2026-08-20 11:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud
P0
2026-08-20 11:06 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-20 11:15 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]
P10
2026-08-20 11:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI
P0
2026-08-20 10:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.
P0
2026-08-20 10:02 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-20 10:15 UTC
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]
P0
2026-08-20 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-08-20 10:15 UTC
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
P0
2026-08-20 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-08-20 10:15 UTC
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
P0
2026-08-20 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Bill Batchelor · indexed 2026-08-20 10:05 UTC
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
P0
2026-08-20 09:46 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-20 10:00 UTC
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]
P70
2026-08-20 08:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-20 09:45 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a […]
P35
2026-08-20 08:42 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to
P0
2026-08-20 08:36 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-20 09:45 UTC
The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, […]
P0
2026-08-20 07:20 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-20 07:30 UTC
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that […]
P15
2026-08-20 06:51 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-20 06:55 UTC
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]
P0
2026-08-20 06:04 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 06:15 UTC
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File
P30
2026-08-20 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-08-20 02:20 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-20 00:20 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-08-20 00:25 UTC
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]
P0
2026-08-20 00:00 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-20 15:30 UTC
Codex curl lifecycle test content.
P0
2026-08-19 20:59 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-19 22:15 UTC
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
P15
2026-08-19 20:59 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-19 21:10 UTC
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
P15
2026-08-19 20:53 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-19 20:55 UTC
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]
P0
2026-08-19 20:32 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-19 21:00 UTC
The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.
P0
2026-08-19 20:07 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-19 20:15 UTC
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
P0
2026-08-19 19:54 UTC
Security Journalism
Dark Reading · indexed 2026-08-20 11:10 UTC
Katie Moussouris of Luta Security talks with the Dark Reading News Desk about how enterprises will now need to monitor risks posed by their own agents in the wake of the recent Hugging Face attack.
P0
2026-08-19 19:02 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 19:55 UTC
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers,
P0
2026-08-19 18:10 UTC
Security Journalism
The Record · indexed 2026-08-19 18:15 UTC
Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.
P0
2026-08-19 18:09 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-19 18:20 UTC
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]
P0
2026-08-19 18:06 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 19:55 UTC
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models become more capable, the risks associated with developing and testing them internally also grow," the AI company
P0
2026-08-19 17:58 UTC
Security Journalism
The Record · indexed 2026-08-19 18:15 UTC
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.
P0
2026-08-19 17:50 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-19 17:55 UTC
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]
P0