2026-08-19 12:00 UTC
Vendor Research
Rapid7 · Cássio De Alcântara · indexed 2026-08-19 14:20 UTC
Cássio De Alcântara is Director, LATAM Sales at Rapid7.Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces.In this environment, security leaders are being asked to understand where risk exists across increasingly distributed environments and quickly eliminate blind spots like Shadow IT and Shadow AI – all wi…
P0
2026-08-19 12:00 UTC
Government
NIST Cybersecurity Insights · Keith Stouffer, Michael Galler · indexed 2026-08-19 12:25 UTC
Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersecurity is an important factor in ensuring the safe and reliable delivery of critical goods and services. For OT owners/operators, it can be challenging to address the range of cybersecurity threats, vulnerabilities and r…
P0
2026-08-19 11:34 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files
P0
2026-08-19 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad
P0
2026-08-19 11:25 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software
P0
2026-08-19 11:14 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 11:35 UTC
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]
P5
2026-08-19 11:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an
P55
2026-08-19 10:12 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 10:15 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]
P40
2026-08-19 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-08-19 10:05 UTC
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
P0
2026-08-19 09:10 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 09:25 UTC
Microsoft has reminded customers that systems running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months. [...]
P0
2026-08-19 08:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-19 09:50 UTC
Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it to a list. That’s the exact problem Microsoft Defender Experts ran […]
P0
2026-08-19 08:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-19 09:50 UTC
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research […]
P0
2026-08-19 08:00 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 08:10 UTC
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
P15
2026-08-19 07:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-19 07:35 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution […]
P50
2026-08-19 06:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 09:45 UTC
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before
P0
2026-08-19 05:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 09:45 UTC
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault
P0
2026-08-19 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-08-19 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-19 01:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-19 01:10 UTC
In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.
P0
2026-08-19 00:41 UTC
Vendor Research
Tenable Blog · Research Special Operations · indexed 2026-08-19 00:50 UTC
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.Key TakeawaysThe August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates154 issues (16.3% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patchesBackgroundOn August 18, Oracle released its Critical Security Patch …
P5
2026-08-18 21:25 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-08-18 21:45 UTC
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
P5
2026-08-18 20:46 UTC
Vendor Research
AWS Security Blog · Nishant Mainro · indexed 2026-08-18 21:00 UTC
When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use legacy authentication mechanisms such as HTTP Basic Authentication (Basic Auth) (RFC 7617). The extensible architecture of AgentCore […]
P0
2026-08-18 20:41 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-19 01:00 UTC
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.Key TakeawaysThe August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates154 issues (16.3% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patchesBackgroundOn August 18, Oracle released its Critical Security Patch …
P5
2026-08-18 20:17 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-18 20:45 UTC
Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.
P0
2026-08-18 20:14 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-18 20:25 UTC
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
P0
2026-08-18 19:09 UTC
Security Journalism
Dark Reading · indexed 2026-08-19 19:45 UTC
Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to take away from AI agents escaping their environments to launch attacks.
P0
2026-08-18 19:05 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-18 20:45 UTC
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.
P0
2026-08-18 18:32 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-08-18 20:15 UTC
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.
P0
2026-08-18 18:05 UTC
Security Journalism
The Record · indexed 2026-08-18 18:15 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.
P15
2026-08-18 17:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-18 19:10 UTC
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance […]
P0
2026-08-18 17:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced
P0