2026-08-15 14:14 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
P0
2026-08-14 23:24 UTC
Security Journalism
TIER 3
BleepingComputer · Mayank Parmar · indexed 2026-08-16 02:02 UTC
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]
P0
2026-08-14 21:36 UTC
Vendor Research
TIER 2
Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.The Taiwan campaign is…
P30
2026-08-14 21:27 UTC
Vendor Research
TIER 2
Rapid7 · Rapid7 Labs · indexed 2026-08-16 02:02 UTC
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-fr…
P20
2026-08-14 20:31 UTC
Security Journalism
TIER 3
The Record · indexed 2026-08-16 02:02 UTC
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.
P0
2026-08-14 19:24 UTC
Security Journalism
TIER 3
Dark Reading · Kristina Beek · indexed 2026-08-16 02:02 UTC
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.
P0
2026-08-14 19:21 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks Crosswork Industrial Ethernet 1000 Series Switches Packaged Contact Center Enterprise and Unified Contact Center Enterprise RoomOS Secure Workload Unified Intelligence Center To fully remediate vulnerabilities to be disclosed on August 19, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories. For more information abo…
P0
2026-08-14 18:04 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
P0
2026-08-14 17:32 UTC
Security Journalism
TIER 3
Dark Reading · Robert Lemos · indexed 2026-08-16 02:02 UTC
Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
P0
2026-08-14 15:58 UTC
Security Journalism
TIER 3
Dark Reading · Nate Nelson · indexed 2026-08-16 02:02 UTC
One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.
P0
2026-08-14 14:59 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
P10
2026-08-14 14:00 UTC
Security Journalism
TIER 3
BleepingComputer · Sponsored by Material Security · indexed 2026-08-16 02:02 UTC
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
P0
2026-08-14 14:00 UTC
Vendor Research
TIER 2
Google Security Blog · Jeremy Kun · indexed 2026-08-16 02:02 UTC
heir logo
P0
2026-08-14 14:00 UTC
Security Journalism
TIER 3
Dark Reading · Chris Drumgoole · indexed 2026-08-16 02:02 UTC
Why do so many boards underestimate technology risk until it becomes a crisis?
P0
2026-08-14 13:45 UTC
Security Journalism
TIER 3
BleepingComputer · Sergiu Gatlan · indexed 2026-08-16 02:02 UTC
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]
P15
2026-08-14 13:14 UTC
Security Journalism
TIER 3
The Record · indexed 2026-08-16 02:02 UTC
French authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.
P0
2026-08-14 12:17 UTC
Security Journalism
TIER 3
Dark Reading · Jeffrey Schwartz · indexed 2026-08-16 02:02 UTC
The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.
P0
2026-08-14 11:57 UTC
Security Journalism
TIER 3
SecurityWeek · SecurityWeek News · indexed 2026-08-16 02:02 UTC
Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities appeared first on SecurityWeek.
P0
2026-08-14 11:55 UTC
Security Journalism
TIER 3
BleepingComputer · Sergiu Gatlan · indexed 2026-08-16 02:02 UTC
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
P15
2026-08-14 11:35 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.
P0
2026-08-14 11:24 UTC
Independent Research
TIER 2
Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.
P0
2026-08-14 11:00 UTC
Security Journalism
TIER 3
SecurityWeek · Eduard Kovacs · indexed 2026-08-16 02:02 UTC
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.
P0
2026-08-14 10:52 UTC
Security Journalism
TIER 3
BleepingComputer · Sergiu Gatlan · indexed 2026-08-16 02:02 UTC
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]
P0
2026-08-14 10:24 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers. The post 1.6 Million Likely Impacted by RingCentral Data Breach appeared first on SecurityWeek.
P0
2026-08-14 09:20 UTC
Security Journalism
TIER 3
SecurityWeek · Eduard Kovacs · indexed 2026-08-16 02:02 UTC
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts. The post Over 1,000 Charities Hit by Beacon CRM Data Breach appeared first on SecurityWeek.
P0
2026-08-14 08:27 UTC
Security Journalism
TIER 3
BleepingComputer · Sergiu Gatlan · indexed 2026-08-16 02:02 UTC
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]
P0
2026-08-14 08:16 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers. The post 14,000 Trezor Customers Impacted by Data Breach at ShipMonk appeared first on SecurityWeek.
P0
2026-08-14 07:01 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek.
P40
2026-08-14 06:41 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.
P0
2026-08-14 02:00 UTC
Community
TIER 2
SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0