2026-08-24 21:14 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 21:15 UTC
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
P0
2026-08-24 20:51 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-24 21:15 UTC
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
P0
2026-08-24 20:36 UTC
Security Journalism
The Record · indexed 2026-08-24 20:45 UTC
The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification.
P0
2026-08-24 19:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 19:35 UTC
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
P10
2026-08-24 18:30 UTC
Security Journalism
The Record · indexed 2026-08-24 18:50 UTC
A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.
P0
2026-08-24 17:56 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 18:10 UTC
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
P0
2026-08-24 17:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can
P0
2026-08-24 17:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 23:15 UTC
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,
P0
2026-08-24 17:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-24 18:10 UTC
A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the […]
P0
2026-08-24 16:18 UTC
Vendor Research
Rapid7 · Stephen Fewer · indexed 2026-08-24 17:30 UTC
P20
2026-08-24 15:17 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 15:30 UTC
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
P0
2026-08-24 15:02 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-24 15:50 UTC
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
P15
2026-08-24 14:34 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-24 15:05 UTC
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
P0
2026-08-24 14:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 16:05 UTC
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.
P0
2026-08-24 14:00 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-24 14:05 UTC
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
P0
2026-08-24 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Penta Security · indexed 2026-08-24 14:05 UTC
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
P0
2026-08-24 14:00 UTC
Security Journalism
Dark Reading · Christopher Robinson · indexed 2026-08-24 17:05 UTC
The combination of AI both discovering more vulnerabilities at a faster pace and the tightening regulatory environment is making this an all-hands-on-deck moment for the cybersecurity community.
P0
2026-08-24 12:40 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-24 12:50 UTC
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
P0
2026-08-24 12:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 14:05 UTC
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
P15
2026-08-24 12:15 UTC
Security Journalism
The Record · indexed 2026-08-24 12:30 UTC
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet.
P0
2026-08-24 11:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as
P5
2026-08-24 11:51 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate
P0
2026-08-24 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power
P0
2026-08-24 10:45 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-24 10:50 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
P25
2026-08-24 09:42 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-24 09:50 UTC
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
P0
2026-08-24 08:52 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-24 10:00 UTC
Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about […]
P0
2026-08-24 08:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 08:45 UTC
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open
P0
2026-08-24 07:23 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC
TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, […]
P0
2026-08-24 07:23 UTC
Community
SANS Internet Storm Center · indexed 2026-08-24 07:35 UTC
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn't use real steganography:
P0
2026-08-24 07:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]
P0