FOE
EFF Deeplinks
EFF to Governor Newsom: Veto California’s AB 1709
FOE
The Register (Security)
Healthcare cyberattacks hit pacemakers and millions of patient records
FOE
Dark Reading
Anthropic Users Hit by Infostealer Attacks, Session Thefts
FOE
Bleeping Computer
Cronos blockchain restarts after $74 million Tectonic exploit
FOE
Dark Reading
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
FOE
CSO Online
Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off
FOE
Dark Reading
The Guardrails Debate: Security Researcher Changes His Mind
FOE
SANS Internet Storm Center
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)
FRIEND
EFF Deeplinks
EFF to Courts: Don’t Rewrite Copyright Over AI Hype
FOE
The Register (Security)
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
FOE
Bleeping Computer
Microsoft warns of TerminalFix attacks deploying reverse tunnels
FOE
The Register (Security)
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
FOE
Schneier on Security
Is Someone Hacking DoD Refrigerators?
FOE
EFF Deeplinks
Doxxing Safety Pt I: Prevention and Footprint Management
FOE
EFF Deeplinks
Doxxing Safety Part II: Incident Response
FOE
Dark Reading
AI Model Rules Are Not Security Controls
FOE
The Hacker News
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
FOE
Bleeping Computer
Microsoft Exchange Online outage causes email failures, auth issues
FOE
Bleeping Computer
OpenAI confirms ChatGPT outage as users report errors
FOE
EFF Deeplinks
Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections
FOE
Ars Technica (Security)
Think twice before installing this device promising free movies
FOE
The Register (Security)
Anthropic cracks down on hijacked user accounts mining AI tokens
FRIEND
EFF Deeplinks
LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?
FOE
Bleeping Computer
Chinese Fire Ant hackers turn Cisco routers into spying platforms
FOE
SecurityWeek
Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
FRIEND
Bleeping Computer
File servers are here to stay. Here’s how to manage them securely
FOE
SecurityWeek
ServiceNow Patches 3 Critical Code Injection Vulnerabilities
FOE
The Hacker News
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
FOE
Bleeping Computer
Berlin confirms data theft after Rhysida ransomware attack claims
FOE
SecurityWeek
McKesson Confirms Data Breach as Attacker Deadline Looms
FOE
SecurityWeek
What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
FOE
The Hacker News
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
FOE
SecurityWeek
Anthropic Warns Claude Users of Infostealer Malware Infections
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: This happens a lot here
FOE
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FOE
The Hacker News
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
FOE
The Hacker News
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
FOE
SecurityWeek
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
FOE
CSO Online
OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses
FOE
Schneier on Security
Hiding Prompt Injection in Legal Filing
FOE
SecurityWeek
Boston Scientific Still Recovering From Cyberattack
FOE
SecurityWeek
Extortion Group Claims Manchester Airports Group Data Breach
FOE
CSO Online
Trusted Chrome, Edge extensions weaponized in supply chain campaign
FOE
Bleeping Computer
Nigerians extradited to US for sextortion, deaths of two teens
FOE
SecurityWeek
Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’
FOE
The Hacker News
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
FOE
SecurityWeek
Berlin Won’t Pay Extortion Group Claiming Data Theft
FRIEND
Bleeping Computer
Microsoft asks users to ignore 'Antivirus is turned off' errors
FOE
CSO Online
Is your cloud security strategy ready for AI’s looming threat?
FOE
The Hacker News
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
FOE
SecurityWeek
More Details Emerge on Exploited PaperCut Vulnerabilities
FOE
Risky Business News
Risky Bulletin: Dutch intel services to get extensive new powers
FOE
CISA KEV
CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
FOE
CISA KEV
CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability
FOE
Bleeping Computer
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FOE
Bleeping Computer
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
FOE
Bleeping Computer
Chrome Web Store extensions caught stealing crypto, browser data
FOE
The Register (Security)
Turns out Brits would quite like their private messages to stay private
FOE
The Hacker News
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
FRIEND
SANS Internet Storm Center
YARA-X 1.20.0 Release, (Sun, Aug 30th)
FOE
Bleeping Computer
Anthropic is cutting Claude Code's current weekly limits by 17%
FOE
The Hacker News
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
FRIEND
Bleeping Computer
Brave browser adds email aliases to help users evade tracking
FOE
SecurityWeek
Hasbro Data Breach Exposed Employee Personal Information
FRIEND
Dark Reading
[Virtual Event] Building a Secure AI Strategy for the Enterprise
FRIEND
Dark Reading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
FOE
CSO Online
ServiceNow patches three maximum severity flaws that could put enterprise data at risk
FOE
Bleeping Computer
McKesson discloses breach after ShinyHunters claims patient data theft
FOE
The Hacker News
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
FOE
The Register (Security)
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
FOE
The Hacker News
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
FOE
Dark Reading
Hundreds of OpenAI Agents Invaded Hugging Face Servers
FOE
Bleeping Computer
PaperCut releases second emergency patch for exploited flaws
FOE
CSO Online
GPUThor hardware attack can root Nvidia GPU systems
FOE
Dark Reading
Offensive Security Investments Surge as AI Threats Increase
FOE
Bleeping Computer
GiveWP WordPress donation plugin flaw lets hackers execute server commands
FOE
The Hacker News
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
FRIEND
The Hacker News
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
FOE
The Hacker News
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
FOE
SecurityWeek
In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
FOE
The Hacker News
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
FOE
The Register (Security)
US government snitch-finder pleads guilty to leaking state secrets to foreign spies
FOE
Bleeping Computer
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
FOE
Dark Reading
You Need Cyber Deception for OT
FOE
SecurityWeek
ATF Confirms Cyber Incident After Ransomware Group Claims Attack
FOE
Dark Reading
Defining an AI Kill Switch Is Hard, But Necessary
FOE
Dark Reading
The Vulnpocalypse Is Repricing the Bug Bounty Economy
FOE
Bleeping Computer
Over 8,300 Gitea servers vulnerable to code execution attacks
FOE
SecurityWeek
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
FOE
The Hacker News
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It knows everything
FOE
Bleeping Computer
Toy-making giant Hasbro disclose data breach affecting employees
FRIEND
The Hacker News
Key Reasons Why Identity Fabric Matters in 2026
FOE
The Register (Security)
CISA: Most exploited vulnerabilities should have been eradicated decades ago
FOE
The Hacker News
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
FOE
Ars Technica (Security)
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
FOE
Schneier on Security
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
FRIEND
SecurityWeek
Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
FOE
The Register (Security)
Industry that built the problem offers to sell you the solution
FOE
The Hacker News
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
FOE
SecurityWeek
Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
FOE
Bleeping Computer
ServiceNow warns of three max severity security vulnerabilities
FOE
CSO Online
The first 24 hours of an AI agent security incident
FOE
The Hacker News
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
FRIEND
CSO Online
Beyond compliance: Designing systems that earn customer trust
FOE
SecurityWeek
PaperCut Releases Emergency Patch for Exploited Zero-Day
FOE
The Hacker News
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
FRIEND
CSO Online
CTEM can give your security team a contextual edge
FOE
The Hacker News
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
FOE
SANS Internet Storm Center
Some Malicious PE Stats, (Thu, Aug 27th)
FOE
The Register (Security)
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
FOE
Risky Business News
Risky Bulletin: Two TeamPCP members arrested in Australia
FRIEND
EFF Deeplinks
EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity
FOE
The Register (Security)
Australian cops cuff alleged TeamPCP masterminds
FOE
Bleeping Computer
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
FOE
The Register (Security)
CRPx0 hacking service for dummies claims victim count more than quintupled
FOE
EPIC
EPIC Urges First and Seventh Circuits to Protect Voter Privacy and Refuse DOJ’s Voter Roll Demand
FOE
Dark Reading
Chinese Routers Sold Worldwide Contain Backdoors
FOE
The Register (Security)
AI girlfriend review site's secrets were exposed to the world for three weeks
FOE
The Hacker News
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
FRIEND
SpecterOps
Why SpecterOps Signed OpenAI’s Call for Collective Cyber Defense
FOE
Dark Reading
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
FOE
The Register (Security)
Omarchy distro gains serious backing
FOE
Bleeping Computer
PaperCut warns of NG, MF flaw exploited in zero-day attacks
FOE
Bleeping Computer
Manchester Airports Group says hackers stole travelers' data
FOE
SpecterOps
Cleartext Credential Recovery in ServiceNow
FOE
The Register (Security)
ATF responds to 'major' cybersecurity incident after ransomware gang's claims
FOE
The Hacker News
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
FOE
The Hacker News
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: We could be more direct
FRIEND
The Register (Security)
Schrödinger's backup: not actually recovered until you try to restore IT
FOE
SecurityWeek
Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
FOE
Ars Technica (Security)
Claude, Codex, and Hermes installed unowned code inside corporate networks
FRIEND
Bleeping Computer
How Threat Research and MDR Help SMBs Build a Defensive Edge
FRIEND
Bleeping Computer
Android 17 adds ECH support to make web browsing harder to track
FOE
The Hacker News
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
FOE
Bleeping Computer
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
FOE
Ars Technica (Security)
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
FOE
The Register (Security)
Cybercrooks jet off with Manchester Airports Group customer data
FOE
SecurityWeek
Australia Arrests 2 Alleged TeamPCP Hackers
FRIEND
Bleeping Computer
Microsoft rolls out fix for Windows 11 crashes, gaming issues
FRIEND
Bleeping Computer
Webinar: How Google Workspace breaches happen and what to do next
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Upside down frowny face
FOE
CISA Alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
Rockwell Automation OTTO Fleet Manager
FOE
CISA Alerts
Xiiaozet LK100W
FOE
CISA Alerts
All-Line Equipment Company Fuel-Boss
FOE
CISA Alerts
Applied Systems Engineering ASE2000 V2 Communications Test Set
FOE
CISA Alerts
Ebyte NA111-M
FOE
CISA Alerts
Mitsubishi Electric Multiple FA Products (Update D)
FOE
SecurityWeek
OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
FOE
The Hacker News
Learn How to Build Security Operations Ready for AI-Powered Attacks
FOE
The Hacker News
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
FRIEND
SecurityWeek
Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security
FOE
CSO Online
AI can be made to read an email much differently than you do
FRIEND
The Hacker News
What the Data Says About AI in Security Operations in 2026
FOE
Dark Reading
Russian Hackers Phish EU Officials Over Messaging Apps
FRIEND
SecurityWeek
CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
FOE
Bleeping Computer
Carhartt data breach exposes information of 12.9 million accounts
FOE
Krebs on Security
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
FOE
The Hacker News
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
FOE
SecurityWeek
Cyberattack Causes Global Disruption at Boston Scientific
FRIEND
SecurityWeek
The Future of AI-Driven Security Depends on Complete Data
FOE
SANS Internet Storm Center
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
FOE
Schneier on Security
LLM-Based Social Engineering Scams
FOE
The Hacker News
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
FOE
Bleeping Computer
CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
FOE
SecurityWeek
US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
FOE
CSO Online
Critical infrastructure’s long, undefended tail exposed by UK energy attack
FOE
Bleeping Computer
ATF confirms “major incident” after recent Qilin breach claims
FOE
The Hacker News
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
FOE
SecurityWeek
Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
FOE
The Hacker News
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
FOE
Risky Business News
China's AI-Enabled APT Operations Are Getting Interesting
FOE
SecurityWeek
Recent Citrix NetScaler Vulnerability Exploited in the Wild
FOE
The Register (Security)
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
FRIEND
Sophos News
A call for collective action on cyber defense
FOE
CISA KEV
CVE-2023-49105: ownCloud Improper Authentication Vulnerability
FOE
CISA KEV
CVE-2026-66384: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
FOE
CISA KEV
CVE-2026-53362: Linux Kernel Unspecified Vulnerability
FOE
Sophos News
The State of Ransomware in Education 2026
FOE
The Register (Security)
OpenAI explains how its naughty AI agents attacked Hugging Face
FOE
The Register (Security)
OpenAI explains how its AI agents did crime and attacked Hugging Face
FOE
Bleeping Computer
Critical Avada WordPress theme flaw enables zero-click RCE
FOE
Dark Reading
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
FOE
EFF Deeplinks
A List of ICE Subpoenas to Tech Companies
FOE
Dark Reading
'HTTP Terminator' Hunts for Novel Desync Attacks
FOE
Dark Reading
Red Flags That Expose Fake North Korean IT Workers
FOE
The Register (Security)
More than 100 water systems were hit in July cyberattacks
FOE
Bleeping Computer
New GPUThor attack defeats NVIDIA ECC protection for root access
FOE
EFF Deeplinks
EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms
FOE
Dark Reading
Android Malware Hijacks Update System for Car Head Units
FOE
The Hacker News
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
FOE
EFF Deeplinks
EFF Statement on Meta Settlement
FOE
EPIC
In New Jersey, Fair Trials Demand Facial Recognition Disclosure. What About the Rest of Us?
