2026-08-26 11:07 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-26 11:15 UTC
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
P0
2026-08-26 10:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 10:35 UTC
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an
P0
2026-08-26 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-08-26 10:05 UTC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
P0
2026-08-26 09:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 10:35 UTC
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a
P0
2026-08-26 09:00 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…
P45
2026-08-26 08:44 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-26 10:00 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for […]
P35
2026-08-26 08:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-26 08:40 UTC
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records, […]
P0
2026-08-26 08:30 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-26 08:35 UTC
The international law enforcement operation focused on disrupting crime-as-a-service networks and infrastructure behind groups like Black Axe.
P0
2026-08-26 08:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-26 08:40 UTC
WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information […]
P0
2026-08-26 08:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-26 08:05 UTC
The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.
P0
2026-08-26 07:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said. "These groups are
P0
2026-08-26 07:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-26 07:40 UTC
INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a […]
P0
2026-08-26 07:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&
P0
2026-08-26 06:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the
P45
2026-08-26 05:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across
P0
2026-08-26 02:40 UTC
Community
SANS Internet Storm Center · indexed 2026-08-26 02:50 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-25 21:58 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-25 22:10 UTC
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
P0
2026-08-25 21:53 UTC
Vendor Research
AWS Security Blog · Kevin Donohue · indexed 2026-08-25 21:55 UTC
This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted […]
P0
2026-08-25 21:39 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-25 21:40 UTC
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
P0
2026-08-25 21:08 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-08-25 21:20 UTC
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
P0
2026-08-25 20:33 UTC
Security Journalism
The Record · indexed 2026-08-25 20:50 UTC
Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.
P0
2026-08-25 20:25 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-25 20:35 UTC
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
P0
2026-08-25 19:50 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-25 20:20 UTC
Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
P0
2026-08-25 19:09 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-25 19:30 UTC
Bulletin ID: 2026-089-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/25/2026 12:00 PM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the python_repl tool, which executes Python code on the agent's host, and the batch tool, which invokes several other tools in a single call. Before executing code, python_repl prompts the ope…
P5
2026-08-25 18:45 UTC
Security Journalism
The Record · indexed 2026-08-25 19:05 UTC
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
P0
2026-08-25 18:17 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 19:20 UTC
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
P0
2026-08-25 17:51 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-25 18:30 UTC
Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, […]
P0
2026-08-25 17:02 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-25 17:30 UTC
Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]
P0
2026-08-25 16:43 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-25 17:30 UTC
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to […]
P15
2026-08-25 16:00 UTC
Vendor Research
Microsoft Security Blog · Igor Sakhnov · indexed 2026-08-25 17:25 UTC
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
P0