CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 57 matching records.
AUTO-POLL // 2026-08-16 03:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-14 21:36 UTC
Vendor Research
TIER 2

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.The Taiwan campaign is…

AI SecurityAPT / Nation-StateCloud SecurityInitial AccessNetwork SecurityThreat ActorsVulnerabilities CVE-2025-3248
P30
2026-08-14 11:00 UTC
Security Journalism
TIER 3

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

SecurityWeek · Eduard Kovacs · indexed 2026-08-16 02:02 UTC

Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.

Cloud Security
P0
2026-08-14 09:20 UTC
Security Journalism
TIER 3

Over 1,000 Charities Hit by Beacon CRM Data Breach

SecurityWeek · Eduard Kovacs · indexed 2026-08-16 02:02 UTC

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek.

Cloud SecurityData Breaches
P0
2026-08-13 21:23 UTC
Vendor Research
TIER 2

AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

AWS Security Blog · Adam Aboudi · indexed 2026-08-16 02:02 UTC

Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]

Cloud Security
P0
2026-08-12 22:16 UTC
Vendor Research
TIER 2

How AWS IAM role manager rethinks the starting point for IAM roles

AWS Security Blog · Zach Jiang · indexed 2026-08-16 02:02 UTC

When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your […]

Cloud Security
P0
2026-08-12 11:13 UTC
Security Journalism
TIER 3

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could

Cloud SecurityVulnerabilities CVE-2026-48362
P15
2026-08-12 08:04 UTC
Security Journalism
TIER 3

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Cloud SecurityThreat Intelligence
P0
2026-08-11 21:50 UTC
Vendor Research
TIER 2

Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact

AWS Security Blog · Kevin Donohue · indexed 2026-08-16 02:02 UTC

Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landing Zone Accelerator on AWS support for digital sovereignty and today we’re announcing the availability of a new independent assessment […]

Cloud Security
P0
2026-08-11 21:10 UTC
Vendor Research
TIER 2

Patch Tuesday - August 2026

Rapid7 · Adam Barnett · indexed 2026-08-16 02:02 UTC

Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday, including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are no…

Cloud SecurityCredential ExposureLinuxMicrosoftSecurity ResearchVulnerabilities CVE-2026-50656CVE-2026-55040CVE-2026-62832CVE-2026-63520CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-72971
P95
2026-08-11 20:10 UTC
Security Journalism
TIER 3

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

Cloud SecurityLinuxMicrosoftVulnerabilities CVE-2026-68820
P30
2026-08-11 19:08 UTC
Security Journalism
TIER 3

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it

Cloud Security
P0
2026-08-11 18:53 UTC
Vendor Research
TIER 2

Summer 2026 SOC 1 report is now available with 185 services in scope

AWS Security Blog · Baj Bajwa · indexed 2026-08-16 02:02 UTC

Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 12-month period from July 1, 2025–June 30, 2026, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering to the heightened […]

Cloud Security
P0
2026-08-11 16:12 UTC
Vendor Research
TIER 2

AWS successfully completed its 2025-26 NHS DSPT assessment

AWS Security Blog · Tariro Dongo · indexed 2026-08-16 02:02 UTC

Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their performance against the National Data Guardian’s 10 data security standards. All organizations […]

Cloud Security
P0
2026-08-11 14:04 UTC
Vendor Research
TIER 2

Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Services (AD CS)Application Information ServicesAzure Active DirectoryAzure CycleCloudAzure Monitor Agent…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2022-21919CVE-2022-26904CVE-2024-38193CVE-2025-21418CVE-2025-32709CVE-2026-61348CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62718CVE-2026-62720CVE-2026-62742CVE-2026-62745CVE-2026-62761CVE-2026-62776CVE-2026-62803CVE-2026-62807CVE-2026-62812CVE-2026-62814CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-70307
P65
2026-08-11 09:16 UTC
Security Journalism
TIER 3

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

AppleCloud SecurityNetwork SecurityRansomware
P15
2026-08-10 20:21 UTC
Vendor Research
TIER 2

AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)