FRIEND
SANS Internet Storm Center
Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)
FOE
The Register (Security)
Boston Scientific discloses 'global disruption' in ongoing cyberattack
FOE
The Hacker News
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
FOE
SecurityWeek
AI Speeds Up Malware Development, Not Its Success Rate: Analysis
FOE
Bleeping Computer
Boston Scientific says cyberattack disrupted operations globally
FOE
The Register (Security)
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed
FOE
Bleeping Computer
Hackers target Microsoft SharePoint RCE chain with PoC exploit
FRIEND
EFF Deeplinks
French Top Court Gets It Right, Strikes Down Social Media Ban For Youths
FOE
Bleeping Computer
FBI disrupts proxy network enabling Chinese espionage operations
FOE
Bleeping Computer
Snowflake ends service-account passwords. Now comes the hard part
FOE
The Hacker News
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
FOE
Bleeping Computer
Ubiquiti patches three max severity security vulnerabilities
FOE
The Hacker News
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
FRIEND
SecurityWeek
Adobe and Nvidia Patch Dozens of Vulnerabilities
FRIEND
Bleeping Computer
Microsoft tests new privacy controls for Windows 11 desktop apps
FOE
Schneier on Security
Spyware for Babies
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Turn those lights down
FOE
CISA Alerts
CISA Adds Six Known Exploited Vulnerabilities to Catalog
FRIEND
CISA Alerts
CISA Vulnerability Review
FOE
The Hacker News
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
FRIEND
The Hacker News
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
FOE
CSO Online
NemoClaw’s AI can be poisoned through a browser tab
FOE
Dark Reading
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
FOE
SecurityWeek
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
FOE
CSO Online
Microsoft warns patch window is collapsing, urges shift to network-level containment
FOE
Bleeping Computer
Hackers now exploit critical Gitea flaw in code injection attacks
FOE
SecurityWeek
The MFA Identity Trap: When Authentication Creates a False Sense of Security
FRIEND
Pen Test Partners
Estate planning of credentials
FOE
The Hacker News
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
FOE
The Intercept (Privacy)
It’s Time to Rein in Lethal AI Drones
FOE
SecurityWeek
Chrome 152 Patches Over 300 Vulnerabilities
FOE
The Hacker News
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
FOE
Dark Reading
Interpol's Jackal IV Disrupts West African Crime Infrastructure
FOE
CSO Online
Who is accountable when your AI agent goes rogue?
FRIEND
Dark Reading
Nigeria Looks to Sovereign Cloud for Cyber, National Security
FOE
The Hacker News
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
FOE
SecurityWeek
Sensitive Information Exposed in Nutex Health Data Breach
FOE
The Hacker News
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
FOE
The Hacker News
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
FOE
The Hacker News
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
FOE
SecurityWeek
CISA Warns of Exploited Gitea Vulnerability
FOE
Risky Business News
Risky Bulletin: Russia starts blocking DoH and DoT
FOE
CISA KEV
CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability
FOE
CISA KEV
CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability
FOE
CISA KEV
CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability
FOE
CISA KEV
CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
FOE
CISA KEV
CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
FOE
CISA KEV
CVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
FOE
Bleeping Computer
LACMA data breach last year exposed social security and medical data
FOE
Bleeping Computer
Hackers abuse npm mirrors to host phishing redirect pages
FOE
Dark Reading
Hidden Prompts Trick AI Into False Email Summaries
FOE
Bleeping Computer
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
FOE
Dark Reading
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
FOE
The Hacker News
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
FRIEND
SecurityWeek
Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
FOE
The Register (Security)
You could've applied all 1,449 Oracle patches and still been hit by this attack
FOE
Bleeping Computer
Massive DDoS attack disrupts Norway’s government digital services
FOE
SANS Internet Storm Center
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: It’s the moment when everything happens
FOE
Dark Reading
Is Cyber Facing an Affordability Crisis?
FOE
Bleeping Computer
Hospital operator Nutex Health says data stolen in cyberattack
FRIEND
PortSwigger Research
What's in a tag name? JavaScript, apparently
FRIEND
SecurityWeek
Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails
FOE
The Hacker News
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
FOE
Bleeping Computer
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
FOE
SecurityWeek
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
FRIEND
The Hacker News
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
FRIEND
Bleeping Computer
WhatsApp adds stronger two-step verification, multiple passkeys
FRIEND
SecurityWeek
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
FRIEND
CSO Online
Nucleus wants to get ahead of scanners on new vulnerabilities
FRIEND
SecurityWeek
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
FOE
The Hacker News
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
FOE
Bleeping Computer
Hackers breached over 270 Zimbra servers in ongoing attacks
FOE
CSO Online
New attack lets hackers plant hidden instructions in AI memory with a single prompt
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: It catches everything
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
CISA Alerts
Rently Smart Home
FOE
CISA Alerts
PayRange API
FOE
CISA Alerts
Zoneminder
FOE
CISA Alerts
Siemens SIMATIC IoT2050 Advanced
FOE
CISA Alerts
FURUNO FA-50 Class B AIS Transponder
FOE
CISA Alerts
Bendix EC80 Brake ECU
FOE
CISA Alerts
Ebyte NE2-D11
FRIEND
CISA Alerts
A Tale of Two SOCs: Insights From Two Red Team Assessments
FOE
The Hacker News
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
FOE
The Hacker News
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
FOE
CSO Online
AI helps Chinese-speaking hackers speed up attacks on exposed servers
FOE
The Hacker News
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
FOE
SecurityWeek
First Malware Built Specifically for Car Head Units Fuels Botnet
FRIEND
The Hacker News
Frontier AI: Vulnerability Management's Systemic Revolution
FRIEND
Schneier on Security
Black Hat State of Security Vendors
FOE
Bleeping Computer
Police arrests dozens of suspects in global cybercrime crackdown
FOE
The Register (Security)
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
FOE
SecurityWeek
Silent Patches Don’t Stop Attackers – They Blind Defenders
FOE
The Register (Security)
Crooks push Mac malware through fake OpenAI Codex ads
FOE
The Hacker News
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
FOE
SecurityWeek
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
FOE
CSO Online
How Equifax is using AI to elevate its cybersecurity
FOE
SecurityWeek
CISA Warns of Exploited Oracle WebLogic Vulnerability
FOE
The Hacker News
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
FRIEND
TrustedSec
SpooNMAP Grows Up: Findings, Local LLM Detection, and a Whole Lot Less Waiting
FRIEND
Sophos News
Sophos Ranked #1 Overall in Endpoint, XDR, MDR, and Firewall in the G2 Fall 2026 Reports
FOE
CISA KEV
CVE-2026-60004: Gitea Code Injection Vulnerability
FOE
Dark Reading
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
FOE
The Register (Security)
You don't want this Sleepwalker backdoor on your Windows machine
FOE
Bleeping Computer
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
FOE
The Register (Security)
Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks
FOE
Dark Reading
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
FOE
Bleeping Computer
Hackers target WordPress sites in miniOrange auth bypass attacks
FOE
Ars Technica (Security)
Inaudible sounds used to fingerprint browsers catch AliExpress red handed
FOE
Bleeping Computer
TikTok reaches $400M settlement with US over COPPA violations
FOE
The Hacker News
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
FOE
SecurityWeek
ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
FOE
The Register (Security)
Iran-linked cyberattack shut down a UK power plant
FOE
Bleeping Computer
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
FOE
Dark Reading
Tricky 'SynkLoader' Multitool May Herald Ransomware
FOE
Dark Reading
ToxicPanda Banking Trojan Matures into Enterprise Threat
FOE
The Hacker News
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
FRIEND
Bleeping Computer
Microsoft Teams now lets admins block external bots from meetings
FOE
Bleeping Computer
South Korean startup platform breach exposes key management failures
FOE
Dark Reading
The Vulnerability Gap: Why Discovery Is Outrunning Repair
FRIEND
SecurityWeek
Hired for One Job, Judged on Another: The CISO’s Real Problem
FOE
Pen Test Partners
One SSID To Rule Them All
FOE
SecurityWeek
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
FOE
Bleeping Computer
Microsoft: August updates break printing, PDF export in WPF apps
FOE
The Hacker News
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
FOE
The Register (Security)
AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: I might be allergic to my phone
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
SecurityWeek
91 Vulnerabilities Patched in Spring Application Framework
FOE
The Hacker News
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
FOE
The Hacker News
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
FOE
The Hacker News
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
FOE
CSO Online
Windows Defender’s own driver can leave systems defenseless
FOE
The Hacker News
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
FOE
SecurityWeek
Venezuelan Gets Record Federal Prison Term for ATM Jackpotting
FOE
Bleeping Computer
CISA orders urgent patching of actively exploited Zimbra flaw
FOE
Schneier on Security
Criminal Deception in Silicon Valley
FRIEND
The Register (Security)
Security vets rally around $4 paper password books for sale in Australia
FOE
SecurityWeek
Personal Information Exposed in Apollo Global Data Breach
FOE
SecurityWeek
Rethinking Application Security for the AI Era
