2026-08-21 20:12 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 20:20 UTC
Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. We identified CVE-2026-77811, a stored cross-site scripting issue in the dashboards-observability plugin in OpenSearch Dashboards. Improper input validation in the integrations static file endpoint allows a remote authenticated actor with write …
P5
2026-08-21 19:56 UTC
Security Journalism
The Record · indexed 2026-08-21 20:10 UTC
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
P0
2026-08-21 19:42 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 20:00 UTC
Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Ath…
P5
2026-08-21 18:53 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 20:30 UTC
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's
P0
2026-08-21 18:03 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-21 18:45 UTC
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]
P0
2026-08-21 18:01 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-21 18:05 UTC
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
P0
2026-08-21 17:59 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 18:10 UTC
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions. - CVE-2026-77234: This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected. - CVE-20…
P5
2026-08-21 17:36 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-21 17:45 UTC
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.
P0
2026-08-21 16:54 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-19 16:10 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by …
P30
2026-08-21 16:16 UTC
Security Journalism
The Record · indexed 2026-08-21 16:30 UTC
The bank said there is no evidence that its own systems, networks or data repositories were compromised.
P0
2026-08-21 15:55 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-21 16:05 UTC
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
P0
2026-08-21 15:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a
P0
2026-08-21 15:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of
P0
2026-08-21 15:00 UTC
Security Journalism
The Record · indexed 2026-08-21 15:05 UTC
The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.
P15
2026-08-21 14:54 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-21 15:05 UTC
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
P0
2026-08-21 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by ANONYOME LABS · indexed 2026-08-21 14:10 UTC
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]
P0
2026-08-21 14:00 UTC
Security Journalism
Dark Reading · Darshan Tiwari · indexed 2026-08-21 14:05 UTC
Government agencies with smaller budgets need support — and here's how you can help.
P0
2026-08-21 14:00 UTC
Security Journalism
Dark Reading · Darshan Tiwari · indexed 2026-08-20 19:05 UTC
Government agencies with smaller budgets need support — and here's how you can help.
P0
2026-08-21 13:55 UTC
Security Journalism
The Record · indexed 2026-08-21 14:05 UTC
The statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform.
P0
2026-08-21 13:39 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-21 13:40 UTC
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
P0
2026-08-21 13:30 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-21 13:35 UTC
The new AI security controls follow the Hugging Face incident last month, though experts say many of these additions should have been in place prior to the frontier models escaping.
P0
2026-08-21 13:10 UTC
Security Journalism
Dark Reading · Agam Shah · indexed 2026-08-23 10:25 UTC
The coming threat of super-powerful computers capable of cracking today's algorithms requires upgrading encryption now. Tech companies have begun building defenses.
P0
2026-08-21 12:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-21 12:40 UTC
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe. […]
P10
2026-08-21 12:25 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-21 12:35 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]
P25
2026-08-21 11:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 12:35 UTC
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate
P0
2026-08-21 11:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-21 11:40 UTC
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers, […]
P0
2026-08-21 11:04 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-21 11:10 UTC
Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that allowed attackers to gain remote code execution and escalate privileges. [...]
P25
2026-08-21 11:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-21 11:10 UTC
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
P0
2026-08-21 10:10 UTC
Security Journalism
BleepingComputer · Ax Sharma · indexed 2026-08-21 10:25 UTC
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]
P0
2026-08-21 10:03 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 11:25 UTC
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -
P5