2026-08-31 18:41 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-31 18:55 UTC
Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We identified CVE-2026-83497 where a remote authenticated user with basic read/search permissions can run arbitrary code on the server by providing a crafted cursor parameter to the plugins/sql endpoint. Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.8 to…
P5
2026-08-31 17:34 UTC
Security Journalism
Dark Reading · Jacob Krell · indexed 2026-08-31 17:55 UTC
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
P0
2026-08-31 17:24 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 18:05 UTC
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,
P0
2026-08-31 17:18 UTC
Vendor Research
AWS Security Blog · Jonathan Nguyen · indexed 2026-08-31 17:20 UTC
AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility […]
P0
2026-08-31 17:07 UTC
Vendor Research
Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC
GCP Apigee PE to Service Agent with API Proxy Tenable Research has identified and responsibly disclosed a privilege escalation vulnerability in Google Cloud Apigee. This vulnerability allowed an attacker with restricted Apigee permissions to exfiltrate the OAuth access token of the privileged Apigee Core Service Agent.The vulnerability stems from Apigee API Proxies' ability to execute custom JavaScript policy scripts that can access the underlying Instance Metadata Service (IMDS).An attacker wi…
P10
2026-08-31 16:56 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-31 17:00 UTC
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. [...]
P0
2026-08-31 16:50 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-08-31 17:00 UTC
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
P0
2026-08-31 15:42 UTC
Vendor Research
Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC
WordPress - Kubio AI Website Builder DoS The REST endpoint `GET /wp-json/kubio/v1/enable-theme` passes the client-supplied `name` parameter directly and without validation into WordPress core's `switch_theme()`:// lib/api/colibri.php function kubio_enable_theme( WP_REST_Request $data ) { switch_theme( $data['name'] ); // $data['name'] ) ); }Because `$data['name']` is not type-checked, an authorized request can supply `name` as an array instead of a string. `switch_theme()` persists that value i…
P0
2026-08-31 14:52 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 15:00 UTC
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
P0
2026-08-31 14:45 UTC
Security Journalism
The Record · indexed 2026-08-31 15:00 UTC
Governing Mayor Kai Wegner said that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.
P0
2026-08-31 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Tenfold Software · indexed 2026-08-31 14:20 UTC
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]
P0
2026-08-31 13:50 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 14:30 UTC
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept
P0
2026-08-31 13:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 13:40 UTC
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
P15
2026-08-31 12:45 UTC
Security Journalism
The Record · indexed 2026-08-31 13:00 UTC
The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.
P0
2026-08-31 12:30 UTC
Security Journalism
The Record · indexed 2026-08-31 12:45 UTC
One of Slovenia’s largest gambling and tourism groups has begun reopening its casinos after a cyberattack forced them to shut down for several days.
P0
2026-08-31 12:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
P0
2026-08-31 11:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its
P15
2026-08-31 11:31 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate. AI has moved from the browser tab to the
P0
2026-08-31 11:10 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-31 11:40 UTC
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising […]
P0
2026-08-31 10:23 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-31 10:30 UTC
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]
P0
2026-08-31 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Noam Sala · indexed 2026-08-31 10:15 UTC
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
P0
2026-08-31 09:22 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-31 09:35 UTC
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]
P0
2026-08-31 09:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-31 09:40 UTC
Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touching your password. “Our investigation is ongoing. Our findings to date suggest that […]
P0
2026-08-31 09:04 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 10:35 UTC
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor
P0
2026-08-31 08:29 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-31 08:35 UTC
Microsoft asked customers this week to ignore alerts that Defender Antivirus has been turned off after installing the latest Defender updates. [...]
P0
2026-08-31 07:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 08:40 UTC
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department
P0
2026-08-31 07:41 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-31 08:40 UTC
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated attacker execute commands on the server. Patchstack disclosed the flaw on August 28, after researcher […]
P10
2026-08-31 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-08-31 02:20 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-30 17:21 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-30 17:45 UTC
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole […]
P0
2026-08-30 15:00 UTC
Security Journalism
BleepingComputer · Ax Sharma · indexed 2026-08-30 15:10 UTC
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]
P0