AWS Security Blog · Tariro Dongo · indexed 2026-08-16 02:02 UTC

We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This demonstrates our continuous commitment to adhere to the heightened expectations of customers […]

Cloud Security
P0
2026-08-10 17:09 UTC
Vendor Research
TIER 2

2026 AWS CyberVadis report now available for due diligence on third-party suppliers

AWS Security Blog · Tariro Dongo · indexed 2026-08-16 02:02 UTC

We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now use the 2026 AWS CyberVadis report and scorecard to reduce their supplier […]

Cloud Security
P0
2026-08-10 16:35 UTC
Vendor Research
TIER 1

Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy Tenable Research has identified and responsibly disclosed a critical cross-tenant data exfiltration vulnerability in Google Cloud Apigee. This flaw allowed an attacker to abuse a "confused deputy" in Apigee's internal analytics infrastructure to read arbitrary Google Cloud Storage (GCS) objects across different tenants, as well as shared production infrastructure buckets. The vulnerability stems from how Apigee's backend analytics services, specifically the first-party service accounts edge-uap@system.gservi…

Cloud SecuritySecurity ResearchVulnerabilities
P0
2026-08-10 11:33 UTC
Security Journalism
TIER 3

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain

Cloud SecurityThreat ActorsVulnerabilities
P0
2026-08-07 19:37 UTC
Vendor Research
TIER 2

A decade of enterprise identity in the cloud with AWS Managed Microsoft AD

AWS Security Blog · Vladimir Provorov · indexed 2026-08-16 02:02 UTC

Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applications and your business.” A decade later, AWS Managed Microsoft AD […]

Cloud SecurityMicrosoft
P0
2026-08-07 16:46 UTC
Vendor Research
TIER 2

Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access

AWS Security Blog · Hetal Kolekar · indexed 2026-08-16 02:02 UTC

Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix over-permissioned S3 buckets across your AWS environment, along with […]

Cloud Security
P0
2026-08-07 12:00 UTC
Vendor Research
TIER 2

Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026

Tenable Blog · Nick Hayes · indexed 2026-08-16 02:02 UTC

Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event.Key takeawaysBuilding defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove the cost of finding and exploiting a vulnerability down to 1990s levels; it also removed the engineering barrier that kept defenders from building the automation they’ve always wanted. The unglamorous work won the room: triage, reconciliation…

AI SecurityCloud SecurityMicrosoftThreat ActorsVulnerabilities
P0
2026-08-07 08:18 UTC
Security Journalism
TIER 3

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.

Cloud Security
P0
2026-08-06 22:03 UTC
Vendor Research
TIER 2

Automate certificates with ACME support in AWS Certificate Manager

AWS Security Blog · Anthony Harvey · indexed 2026-08-16 02:02 UTC

Customers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum validity drops to 100 days. By March 2029, it lasts for 47 days. For an […]

Cloud Security
P0
2026-08-06 16:16 UTC
Vendor Research
TIER 2

Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale

AWS Security Blog · Maria Gutovsky · indexed 2026-08-16 02:02 UTC

This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven financial crime detection platform on Amazon Web Services (AWS). NICE Actimize, a leading provider […]

Cloud Security
P0
2026-08-06 12:00 UTC
Vendor Research
TIER 2

AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing

Tenable Blog · Robert Huber, Tenable Research · indexed 2026-08-16 02:02 UTC

We spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger.Key takeawaysFrontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40 billion tokens testing Claude Mythos Preview across source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic testing. Human expertise turns frontier AI findings into real risk reduction. More findings don't auto…

Cloud SecurityMicrosoft
P0
2026-08-05 21:00 UTC
Vendor Research
TIER 2

AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows

AWS Security Blog · Chet Kapoor · indexed 2026-08-16 02:02 UTC

Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and lower token costs. Getting the strongest AI-powered security will come from tools that combine the most relevant models with deep knowledge of a customer’s specific environment. AWS Continuum for code vulnerabilities (Preview) is built […]

Cloud SecurityMicrosoft
P0
12