2026-08-07 08:18 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.
P0
2026-08-07 07:22 UTC
Community
TIER 2
SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:
P0
2026-08-06 22:26 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
P0
2026-08-06 22:03 UTC
Vendor Research
TIER 2
AWS Security Blog · Anthony Harvey · indexed 2026-08-16 02:02 UTC
Customers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum validity drops to 100 days. By March 2029, it lasts for 47 days. For an […]
P0
2026-08-06 21:42 UTC
Security Journalism
TIER 3
Dark Reading · Arielle Waldman · indexed 2026-08-16 02:02 UTC
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
P0
2026-08-06 20:39 UTC
Security Journalism
TIER 3
Dark Reading · Nate Nelson · indexed 2026-08-16 02:02 UTC
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.
P0
2026-08-06 20:38 UTC
Security Journalism
TIER 3
Dark Reading · Alexander Culafi · indexed 2026-08-16 02:02 UTC
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.
P0
2026-08-06 19:00 UTC
Security Journalism
TIER 3
Dark Reading · Arielle Waldman · indexed 2026-08-16 02:02 UTC
Two former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support — and a dose of absurdity.
P0
2026-08-06 18:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-08-16 02:02 UTC
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
P0
2026-08-06 17:00 UTC
Independent Research
TIER 2
Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.
P0
2026-08-06 16:16 UTC
Vendor Research
TIER 2
AWS Security Blog · Maria Gutovsky · indexed 2026-08-16 02:02 UTC
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven financial crime detection platform on Amazon Web Services (AWS). NICE Actimize, a leading provider […]
P0
2026-08-06 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory…
P0
2026-08-06 12:00 UTC
Vendor Research
TIER 2
Tenable Blog · Robert Huber, Tenable Research · indexed 2026-08-16 02:02 UTC
We spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger.Key takeawaysFrontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40 billion tokens testing Claude Mythos Preview across source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic testing. Human expertise turns frontier AI findings into real risk reduction. More findings don't auto…
P0
2026-08-06 10:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.
P0
2026-08-05 23:35 UTC
Security Journalism
TIER 3
Dark Reading · Tara Seals · indexed 2026-08-16 02:02 UTC
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
P0
2026-08-05 23:30 UTC
Security Journalism
TIER 3
Dark Reading · Jai Vijayan · indexed 2026-08-16 02:02 UTC
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.
P0
2026-08-05 22:18 UTC
Security Journalism
TIER 3
Dark Reading · Alexander Culafi · indexed 2026-08-16 02:02 UTC
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.
P0
2026-08-05 21:00 UTC
Vendor Research
TIER 2
AWS Security Blog · Chet Kapoor · indexed 2026-08-16 02:02 UTC
Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and lower token costs. Getting the strongest AI-powered security will come from tools that combine the most relevant models with deep knowledge of a customer’s specific environment. AWS Continuum for code vulnerabilities (Preview) is built […]
P0
2026-08-05 19:47 UTC
Security Journalism
TIER 3
Dark Reading · Kristina Beek · indexed 2026-08-16 02:02 UTC
CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.
P0
2026-08-05 19:08 UTC
Security Journalism
TIER 3
Dark Reading · Nate Nelson · indexed 2026-08-16 02:02 UTC
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
P0
2026-08-05 18:03 UTC
Security Journalism
TIER 3
Dark Reading · Elizabeth Montalbano · indexed 2026-08-16 02:02 UTC
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.
P0
2026-08-05 17:17 UTC
Vendor Research
TIER 2
AWS Security Blog · Kiran Dongara · indexed 2026-08-16 02:02 UTC
Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastructure at scale, this scenario has been all too familiar. Whether you’re a CISO evaluating security […]
P0
2026-08-05 16:30 UTC
Vendor Research
TIER 2
Microsoft Security Blog · Ran Rosin · indexed 2026-08-16 02:02 UTC
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog.
P0
2026-08-05 16:01 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273 Critical 9.8 Cisco Integrated Management Controller Argument Injection Vulnerabilities CVE-2026-2020…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information. Cisco has released softw…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Cisco has released software updates that address this vulnerabilit…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker mus…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacke…
P5