2026-08-14 01:19 UTC
Security Journalism
TIER 3
BleepingComputer · Mayank Parmar · indexed 2026-08-16 02:02 UTC
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]
P0
2026-08-13 21:23 UTC
Vendor Research
TIER 2
AWS Security Blog · Adam Aboudi · indexed 2026-08-16 02:02 UTC
Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]
P0
2026-08-13 21:12 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
P0
2026-08-13 20:47 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
P15
2026-08-13 20:45 UTC
Security Journalism
TIER 3
Dark Reading · Rob Wright · indexed 2026-08-16 02:02 UTC
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
P5
2026-08-13 20:11 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because th…
P5
2026-08-13 18:15 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
P0
2026-08-13 18:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · William Largent · indexed 2026-08-16 02:02 UTC
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
P0
2026-08-13 17:46 UTC
Security Journalism
TIER 3
BleepingComputer · Sergiu Gatlan · indexed 2026-08-16 02:02 UTC
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]
P25
2026-08-13 17:33 UTC
Security Journalism
TIER 3
BleepingComputer · Ax Sharma · indexed 2026-08-16 02:02 UTC
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]
P0
2026-08-13 16:47 UTC
Security Journalism
TIER 3
The Record · indexed 2026-08-16 02:02 UTC
All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.
P0
2026-08-13 15:52 UTC
Security Journalism
TIER 3
The Record · indexed 2026-08-16 02:02 UTC
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
P0
2026-08-13 14:41 UTC
Security Journalism
TIER 3
SecurityWeek · Eduard Kovacs · indexed 2026-08-16 02:02 UTC
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek.
P0
2026-08-13 14:17 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.
P5
2026-08-13 13:37 UTC
Security Journalism
TIER 3
The Record · indexed 2026-08-16 02:02 UTC
Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.
P0
2026-08-13 10:20 UTC
Vendor Research
TIER 2
Google Security Blog · Daniel Fabian · indexed 2026-08-16 02:02 UTC
At Google, our Red Teams have always operated on the cutting edge of security. We’ve shared our journey in the past: from the high-stakes operations showcased in our Hac…
P0
2026-08-13 10:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Chetan Raghuprasad · indexed 2026-08-16 02:02 UTC
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
P0
2026-08-13 10:00 UTC
Security Journalism
TIER 3
Dark Reading · Nate Nelson · indexed 2026-08-16 02:02 UTC
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
P0
2026-08-13 07:00 UTC
Security Journalism
TIER 3
Dark Reading · Nate Nelson · indexed 2026-08-16 02:02 UTC
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
P15
2026-08-13 06:09 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication
P15
2026-08-13 02:00 UTC
Community
TIER 2
SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-13 01:26 UTC
Community
TIER 2
SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the data against VirusTotal and CyberGordon. 
P0
2026-08-12 22:16 UTC
Vendor Research
TIER 2
AWS Security Blog · Zach Jiang · indexed 2026-08-16 02:02 UTC
When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your […]
P0
2026-08-12 21:08 UTC
Security Journalism
TIER 3
Dark Reading · Jai Vijayan · indexed 2026-08-16 02:02 UTC
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
P0
2026-08-12 19:50 UTC
Vendor Research
TIER 1
Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC
Control iD iDSecure Multiple Denial of Service Vulnerabilities Control iD iDSecure is an on-premises access control and time attendance management application for Windows. Version 4.8.1.0 is affected by multiple vulnerabilities:Unauthenticated Service Restart Denial of Service (High): The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous …
P0
2026-08-12 19:17 UTC
Vendor Research
TIER 1
Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC
ScadaLTS Multiple Vulnerabilities ScadaLTS is an open-source, web-based SCADA/HMI application. Version 2.7.8.1 is affected by multiple vulnerabilities: CVE-2026-19656: Authenticated Remote Code Execution (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)A server-side method is exposed without any authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating-system commands on the underlying host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full com…
P20
2026-08-12 17:39 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
P25
2026-08-12 16:28 UTC
Security Journalism
TIER 3
Dark Reading · Richard Thurston · indexed 2026-08-16 02:02 UTC
Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises
P0
2026-08-12 14:21 UTC
Community
TIER 2
SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash_history" and collecting meaningful additional data. Our reader David commented that this can also be done quite well with Linux's kernel process accounting feature, and I think he is very right. I really like Linux process accounting for a number of reasons, so here is a quick introduction.
P0
2026-08-12 14:09 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66
P0