FOE
Bleeping Computer
Microsoft shares temporary fix for Windows 11 gaming issues
FOE
SecurityWeek
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
FOE
SecurityWeek
TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
FRIEND
CSO Online
7 ways AI can be used to enhance security operations
FOE
The Hacker News
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
FOE
SANS Internet Storm Center
DOUBLECUP's PNG Payload, (Mon, Aug 24th)
FRIEND
SecurityWeek
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
FOE
Risky Business News
Risky Bulletin: Expired cards can be used for new transactions
FOE
CISA KEV
CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
FOE
Bleeping Computer
ToxicPanda Android malware uses VPN permissions to block Google Play
FOE
The Register (Security)
If you're not using AI to attack your own systems, your adversaries will
FOE
The Hacker News
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
FOE
Bleeping Computer
Hackers infect Android car head units with proxy botnet malware
FOE
Bleeping Computer
Named Pipes Under Attack: Securing Windows Interprocess Communication
FOE
SecurityWeek
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
FOE
The Register (Security)
AWS Security makes an inscrutable choice
FOE
Dark Reading
How an Emerging Industrial Protocol Family Could Put OT at Risk
FOE
The Hacker News
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
FOE
Bleeping Computer
New SynkLoader malware pushed in Microsoft Teams phishing campaign
FRIEND
Dark Reading
OWASP Flags Top AI Skill Risks in New Security Blueprint
FOE
Schneier on Security
AI Is Learning to Write Genetic Code
FOE
The Register (Security)
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
FRIEND
SecurityWeek
Former NSA Director Paul Nakasone Launches National Security Advisory Firm
FOE
EFF Deeplinks
EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition
FOE
Bleeping Computer
Hundreds of leaked AWS keys give full control over corporate accounts
FOE
The Hacker News
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
FOE
The Hacker News
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
FOE
SecurityWeek
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
FOE
The Register (Security)
Hackers poison popular Rust crates to steal developers' credentials
FOE
SecurityWeek
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
FOE
SecurityWeek
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
FRIEND
Bleeping Computer
Is Online Privacy Possible? How Digital Identities Can Help
FRIEND
Dark Reading
Calling on Cyber Pros to Help Defend City Hall
FRIEND
Dark Reading
OpenAI Adds Controls That Should've Been There Already
FRIEND
Dark Reading
Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near
FOE
SecurityWeek
Critical Isolated-vm Vulnerability Leads to RCE on Host
FOE
Bleeping Computer
CISA orders feds to patch actively exploited TrueConf Server flaws
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Sign right here
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
The Hacker News
Wazuh and AI For Enhanced SOC Workflows
FRIEND
Pen Test Partners
DEFCON 34: Planes, PLCs and 6am runs
FOE
Bleeping Computer
Microsoft warns of max severity Entra ID flaw exploited in attacks
FOE
Bleeping Computer
Hackers abuse FTP server banners to deliver new Windows malware
FOE
Bleeping Computer
SickKids data breach exposes employee and job applicant info
FOE
The Hacker News
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
FRIEND
CSO Online
OpenAI adds an AI safety layer to detect misuse without retaining enterprise data
FOE
Schneier on Security
More Incidents of AIs Going Rogue in Cybersecurity Challenges
FOE
CSO Online
Backdoored Rust packages hit crates.io, exposing developers to malware at build time
FOE
SecurityWeek
Rust Supply Chain Attack Linked to North Korean Hackers
FOE
CSO Online
AI threats are everywhere. A risk-first CISO decides what to prioritize
FOE
SecurityWeek
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
FOE
CSO Online
Ransomware takes aim at enterprise resilience
FRIEND
SecurityWeek
Microsoft Rolls Out 22 Fresh Security Patches
FOE
SecurityWeek
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
FOE
The Hacker News
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
FOE
The Hacker News
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
FOE
The Register (Security)
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
FOE
Risky Business News
Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall
FRIEND
SANS Internet Storm Center
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
FRIEND
SANS Internet Storm Center
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)
FOE
The Register (Security)
Russian snoops add OAuth abuse to targeted phishing campaigns
FOE
CISA KEV
CVE-2026-69836: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
FOE
CISA KEV
CVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
FOE
EFF Deeplinks
Intermediary Liability in Brazil: The Intricate Path Ahead
FOE
CSO Online
Critical flaw patched in popular JavaScript sandbox used in AI projects
FRIEND
Dark Reading
New CUSTODY Framework Constrains AI Agents Inside the Network
FOE
The Hacker News
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
FRIEND
Dark Reading
Calling on Cyber Pros to Help Defend City Hall
FOE
The Hacker News
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
FOE
Dark Reading
What We Missed: Delta Flight Disrupted With Wi-Fi Hack
FOE
CSO Online
Citrix issues critical security updates for its NetScaler devices
FOE
Bleeping Computer
Hackers poison arrayref Rust crate to push infostealer malware
FOE
Schneier on Security
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
FOE
Dark Reading
N-able Bug Exposes Password Vault Master Keys
FOE
Dark Reading
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
FOE
The Register (Security)
US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
FOE
The Hacker News
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
FOE
The Hacker News
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
FOE
The Register (Security)
Researcher tricks Apple’s Find My into sharing location data with Linux
FOE
Pen Test Partners
GivEnergy enters administration, batteries expose home networks
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Where you headed
FOE
Dark Reading
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
FOE
SecurityWeek
Hackers Target Zimbra Servers in Active Exploitation Campaign
FOE
Bleeping Computer
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
FOE
The Hacker News
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
FOE
SecurityWeek
Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
FOE
The Register (Security)
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
FOE
Bleeping Computer
How MSPs can catch phishing attacks email filters miss
FOE
The Hacker News
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
FOE
EPIC
PRESS RELEASE: EPIC and CFA Publish New Resource: Explaining Surveillance Pricing and Other Data-Driven Pricing Practices
FOE
The Hacker News
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
FOE
Dark Reading
'Grandoreiro' Malware Resurfaces With Mexico Campaign
FOE
The Hacker News
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
FOE
SecurityWeek
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
FRIEND
SANS Internet Storm Center
Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)
FOE
Ars Technica (Security)
Grok exfiltrates user data when malicious instructions are encrypted
FOE
The Register (Security)
Grok chat duped into swallowing injected instructions
FOE
The Register (Security)
French tax authority says break-in exposed data of 600K, including some private messages
FOE
SecurityWeek
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
FOE
Bleeping Computer
Citrix urges admins to patch new NetScaler flaws as soon as possible
FOE
SecurityWeek
MLflow Vulnerability Exploited for Cloud Credential Theft
FOE
The Hacker News
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It works for a bit
FOE
CSO Online
Kriminal breaks out of Grok, Claude guardrails at $12.99
FOE
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
Johnson Controls Simplex Incident Manager
FRIEND
SANS Internet Storm Center
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
FOE
SecurityWeek
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
FOE
The Hacker News
Why "Shady AI" is Security's Next Big Governance Problem
FOE
The Hacker News
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
FOE
The Hacker News
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
FRIEND
SecurityWeek
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
FOE
Bleeping Computer
CISA warns of hackers exploiting critical MLflow vulnerability
FOE
The Hacker News
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
FOE
The Hacker News
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
FRIEND
SecurityWeek
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
FOE
Bleeping Computer
New Manic Android malware can exfiltrate data through nearby devices
FOE
Schneier on Security
Police Are Hiding Their Use of Flock Surveillance Cameras
FOE
Bleeping Computer
Critical Zimbra RCE flaw now actively exploited in attacks
FOE
The Hacker News
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
FOE
SecurityWeek
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
FOE
SecurityWeek
Critical GitLab Flaw Exploited Shortly After Disclosure
FOE
SecurityWeek
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
FOE
The Register (Security)
AI agent suggested installing a malware package. Engineer almost took its advice
FOE
Bleeping Computer
Microsoft says August Windows updates may cause gaming issues
FOE
The Hacker News
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
FOE
Risky Business News
Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea
FRIEND
CSO Online
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
FOE
Bleeping Computer
OpenAI confirms ChatGPT is down as logins and signups fail
FRIEND
CSO Online
OpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention for select frontier model customers
FOE
CISA KEV
CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability
FOE
CISA KEV
CVE-2026-72530: TrueConf Server Code Injection Vulnerability
FOE
The Register (Security)
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
FOE
EFF Deeplinks
Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.
