The Hacker News Aug 19, 2026, 11:34 AM (UTC)
Read
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay tech…
The Hacker News Aug 19, 2026, 11:30 AM (UTC)
Read
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's inten…
The Hacker News Aug 19, 2026, 11:25 AM (UTC)
Read
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track…
The Hacker News Aug 19, 2026, 11:01 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are li…
Infosecurity Magazine Aug 19, 2026, 10:50 AM (UTC)
Read
The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter
Infosecurity Magazine Aug 19, 2026, 09:30 AM (UTC)
Read
The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations
Infosecurity Magazine Aug 19, 2026, 08:45 AM (UTC)
Read
Cifas data finds account takeover and identity fraud are driving a surge in fraud cases
The Hacker News Aug 19, 2026, 06:01 AM (UTC)
Read
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval throu…
The Hacker News Aug 19, 2026, 05:39 AM (UTC)
Read
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from Reli…
The Hacker News Aug 18, 2026, 05:47 PM (UTC)
Read
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws…
The Hacker News Aug 18, 2026, 05:44 PM (UTC)
Read
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and…
The Hacker News Aug 18, 2026, 04:58 PM (UTC)
Read
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages,…
Infosecurity Magazine Aug 18, 2026, 03:30 PM (UTC)
Read
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Infosecurity Magazine Aug 18, 2026, 03:00 PM (UTC)
Read
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds
Infosecurity Magazine Aug 18, 2026, 02:30 PM (UTC)
Read
Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers
The Hacker News Aug 18, 2026, 12:38 PM (UTC)
Read
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry s…
The Hacker News Aug 18, 2026, 12:38 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Mic…
Cybersecurity Ventures Aug 18, 2026, 12:37 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 18, 2026 – Listen to the Podcast After cybercriminals hacked her network and devastated her finances, career, health, and marriage, Jocelyn King spent years in the cybe…
The Hacker News Aug 18, 2026, 11:30 AM (UTC)
Read
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has…
The Hacker News Aug 18, 2026, 11:20 AM (UTC)
Read
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The…
Infosecurity Magazine Aug 18, 2026, 11:20 AM (UTC)
Read
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume
Infosecurity Magazine Aug 18, 2026, 10:00 AM (UTC)
Read
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
The Hacker News Aug 18, 2026, 09:10 AM (UTC)
Read
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers w…
Infosecurity Magazine Aug 18, 2026, 08:17 AM (UTC)
Read
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks
The Hacker News Aug 18, 2026, 06:34 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed comput…
The Hacker News Aug 17, 2026, 09:03 PM (UTC)
Read
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public proje…
The Hacker News Aug 17, 2026, 06:44 PM (UTC)
Read
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a w…
The Hacker News Aug 17, 2026, 06:22 PM (UTC)
Read
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is…
The Hacker News Aug 17, 2026, 05:41 PM (UTC)
Read
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing m…
Infosecurity Magazine Aug 17, 2026, 03:45 PM (UTC)
Read
UNISOC modem flaw enabled kernel-level code execution through video calls
Infosecurity Magazine Aug 17, 2026, 01:30 PM (UTC)
Read
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
The Hacker News Aug 17, 2026, 01:23 PM (UTC)
Read
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot…
Cybersecurity Ventures Aug 17, 2026, 12:56 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 17, 2026 – Read the Press Release Cybersecurity Ventures launched a Platinum Media Program for VC funded startups, emerging players, and the largest brands in the cyber…
The Hacker News Aug 17, 2026, 11:58 AM (UTC)
Read
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure…
Infosecurity Magazine Aug 17, 2026, 11:15 AM (UTC)
Read
The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act
The Hacker News Aug 17, 2026, 10:52 AM (UTC)
Read
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published Aug…
The Hacker News Aug 17, 2026, 09:29 AM (UTC)
Read
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware r…
Infosecurity Magazine Aug 17, 2026, 09:10 AM (UTC)
Read
Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach
Infosecurity Magazine Aug 17, 2026, 07:30 AM (UTC)
Read
Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026
Infosecurity Magazine Aug 14, 2026, 02:49 PM (UTC)
Read
Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents
Infosecurity Magazine Aug 14, 2026, 01:00 PM (UTC)
Read
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
Cybersecurity Ventures Aug 14, 2026, 12:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 14, 2026 – Watch the YouTube video “One thing is really clear in all the CISO conversations I’ve had – is that everybody is worried about the number of CVEs (common vul…
Krebs on Security Aug 14, 2026, 11:24 AM (UTC)
Read
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has re…
Infosecurity Magazine Aug 14, 2026, 10:45 AM (UTC)
Read
AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data
Infosecurity Magazine Aug 14, 2026, 07:30 AM (UTC)
Read
Threat intelligence researchers from Broadcom revealed that a known Chinese APT group may be linked to a lucrative crypto fraud operation
Infosecurity Magazine Aug 13, 2026, 03:30 PM (UTC)
Read
CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data
Infosecurity Magazine Aug 13, 2026, 03:00 PM (UTC)
Read
Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028
Infosecurity Magazine Aug 13, 2026, 02:00 PM (UTC)
Read
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it
Cybersecurity Ventures Aug 13, 2026, 12:45 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 13, 2026 – Watch the YouTube video Kai was founded on a simple and radical conviction: you cannot win a machine-speed war with human-speed defenses. Not with more tools…
Infosecurity Magazine Aug 13, 2026, 12:35 PM (UTC)
Read
The White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attribution risks
Infosecurity Magazine Aug 13, 2026, 09:30 AM (UTC)
Read
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Infosecurity Magazine Aug 13, 2026, 08:30 AM (UTC)
Read
The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach
Infosecurity Magazine Aug 12, 2026, 02:30 PM (UTC)
Read
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Infosecurity Magazine Aug 12, 2026, 01:35 PM (UTC)
Read
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Infosecurity Magazine Aug 12, 2026, 01:15 PM (UTC)
Read
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
Cybersecurity Ventures Aug 12, 2026, 12:53 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 12, 2026 – Listen to the podcast Cybercrime Magazine Podcast Host Scott Schober recently interviewed Dustin Holden, a reformed hacker who pled guilty to computer fraud…
Infosecurity Magazine Aug 12, 2026, 12:30 PM (UTC)
Read
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research
Infosecurity Magazine Aug 12, 2026, 09:30 AM (UTC)
Read
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
Infosecurity Magazine Aug 12, 2026, 08:12 AM (UTC)
Read
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
Krebs on Security Aug 11, 2026, 09:28 PM (UTC)
Read
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Infosecurity Magazine Aug 11, 2026, 03:00 PM (UTC)
Read
Six npm packages queried an Ethereum wallet to locate C2 infrastructure
Infosecurity Magazine Aug 11, 2026, 02:30 PM (UTC)
Read
Cursor fixed a pre-trust code execution path in three days then closed the report as informative
Infosecurity Magazine Aug 11, 2026, 12:00 PM (UTC)
Read
Police and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week also
Infosecurity Magazine Aug 11, 2026, 11:30 AM (UTC)
Read
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models
Infosecurity Magazine Aug 11, 2026, 10:45 AM (UTC)
Read
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius
Infosecurity Magazine Aug 11, 2026, 09:00 AM (UTC)
Read
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns
Infosecurity Magazine Aug 11, 2026, 08:00 AM (UTC)
Read
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
Infosecurity Magazine Aug 10, 2026, 03:30 PM (UTC)
Read
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data
Infosecurity Magazine Aug 10, 2026, 02:30 PM (UTC)
Read
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files
Infosecurity Magazine Aug 10, 2026, 10:45 AM (UTC)
Read
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports
Infosecurity Magazine Aug 10, 2026, 10:00 AM (UTC)
Read
A macOS malware variant has been detected stealing crypto, passwords and more
Infosecurity Magazine Aug 10, 2026, 09:00 AM (UTC)
Read
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange