2026-08-30 14:30 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-08-30 14:40 UTC
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]
P0
2026-08-30 14:17 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-30 14:25 UTC
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
P0
2026-08-30 12:31 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-30 13:00 UTC
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop Resolver Delivering Novel RATs The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic […]
P0
2026-08-30 11:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-30 11:40 UTC
PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers. Researchers at Huntress found evidence […]
P40
2026-08-30 08:38 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-30 09:40 UTC
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: Unitree G1 Security Flaws Rhysida Ransomware Group Targets Berlin Government Ahead […]
P15
2026-08-30 07:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-30 08:50 UTC
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex
P0
2026-08-30 07:14 UTC
Community
SANS Internet Storm Center · indexed 2026-08-30 07:30 UTC
YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes.
P0
2026-08-29 23:11 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-08-29 23:20 UTC
Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]
P0
2026-08-29 16:25 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-29 17:20 UTC
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in
P30
2026-08-29 14:19 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-29 14:40 UTC
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]
P0
2026-08-29 11:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-29 12:50 UTC
A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable. In his technical […]
P0
2026-08-29 10:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-29 11:35 UTC
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group […]
P15
2026-08-29 09:16 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-29 09:40 UTC
An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy, using well-known vulnerabilities in internet-facing ownCloud and WordPress systems. The activity was uncovered after Hunt.io found an exposed […]
P0
2026-08-29 03:43 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Sagar Patil, Suriyaraj Natarajan and Parasharan Raghavan · indexed 2026-08-29 05:20 UTC
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.
P0
2026-08-28 23:25 UTC
Security Journalism
Dark Reading · indexed 2026-08-28 23:25 UTC
DR-Cloud-AI-VE-2026.jpg
P0
2026-08-28 23:10 UTC
Security Journalism
Dark Reading · indexed 2026-08-28 23:10 UTC
DRIW-AI-Strategy-VE-Oct26.jpg
P0
2026-08-28 22:40 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-28 22:50 UTC
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
P0
2026-08-28 22:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Tony Li, Hongliang Liu and Yuhao Wu · indexed 2026-08-28 22:10 UTC
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.
P0
2026-08-28 21:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 22:10 UTC
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
P0
2026-08-28 20:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 21:00 UTC
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=
P0
2026-08-28 20:19 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-28 20:45 UTC
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
P0
2026-08-28 20:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-28 21:15 UTC
Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the […]
P0
2026-08-28 19:08 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-28 19:15 UTC
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]
P30
2026-08-28 18:53 UTC
Vendor Research
AWS Security Blog · Madhur Kulkarni · indexed 2026-08-28 19:15 UTC
Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to authorized AWS accounts and corporate networks, but the console itself required internet connectivity. This was creating tension between […]
P0
2026-08-28 18:25 UTC
Security Journalism
Dark Reading · indexed 2026-08-28 18:30 UTC
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
P0
2026-08-28 18:18 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-28 18:30 UTC
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
P0
2026-08-28 18:06 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-28 18:20 UTC
Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, on-premises servers, and virtual machines (VMs). Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources. We identified CVE-2026-81849, where an improper limitation of a …
P5
2026-08-28 18:00 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-28 19:20 UTC
Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote activity or supply-chain disruption. The timing matters. The White House points to the rapid expansion of […]
P0
2026-08-28 17:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 18:30 UTC
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
P0
2026-08-28 16:50 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-28 17:05 UTC
Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the inte…
P5