FRIEND
Professor Messer
Professor Messer’s SY0-701 Security+ Study Group – August 2026
FOE
Bleeping Computer
Rogue ransomware affiliate poses as recovery firm to steal payments
FOE
Bleeping Computer
Rogue ransomware affiliate poses as data recovery firm to steal payments
FOE
Bleeping Computer
Sakura Internet hack exposes data of up to 1.36 million accounts
FOE
Dark Reading
No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
FOE
Bleeping Computer
Healthtech firm CareCloud data breach impacts 3.7 million patients
FOE
Dark Reading
Agentic AI Presents New Insider Threat Model for Orgs
FOE
The Hacker News
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
FOE
The Register (Security)
ICE boss to agents: Leave the Meta spy glasses at home
FOE
Bleeping Computer
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
FOE
The Hacker News
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
FOE
Bleeping Computer
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
FOE
Dark Reading
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
FOE
EFF Deeplinks
📍 The Sneaky Code Tracking App Users | EFFector 38.15
FOE
The Register (Security)
Flock surveillance backlash mounts as fiendish Halloween plans circulate
FRIEND
SpecterOps
AWSHound: An OpenSource AWS OpenGraph Collector
FOE
Bleeping Computer
US charges Iranian hackers over $3.4 billion intellectual property theft
FOE
EPIC
EPIC, Coalition Urge Congressional Leaders to Protect Americans and Reform FISA Section 702
FOE
SANS Internet Storm Center
Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)
FOE
Bleeping Computer
Password spraying attacks surge 155x as hackers exploit MFA gaps
FRIEND
SecurityWeek
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
FRIEND
The Register (Security)
Comcast gives its Wi-Fi motion detector a security makeover
FOE
The Hacker News
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Something you won’t eat
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
CISA Alerts
Defending Against an Active Threat to Siemens S7 Series PLCs
FRIEND
SecurityWeek
Prevalent AI Raises $22 Million to Expand Data Fabric Platform
FOE
The Hacker News
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
FOE
SecurityWeek
US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
FOE
The Hacker News
Phishing 3.0: The Fight Moves to Agent Versus Agent
FOE
The Hacker News
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
FRIEND
Bleeping Computer
Microsoft fixes known issue causing Windows Defender crashes
FOE
CSO Online
Snowflake flaw slips past AI checks, gets exploited by another AI
FOE
SecurityWeek
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
FOE
The Hacker News
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
FOE
SecurityWeek
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
FOE
Bleeping Computer
Critical RCE flaw in Windows IKE Extension now actively exploited
FOE
SecurityWeek
943 Patches Rolled Out With Oracle’s August 2026 Security Update
FOE
Bleeping Computer
Windows 11 24H2 Home and Pro reach end of support in 2 months
FOE
CSO Online
Most organizations aren’t ready for a Hugging Face-level event
FRIEND
CSO Online
CISOs are struggling to threat-model AI. Can 15-minute sessions help?
FOE
SecurityWeek
Chrome, Firefox Updates Patch Dozens of Vulnerabilities
FOE
Bleeping Computer
CISA: Medusa ransomware hit over 500 critical infrastructure orgs
FOE
SecurityWeek
CareCloud Data Breach Impact Grows to 3.7 Million Individuals
FOE
The Hacker News
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
FOE
The Hacker News
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
FOE
Risky Business News
Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
FOE
CSO Online
Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
FOE
The Register (Security)
Australian hotel chain leaks guests’ PII after breach at third-party database operator
FOE
Dark Reading
China-Linked Hacker Shows AI Capabilities in APAC Attack
FOE
CISA KEV
CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability
FOE
Sophos News
Fake AI, real malware: Attackers impersonating AI brands
FOE
The Register (Security)
OpenAI's overhead will rise 20 percent for some workloads as it hardens security
FOE
EFF Deeplinks
Ninth Circuit Ruling Will Force Online Platforms That Host User Speech to Fight Lengthy and Costly Lawsuits Before They Are Dismissed Under Section 230
FOE
EFF Deeplinks
ZKP’s Aren’t Age Verification Silver Bullets
FOE
Dark Reading
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
FOE
The Register (Security)
Expired credit cards revived by researchers to make unauthorized payments
FOE
Dark Reading
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
FRIEND
Bleeping Computer
Comcast turns your Xfinity WiFi into a home motion detector
FOE
CSO Online
Critical GitLab flaw allows attackers to delete and modify public repos
FOE
Dark Reading
The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed
FOE
Dark Reading
CISOs Break Their Silence in 'Declassified' Docuseries
FOE
The Hacker News
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
FOE
The Hacker News
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
FOE
Bleeping Computer
Clop created custom web shell for Windchill data theft attacks
FOE
The Hacker News
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
FOE
The Register (Security)
CISA gives feds 3 days to fix actively exploited Ray RCE bug
FRIEND
SecurityWeek
Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: I have a few sitting around
FOE
The Register (Security)
Apple plugs image-processing hole ripe for spyware abuse
FRIEND
SecurityWeek
CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
FOE
Bleeping Computer
Your Controls Block Known Attacks. What About the Behavior?
FOE
Ars Technica (Security)
Microsoft Copilot reveals secret input that allowed it to be hacked
FOE
The Register (Security)
Copilot tricked into telling reseachers how to hack itself
FOE
Dark Reading
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
FOE
Dark Reading
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
FOE
SecurityWeek
AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
FOE
The Hacker News
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
FOE
The Hacker News
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
FRIEND
SecurityWeek
Xpander Raises $7.5 Million for AI Management and Governance
FRIEND
SecurityWeek
Fortinet Acquires AI Security Company Virtue AI
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It fixes everything
FOE
CISA Alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
Siemens Simcenter Nastran
FOE
CISA Alerts
CISA Malcolm
FOE
The Hacker News
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
FOE
The Hacker News
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
FOE
CSO Online
New Malware turns Microsoft cloud into its control center
FOE
SecurityWeek
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
FOE
Schneier on Security
LLMs and Contextual Integrity
FOE
Bleeping Computer
CISA: Windows Task Host flaw now exploited by ransomware gangs
FOE
Bleeping Computer
Microsoft confirms outage affecting search in Microsoft 365 apps
FOE
SecurityWeek
Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
FOE
The Hacker News
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
FOE
CSO Online
What you say during a cyber breach can — and will — be used against you
FOE
SecurityWeek
GitLab Patches Critical Code Injection Vulnerability
FOE
CSO Online
AI can find zero-days but still can’t reliably write secure code
FOE
Bleeping Computer
Microsoft starts removing WMIC tool used by cybercriminals
FOE
SecurityWeek
Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
FOE
The Hacker News
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
FRIEND
TrustedSec
We've Seen This Movie: The OT/IT Technology Divide
FRIEND
CSO Online
OpenAI president’s blog pushing agentic AI most notable for what it did not say
FOE
CISA KEV
CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability
FOE
CISA KEV
CVE-2026-65400: Apple macOS Improper Authentication Vulnerability
FOE
CISA KEV
CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability
FOE
CISA KEV
CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
FOE
CISA KEV
CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability
FOE
Dark Reading
Video Call Exploit Chains Two Flaws in Unisoc Modems
FOE
The Hacker News
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
FRIEND
SANS Internet Storm Center
Apple Patches iOS and macOS, (Mon, Aug 17th)
FOE
Dark Reading
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
FOE
Bleeping Computer
Hacker claims 3.6 million Azure account records stolen from major companies
FOE
Dark Reading
Adam Shostack Talks Hugging Face & PHANTOM-B
FOE
Bleeping Computer
Pokémon Center data breach exposes customer info, cancels some orders
FOE
The Hacker News
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
FOE
The Hacker News
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
FOE
The Hacker News
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
FOE
The Register (Security)
An AI broke Snowflake's code. Then another AI agent exploited it
FOE
Dark Reading
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
FOE
Bleeping Computer
Microsoft confirms GitHub is down worldwide
FOE
SANS Internet Storm Center
Apple Screen Sharing Security, (Mon, Aug 17th)
FOE
Bleeping Computer
Certighost and the Privilege Hiding in Your Certificate Authority
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: We see everything
FRIEND
CSO Online
Why data quality dictates security operations success
FOE
SecurityWeek
680,000 Impacted by French Tax Authority Data Breach
FOE
The Hacker News
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
FOE
Bleeping Computer
Windows Server 2022 reaches end of mainstream support in 60 days
FOE
CSO Online
Zhipu says new coding AI developed advanced cyber skills faster than expected
FOE
SecurityWeek
Irregular Details How a Naming Error Let AI Models Attack a Real Company
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
The Hacker News
How MCP Servers Can Expose Enterprise Secrets
FOE
The Register (Security)
Crook hawks millions of records allegedly plundered from corporate Azure tenants
FOE
CSO Online
New macOS malware turns stolen browsers into attacker-controlled sessions
FOE
Bleeping Computer
Philips and GE investigating Clop ransomware data theft claims
FOE
Schneier on Security
Hacking Public Wi-Fi DNS to Steal Credentials
FOE
SecurityWeek
Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
FOE
The Hacker News
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
FOE
Bleeping Computer
French tax authority data breach affects 678,000 individuals
FOE
SecurityWeek
40,000 Impacted by SafePal Data Breach
FOE
The Hacker News
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
FOE
Bleeping Computer
Microsoft working on Defender patch for ShieldBreak zero-day
FRIEND
The Register (Security)
Code fixers have fired up the AI warp drive. Strange new worlds await
FOE
SecurityWeek
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
FRIEND
CSO Online
What the CISO role will look like in 2029
FOE
SecurityWeek
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
FOE
The Hacker News
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
FOE
The Register (Security)
Black Hat and DEF CON are AI conferences now, too
FOE
SecurityWeek
Fortune 500 Companies Hit in Azure Data Theft Campaign
FOE
Risky Business News
Risky Bulletin: The EU publishes its upcoming cybersecurity standards
FOE
The Register (Security)
Microsoft blames AI for delayed Exchange update, can’t say when it will arrive
FRIEND
The Register (Security)
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI
FOE
The Register (Security)
Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI
FOE
Sophos News
A heap of overflow in August’s Patch Tuesday haul
FOE
Sophos News
Reviving the Undead: Accelerating NetNTLMv1 Lookups Without GPUs
FOE
Bleeping Computer
SafePal data breach impacts 39,798 customers, stolen info for sale
FOE
Bleeping Computer
Anthropic confirms Claude is down in major outage affecting multiple services
FRIEND
SANS Internet Storm Center
Wireshark 4.6.8 Released, (Sun, Aug 16th)
FOE
Bleeping Computer
Large-scale DDoS attacks disrupted Threema secure messaging service
FOE
Bleeping Computer
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
FRIEND
The Register (Security)
Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do
FOE
The Intercept (Privacy)
Secret ICE Agent Tried to ‘Entice’ Minneapolis Activists Into Confrontational Tactics
FOE
Bleeping Computer
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
FOE
The Register (Security)
ChainDrop worm crawls into npm supply chain, evades standard defenses
FOE
The Hacker News
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
FOE
The Hacker News
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
FRIEND
Bleeping Computer
How Anthropic plans to watermark Claude's AI-generated text
FRIEND
Dark Reading
Mission-Driven Security: Inside a Global Bank's Defense
FOE
The Hacker News
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
FOE
Ars Technica (Security)
Vulnerability giving attackers full control of Macs is under active exploitation
FOE
Bleeping Computer
Hackers arrested over €30M bank fraud exploiting service provider flaw
FOE
The Register (Security)
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
FRIEND
Dark Reading
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
FRIEND
The Hacker News
IAM Compliance Requirements and Best Practices
FRIEND
Schneier on Security
Upcoming Speaking Engagements
FOE
Dark Reading
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
FOE
Bleeping Computer
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
FOE
The Register (Security)
French tax authority admits data heist after crook touts 2M records
FOE
Bleeping Computer
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
FOE
Dark Reading
What Boards Need to Know About Tech Risk
FOE
Bleeping Computer
Max severity SAP Commerce Cloud flaw now targeted in attacks
FOE
CSO Online
Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks
FRIEND
CSO Online
Oracle’s new database security tool is free — for six months
FOE
The Hacker News
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
FOE
The Register (Security)
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
FRIEND
Dark Reading
Cyera's Oasis Security Buy is All About AI Agent Control
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Just pick some numbers
FOE
SecurityWeek
In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
FOE
Bleeping Computer
Shell investigates 'potential incident' after Clop data theft claims
FOE
SecurityWeek
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
FOE
Krebs on Security
Who’s Tracking You? Use This New Service to Find Out
FOE
The Hacker News
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
FOE
Schneier on Security
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
FRIEND
SecurityWeek
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
FOE
The Hacker News
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps
FOE
Bleeping Computer
RingCentral data breach exposed info of 1.6 million accounts
FOE
The Hacker News
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
FOE
The Register (Security)
Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach
FOE
SecurityWeek
1.6 Million Likely Impacted by RingCentral Data Breach
FRIEND
The Hacker News
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
FOE
SecurityWeek
Over 1,000 Charities Hit by Beacon CRM Data Breach
FOE
CSO Online
Akira ransomware reboots into Windows Safe Mode to knock EDR offline
FRIEND
CSO Online
The cybersecurity backlog is not a security problem
FOE
The Register (Security)
Scottish prosecutors cast eye over leaky supplier after staff data exposed
FOE
Bleeping Computer
Data analyst sent to prison for stealing data, extorting employer
FRIEND
CSO Online
How CSOs can turn cybersecurity into a business growth strategy
FOE
SecurityWeek
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
FOE
The Hacker News
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
FOE
SecurityWeek
Hackers Exploiting Unpatched GeoServer Zero-Day
FOE
SecurityWeek
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
FOE
Risky Business News
Risky Bulletin: White House lets private companies carry out offensive cyber ops
FOE
The Register (Security)
New Zealand says China tried using space investments to spy on local affairs
FOE
CSO Online
5 key takeaways from Black Hat USA 2026
FOE
Bleeping Computer
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
FOE
The Register (Security)
OpenAI ditches Recall-style screenshot surveillance for friendly keylogging
FOE
Bleeping Computer
Ukraine shuts down 94 fraudulent call centers, seize millions in cash
FOE
EFF Deeplinks
Too Little, Too Late: Flock Admits Their Technology Needs Reforms
FOE
Bleeping Computer
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
FOE
Dark Reading
Global Threat Campaign Hits Critical VMware vCenter Flaw
FOE
CSO Online
Attackers target zero-day vulnerability in geospatial data platform GeoServer
FOE
Ars Technica (Security)
Private security firms will soon be allowed to hack overseas cybercriminals
FRIEND
Red Siege
Improving Your Simple Windows Domain for Offensive Testing: Sysmon
FOE
The Hacker News
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
FOE
The Hacker News
ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
FOE
Bleeping Computer
Hackers breach govt webmail while running parallel crypto fraud
FOE
Bleeping Computer
Microsoft patches LegacyHive Windows zero-day vulnerability
FOE
Bleeping Computer
AI 'watermark removers' flood the web. Almost none can prove they work.
FOE
EPIC
EPIC and Coalition Urge Senate and Thompson Reuters to Stop Commercial Surveillance
FOE
Bleeping Computer
Critical VMware vCenter RCE flaw exploited for reverse SSH access
FOE
EPIC
Riley Says Get a Warrant — So Why Are Schools Skipping That Step?
FOE
SpecterOps
Attack of The Extensions
FOE
SpecterOps
Return of the Cookie Monster
FOE
Bleeping Computer
Trezor discloses data breach affecting nearly 14,000 customers
FOE
The Register (Security)
Trump wants to grant private cyber firms a license to hack back
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: Stuck at the four way stop
FOE
The Hacker News
New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
FOE
The Register (Security)
The backup Microsoft never promised you
FRIEND
SecurityWeek
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
FOE
SecurityWeek
Adobe Commerce Bug Targeted Immediately After Disclosure
FOE
Bleeping Computer
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
FOE
The Hacker News
AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
FOE
Bleeping Computer
White House taps security firms for offensive hack-back operations
FOE
CSO Online
AI agents wage near-autonomous cyberattack on Asian government networks
FOE
SecurityWeek
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
FOE
CSO Online
Trump administration opens door to private-sector cyber offensives
FOE
CSO Online
It took $58 to break Microsoft’s SCCM, but a patch made it harder
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: It’s important to be polite
FOE
CISA Alerts
Flow Neuroscience FL-100
FOE
CISA Alerts
Haiwell IoT Cloud HMI Gateway
FOE
CISA Alerts
Siemens Parasolid
FOE
CISA Alerts
Siemens Siveillance Video
FOE
CISA Alerts
Siemens Desigo DXR and PXC Controllers
FOE
CISA Alerts
Johnson Controls Metasys
FOE
CISA Alerts
Siemens Simcenter Femap
FOE
CISA Alerts
Siemens License Server (SLS)
FOE
CISA Alerts
Siemens LOGO! Soft Comfort
FOE
CISA Alerts
AVEVA Enterprise SCADA
FOE
CISA Alerts
Hitachi Energy APM Edge Product
FOE
CISA Alerts
ANDRITZ HIPASE-250 and 250 SCALA
FOE
CISA Alerts
Johnson Controls Inc. Airwall
FOE
CISA Alerts
Siemens Solid Edge
FOE
The Hacker News
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
FRIEND
Bleeping Computer
WhatsApp rolls out new feature that flags potential scam messages
FOE
The Hacker News
North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
FRIEND
SecurityWeek
Venture Firm Team8 Secures Additional $365 Million
FOE
The Register (Security)
AWS key exposed in JavaScript may have lit way to Beacon's charity data
FOE
Schneier on Security
Separating AI’s Technological Problems from Its Capitalism Problems
FOE
SecurityWeek
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
FOE
Dark Reading
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
FRIEND
SecurityWeek
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
FOE
Risky Business News
Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!
