2026-08-14 21:27 UTC
Vendor Research
Rapid7 · Rapid7 Labs · indexed 2026-08-15 18:55 UTC
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (mo…
P20
2026-08-14 20:31 UTC
Security Journalism
The Record · indexed 2026-08-15 18:55 UTC
Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.
P0
2026-08-14 19:24 UTC
Security Journalism
Dark Reading · Kristina Beek · indexed 2026-08-15 18:55 UTC
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.
P0
2026-08-14 18:48 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400
P0
2026-08-14 18:04 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-15 14:33 UTC
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
P0
2026-08-14 17:32 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-15 18:55 UTC
Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.
P0
2026-08-14 17:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can
P0
2026-08-14 17:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC
Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already […]
P0
2026-08-14 15:58 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-15 18:55 UTC
One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.
P0
2026-08-14 14:59 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-15 14:33 UTC
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
P10
2026-08-14 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Material Security · indexed 2026-08-15 14:33 UTC
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]
P0
2026-08-14 14:00 UTC
Security Journalism
Dark Reading · Chris Drumgoole · indexed 2026-08-15 18:55 UTC
Why do so many boards underestimate technology risk until it becomes a crisis?
P0
2026-08-14 14:00 UTC
Vendor Research
Google Security Blog · Jeremy Kun · indexed 2026-08-15 18:55 UTC
heir logo
P0
2026-08-14 13:45 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-15 14:33 UTC
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]
P15
2026-08-14 13:14 UTC
Security Journalism
The Record · indexed 2026-08-15 18:55 UTC
French authorities confirmed that someone gained unauthorized access to systems at the Directorate General of Public Finances in late June after stealing or misusing someone’s identity.
P0
2026-08-14 13:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan,
P0
2026-08-14 12:17 UTC
Security Journalism
Dark Reading · Jeffrey Schwartz · indexed 2026-08-15 18:55 UTC
The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.
P0
2026-08-14 11:55 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-15 14:33 UTC
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
P15
2026-08-14 11:24 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities tha…
P0
2026-08-14 11:07 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes that an operator already has code execution on the Windows host and does not involve
P0
2026-08-14 10:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap, said it
P0
2026-08-14 10:52 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-15 14:33 UTC
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]
P0
2026-08-14 10:44 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple began sending threat notifications to users in late 2021.
P0
2026-08-14 09:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them. "By partnering with vetted United States companies subject to the direction and
P0
2026-08-14 08:27 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-15 14:33 UTC
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]
P0
2026-08-14 07:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control
P0
2026-08-14 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-08-15 14:33 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-14 01:19 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-08-15 14:33 UTC
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]
P0
2026-08-13 21:23 UTC
Vendor Research
AWS Security Blog · Adam Aboudi · indexed 2026-08-15 18:55 UTC
Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]
P0
2026-08-13 21:12 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-15 14:33 UTC
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
P0