CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 406 matching records.
AUTO-POLL // 2026-08-16 03:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-13 21:23 UTC
Vendor Research
TIER 2

AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

AWS Security Blog · Adam Aboudi · indexed 2026-08-16 02:02 UTC

Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]

Cloud Security
P0
2026-08-13 20:11 UTC
Vendor Research
TIER 1

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because th…

LinuxMicrosoftVulnerabilities CVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345CVE-2026-20346CVE-2026-20347CVE-2026-20348
P5
2026-08-13 18:00 UTC
Vendor Research
TIER 2

Curiouser and Curiouser

Cisco Talos Intelligence Blog · William Largent · indexed 2026-08-16 02:02 UTC

In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.

P0
2026-08-13 17:33 UTC
Security Journalism
TIER 3

AI 'watermark removers' flood the web. Almost none can prove they work.

BleepingComputer · Ax Sharma · indexed 2026-08-16 02:02 UTC

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]

P0
2026-08-13 16:47 UTC
Security Journalism
TIER 3

Flock tightens privacy controls amid scandals over officer abuse

The Record · indexed 2026-08-16 02:02 UTC

All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.

P0
2026-08-13 14:41 UTC
Security Journalism
TIER 3

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

SecurityWeek · Eduard Kovacs · indexed 2026-08-16 02:02 UTC

Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek.

Network Security
P0
2026-08-13 13:37 UTC
Security Journalism
TIER 3

Brazil orders Discord to suspend livestreaming after teen suicide

The Record · indexed 2026-08-16 02:02 UTC

Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.

P0
2026-08-13 10:20 UTC
Vendor Research
TIER 2

The Evolving Role of the Red Team in the Era of Agentic Security

Google Security Blog · Daniel Fabian · indexed 2026-08-16 02:02 UTC

At Google, our Red Teams have always operated on the cutting edge of security. We’ve shared our journey in the past: from the high-stakes operations showcased in our Hac…

P0
2026-08-13 10:00 UTC
Vendor Research
TIER 2

Dissecting the JWR phishing framework

Cisco Talos Intelligence Blog · Chetan Raghuprasad · indexed 2026-08-16 02:02 UTC

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.

Phishing
P0
2026-08-13 07:00 UTC
Security Journalism
TIER 3

Belgium's eID Authentication Opens Citizen Accounts to RCE

Dark Reading · Nate Nelson · indexed 2026-08-16 02:02 UTC

The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.

Vulnerabilities
P15
2026-08-13 06:09 UTC
Security Journalism
TIER 3

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

MicrosoftThreat ActorsVulnerabilities CVE-2026-55040
P15
2026-08-13 01:26 UTC
Community
TIER 2

Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)

SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC

In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the data against VirusTotal and CyberGordon. 

Malware
P0
2026-08-12 22:16 UTC
Vendor Research
TIER 2

How AWS IAM role manager rethinks the starting point for IAM roles

AWS Security Blog · Zach Jiang · indexed 2026-08-16 02:02 UTC

When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your […]

Cloud Security
P0
2026-08-12 19:50 UTC
Vendor Research
TIER 1

Control iD iDSecure Multiple Denial of Service Vulnerabilities

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Control iD iDSecure Multiple Denial of Service Vulnerabilities Control iD iDSecure is an on-premises access control and time attendance management application for Windows. Version 4.8.1.0 is affected by multiple vulnerabilities:Unauthenticated Service Restart Denial of Service (High): The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous …

Microsoft
P0
2026-08-12 19:17 UTC
Vendor Research
TIER 1

ScadaLTS Multiple Vulnerabilities

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

ScadaLTS Multiple Vulnerabilities ScadaLTS is an open-source, web-based SCADA/HMI application. Version 2.7.8.1 is affected by multiple vulnerabilities: CVE-2026-19656: Authenticated Remote Code Execution (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)A server-side method is exposed without any authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating-system commands on the underlying host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full com…

ICS / OTVulnerabilities CVE-2026-19656CVE-2026-19657
P20
2026-08-12 17:39 UTC
Security Journalism
TIER 3

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

APT / Nation-StateMalwareMicrosoftThreat ActorsVulnerabilities
P25
2026-08-12 16:28 UTC
Security Journalism
TIER 3

Walmart Takes a 'Trusted Agent' Approach to Purple Teaming

Dark Reading · Richard Thurston · indexed 2026-08-16 02:02 UTC

Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises

P0
2026-08-12 14:21 UTC
Community
TIER 2

Linux Kernel Process Accounting, (Wed, Aug 12th)

SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC

A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash_history" and collecting meaningful additional data. Our reader David commented that this can also be done quite well with Linux's kernel process accounting feature, and I think he is very right. I really like Linux process accounting for a number of reasons, so here is a quick introduction.

Linux
P0
2026-08-12 14:09 UTC
Security Journalism
TIER 3

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66

Network Security
P0
1234