FOE
SecurityWeek
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
FOE
SecurityWeek
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
FOE
CSO Online
Microsoft wants you to rethink your approach to cyber defense
FOE
The Register (Security)
Passwords stored in public Google Doc then showed up in search results
FOE
Dark Reading
Belgium's eID Authentication Opens Citizen Accounts to RCE
FOE
The Hacker News
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
FOE
TrustedSec
AI Offense is Not Noclip Mode
FOE
The Register (Security)
Chinese Loongson processors have leaky caches, researchers find
FOE
SANS Internet Storm Center
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)
FOE
Bleeping Computer
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
FRIEND
Professor Messer
Professor Messer’s N10-009 Network+ Study Group – August 2026
FOE
Bleeping Computer
Android malware combo takes out loans and relays victims' credit cards
FOE
The Register (Security)
'Near-autonomous' AI agents attack Taiwan's nuclear safety agency
FOE
Ars Technica (Security)
Terabytes of credentials leaked in massive supply-chain attack
FOE
The Intercept (Privacy)
Francesca Hong’s Loss in Wisconsin is a Win for AI Data Centers — for Now
FOE
Dark Reading
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
FOE
CSO Online
Researcher bypasses Microsoft Defender security patch, seizing control
FOE
CSO Online
Researcher creates workaround for Microsoft Defender security patch
FOE
Bleeping Computer
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
FOE
EPIC
EPIC Urges 7th Circuit to Uphold Wiretap Act to Protect Private Communications Containing Sensitive Health Data
FOE
The Register (Security)
Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible
FOE
Bleeping Computer
Hundreds of fake Chrome VPN extensions route traffic through a proxy
FOE
The Hacker News
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
FRIEND
Dark Reading
Walmart's "Trusted Agent" Approach to Purple Teaming
FOE
Bleeping Computer
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
FRIEND
SpecterOps
Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders
FOE
Bleeping Computer
Lazarus hackers exploited Windows zero-day to target defense firms
FOE
SecurityWeek
SharePoint Vulnerability Exploited Shortly After PoC Release
FOE
The Register (Security)
Uber Freight keeps on trucking after extortion crew breaks in
FRIEND
SANS Internet Storm Center
Linux Kernel Process Accounting, (Wed, Aug 12th)
FOE
Bleeping Computer
FBI: Hackers target online accounts to steal nude photos
FOE
The Hacker News
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
FOE
Bleeping Computer
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
FOE
Dark Reading
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
FOE
The Register (Security)
Exposed: Woeful security at UK criminal records office that led to sensitive data leak
FOE
EPIC
Lawfare: Closing the Front Door: The Case for DOJ’s Bulk Data Security Program
FOE
EPIC
Common Dreams: Thomson Reuters Slammed for Deal That Gives ICE Access to Private Profiles of Tens of Millions of Americans
FOE
Ars Technica (Security)
Researchers found a way to hijack devices through Zoom screen sharing
FRIEND
SecurityWeek
Mindgard Raises $30 Million to Protect AI Systems
FOE
The Register (Security)
Akira ransomware scum blocked victim's security tools – and broke their own encryptor
FRIEND
SecurityWeek
WhatsApp Unveils New Scam Alert Feature
FOE
SecurityWeek
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
FRIEND
Dark Reading
Walmart Leaders Transform Security Operations Without Going Bananas
FOE
Bleeping Computer
Hackers leverage new Microsoft SharePoint exploit in attacks
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: Something with a modern feel
FOE
CISA Alerts
Siemens RUGGEDCOM APE1808
FOE
The Hacker News
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
FOE
The Hacker News
Enterprise Defenses Recovered at the Edge and Collapsed Inside
FOE
SecurityWeek
Ceva Logistics Operations Disrupted by Cyberattack
FOE
CSO Online
Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool
FRIEND
Bleeping Computer
Signal adds new security feature to thwart man-in-the-middle attacks
FOE
The Register (Security)
Brit rail cops bring live facial recognition to the London Underground
FOE
The Hacker News
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
FOE
SecurityWeek
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
FOE
Bleeping Computer
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
FRIEND
Schneier on Security
Prompt Injections for Defense
FOE
SecurityWeek
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack
FOE
The Hacker News
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
FOE
CSO Online
4 gaps slowing AI in enterprise SOCs
FOE
SecurityWeek
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
FOE
CSO Online
The AI harness is the new attack surface
FOE
SecurityWeek
Ivanti EPM Update Patches Remotely Exploitable Flaws
FOE
The Hacker News
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
FOE
SecurityWeek
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
FOE
The Hacker News
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
FOE
SecurityWeek
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
FOE
CSO Online
17 old software bugs that took way too long to squash
FOE
The Hacker News
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
FOE
The Hacker News
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
FOE
SecurityWeek
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
FOE
Risky Business News
Risky Bulletin: Russian hackers adopt the fake job interview tactics
FOE
CSO Online
Metabase SQLi exploit grants attackers total access
FRIEND
Bleeping Computer
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
FOE
CSO Online
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
FOE
Ars Technica (Security)
DEF CON crowd suspected in fake-hotspot attack on Delta flight
FOE
CSO Online
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
FOE
Bleeping Computer
DeadLock ransomware uses blockchain to resist infrastructure takedown
FRIEND
The Register (Security)
Signal adds an extra layer of security to make sure you're actually chatting with the right person
FOE
Dark Reading
Microsoft's Patch Tuesday Deluge Continues With August Updates
FOE
The Register (Security)
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one
FOE
Krebs on Security
Microsoft Plugs Nearly 400 Security Holes
FOE
Dark Reading
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
FOE
Bleeping Computer
Sandworm hackers target IT pros with trojanized WireGuard VPN client
FRIEND
Ars Technica (Security)
Chrome adopts what may be the best protection yet against account takeovers
FRIEND
EFF Deeplinks
Who (or What) Generates Images for EFF?
FOE
The Hacker News
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
FOE
Bleeping Computer
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
FOE
The Hacker News
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
FOE
The Hacker News
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
FOE
SecurityWeek
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
FOE
The Hacker News
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
FOE
Bleeping Computer
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
FRIEND
Bleeping Computer
Microsoft releases Windows 10 KB5120249 extended security update
FOE
Bleeping Computer
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
FRIEND
EPIC
EPIC, Advocates Celebrate As New Jersey Signs Nation-Leading Kids’ Online Safety Bills Into Law
FOE
SANS Internet Storm Center
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
FRIEND
Bleeping Computer
Windows 11 KB5121003 & KB5120240 cumulative updates released
FOE
SecurityWeek
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
FOE
The Hacker News
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
FOE
The Hacker News
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
FOE
The Register (Security)
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
FOE
Bleeping Computer
Wesco confirms security incident after ExfilSquad claims data theft
FOE
Schneier on Security
AI Genie in the Wild
FOE
SecurityWeek
Zoom Patches Zero-Click Code Execution Vulnerability
FOE
The Register (Security)
Two wars and a World Cup lead to epic DDoS attacks on publishers
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: It’s like springtime
FOE
SecurityWeek
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
FOE
SecurityWeek
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
FRIEND
SecurityWeek
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
FOE
EPIC
FedScoop: TikTok can be on government phones. Managing it comes next.
FRIEND
Bleeping Computer
Mozilla updates GPG signing key for Firefox releases after exposure
FOE
Ars Technica (Security)
New surveillance tech links your phone to your license plate
FOE
Bleeping Computer
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
FOE
The Hacker News
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
FOE
Bleeping Computer
DDoS attacks over 1 Tbps surged fivefold in the second quarter
FOE
The Register (Security)
Deepfake hiccup unmasks suspected digital certificate fraudster
FOE
Bleeping Computer
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
FOE
The Hacker News
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
FOE
The Hacker News
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
FRIEND
CSO Online
GitHub already has an EDR. You just have to listen to it
FRIEND
SecurityWeek
Corma Raises $60 Million for Defensive Cybersecurity AI Model
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Do not look at this
FOE
CISA Alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
Pulsetto Vagus Nerve Stimulator
FOE
CISA Alerts
Mira Hormone Monitor, Mira Android App
FOE
The Register (Security)
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
FOE
The Hacker News
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
FOE
Ars Technica (Security)
New Pass-ta-key attack reveals all the things we didn't know about passkeys
FRIEND
CSO Online
OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window
FOE
Schneier on Security
AI for Military Support
FOE
SecurityWeek
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
FOE
Bleeping Computer
Cisco warns of high-severity ClamAV flaws with public exploits
FOE
The Hacker News
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
FOE
The Hacker News
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
FRIEND
SecurityWeek
Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
FOE
Privacy International
Lack of transparency and national guidelines mark the expansion of facial recognition in brazilian education
FOE
Bleeping Computer
US and South Korea warn of Gunra ransomware targeting govt agencies
FRIEND
SecurityWeek
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
FOE
The Register (Security)
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
FOE
The Hacker News
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
FOE
CSO Online
Security leaders’ rogue AI confidence could actually be disastrous
FOE
The Hacker News
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
FRIEND
SecurityWeek
Mozilla Issues New Firefox GPG Key Following Exposure
FOE
The Hacker News
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
FRIEND
TrustedSec
A Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI
FRIEND
CSO Online
The future of AI security research isn’t autonomous, it’s human-amplified
FOE
Sophos News
Abuse of alternative runtime environments Deno-tes defender headaches
FOE
Sophos News
ClickFix campaign abuses Deno runtime for infostealer delivery
FOE
CISA KEV
CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
FOE
CISA KEV
CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
FOE
CISA KEV
CVE-2026-72898: Metabase SQL Injection Vulnerability
FOE
Bleeping Computer
Hackers breached a small Polish energy plant via private APN last year
FOE
Dark Reading
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
FOE
Dark Reading
Multistate Water System Attacks Widen, Iran Suspected
FOE
Bleeping Computer
BdThemes plugins supply-chain hack creates rogue WordPress admins
FRIEND
The Register (Security)
DEF CON hackers add new muscle to water utility protection
FOE
Dark Reading
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
FRIEND
Bleeping Computer
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
FRIEND
Dark Reading
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
FOE
Bleeping Computer
New StormEncryptor ransomware used by former Medusa affiliate
FOE
The Register (Security)
North Korean spies are running local LLMs to cause AI mischief
FOE
EFF Deeplinks
Meta Must Stop Silencing Reproductive Health Information
FOE
Dark Reading
Coruna, DarkSword iOS Exploits Proliferate Globally
FOE
The Register (Security)
Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list
FOE
The Hacker News
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
FRIEND
Dark Reading
Outdated Cybercrime Laws Put Security Researchers at Risk
FOE
SANS Internet Storm Center
Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)
FRIEND
Dark Reading
Sherlock Holmes was the “OG” Social Engineer
FOE
The Hacker News
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
FOE
Bleeping Computer
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
FOE
SecurityWeek
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
FOE
Ars Technica (Security)
A researcher bought noreply.net. Companies started sending him secrets.
FRIEND
SecurityWeek
Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
FOE
SecurityWeek
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
FOE
Bleeping Computer
When Credentials Are No Longer Enough: Device Trust in the AI Era
FOE
The Register (Security)
Attackers pick Levi's pockets in social engineering attack
FOE
The Hacker News
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
FOE
SecurityWeek
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
FOE
Bleeping Computer
Member of The Com sent to prison for blackmail, sextortion
FOE
The Hacker News
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
FOE
The Register (Security)
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
FOE
Bleeping Computer
LexisNexis shuts down services after suspicious activity on servers
FOE
CSO Online
OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: You’ll get your data when they return
FOE
CISA Alerts
#StopRansomware: Gunra Ransomware
FOE
CSO Online
One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack
FRIEND
The Hacker News
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
FOE
Bleeping Computer
Valve notifies Steam hardware customers of a data breach
FOE
SecurityWeek
New Jersey, Alabama Join States Targeted in Water Cyberattacks
FOE
The Hacker News
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
FOE
The Register (Security)
Framework loses customer data in Metabase zero-day attack
FOE
SecurityWeek
Metabase Patches Vulnerability Exploited as Zero-Day
FRIEND
Schneier on Security
Python Now Has a Post-Quantum Encryption Library
FOE
SecurityWeek
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
FOE
Bleeping Computer
Critical Progress LoadMaster flaw now actively exploited in attacks
FOE
SecurityWeek
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
FOE
CSO Online
4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofing
FOE
SecurityWeek
Corporate Data Stolen in Levi Strauss Cyberattack
FRIEND
CSO Online
7 key trends defining the cybersecurity market today
FOE
The Hacker News
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
FOE
The Hacker News
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
FOE
SecurityWeek
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
FOE
The Register (Security)
Advertisers are trying to influence AI bots with secret ads
FOE
Risky Business News
Risky Bulletin: Pwnie Awards 2026 winners
FRIEND
Sophos News
Sophos Working with OpenAI on security from AI, with AI, and for AI
FOE
EPIC
NewsNation: Tips for short-circuiting ‘surveillance pricing’
FOE
The Register (Security)
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
FOE
Bleeping Computer
Hackers breach TrueConf to trojanize client installers with backdoors
FOE
The Register (Security)
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
FOE
SecurityWeek
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
FOE
The Hacker News
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
FOE
The Hacker News
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
FOE
The Hacker News
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
FOE
The Hacker News
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
FOE
The Hacker News
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
FOE
The Register (Security)
OpenAI pledges to add Astra security as Anthropic loosens Fable's leash
FRIEND
Professor Messer
Professor Messer’s CompTIA A+ 220-1202 Study Group – August 2026
FOE
Bleeping Computer
Metabase SQLi zero-day exploited in customer data-theft attacks
FOE
The Register (Security)
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
FOE
Bleeping Computer
Unlimited Technology Systems breach impacts 3.8 million people
FOE
The Hacker News
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
FOE
The Hacker News
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
FOE
The Hacker News
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
FOE
CSO Online
Trojanized AI skills gain 1.7M installs in agent-targeted attack
FOE
Dark Reading
AI-Generated Patches Fail Half the Time
FOE
The Register (Security)
Ransomware attacks spike as world distracted by AI
FOE
The Intercept (Privacy)
State Department Wants Palantir’s Advice on Free Speech and “Countering Digital Surveillance”
FOE
Bleeping Computer
Levi Strauss & Co. says hackers stole corporate data in cyberattack
FOE
The Register (Security)
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
FOE
CSO Online
Moonshot’s Kimi AI model has also escaped from a test environment
FOE
SecurityWeek
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
FOE
The Register (Security)
MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
FOE
Bleeping Computer
Real emails, hijacked payments: Two H1 2026 attack chains
FOE
The Register (Security)
Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder
FOE
Bleeping Computer
North Carolina Ports confirms cyberattack disrupting operations
FOE
CSO Online
Snowflake attacker pleads guilty to hack of 165 companies’ data
FOE
The Hacker News
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: With a nail
FOE
CISA Alerts
CPDLC over ATN-B1 Vulnerabilities
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
The Hacker News
Growing Up The Hard Way
FOE
Pen Test Partners
Breaking the attack chain created by exposed cloud secrets
FOE
The Register (Security)
Attacker phished way into US defense supplier's Microsoft 365 account
FOE
The Hacker News
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
FOE
SecurityWeek
Vishing Extortion Group UNC6671 Rebrands After Making Millions
FOE
The Hacker News
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
FOE
Schneier on Security
ICE Is Buying Access to Credit Card Records
FOE
The Hacker News
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
FOE
The Register (Security)
'Asimov was right' about rules for robots, says ex-US Cyber Director
FOE
SecurityWeek
Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
FOE
The Hacker News
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
FRIEND
SecurityWeek
Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)
FRIEND
SecurityWeek
Microsoft, Apple Release Fresh Security Updates
FOE
CSO Online
Python package security in 2026: How supply chain attacks are targeting your AI development environment
FOE
The Hacker News
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
FOE
CSO Online
Human oversight is still critical as AI patching tools miss security risks
FOE
CSO Online
What does a data breach cost? AI is a sizable factor
FOE
The Hacker News
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
FRIEND
SANS Internet Storm Center
Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
FOE
SecurityWeek
3.8 Million Impacted by Unlimited Technology Systems Data Breach
FOE
SecurityWeek
Critical Vulnerabilities Patched With Chrome 151 Update
FOE
The Hacker News
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
FOE
The Register (Security)
China launches mysterious probe into security of Palo Alto Networks' products
FOE
Risky Business News
Risky Bulletin: Meta's AI joins Anthropic and OpenAI in the hacky-hacky
FOE
CISA KEV
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
FRIEND
The Register (Security)
How the famed USENIX Security conf is managing a flood of papers in the AI era
FOE
Bleeping Computer
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
FOE
Bleeping Computer
ClickFix attack pushes macOS infostealer for crypto theft attacks
FOE
Dark Reading
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
FRIEND
CSO Online
Why exposure management is replacing vulnerability management
FOE
Dark Reading
Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride
FOE
Dark Reading
Researcher Claims Control of ChatGPT Secure Sandbox
FOE
Bleeping Computer
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
FOE
The Register (Security)
AI struggles to patch vulns without adult supervision
FOE
EPIC
Judges Sides with EPIC and AG, Telling Google, TikTok, and Meta Their Addictive Social Media Features Are Not 1A Speech
FRIEND
Dark Reading
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
FOE
CSO Online
NatJack exploits put NAT security assumptions to the test at Black Hat
FOE
Bleeping Computer
Swiss government SharePoint breach compromised 200 accounts
FOE
Bleeping Computer
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
FOE
The Hacker News
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
FOE
The Hacker News
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
FOE
Krebs on Security
Canadian Man Pleads Guilty in Snowflake Extortions
FOE
The Register (Security)
Humans in the loop miss a third of dangerous AI coding agent requests
FOE
The Hacker News
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
FOE
Bleeping Computer
Meta AI model hacked a company during misconfigured cyber test
FOE
The Hacker News
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
FRIEND
Professor Messer
Today’s SY0-701 CompTIA Security+ Pop Quiz: The names are getting weirder
FOE
SecurityWeek
Snowflake Hacker Pleads Guilty in US Court
FRIEND
Professor Messer
Professor Messer’s CompTIA A+ 220-1201 Study Group – August 2026
FOE
Bleeping Computer
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
FOE
CSO Online
How a software provider closed unknown paths to cloud compromise
FRIEND
CSO Online
How a global investment firm reduced security surprises
FOE
CSO Online
Meta joins OpenAI, Anthropic in latest AI test breach
FOE
CSO Online
Meta joins OpenAI, Anthropic in latest AI test breach
FOE
CSO Online
You’re only as secure as your last evaluation
FOE
SecurityWeek
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
FOE
CSO Online
Cybersecurity needs a new operating model
FOE
CSO Online
The exploit window is shrinking. Most security workflows are not
FRIEND
CSO Online
CTEM isn’t failing. It’s not being operationalized
FOE
The Hacker News
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
FOE
CSO Online
Autonomy is earned, not claimed
FOE
CSO Online
Attackers hid malware inside Oracle Database after SQL injection breach
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: It’s not a great conversationalist
FOE
CISA Alerts
Medixant RadiAnt DICOM
FOE
CISA Alerts
Johnson Controls Inc. TL280
FOE
CISA Alerts
ABB Ability Zenon
FOE
The Register (Security)
IT department put sticky notes on the laptops to help employees log in
FRIEND
SecurityWeek
Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway
FOE
The Hacker News
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
FOE
CSO Online
Verification closes the loop
FOE
The Hacker News
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
FOE
The Hacker News
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
FOE
SecurityWeek
Critical Paperclip Flaw Allowed Admin Access, Code Execution
FOE
Schneier on Security
Adversarial Clothing Designed to Fool Facial Recognition Systems
FOE
CSO Online
Why the ‘rogue AI’ problem will lead to an era of headaches for security practitioners
FOE
SecurityWeek
Meta AI Hacked External Systems During Cybersecurity Testing
FOE
SecurityWeek
Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
FOE
The Hacker News
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
FOE
CSO Online
Practical lessons from deploying AI securely at scale
FOE
The Hacker News
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
FOE
CSO Online
Evidence points to cybercriminals stepping up their AI game
FOE
The Hacker News
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
FOE
SecurityWeek
Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
FOE
The Hacker News
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
FOE
The Hacker News
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
FOE
SecurityWeek
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
FOE
The Hacker News
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
FOE
The Register (Security)
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
FOE
Risky Business News
Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun
FOE
TrustedSec
The Art of Hunting Azure Cloud Secrets
FOE
The Register (Security)
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
FOE
SANS Internet Storm Center
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
FOE
CSO Online
Enterprise passkey security under threat from malware
FOE
CSO Online
Report: Passkey security issues could allow account takeover
FOE
Dark Reading
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
FOE
Bleeping Computer
Ransom Cartel ransomware creator sentenced to 16 years in prison
FOE
Ars Technica (Security)
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
FOE
Dark Reading
No Perfect Fix for AI Browser Prompt Injection Flaws
FOE
CSO Online
Security validation should begin where attackers begin
FOE
Bleeping Computer
Canadian pleads guilty to Snowflake cloud data-theft attacks
FOE
CSO Online
Why security validation must follow the attack path
FOE
The Register (Security)
Prompt injection isn't the bug, AI agent frameworks are
FOE
Ars Technica (Security)
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
FOE
Bleeping Computer
Hackers run khunt post-exploitation toolkit from Oracle database
FOE
Dark Reading
CSS: The Hidden Threat Lurking in Your Inbox
FOE
SecurityWeek
How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
FOE
Dark Reading
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
FOE
The Hacker News
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
FOE
The Hacker News
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
FOE
Dark Reading
Flaws in Google APK for Python Unlock Agent-to-Agent Attack
FOE
Dark Reading
AI Sends Global Crime Syndicates Into Fraud Nirvana
FOE
SANS Internet Storm Center
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
FOE
Bleeping Computer
COLDCARD security audit phishing attack installs remote access tool
FOE
SpecterOps
Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1
FOE
SpecterOps
Of Course We Built a WSUS Ludus Lab
FOE
SpecterOps
Weaponizing Windows Updates with NotWSUSpicious
FOE
SpecterOps
Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2
FOE
The Register (Security)
IBM's agentic AI platform is under active attack - patch now
FOE
Bleeping Computer
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
FOE
EPIC
Senate Commerce Committee Advances Youth AI Privacy Act
FOE
The Hacker News
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
FOE
The Hacker News
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
FOE
Bleeping Computer
Google Blogger locks hundreds of blogs in malware false positive
FRIEND
SecurityWeek
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
FOE
The Hacker News
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
FOE
Bleeping Computer
How AI-powered phishing killed blocklists for good
FOE
The Hacker News
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
FOE
The Register (Security)
London cops handed victim's new address and number to her stalker, watchdog says
FOE
SecurityWeek
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
FOE
SecurityWeek
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: It smells delicious
FOE
CSO Online
Critical Paperclip bugs expose AI agent trust failures
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
The Hacker News
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
FOE
The Hacker News
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
FOE
CSO Online
OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidents
FOE
SecurityWeek
311,000 Impacted by Brown Health Medical Group-MA Data Breach
FRIEND
SecurityWeek
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
FOE
The Register (Security)
UK charities count the cost of Beacon CRM cyberattack
FOE
The Hacker News
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
FOE
The Hacker News
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
FOE
SecurityWeek
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
FOE
CSO Online
One C2 kit. 30 customers. 2 governments
FOE
SecurityWeek
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
FOE
Schneier on Security
Vulnerabilities in Car Anti-Theft Device
FOE
The Hacker News
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
FOE
CSO Online
Your orchestration framework choice is a security decision, not just an engineering one
FOE
SecurityWeek
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
FOE
CSO Online
Why you need a reliable AI agent kill switch
FOE
Dark Reading
Angola's Largest Telco Breached Hours Before IPO
FOE
The Hacker News
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
FOE
The Hacker News
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
FOE
CSO Online
AI threat report: Rogue agents, workflow attacks
FOE
SecurityWeek
Water Sector Cyberattacks Reportedly Hit at Least 12 States
FOE
The Hacker News
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
FOE
Risky Business News
Risky Bulletin: Hacker breaches Hungary's State Treasury
FOE
CSO Online
Ruby on Rails critical bug puts every image upload under scrutiny
FOE
The Register (Security)
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
FOE
EFF Deeplinks
Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction
FRIEND
Sophos News
Sophos DNS Protection update for GenAI
FOE
CISA KEV
CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
FOE
Bleeping Computer
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
FOE
CSO Online
ChainDrop credential stealing worm infects over 400 npm packages
FRIEND
EFF Deeplinks
Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA
FOE
Bleeping Computer
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
FOE
Bleeping Computer
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
FRIEND
SpecterOps
Mythic 4 Public Beta: More Than a New Coat of Paint
FOE
EFF Deeplinks
Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds
FOE
EFF Deeplinks
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
FOE
Bleeping Computer
New XCSSET variant targets macOS devs via compromised Xcode projects
FOE
Schneier on Security
Iran Cyberattacks Against Minnesota Water Systems
FOE
Bleeping Computer
77 Open VSX extensions found harvesting developer info
FOE
Dark Reading
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
FOE
The Hacker News
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
FOE
The Register (Security)
Bypassing AI guardrails is so easy a script kiddie can do it
FRIEND
SecurityWeek
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
FRIEND
CSO Online
Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security
FRIEND
The Register (Security)
This one time, at Hacker Summer Camp …
FOE
SecurityWeek
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
FRIEND
EPIC
EPIC, Coalition Urge Senate Commerce Committee to Advance Youth AI Privacy Act
FOE
The Register (Security)
Feds get 3 days to patch N-able God mode flaw under active exploit
FOE
Bleeping Computer
Massive ChainDrop npm supply-chain attack infects hundreds of packages
FRIEND
Professor Messer
Today’s N10-009 CompTIA Network+ Pop Quiz: We need more duct tape
FRIEND
SecurityWeek
Oligo Raises $60 Million for Runtime Security
FRIEND
The Register (Security)
AI helps Microsoft bug hunters chase a record $20M payday
FRIEND
SecurityWeek
CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout
FRIEND
EFF Deeplinks
Technology's Power in the Hands of the People
FRIEND
Bleeping Computer
Varonis Agent IBAC keeps AI agents within their intended boundaries
FOE
SecurityWeek
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
FRIEND
SecurityWeek
Zenity Raises $125 Million in Series C Funding
FOE
The Hacker News
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
FOE
The Hacker News
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
FOE
Dark Reading
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
FOE
SANS Internet Storm Center
Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
FOE
CSO Online
Critical Azure Cosmos DB flaw threatened cross-tenant database takeover
FRIEND
Professor Messer
Today’s 220-1201 CompTIA A+ Pop Quiz: The most important meal of the day
FRIEND
CSO Online
The top new cybersecurity products at Black Hat USA 2026
FOE
CSO Online
The top cybersecurity product announcements from Black Hat 2026
FOE
CISA Alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog
FOE
CISA Alerts
Acrisure KARR BT and DR-100
FOE
CISA Alerts
Thermo Fisher Applied Biosystems Genetic Analyzers
FRIEND
SecurityWeek
Obsidian Security Raises $85 Million at $1.1 Billion Valuation
FOE
SecurityWeek
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
FOE
CSO Online
Google ADK flaws reveal what happens when AI agents trust the wrong message
FOE
The Hacker News
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
FOE
The Register (Security)
CAF Bank reopens online service but warns of further outages
FOE
The Hacker News
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
FOE
SecurityWeek
Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
FOE
The Hacker News
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
FOE
Schneier on Security
Some Claude Chats Are Searchable on Google
FOE
CSO Online
Secure AI adoption starts with API best practices
FOE
SecurityWeek
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
FOE
The Hacker News
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
FOE
CSO Online
The Minnesota attackers may hold a better backup of your plant than you do
FOE
SecurityWeek
150,000 Impacted by Madera Community Hospital Data Breach
FOE
CSO Online
Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpers
FOE
The Hacker News
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
FOE
Dark Reading
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
FRIEND
SecurityWeek
Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
FRIEND
The Register (Security)
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
FRIEND
TrustedSec
TLS Encryption and Compliance
FRIEND
SecurityWeek
New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
FOE
Bleeping Computer
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
FOE
Sophos News
N-able N-central exploitation results in RMM tool deployment
FOE
Sophos News
Interlock ransomware gang creates volatile situation
FOE
CISA KEV
CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
FOE
CISA KEV
CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
FOE
CISA KEV
CVE-2026-9198: IBM Langflow Code Injection Vulnerability
FOE
Bleeping Computer
New Pass-ta-key attacks let malware hijack Google-synced passkeys
FOE
EFF Deeplinks
The Senate Should Reject KOSA's Privacy Risks
FOE
EFF Deeplinks
EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act
FOE
EFF Deeplinks
EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal
FOE
Dark Reading
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
FOE
EFF Deeplinks
The Youth AI Privacy Act’s Privacy Paradox
FOE
Dark Reading
New Tool Traces AI Videos Back to Their Source
FOE
Dark Reading
Anthropic: AI Attacks Result of Security Gaps, Not Model Issues
FOE
The Register (Security)
Google dev kit spurs first-ever agent-on-agent violence
FOE
EPIC
PRESS RELEASE: Coalition Challenges Dramatic Data Privacy Changes to Federal Assistance Program
FOE
Bleeping Computer
New DOUBLECUP ClickFix service hides malware in browser cache images
FOE
Bleeping Computer
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
FOE
The Hacker News
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
FOE
EPIC
EPIC, Coalition Urge Congress to Reject Defense Department’s Attempt to Withhold Information from FOIA
FOE
EPIC
EPIC, Coalition Urge GSA to Remove ‘Unbiased AI’ Requirements From Federal AI Contracts
FOE
The Register (Security)
AI slop pollutes the CVE pipeline with fake vulns
FOE
Schneier on Security
More on the OpenAI Agent’s Attack on Hugging Face
FOE
Bleeping Computer
N-able warns of N-central auth bypass flaw exploited in attacks
FOE
The Hacker News
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
FOE
The Hacker News
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
FOE
SpecterOps
ConfigManBearPig 2.0 – Things Are Getting Cereal
FRIEND
SecurityWeek
Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
FOE
Dark Reading
Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
FOE
The Register (Security)
Russian spies turn public Wi-Fi into malware delivery systems
FRIEND
SecurityWeek
Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion
FOE
SecurityWeek
Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations
FOE
Bleeping Computer
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
FOE
Bleeping Computer
Inside the Underground Business of the Android BTMOB RAT malware
FRIEND
EFF Deeplinks
EFF at BSidesLV, Black Hat, and DEF CON 👨💻
FOE
The Hacker News
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
FOE
Dark Reading
Is There Really a Fix for CISO Fatigue?
FOE
The Register (Security)
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
FOE
SecurityWeek
River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
FRIEND
SecurityWeek
Horizon3 Raises $250 Million to Fund Continuing Growth
FRIEND
CSO Online
Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls
FOE
SecurityWeek
N‑able Patches Vulnerability Exploited to Hack N-central Servers
FRIEND
Professor Messer
Today’s 220-1202 CompTIA A+ Pop Quiz: Don’t forget the bananas
FOE
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog
FOE
SecurityWeek
Brinks Home Discloses Data Breach as Hackers Leak Files
FRIEND
The Hacker News
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
FOE
The Register (Security)
UK government investment arm cops to 40-hour leak of officials' contact details
FOE
The Hacker News
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
FOE
Schneier on Security
The OpenAI Hack Shows the Genie Is Out of the Bottle
FOE
SecurityWeek
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
FOE
SecurityWeek
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
FOE
The Hacker News
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
FOE
CSO Online
Stop depending on heroics and start operationalizing third-party risk
FOE
SecurityWeek
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
FOE
CSO Online
AI is making cybersecurity fundamentals more important than ever
FOE
The Hacker News
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
FOE
The Register (Security)
AI is 'both the weapon and the target' in latest wave of cyberattacks
FOE
The Hacker News
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
FOE
The Hacker News
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
FOE
Risky Business News
Risky Bulletin: Russia is behind the recent hotel WiFi hacks
FOE
CISA KEV
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
FOE
Bleeping Computer
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
FOE
Bleeping Computer
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
FRIEND
Bleeping Computer
Google Chrome may soon block New Tab hijacker extensions by default
FOE
SANS Internet Storm Center
Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
FOE
The Hacker News
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
FOE
Bleeping Computer
Rails patches critical Active Storage flaw with RCE potential
FRIEND
SecurityWeek
Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments
FOE
SecurityWeek
Ruby on Rails Patches Critical Vulnerability
FRIEND
Ars Technica (Security)
Defcon's new badge is a security key you can see inside
FOE
The Hacker News
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
FOE
SANS Internet Storm Center
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
FOE
The Hacker News
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
FOE
The Hacker News
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware