12Aug 2026

Nvidia’s $500B AI investment pool could impact enterprise chip pricing, availability

Nvidia and six financial partners are creating a $500 billion investment pool to help Nvidia customers including frontier AI labs, AI clouds, and other enterprises buy its chips on credit.  The impact of such a cash infusion on enterprise AI is uncertain, but analysts fear that it could both further increase enterprise AI infrastructure costs […]

12Aug 2026

The IT leadership rules have changed: 3 things you need to architect now

Here is the statistic that should frame every IT leadership conversation this year. In CIO.com’s 2026 State of the CIO, fewer than one in five leaders say their AI initiatives have met or exceeded business goals. After three years of investment, that is not the number anyone expected. And the window to fix it is […]

12Aug 2026

What successful AI centers of excellence actually do: Lessons from real enterprise implementations

Most articles about AI Centers of Excellence (CoEs) focus heavily on organizational structures, steering committees and high-level governance models.  They explain why enterprises need an AI CoE, but they rarely address the far more difficult challenge of how successful organizations operationalize AI at enterprise scale.  In practice, many of these discussions remain theoretical, emphasizing aspirational […]

12Aug 2026

Where IT leaders find strength and opportunity in the age of AI

With vision comes perspective, and over a distinguished career, IT and digital transformation leader Niraj Bhatt has held may titles, and earned three consecutive CIO 100 awards since 2023. As a storied advisor for startups and Fortune 500 companies, helping them navigate the unpredictability and fluidity of AI, Bhatt knows how emerging tech is rapidly […]

12Aug 2026

4 RPA lessons that still hold true in the AI boom

Enterprises of all sizes in all industries are rapidly deploying generative and agentic AI to automate processes. But the efforts aren’t always panning out. Some reasons are new and unique to this technology. But others are related to issues we should’ve been prepared for because we saw them during the age of RPA. And in […]

12Aug 2026

New US CIO appointments, August 2026

Movers & Shakers is where you can keep up with new CIO appointments and gain valuable insight into the job market and CIO hiring trends. As every company becomes a technology company, CEOs and corporate boards are seeking multi-dimensional CIOs and IT leaders with superior skills in technology, communications, business strategy, and digital innovation. The […]

12Aug 2026

Don’t let AI negotiate with reality

We are all transforming now. Some companies have formally named transformation programs. Others are being transformed by a new regulation, an AI mandate, a cyber event, a weather disruption, a change in customer behavior, a competitor’s move or an urgent demand to reduce costs. The label is almost beside the point. The operating assumptions keep […]

12Aug 2026

Oracle set to bring quantum computing to OCI for hybrid AI

Oracle said it will deploy Quantinuum’s Helios quantum computer inside its cloud infrastructure and provide enterprise customers access through a planned Oracle Cloud Infrastructure (OCI) quantum service for hybrid quantum-AI workloads. The companies have forged a multi-year partnership in this regard. The partnership will see Helios installed in a US-based OCI AI data center, where […]

12Aug 2026

Zoom Patches Zero-Click Code Execution Vulnerability

Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek.

12Aug 2026

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

The security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek.

12Aug 2026

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek.

12Aug 2026

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek.

12Aug 2026

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek.

12Aug 2026

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact

CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek.

12Aug 2026

Ivanti EPM Update Patches Remotely Exploitable Flaws

The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek.

12Aug 2026

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek.

12Aug 2026

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek.

12Aug 2026

Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined

Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution. The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared first on SecurityWeek.

12Aug 2026

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for […]

12Aug 2026

4 gaps slowing AI in enterprise SOCs

Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements. The issue isn’t whether AI belongs in the SOC. It does. The challenge is that many organizations are approaching AI adoption in […]

12Aug 2026

The AI harness is the new attack surface

Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted. That instinct is increasingly out of date. A growing body of security research — exploit demonstrations, independent […]

12Aug 2026

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential […]

12Aug 2026

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. “SAP Commerce Cloud […]

12Aug 2026

17 old software bugs that took way too long to squash

In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one would be forthcoming. Fortunately, that’s because the […]

12Aug 2026

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described

12Aug 2026

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker […]

12Aug 2026

Risky Business #848 -- OpenAI comes clean

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including: The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI’s legal team allowed the company to spill all the Hugging […]

12Aug 2026

Metabase SQLi exploit grants attackers total access

Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-72898, is identified as critical, with a severity score of 10, the highest possible rating. It is present in […]

12Aug 2026

ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)

Post Content

12Aug 2026

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-2026-68820), which, according to Todd Schell, principal product manager at Ivanti, […]

11Aug 2026

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them. Three of the vulnerabilities affect all Zoom client applications for all platforms before versions 7.1.5 and 7.0.6, while the […]

11Aug 2026

25-01611.pdf

25-01611.pdf Anonymous (not verified) Tue, 08/11/2026 – 17:35 Case ID 25-01611 Forum FINRA Document Type Award Claimants Beatriz Jones Casoria Respondents Wells Fargo Clearing Services, LLC Neutrals Harry G. Mason Andy W. Morgan Ahmed Mahmood Hearing Site Atlanta, GA Award Document 25-01611.pdf Documentum DocID 72aa8735 Award Date Official Tue, 08/11/2026 – 12:00 Related Content Off […]

11Aug 2026

25-02795.pdf

25-02795.pdf Anonymous (not verified) Tue, 08/11/2026 – 17:35 Case ID 25-02795 Forum FINRA Document Type Award Claimants Fabrice Dejean Respondents Apex Clearing Corporation SoFi Securities LLC Neutrals Andrew W. Levin Hearing Site Los Angeles, CA Award Document 25-02795.pdf Documentum DocID 128e980e Award Date Official Tue, 08/11/2026 – 12:00 Related Content Off Claimant Representatives Fabrice Dejean […]

11Aug 2026

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its […]

11Aug 2026

ROCKEFELLER FINANCIAL LLC

ROCKEFELLER FINANCIAL LLC fnrw-backend Tue, 08/11/2026 – 16:50 MC ID ROCK MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/rock/ MC Last Updated Tue, 08/11/2026 – 16:49

11Aug 2026

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out […]

11Aug 2026

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. “Kimwolf v7 adds an […]

11Aug 2026

Douro Labs LLC and Securitize Markets, LLC Comment On Regulatory Notice 26-15

Douro Labs LLC and Securitize Markets, LLC Comment On Regulatory Notice 26-15 fnrw-backend Tue, 08/11/2026 – 15:17 Brandon Ferrick and Joe Nikolson NJ US brandon@dourolabs.xyz Douro Labs LLC and Securitize Markets, LLC Regulatory Notice 26-15 Core Official Date Tue, 08/11/2026 – 12:00 Comment File Douro Labs – FINRA 5310 Letter (Notice 26-15).pdf

11Aug 2026

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter’s. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in […]

11Aug 2026

T. ROWE PRICE INVESTMENT SERVICES, INC.

T. ROWE PRICE INVESTMENT SERVICES, INC. fnrw-backend Tue, 08/11/2026 – 14:56 MC ID PICE MC Reporter Type Broker-Dealer MC Paragraph MC Link https://nms605.karngroup.com/eeeff85c55456c4452513d3d MC Last Updated Tue, 08/11/2026 – 14:56

11Aug 2026

Introducing ResOps, the operating discipline built for quick, clean recovery

Organizations have spent years and billions of dollars hardening their defenses against cyberattacks, but prevention alone no longer settles the question that matters most to a board. Accenture’s State of Cybersecurity Resilience 2025 report stated that organizations had faced an average of 1,876 cyberattacks in a single quarter, a 75% increase over the prior year. […]

11Aug 2026

From ‘dumb iron’ to smart machines: Why data control is the real Industry 5.0

On the modern factory floor, the phrase “industrial equipment” no longer tells the whole story. It conjures images of steel, hydraulics, conveyor belts and machinery built to perform the same task with unwavering precision day after day. Physical engineering remains fundamental, of course, but it’s no longer the sole measure of a machine’s value. The […]

11Aug 2026

The code review crisis and how you should rebuild review models

“We’re generating more code than ever. My senior engineers are drowning in review,” a VP of engineering at a mid-sized software company told me. I hear this from engineering leaders almost every week. AI was supposed to fix delivery, but it just moved the bottleneck. If you feel the same way, you’re neither wrong nor alone: in CloudBees’ 2026 State of Code […]

11Aug 2026

How Mercedes-Benz is scaling AI-powered business automation

At Mercedes-Benz, “Digital First” has long been more than just a theoretical concept; it’s a lived strategy, as a visit to the Digital Factory Campus in Berlin demonstrated. Now, the automaker aims to take the next step in scaling artificial intelligence: Together with the German low-code specialist n8n, the company is introducing a global platform that will […]

11Aug 2026

Why the CIO is becoming the most commercial role in the boardroom

My mum has asked me the same question for almost 30 years. “So…what is it you actually do?” I’ve explained it hundreds of times. I lead the team that look after the network, the servers, the applications and cyber security that help the business work. And more recently, AI. She’d smile politely, nod and then […]

11Aug 2026

7 mistakes IT leaders make when deploying AI agents

CIOs are under pressure to deploy more AI agents and demonstrate their business value. But a “move fast and break things” approach can lead to rogue AI agents, AI debt, business impacts, and compliance issues. Avoiding mistakes starts with a strong plan and foundational practices. CIOs must have a process to evaluate an AI agent’s […]

11Aug 2026

Don’t automate bad workflows: Why AI should begin with redesign

Artificial intelligence has quickly become one of the biggest priorities in the executive suite. Organizations are investing heavily in new capabilities, employees are experimenting with AI every day, and technology leaders are under pressure to identify opportunities that improve productivity and reduce costs. In many organizations, the first question is, “What can we automate?” It […]

11Aug 2026

OpenAI targets heavy users with premium ChatGPT Business seats

OpenAI is introducing a higher-priced “Premium” tier for its ChatGPT Business offering, allowing enterprises to assign higher-capacity access to select users alongside standard licences – a move analysts said is about enterprise AI vendors redesigning pricing to capture more value from high-intensity workloads. The company said the new tier provides “5x more usage than Standard” […]

11Aug 2026

What CIOs must get right before AI can scale

AI is reshaping operations faster than organizations can keep up. Technology leaders — from chief data officers to CIOs and CTOs — are under pressure to get the fundamentals right. That means building the data infrastructure AI requires, preparing workforces for roles that are changing in real time, and scaling AI in ways that are […]

11Aug 2026

Server prices to rise by up to 87% at OVHcloud

OVH is increasing the prices of its servers, some by as much as 87%, for both new and existing customers, blaming AI’s insatiable demand driving the rising cost of the RAM and storage it uses in its data centers. The European cloud operator specializes in low-cost bare metal and public cloud offerings. CIOs will be […]

11Aug 2026

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup […]

11Aug 2026

Stolen Change Healthcare data gets new handling rules in court order

Naomi Diaz reports: A federal judge in Minnesota has signed off on a strict set of rules for how the data stolen in Change Healthcare’s 2024 cyberattack can be handled during the ongoing lawsuit. Magistrate Judge Dulce J. Foster approved the plan, reviewed by Becker’s, Aug. 7. It applies to the combined lawsuit against UnitedHealth Group and several of… […]

11Aug 2026

Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs. 

11Aug 2026

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft’s

11Aug 2026

GitHub already has an EDR. You just have to listen to it

Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said. At their Black Hat USA 2026 presentation, researchers Yossi Weizman of Microsoft and Mor Weinberger of Echo argued the case, saying, “GitHub can tell you’re being hacked. You’re just not listening.” The […]

11Aug 2026

Mira Hormone Monitor, Mira Android App

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The following versions of Mira Hormone Monitor, Mira Android App are affected: Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, […]

11Aug 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities […]

11Aug 2026

Pulsetto Vagus Nerve Stimulator

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Nerve Stimulator are affected: Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844) CVSS Vendor Equipment Vulnerabilities v3 8.1 Pulsetto Pulsetto Vagus Nerve Stimulator Hidden […]

11Aug 2026

OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window

OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats. Daybreak now has two access levels. Blue gives approved defenders access to frontier general-purpose models such as GPT-5.6 Sol for authorized defensive […]

11Aug 2026

Metabase Patches Vulnerability Exploited as Zero-Day

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

11Aug 2026

New Jersey, Alabama Join States Targeted in Water Cyberattacks

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek.

11Aug 2026

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek.

11Aug 2026

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek.

11Aug 2026

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek.

11Aug 2026

OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold.  The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek.

11Aug 2026

Mozilla Issues New Firefox GPG Key Following Exposure

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.

11Aug 2026

OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber

OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared first on SecurityWeek.

11Aug 2026

Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption

Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek.

11Aug 2026

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level […]

11Aug 2026

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, […]

11Aug 2026

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. “Gunra is another variant in the ongoing trend of

11Aug 2026

Security leaders’ rogue AI confidence could actually be disastrous

A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope. Nine in 10 IT and security leaders surveyed by IT observability vendor WanAware […]

11Aug 2026

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still […]

11Aug 2026

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily disable their downloads. “Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository,” Wordfence researcher Paolo Tresso said.

11Aug 2026

The future of AI security research isn’t autonomous, it’s human-amplified

Meet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was guided by a human the entire time, which may be the most […]

11Aug 2026

The future of AI security research isn’t autonomous, it’s human-amplified

Meet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.” But it didn’t do it alone; it was guided by a human the entire time, which may be the most […]

11Aug 2026

ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)

Post Content

10Aug 2026

25-01586.pdf

25-01586.pdf Anonymous (not verified) Mon, 08/10/2026 – 19:10 Case ID 25-01586 Forum FINRA Document Type Award Claimants Thomas Jerome Surendran Respondents Interactive Brokers LLC Neutrals Kathy L. Eisenmenger Roger A. Geddes Richard K. Mahrle Hearing Site Salt Lake City, UT Award Document 25-01586.pdf Documentum DocID 2b6ca901 Award Date Official Mon, 08/10/2026 – 12:00 Related Content […]

10Aug 2026

2023080063701 Qi Hua Yang CRD 7439718 AWC lp.pdf

2023080063701 Qi Hua Yang CRD 7439718 AWC lp.pdf Anonymous (not verified) Mon, 08/10/2026 – 16:40 Case ID 2023080063701 Document Number 6a4d374d Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Individuals Qi Hua Yang Action Date Mon, 08/10/2026 – 12:00 Related Content Off Attachment 2023080063701 Qi Hua Yang CRD 7439718 AWC lp.pdf Individual CRD 7439718

10Aug 2026

CISA Advisory: #StopRansomware: Gunra Ransomware

Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom… […]

10Aug 2026

25-02788.pdf

25-02788.pdf Anonymous (not verified) Mon, 08/10/2026 – 15:00 Case ID 25-02788 Forum FINRA Document Type Award Claimants Frederick Kort Respondents UBS Financial Services Inc. Neutrals Douglas Earl McLaren Constance Ellen Boukidis Christopher M. McMurray Hearing Site Chicago, IL Award Document 25-02788.pdf Documentum DocID 5d1d9f86 Award Date Official Wed, 08/05/2026 – 12:00 Related Content Off Claimant […]

10Aug 2026

The modern CIO: From technology expert to business leader

The role of the CIO has changed more in the last five years than it did in the previous 20. Cloud computing, cybersecurity, data, automation and artificial intelligence are reshaping organizations at a pace few leaders have experienced before. Today’s competitive advantage often becomes tomorrow’s baseline capability. In this environment, expecting a CIO to be […]

10Aug 2026

The AI reckoning every CIO saw coming (and still wasn’t ready for)

Earlier this year, the National Bureau of Economic Research released survey results from over 6,000 U.S. leaders showing that while AI adoption is widespread at 69%, we’re seeing little to no impact on productivity. Anecdotally, we’ve seen leaders from top companies echo that refrain. It’s the reckoning many CIOs, CTOs and COOs are navigating as […]

10Aug 2026

What the San Diego Padres CIO does to deliver major league IT experiences

Petco Park consistently ranks among MLB’s top ballparks for fan experience. That doesn’t happen by accident, and it didn’t wait for a star-studded roster or a deep postseason run. According to Padres CIO Ray Chan, the club made a deliberate choice more than a decade ago to run its tech organization as if every seat […]

10Aug 2026

CIO 100 Award winners spotlight IT’s power to transform

Each year the CIO 100 Awards showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers. The 2026 cohort of winners is no different. Each one demonstrates how IT executives and their teams successfully move […]

10Aug 2026

Why enterprise IT environments get more complex as companies grow

The most complicated IT environments I’ve worked in weren’t built that way on purpose. They got there through a sequence of reasonable decisions made by reasonable people under real pressure. A cloud provider added because the incumbent couldn’t hit a latency requirement. A point solution brought in because a business unit needed something fast. A […]

10Aug 2026

Microsoft’s PostgreSQL alternative, HorizonDB: Worth the wait?

Microsoft is betting that the integration of HorizonDB, the cloud-native PostgreSQL alternative it is developing, with Azure will attract more enterprise AI and agentic workloads to its cloud services. Enterprises may not be willing to take that bet. It’s been nine months since Microsoft unveiled HorizonDB, but the service remains in public preview with no […]

10Aug 2026

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, […]

10Aug 2026

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary’s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. “StormEncryptor is written in C++ and appends the file name extension .encrypted

10Aug 2026

Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)

Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either “speak” JSON or gRPC. One implementation often used for development is “surfpool,” which is used to test programs before deploying them […]

10Aug 2026

Cybersecurity Effective Practices

Cybersecurity Effective Practices K30658 Mon, 08/10/2026 – 12:20 August 2026 This framework of 12 cybersecurity principles and effective practices is designed to help FINRA member firms strengthen their cybersecurity programs. The effective practices are informed by member firms’ regulatory obligations, industry risk principles and practices FINRA has observed through member firm oversight. Each practice presented […]

10Aug 2026

GOLDMAN SACHS CUSTODY SOLUTIONS

GOLDMAN SACHS CUSTODY SOLUTIONS fnrw-backend Mon, 08/10/2026 – 11:08 MC ID FTBR MC Reporter Type Broker-Dealer MC Paragraph MC Link https://folioclient.com/fcfooter/sec-605-disclosure.jsp MC Last Updated Mon, 08/10/2026 – 11:08

10Aug 2026

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was […]

10Aug 2026

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security […]

10Aug 2026

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a 

10Aug 2026

#StopRansomware: Gunra Ransomware

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data […]

10Aug 2026

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.

10Aug 2026

Corporate Data Stolen in Levi Strauss Cyberattack

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.

10Aug 2026

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.

10Aug 2026

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.

10Aug 2026

4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofing

Key takeaways OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, rotated or blank. AADSTS700016 paired with an unrecognized client ID can mean valid credentials, not a broken app registration — treat it as a triage signal, not noise. Effective detection logic […]

10Aug 2026

7 key trends defining the cybersecurity market today

AI is having a seismic impact on the cybersecurity market. Record-shattering amounts of venture capital is flowing into a new generation of startups focused on AI cybersecurity. At the same time, established cybersecurity vendors are racing to integrate AI and agentic AI features into their platforms, triggering a surge in acquisition activity. But while AI […]

10Aug 2026

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository

10Aug 2026

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it’s implementing security controls for higher-capability models and associated activities, such as isolated

10Aug 2026

ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)

Post Content

09Aug 2026

KR: 3Pro TV Data Breach Exposes 460,000 Records, Including 2,979 Bank Accounts

Park Hyo-jung reports: More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV. E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet’s website saying it had confirmed that “an external actor illegally accessed the… […]

09Aug 2026

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

Carly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data… […]

09Aug 2026

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

08Aug 2026

City of Suisun declares local emergency after cyberattack downs 911 dispatch system

Katie Chavez reports: Suisun City officials declared a state of emergency Saturday, Aug. 8, after a cyberattack took out the city’s emergency dispatch line and other key systems. City officials said that “malicious software infected and compromised IT systems” at about 5:45 a.m. on Friday. The cybersecurity issue forced the city to shut down its… […]

08Aug 2026

From ambition to action: What Canadian tech leaders must get right to see meaningful value from transformation efforts

It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO to play a key […]

08Aug 2026

City of Coweta refuses to pay ransom after system-wide cyberattack

An update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who don’t keep their word do spoil it for… […]

08Aug 2026

Vishing Extortion Group UNC6671 Rebrands After Making Millions

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.

08Aug 2026

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek.

08Aug 2026

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. […]

08Aug 2026

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger […]

08Aug 2026

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to […]

08Aug 2026

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. “This […]

08Aug 2026

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

07Aug 2026

US cloud ‘kill switch’ is as dangerous as ransomware, European businesses fear

Emma Woollacott reports: European firms are more concerned about a potential US government-imposed ‘kill switch’ for cloud services than almost anything else. In a survey of 1,500 businesses in the UK, France, and Germany, Proton found that with many having built their operations around a small number of US-based providers, they’re worried that access to those platforms could be… […]

07Aug 2026

New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc.

A press release from the NYS DFS: August 5, 2026 New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulation (23 NYCRR Part 500). DFS investigators identified deficiencies in the company’s cybersecurity program… […]

07Aug 2026

City of Coweta hit with system-wide ransomware attack, has backup

KTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity professionals to secure their systems to prevent any further intrusion and to begin a recovery… […]

07Aug 2026

Deepfakes are targeting your executives. Here’s what actually works

Two years ago, I sat across from a chief financial officer who had just spent forty minutes on a video call authorizing what he believed was a legitimate acquisition payment. The call included his CEO and two board members, all speaking in familiar voices, all making the kind of small unscripted comments that make a […]

07Aug 2026

Enterprise-wide AI transformation starts with change management

Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only 28% of AI use cases in infrastructure and operations fully succeed and meet ROI expectations, while 20% fail outright. The conversation around AI often focuses […]

07Aug 2026

How AI is changing the business analyst role for the better

AI’s impact has been felt across nearly every industry, and its rise has already started to alter several roles in tech, including that of the business analyst. While the rise of agentic AI may have some questioning whether AI will replace business analyst jobs entirely, as we’ve seen with most roles impacted by AI, it’s […]

07Aug 2026

Your AI hiring tool isn’t an HR problem. It’s a security one

For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a […]

07Aug 2026

Inside the post-merger IT overhaul at Alaska Airlines

As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger. By her count, she’s been involved in four such projects. But none, she says, has brought her greater satisfaction than leading the overhaul […]

07Aug 2026

Beyond chatbots: How embedded GenAI is transforming banking application development

Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline […]

07Aug 2026

AMD wants to make enterprise inference cheaper and faster with chips from Taalas

As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU. AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights into custom silicon, instead […]

07Aug 2026

There are two completely different roles called ‘FDE’

There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different things depending on the business you’re running. I spent […]

07Aug 2026

Snowflake attacker pleads guilty to hack of 165 companies’ data

A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars. Industry sources have identified Moucka as one of the […]

07Aug 2026

Agentic AI workforce is more than doubling year on year, says Salesforce

Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters. It compiled data from customers who had activated agents in production every month of the analysis period to determine how […]

07Aug 2026

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer […]

07Aug 2026

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU […]

07Aug 2026

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees […]

07Aug 2026

Trojanized AI skills gain 1.7M installs in agent-targeted attack

Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction and configuration files for agentic tools. Discovered by researchers from security firm Zenity, the […]

07Aug 2026

Boston Children’s Hospital named in North Korean hacking operation

Naomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached, saying the issue traced to a former contractor’s personal device. Mr. Stykas, chief technology officer at… […]

07Aug 2026

CETERA WEALTH SERVICES, LLC

CETERA WEALTH SERVICES, LLC fnrw-backend Fri, 08/07/2026 – 13:04 MC ID FNIC MC Reporter Type Broker-Dealer MC Paragraph MC Link https://nms605.karngroup.com/652f52bd526b354a51773d3d MC Last Updated Fri, 08/07/2026 – 13:04

07Aug 2026

Moonshot’s Kimi AI model has also escaped from a test environment

Yet another AI model has escaped from a cybersecurity test lab: This time, it’s the Chinese company Moonshot’s Kimi K3 model on the run. Frontier Security spotted that Kimi K3 had found a loophole in the UK AI Safety Institute’s test environment for AI models performing cybersecurity tasks. The news follows similar exploits by models […]

07Aug 2026

25-00424.pdf

25-00424.pdf Anonymous (not verified) Fri, 08/07/2026 – 10:05 Case ID 25-00424 Forum FINRA Document Type Award Claimants Alice Krell Respondents Morgan Stanley Neutrals Robert D. Sussin Daniel Lawrence Pearlman Kenneth R. Jackson Hearing Site Los Angeles, CA Award Document 25-00424.pdf Documentum DocID aadf7314 Award Date Official Thu, 08/06/2026 – 12:00 Related Content Off Claimant Representatives […]

07Aug 2026

26-00334.pdf

26-00334.pdf Anonymous (not verified) Fri, 08/07/2026 – 10:05 Case ID 26-00334 Forum FINRA Document Type Award Claimants Tradestation Securities, Inc. Respondents Mohsen Ravanbakhsh Neutrals Olivia J. Valentine Hearing Site Los Angeles, CA Award Document 26-00334.pdf Documentum DocID 683aaaaf Award Date Official Thu, 08/06/2026 – 12:00 Related Content Off Claimant Representatives Myra C. Mormile-Wolper Respondent Representatives […]

07Aug 2026

WEDBUSH SECURITIES INC.

WEDBUSH SECURITIES INC. fnrw-backend Fri, 08/07/2026 – 09:50 MC ID WEDB MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/wedb/ MC Last Updated Fri, 08/07/2026 – 09:50

07Aug 2026

AU: Hackers leak sensitive Victorian court data to dark web

Kristian Silva and Danny The personal information of Victorian court users has been posted on the dark web, sparking a police investigation. Names, emails and job titles of people who attended online hearings in regional courts were posted on an underground hacking forum in July. A user has claimed responsibility in a post. […] Court… […]

07Aug 2026

What Canvas learned from a massive cyberattack

Alcino Donadel reports: …. Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher ed. Higher education’s more meditative, governed approach to technological change is useful for reviewing rigor and long-term quality assurance, Pendleton… […]

07Aug 2026

Unlimited Technology Systems Data Breach Affects 3.8 Million Patients

HIPAA Journal reports an update to the Unlimited Technology Systems breach that occurred between October 10 – 15, 2025, and was discovered on October 19, 2025: On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-based provider of revenue cycle management services. At the time, the… […]

07Aug 2026

Snowflake attacker pleads guilty to hack of 165 companies’ data

A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars. Industry sources have identified Moucka as one of the […]

07Aug 2026

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity

07Aug 2026

CPDLC over ATN-B1 Vulnerabilities

View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness. The […]

07Aug 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates […]

07Aug 2026

Growing Up The Hard Way

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back […]

07Aug 2026

Critical Paperclip Flaw Allowed Admin Access, Code Execution

An attacker could self-register, sign in for board-level API access, and import a new company for code execution. The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek.

07Aug 2026

Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway

(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field. The post Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway appeared first on SecurityWeek.

07Aug 2026

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on SecurityWeek.

07Aug 2026

Snowflake Hacker Pleads Guilty in US Court

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada.  The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek.

07Aug 2026

Critical Vulnerabilities Patched With Chrome 151 Update

The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek.

07Aug 2026

3.8 Million Impacted by Unlimited Technology Systems Data Breach

Hackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek.

07Aug 2026

Microsoft, Apple Release Fresh Security Updates

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek.

07Aug 2026

Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)

Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek.

07Aug 2026

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.

07Aug 2026

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. “The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

07Aug 2026

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning

07Aug 2026

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and

07Aug 2026

Python package security in 2026: How supply chain attacks are targeting your AI development environment

On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82.7 and 1.82.8 to the package index. The payload was subtle: a .pth file, […]

07Aug 2026

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim’s Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods […]

07Aug 2026

Human oversight is still critical as AI patching tools miss security risks

AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research. Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader concerns such as architectural intent, business requirements, security implications, and long-term maintainability, despite being syntactically correct. “We studied what happens when […]

07Aug 2026

What does a data breach cost? AI is a sizable factor

The financial impact of a data breach is substantial for any modern business, regardless of industry or size. IBM’s latest Cost of a Data Breach report discovered that, from March 2025 to February 2026, the average cost of a data breach rose to $6 million, up 35% from $4.44 million a year earlier. The 2026 […]

07Aug 2026

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor’s agent in the configuration that the vendor ships by […]

07Aug 2026

Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)

UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of “modern” logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:

07Aug 2026

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. “The connection is supported by overlapping domains, malware deployment paths, staging techniques, […]

07Aug 2026

25-01715.pdf

25-01715.pdf Anonymous (not verified) Fri, 08/07/2026 – 00:05 Case ID 25-01715 Forum FINRA Document Type Award Claimants UBS Financial Services Inc. UBS Credit Corp. Respondents Terance Takyi Neutrals Andrew M. Schmertz Lorraine Marie Brennan Hovnan Melkonian Hearing Site New York, NY Award Document 25-01715.pdf Documentum DocID 3fc8c1fa Award Date Official Thu, 08/06/2026 – 12:00 Related […]

07Aug 2026

ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)

Post Content

06Aug 2026

2024083156201 Mark L. Sullivan CRD 2531982 AWC ks.pdf

2024083156201 Mark L. Sullivan CRD 2531982 AWC ks.pdf Anonymous (not verified) Thu, 08/06/2026 – 18:05 Case ID 2024083156201 Document Number 5bafa332 Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Individuals Mark L. Sullivan Action Date Thu, 08/06/2026 – 12:00 Related Content Off Attachment 2024083156201 Mark L. Sullivan CRD 2531982 AWC ks.pdf Individual CRD 2531982

06Aug 2026

Why exposure management is replacing vulnerability management

Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becoming harder to attack? That question sits at the center of a growing problem. Security programs have […]

06Aug 2026

Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.

There have been approximately 4 dozen new threat actor groups targeting U.S. medical entities in the first half of 2026. One of them calls itself “Orova.” They have no “About” page or information about themselves on their dark web leak site, so seeing that they had recently listed two U.S. medical entities, DataBreaches contacted them… […]

06Aug 2026

Reminder on Completing Continuing Education Requirements

Reminder on Completing Continuing Education Requirements K34060 Thu, 08/06/2026 – 14:59 August 5, 2026 Features Reminder on Completing Continuing Education Requirements All registered representatives must complete the Regulatory Element annually by year end for each registration that they hold. In addition, firms must maintain a Continuing Education (CE) program, the Firm Element, for their registered representatives […]

06Aug 2026

NatJack exploits put NAT security assumptions to the test at Black Hat

For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assumption might not be entirely accurate anymore (if it ever really was). […]

06Aug 2026

Why AI ROI metrics are measuring the wrong thing

The loudest conversation in business right now is about how much value AI actually generates. Over the last year, AI has moved from a side experiment to a strategic priority. It has its own budget line, its own place on the board’s agenda and its own pressure to show results. Every leader is asking a […]

06Aug 2026

How AI takes flight at GE Aerospace

The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk? Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI across its business, Burns is helping lead […]

06Aug 2026

Algorithms aren’t enough: Why factories need an AI reasoning layer

The scheduling fallacy and the shift to autonomy Walk onto almost any manufacturing shop floor, and you will witness the same systemic vulnerability: a brilliantly engineered, multi-million-dollar Advanced Planning and Scheduling (APS) system rendered completely useless by a single delayed delivery truck, an unexpected machine drift or a sudden workforce shortage. Industrial operations do not […]

06Aug 2026

7 use cases for leveraging AI in the physical world

The next big AI wave won’t be a chatbot in your laptop, or an agent that works behind the scenes to turn meeting notes into project tickets, but AI that takes control of devices that move and interact with the environment. Physical AI can be defined as the integration of AI into autonomous systems, allowing […]

06Aug 2026

Structural agile: Why fast delivery quietly loses its meaning

Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the end, […]

06Aug 2026

Why AI is forcing a rethink of data center cooling

For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the capabilities of traditional air-cooling that was designed to sustain normal growth. This let organizations […]

06Aug 2026

The hidden costs of scaling AI agents without coordination

Engineering organizations tasked with scaling AI agents are discovering that the speed they initially achieved is being lost to endless rework. Without proper coordination, ten developers each running several agents against the same codebase becomes an alignment problem that compounds daily. This is a different challenge than individual productivity, and it’s where agent orchestration comes […]

06Aug 2026

Why governance is the accelerator for coding agents

Governance is what lets a team run coding agents and stand behind what they ship. As more code originates from agents, the question every engineering leader is now answering is not how fast the work moves, but who owns it and how it gets checked before it lands. The teams pulling ahead decide on the […]

06Aug 2026

FUTU CLEARING INC

FUTU CLEARING INC fnrw-backend Thu, 08/06/2026 – 14:08 MC ID FUTF MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.futuclearing.com MC Last Updated Thu, 08/06/2026 – 14:08

06Aug 2026

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which manages […]

06Aug 2026

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. “These vulnerabilities were […]

06Aug 2026

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of […]

06Aug 2026

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux […]

06Aug 2026

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor. […]

06Aug 2026

2017053428201_Fernandez_283594_DreamfundedMarketplace_6639970_SEC_jhjr.pdf

2017053428201_Fernandez_283594_DreamfundedMarketplace_6639970_SEC_jhjr.pdf Anonymous (not verified) Thu, 08/06/2026 – 10:30 Case ID 2017053428201 Document Number 5355c011 Document Type SEC Decisions Individuals Manuel Fernandez Action Date Mon, 08/03/2026 – 12:00 Related Content On Attachment 2017053428201_Fernandez_283594_DreamfundedMarketplace_6639970_SEC_jhjr.pdf Individual CRD 6639970

06Aug 2026

How a software provider closed unknown paths to cloud compromise

A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative access. Multifactor authentication (MFA) was enforced broadly, vulnerability scanning was routine, and annual penetration tests were part of the organization’s broader security […]

06Aug 2026

How a global investment firm reduced security surprises

Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter? For a global investment firm operating across 18 locations, that question became […]

06Aug 2026

Meta joins OpenAI, Anthropic in latest AI test breach

Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center of a series of disclosures involving the industry’s leading AI labs. During a “capture-the-flag” test […]

06Aug 2026

You’re only as secure as your last evaluation

The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat landscape faced by the DIB. Updated CMMC guidance issued in […]

06Aug 2026

Cybersecurity needs a new operating model

For decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure. Deploy patches. Verify that critical systems remained protected. That assumption shaped how organizations built security programs, how vendors developed security products, and how regulators measured cyber resilience. That assumption no longer holds AI has not created a […]

06Aug 2026

Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

There is an update to the case of Maksim Silnikau, who was extradited from Poland to the U.S. in August 2024 to stand trial here.  Ionut Arghire reports: The Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison in the US. Maksim Silnikau, 40, built the ransomware operation… […]

06Aug 2026

Dutch retailer Bol follows De Bijenkorf in warning of data breach as leaked data appears on dark web

The NL Times reports: Online retailer Bol has warned customers about a data breach involving one of its logistics partners. The company said unauthorized parties accessed the partner’s systems, but emphasized that Bol’s own systems were not affected. Even so, some customer information may have been viewed or copied, the company said in a statement…. […]

06Aug 2026

ABB Ability Zenon

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/*  CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of […]

06Aug 2026

Johnson Controls Inc. TL280

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63  CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure […]

06Aug 2026

Medixant RadiAnt DICOM

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened. The following versions of Medixant RadiAnt DICOM are affected: RadiAnt DICOM <=2025.2 CVSS Vendor Equipment Vulnerabilities v3 4.3 Medixant Medixant RadiAnt DICOM Out-of-bounds Write Background Critical Infrastructure Sectors: Healthcare […]

06Aug 2026

Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data 

The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations. The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data  appeared first on SecurityWeek.

06Aug 2026

311,000 Impacted by Brown Health Medical Group-MA Data Breach

Hackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.

06Aug 2026

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.

06Aug 2026

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield. The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek.

06Aug 2026

Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) appeared first on SecurityWeek.

06Aug 2026

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones  appeared first on SecurityWeek.

06Aug 2026

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek.

06Aug 2026

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code. The post Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities appeared first on SecurityWeek.

06Aug 2026

Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution. The post Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison appeared first on SecurityWeek.

06Aug 2026

Meta AI Hacked External Systems During Cybersecurity Testing

The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek.

06Aug 2026

In The Loop July 2026

In the Loop, Tactical Tech’s monthly newsletter, includes new releases, open calls, job opportunities, information about our partners, events, recommended resources and more.

06Aug 2026

Why the ‘rogue AI’ problem will lead to an era of headaches for security practitioners

Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours, as many assumed, but had in fact been wreaking havoc […]

06Aug 2026

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks […]

06Aug 2026

Practical lessons from deploying AI securely at scale

When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities. I was wrong — or at least incomplete. The technology certainly matters, but after working with multiple […]

06Aug 2026

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent’s tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a […]

06Aug 2026

Evidence points to cybercriminals stepping up their AI game

More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research. Drawing on recovered prompt logs, attack tooling, and threat actor conversations, research from Cisco Talos documents how AI is being used to develop malicious code, build fraud […]

06Aug 2026

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt […]

06Aug 2026

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according […]

06Aug 2026

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a […]

06Aug 2026

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took […]

06Aug 2026

ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)

Post Content

06Aug 2026

22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)

[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]

05Aug 2026

Report: Passkey security issues could allow account takeover

Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion. They also pointed out that the issues are not strictly caused by […]

05Aug 2026

25-02756.pdf

25-02756.pdf Anonymous (not verified) Wed, 08/05/2026 – 18:50 Case ID 25-02756 Forum FINRA Document Type Award Claimants David Ejchorszt Respondents Wells Fargo Clearing Services, LLC Neutrals James A. McIntosh Hearing Site St. Louis, MO Award Document 25-02756.pdf Documentum DocID 3aae598c Award Date Official Wed, 08/05/2026 – 12:00 Related Content Off Claimant Representatives David Ejchorszt Respondent […]

05Aug 2026

25-01614.pdf

25-01614.pdf Anonymous (not verified) Wed, 08/05/2026 – 18:50 Case ID 25-01614 Forum FINRA Document Type Award Claimants Timothy Hodge Respondents OSAIC Wealth, Inc Neutrals Walter Steven Schwartz Hearing Site Phoenix, AZ Award Document 25-01614.pdf Documentum DocID 773d7a60 Award Date Official Wed, 08/05/2026 – 12:00 Related Content Off Claimant Representatives Peter Lindholm Respondent Representatives Gregory M. […]

05Aug 2026

Security validation should begin where attackers begin

Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target for initial access. For years, security teams have invested heavily in protecting networks, endpoints, […]

05Aug 2026

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions

Connor Riley Moucka, aka “Waifu” and “Judishe,” was scheduled to stand trial in January 2027. Today, he changed his “not guilty” plea to a guilty plea, and pleaded guilty to four counts of the multi-count indictment.   Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in… […]

05Aug 2026

Why security validation must follow the attack path

For years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and cloud infrastructure. Those investments remain essential, but the way attackers operate has changed dramatically. Today’s adversaries move laterally, chaining together weaknesses across multiple technologies until they reach their ultimate target. AI is accelerating the pace of […]

05Aug 2026

26-01053.pdf

26-01053.pdf Anonymous (not verified) Wed, 08/05/2026 – 15:40 Case ID 26-01053 Forum FINRA Document Type Award Claimants Gregory Cash R. Mitchell Wickham Respondents UBS Financial Services Inc. Neutrals Steven Gerard Goerke Linda J. Baer Mitchell Regenbogen Hearing Site Charlotte, NC Award Document 26-01053.pdf Documentum DocID 415d94a2 Award Date Official Wed, 08/05/2026 – 12:00 Related Content […]

05Aug 2026

ALPACA SECURITIES LLC

ALPACA SECURITIES LLC fnrw-backend Wed, 08/05/2026 – 15:31 MC ID ALPO MC Reporter Type OTC Market Maker MC Paragraph MC Link https://alpaca.markets/disclosures MC Last Updated Wed, 08/05/2026 – 15:30

05Aug 2026

ALPACA SECURITIES LLC

ALPACA SECURITIES LLC fnrw-backend Wed, 08/05/2026 – 15:15 MC ID APCA MC Reporter Type Broker-Dealer MC Paragraph MC Link https://alpaca.markets/disclosures MC Last Updated Wed, 08/05/2026 – 15:15

05Aug 2026

With FCC ban on new Chinese-made optical transceivers for DCs likely, it may be time to stock up

A likely US administration ban on Chinese optical transceivers for AI data centers may have an unintended consequence: IT will rush to buy as many of the components as possible before restrictions kick in. The US Federal Communications Commission (FCC) “is working on the measure to bar imports of new Chinese optical transceivers” and officials […]

05Aug 2026

The AI answer you can’t trace is the answer you can’t use

A crude tanker slows off a chokepoint and its AIS transponder, the automatic signal ships broadcast to identify themselves and their position at sea, goes dark for eleven hours. To a generic AI model, that’s a gap in a data stream. To anyone with money or compliance exposure on the line, it’s a question: whose […]

05Aug 2026

The production assumptions AI just broke

Over the past decade, I have worked through multiple technology transitions, from virtualization and cloud adoption to containers and large-scale automation. Each changed how enterprise IT operated, but they all shared one characteristic: production systems still behaved in broadly predictable ways. AI is the first shift I have seen that changes the behavior of production […]

05Aug 2026

Never mind clean data. Annotate as you collect it.

Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale […]

05Aug 2026

Put trust infrastructure before intelligent automation for better collaboration

Astute leaders recognize that many times, automation and technology failures aren’t really about the technology itself. Rather, failures occur because the necessary underlying infrastructure linking people, processes, and technology isn’t in place. For example, consider organizations that try to partner together but don’t take the time to align their tech implementations in a way that […]

05Aug 2026

The 5 stages of AI adoption maturity: Where businesses create real value

Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down. Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding where employee development, decision-making and business value intersect. Each stage provides […]

05Aug 2026

Why mainframe security requires continuous verification

The mainframe remains the system of record for many of the world’s largest organizations and some of their most critical data. As of 2025, 71% of Fortune 500 companies still use mainframes, and nearly 97% of banks worldwide rely on IBM mainframe products. Yet many security programs continue to treat the mainframe differently from the rest […]

05Aug 2026

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake […]

05Aug 2026

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a […]

05Aug 2026

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one […]

05Aug 2026

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. “Advertisements for Poison Claude

05Aug 2026

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application […]

05Aug 2026

AU: Updoc patients notified of security breach where personal information may have been stolen

Emma Kirk reports: Updoc patients have been notified their personal information may have been accessed in a security breach. The website is used for 24/7 telehealth services across Australia. Customers were advised there was a “brief period of unauthorised access to a third party system” where hackers had access to names, email and postal addresses… […]

05Aug 2026

Critical Paperclip bugs expose AI agent trust failures

Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise. An Oasis Security research shared with CSO ahead of its publication on Wednesday disclosed details of three recent vulnerabilities affecting […]

05Aug 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing […]

05Aug 2026

OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidents

OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute. “On 28th July 2026, AISI’s Security Team detected unusual […]

05Aug 2026

Zenity Raises $125 Million in Series C Funding

The AI security company will invest in product innovation, global expansion, and customer experience. The post Zenity Raises $125 Million in Series C Funding appeared first on SecurityWeek.

05Aug 2026

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post Weaponized Email AI Assistants Could Help Attackers Hijack Accounts appeared first on SecurityWeek.

05Aug 2026

CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night. The post CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout appeared first on SecurityWeek.

05Aug 2026

Oligo Raises $60 Million for Runtime Security

The company will use the investment to accelerate product innovation and expand go-to-market operations. The post Oligo Raises $60 Million for Runtime Security appeared first on SecurityWeek.

05Aug 2026

Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. The post Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer appeared first on SecurityWeek.

05Aug 2026

Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek.

05Aug 2026

Water Sector Cyberattacks Reportedly Hit at Least 12 States

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.

05Aug 2026

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.

05Aug 2026

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.

05Aug 2026

AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations

In one instance, an unsanctioned model attempted to inject malicious code into an open source repository. The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.

05Aug 2026

One C2 kit. 30 customers. 2 governments

I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I […]

05Aug 2026

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have […]

05Aug 2026

Your orchestration framework choice is a security decision, not just an engineering one

Comparisons of LangChain, CrewAI and AutoGen are easy to find — dozens of guides this year cover the same ground: developer experience, ecosystem maturity, how easy it is to wire up multi-agent workflows. None of them ask the question I actually care about: does the framework you pick change how easily your agent gets compromised? […]

05Aug 2026

Why you need a reliable AI agent kill switch

Recent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind trust in their AI guardrails. Moreover, they must able to turn off agents quickly when they deviate from intended behavior — before they can do potentially catastrophic damage. For legal services company Purpose Legal, that includes incorporating a […]

05Aug 2026

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, […]

05Aug 2026

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows – CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve […]

05Aug 2026

AI threat report: Rogue agents, workflow attacks

Malicious AI use and threats to AI systems are requiring cyber teams to double down on security fundamentals and rethink the future of their approaches to defense. Newly emerging AI-enabled attacks, proofs of concept, and in-the-wild techniques, as well as the latest AI vulnerability and risk research, present inklings not only about what enterprises presently […]

05Aug 2026

Risky Business #847 -- Oops! Claude's accidental hacking spree

On this week’s show Patrick Gray, and James Wilson are joined by bearded man of leisure Adam Boileau to discuss the week’s cybersecurity news, including: Accidental AI agent hacking sprees have the world’s media freaking out, but we think it’s all pretty funny The bugpocalypse is so chaotic, Microsoft can’t patch fast enough A ColdCard […]

05Aug 2026

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application […]

05Aug 2026

ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th)

Post Content

05Aug 2026

Ruby on Rails critical bug puts every image upload under scrutiny

A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets. Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails. Dubbed “KindaRails2Shell,” […]

04Aug 2026

ChainDrop credential stealing worm infects over 400 npm packages

A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined. The attack began with the compromise of a GitHub account belonging to Jared Wray, who maintains Keyv, […]

04Aug 2026

23-01170(2).pdf

23-01170(2).pdf Anonymous (not verified) Tue, 08/04/2026 – 17:10 Case ID 23-01170 Forum FINRA Document Type Motion to Vacate Claimants Wells Fargo Clearing Services, LLC Respondents Wade Roberts Neutrals George Pinckney Shingler Hearing Site Atlanta, GA Award Document 23-01170(2).pdf Documentum DocID c3828692 Award Date Official Thu, 09/26/2024 – 12:00 Related Content On Claimant Representatives Keith J. […]

04Aug 2026

25-02217.pdf

25-02217.pdf Anonymous (not verified) Tue, 08/04/2026 – 17:00 Case ID 25-02217 Forum FINRA Document Type Award Claimants Scott Seltzer Respondents J.P. Morgan Securities, LLC Neutrals Lise Gabrielle Hunter Joseph V. Simeri Dineo Coleman Gary Hearing Site Boca Raton, FL Award Document 25-02217.pdf Documentum DocID 7c8700e6 Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off […]

04Aug 2026

VIRTU AMERICAS LLC

VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:40 MC ID KCGM MC Reporter Type Alternative Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:39

04Aug 2026

VIRTU AMERICAS LLC

VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:39 MC ID ITGP MC Reporter Type Alternative Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:39

04Aug 2026

VIRTU AMERICAS LLC

VIRTU AMERICAS LLC fnrw-backend Tue, 08/04/2026 – 15:37 MC ID NITQ MC Reporter Type Single Dealer Trading System MC Paragraph MC Link https://www.virtu.com/about/transparency/rule-605-and-606-reporting/ MC Last Updated Tue, 08/04/2026 – 15:37

04Aug 2026

The AI assurance gap: CIOs need proof that agentic AI controls actually work

Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category: systems that interpret instructions, call tools and act across workflows without a mature assurance model built around them. In my work as a leader and investor across technology-enabled businesses, I have spent years around automation, cybersecurity, compliance, workflow […]

04Aug 2026

Don’t let your company be fooled by AI efficiency

The scenario isn’t hypothetical: Some of the companies that went furthest in replacing people with AI have had to backtrack. For example, in 2024 Klarna became a European benchmark for what AI could do for a company. Its AI assistant handled two-thirds of customer service chats in its first month, performing the equivalent of 700 full-time agents. As […]

04Aug 2026

Why AI infrastructure needs a new operating model

The next AI infrastructure crisis may come from unmanaged inference capacity. For the past several years, the AI infrastructure conversation centered on one question: how do we get more compute? That made sense. Enterprises needed GPUs, cloud capacity, foundation models and room to experiment. Compute became shorthand for AI readiness. Production AI changes the operating […]

04Aug 2026

20 traits of innovative and invaluable project managers

Projects are becoming more complex, with higher stakes and faster delivery times. At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines. Some may think that AI and automation will make project managers obsolete, or at least […]

04Aug 2026

The enterprise AI strategy that outlasts any single model

In January of this year, few enterprise tech leaders would have bet on Anthropic over OpenAI. Today, Claude reigns supreme (inspiring a notable 180 by Elon Musk), with Gemini threatening to take market share and introduce pricing models that could flip the leaderboard on its head again. That’s exactly why betting on a single model […]

04Aug 2026

Why meta agents must become the economic intelligence layer of the agentic enterprise

In “Micro and macro agents: The emerging architecture of the agentic enterprise,” I proposed a three-layer architecture for enterprise AI. Micro agents execute specialized tasks. Macro agents orchestrate end-to-end business processes. Meta agents provide governance through monitoring, compliance, security, and human oversight. As enterprises begin deploying thousands — and eventually tens of thousands — of […]

04Aug 2026

AI agents get better at IT ops, but only with humans in the loop

AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operational data, rather than underlying AI infrastructures, is often […]

04Aug 2026

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and

04Aug 2026

Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026. The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centralized policy management for trusted applications and AI agents, and real-time governance over what trusted AI agents […]

04Aug 2026

Sage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguards

Dysruption reports on a critical infrastructure attack in Utah that could have caused more damage than some other recent attacks: Sage Water Resources said workers stopped malicious changes to an automated controller at its oilfield wastewater disposal site near Duchesne, Utah, before the March 15 intrusion caused equipment failure or environmental damage. In an Aug…. […]

04Aug 2026

Florida Man Sentenced for Conspiracy to Commit Wire Fraud

Stolen wallets are still a thing.  From the U.S. Attorney’s Office, Eastern District of Kentucky: July 31, 2026 LEXINGTON, Ky. – An Orlando, Fl., man, Ivory Joe Pruitt, 61, was sentenced on Friday to 63 months imprisonment by U.S. District Judge Robert Wier for conspiracy to commit wire fraud. Pruitt was also ordered to pay $137,392.74… […]

04Aug 2026

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later […]

04Aug 2026

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat

04Aug 2026

Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)

This morning, I noticed specific sources “hunting” for vulnerabilities in URLs that I haven’t noticed before. All of these URLs appear to be associated with diagnostic tools:

04Aug 2026

Republican attorneys general urge OpenAI to preserve records on Hugging Face breach

Miranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO Sam Altman, 15 attorneys general wrote the ChatGPT-maker may have… […]

04Aug 2026

Swiss federal IT office hit by cyberattack

SwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people outside the federal administration. Around 200 accounts were compromised in the incident. There are no indications of any further data breaches. The unknown attackers are… […]

04Aug 2026

Critical Azure Cosmos DB flaw threatened cross-tenant database takeover

A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security […]

04Aug 2026

The top new cybersecurity products at Black Hat USA 2026

Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure management, and recovery capabilities aimed at making autonomous security more practical for enterprise environments. […]

04Aug 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack […]

04Aug 2026

Acrisure KARR BT and DR-100

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware <July_20_2026 DR-100 firmware <July_20_2026 CVSS Vendor Equipment Vulnerabilities v3 8.1 Acrisure Acrisure KARR BT and DR-100 Use of Hard-coded Cryptographic Key Background Critical […]

04Aug 2026

Thermo Fisher Applied Biosystems Genetic Analyzers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Biosystems Genetic Analyzers are affected: Applied Biosystems 3500/3500xL Series Data Collection Software <=4.0.2  Applied Biosystems 3730/3730xL Series Data Collection Software <=5.0.2  […]

04Aug 2026

Google ADK flaws reveal what happens when AI agents trust the wrong message

Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from Pillar Security. The first attack path involved a triage agent that analyzed […]

04Aug 2026

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as “script kiddies,” sat at the other end, running public

04Aug 2026

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so […]

04Aug 2026

Horizon3 Raises $250 Million to Fund Continuing Growth

Venture financing has become an essential factor in growing new business in today’s fast moving economy. Horizon3’s latest funding explains how and why. The post Horizon3 Raises $250 Million to Fund Continuing Growth appeared first on SecurityWeek.

04Aug 2026

River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

The bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek.

04Aug 2026

Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations

The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing. The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek.

04Aug 2026

Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud. The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first on SecurityWeek.

04Aug 2026

Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.

04Aug 2026

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

04Aug 2026

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek.

04Aug 2026

150,000 Impacted by Madera Community Hospital Data Breach

An extortion group stole personal, financial, and medical information from the hospital’s network. The post 150,000 Impacted by Madera Community Hospital Data Breach appeared first on SecurityWeek.

04Aug 2026

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek.

04Aug 2026

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek.

04Aug 2026

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS […]

04Aug 2026

Secure AI adoption starts with API best practices

You don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey reported in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently, Gartner forecast that worldwide spending on AI will top $2.59 trillion in 2026 – an increase of 47% from last year. […]

04Aug 2026

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes […]

04Aug 2026

The Minnesota attackers may hold a better backup of your plant than you do

More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including CSO’s own news analysis — has rightly chased two open questions: Who did it, and […]

04Aug 2026

Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpers

AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn. AI-assisted software developers have been increasingly targeted through malicious IDE extensions, rogue MCP servers, and poisoned AI skills, all of which provide […]

04Aug 2026

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows

04Aug 2026

ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)

Post Content

03Aug 2026

EQUITABLE ADVISORS, LLC

EQUITABLE ADVISORS, LLC fnrw-backend Mon, 08/03/2026 – 18:12 MC ID EQHA MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.lpl.com/disclosures/sec-605-equitable-disclosures.html MC Last Updated Mon, 08/03/2026 – 18:12

03Aug 2026

TRADE-PMR INC.

TRADE-PMR INC. fnrw-backend Mon, 08/03/2026 – 17:29 MC ID TPMR MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.tradepmr.com/order-routing-disclosures MC Last Updated Mon, 08/03/2026 – 17:29

03Aug 2026

2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf

2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:15 Case ID 2021069426901 Document Number 00747591 Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Action Date Fri, 07/31/2026 – 12:00 Related Content Off Attachment 2021069426901 UBS Financial Services Inc. CRD 8174 AWC vrp.pdf

03Aug 2026

26-00488.pdf

26-00488.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:10 Case ID 26-00488 Forum FINRA Document Type Award Claimants Michael Renshaw Respondents Robinhood Securities, LLC Neutrals Chandler R. Bridges Hearing Site Atlanta, GA Award Document 26-00488.pdf Documentum DocID 5c5483ca Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off Claimant Representatives Michael J. Renshaw Respondent Representatives Michael […]

03Aug 2026

26-00144.pdf

26-00144.pdf Anonymous (not verified) Mon, 08/03/2026 – 17:10 Case ID 26-00144 Forum FINRA Document Type Award Claimants Paula Gomoll Respondents Charles Schwab & Co., Inc. Cetera Financial Specialists LLC Eric Wurtel Neutrals Mark W Solock Hearing Site Chicago, IL Award Document 26-00144.pdf Documentum DocID 14dab4c2 Award Date Official Mon, 08/03/2026 – 12:00 Related Content Off […]

03Aug 2026

AI can do your tasks. That doesn’t mean it will do your job

Much of the conversation around AI and work has centered on a single question: Will AI take my job? It’s an understandable concern. Every week AI becomes increasingly more capable. We see AI summarizing meetings, generating content, analyzing data, writing software and automating workflows that once required significant human effort. Agentic AI is also becoming […]

03Aug 2026

12 business analyst certifications to level up your career

Business analysts help organizations make the most of the data they collect by finding trends, patterns, and errors that might otherwise go unnoticed. Successful business analysts have the skills to work with data, the acumen to understand the business side of the organization, and the ability to communicate that information to people outside of IT. […]

03Aug 2026

Frontier AI will not break finance. Slow cyber decisions will

The scariest thing about frontier AI is that it gives lazy criminals better legs. That sounds flippant until you watch how cyber failure works. I have seen that weakness in many costumes: A server waiting for a patch, an access path nobody wants to touch, a supplier marked “low risk” because the contract said so, […]

03Aug 2026

CIOs risk being sidelined in enterprise AI initiatives

The AI revolution has created new opportunities for CIOs, with expanded responsibilities and more authority, but some observers see the opposite happening at some organizations. While many CIOs have become the main executive leading AI strategy and initiatives, some organizations have set the responsibility for AI deployment and adoption with another executive. That puts CIOs […]

03Aug 2026

The missing role in every enterprise AI strategy: The analytics engineer

Every enterprise AI strategy these days has mostly the same core cast: Software engineers who log online events data, data engineers who move data from online to offline data warehouses, data scientists who build machine learning models, AI/ML engineers who deploy these models to production systems and data analysts who consume these data outputs and […]

03Aug 2026

AI’s measurement crisis is over. The translation crisis is next

Last fall, you couldn’t open a business publication without tripping over some version of the same headline: where is the ROI for AI? The anchor for most of that coverage was MIT’s “GenAI Divide” report, which found that despite $30 to 40 billion in enterprise generative AI spending, 95% of pilots delivered no measurable P&L […]

03Aug 2026

Companies winning with AI operate differently. Here’s how.

The first phase of the AI race was largely about access. Companies rushed to adopt tools, launch pilots, and demonstrate that they were moving quickly enough to keep pace with the market. In many organizations, simply showing momentum became the strategy. Leadership teams wanted to signal innovation, employees were encouraged to experiment, and new technologies […]

03Aug 2026

SAP dodges German antitrust investigation over data extraction

SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation. The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a […]

03Aug 2026

The SOC’s AI maturity model

The path to next-generation AI Security Operations Centers (SOCs), where AI works hand-in-hand with human analysts, is paved with ambitious goals. This ideal SOC incorporates AI across every task to stop fast-moving threats. But a fully AI-powered SOC isn’t a single deployment or a switch you just flip on. It is a staged rollout that’s […]

03Aug 2026

Moburst Unveils AI-Driven Mobile Growth Playbook

Moburst, a mobile growth marketing agency, has formalized a mobile-specific approach to Answer Engine Optimization, aimed at helping app publishers get recommended by AI assistants such as ChatGPT, Perplexity, and Google’s AI Overviews, in addition to ranking inside the App Store and Google Play. Why mobile teams are asking this question now A growing share […]

03Aug 2026

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is “lib-mtop,” an unscoped package with the same name as a […]

03Aug 2026

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest […]

03Aug 2026

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its […]

03Aug 2026

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, […]

03Aug 2026

Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls

While AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the […]

03Aug 2026

KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach

The Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seoul Metropolitan Council member Im Gyu-ho of the Democratic Party of Korea… […]

03Aug 2026

UK: Details of 100,000 police staff leaked on the dark web after hack

Bill Curtis reports: The full names and contact details for more than 100,000 police officers and staff have been leaked on the dark web after a hack, The Times can reveal. As part of a major security breach, hackers compromised data belonging to the Ministry of Defence (MoD), the Home Office, National Crime Agency (NCA),… […]

03Aug 2026

Cyberattack hits Liechtenstein, with 31,000 records stolen

DPA reports: The tiny principality of Liechtenstein has fallen victim to a major cyberattack in which the data of 31,000 people were stolen, the government said on Sunday. The country, which lies between Switzerland and Austria, has a population of around 41,000. The government said it had convened a crisis team led by Prime Minister… […]

03Aug 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational […]

03Aug 2026

FOMO in the SOC: Where AI Platforms like Claude Actually Fit

AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI […]

03Aug 2026

US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek.

03Aug 2026

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking

Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek.

03Aug 2026

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek.

03Aug 2026

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a […]

03Aug 2026

PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names

03Aug 2026

Stop depending on heroics and start operationalizing third-party risk

In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and […]

03Aug 2026

AI is making cybersecurity fundamentals more important than ever

When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox — the same kind of fundamental […]

03Aug 2026

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as […]

03Aug 2026

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform

03Aug 2026

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. “These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the

03Aug 2026

ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)

Post Content

02Aug 2026

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained… […]

02Aug 2026

Brinks Home Confirms Data Breach Following ShinyHunters Claim

Guru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment. The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on their… […]

02Aug 2026

TN: Sumner County Schools provides limited update on data breach

Abbey Nutter reports: Sumner County Schools is still working through a reported network breach that forced the district to delay the start of the 2026-27 school year, officials told Main Street Media. The district reported the data breach during a meeting of the Sumner County Board of Education on July 21, one day after the… […]

02Aug 2026

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

02Aug 2026

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

02Aug 2026

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction

01Aug 2026

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to […]

01Aug 2026

23-02357.pdf

23-02357.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:45 Case ID 23-02357 Forum FINRA Document Type Award Claimants Windsor Street Capital, LP Respondents Michael Davis M7 Balanced Stage Fund, LLC M7 Asset Management, LLC Syren Capital Advisors LLC Neutrals Keely D. Parr A. Rene Hollyer Jon Michael Fundaro Hearing Site New York, NY Award Document 23-02357.pdf […]

01Aug 2026

20-00840.pdf

20-00840.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:40 Case ID 20-00840 Forum FINRA Document Type Award Claimants Vincent Yacono Respondents Douglas Guarino Kinan Nimeh Michael Resciniti Rockwell Global Capital LLC Neutrals Patrick R. Westerkamp Hearing Site Syracuse, NY Award Document 20-00840.pdf Documentum DocID ee000223 Award Date Official Fri, 07/31/2026 – 12:00 Related Content Off Claimant […]

01Aug 2026

26-00191.pdf

26-00191.pdf Anonymous (not verified) Sat, 08/01/2026 – 11:35 Case ID 26-00191 Forum FINRA Document Type Award Claimants Xavier Cortada Respondents Fidelity Brokerage Services LLC Neutrals John James Rubin Hearing Site Atlanta, GA Award Document 26-00191.pdf Documentum DocID abd9d4cb Award Date Official Thu, 07/30/2026 – 12:00 Related Content Off Claimant Representatives Xavier Cortada Respondent Representatives Kevin […]

01Aug 2026

Sixth Circuit to Rehear Case on FCC Data Breach Rules Case

Jake Neenan reports: A full panel of federal judges will rehear a case that upheld expanded telecom data breach rules. The Federal Communications Commission, now under Republican control, has indicated it’s likely to reverse the rules anyway. But industry groups and GOP lawmakers want the case’s precedent gone too. They told judges on the U.S…. […]

01Aug 2026

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patients and healthcare professionals. The contrast lies in the type of data compromised and… […]

01Aug 2026

CareCloud Data Breach Impacts Over 350,000

Ionut Arghire reports: Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between… […]

01Aug 2026

Suspected cyberattack disrupts Oceanside, California, school district systems

DysruptionHub reports: A suspected cyberattack disrupted work email, internet access, Google Drive and other applications at Oceanside Unified School District in California as officials investigated and worked to restore service. The district confirmed a computer network disruption but did not identify its cause. NC Pipeline reported that a separate district text described the incident as a cyberattack…. […]

01Aug 2026

AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked

Will Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April after a phishing attack. It wasn’t until almost three months later… […]

01Aug 2026

Mon General Hospital notifies patients of phishing attack and breach

WDTV reports: Monongalia County General Hospital Company, known as Mon General, announced it was recently the victim of a phishing attack that may have compromised the personal and medical information of some patients. Hospital officials say the incident was discovered on May 6, when they identified that a phishing attack had targeted a small number… […]

01Aug 2026

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek.

01Aug 2026

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek.

01Aug 2026

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek.

01Aug 2026

System Announcement: Maintenance

DataBreaches.net will be undergoing some maintenance and upgrades this weekend and may be unavailable at times. We’ll be back, though! Thank you for your patience. Source

01Aug 2026

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and […]

01Aug 2026

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose “something”: money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

01Aug 2026

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could […]

01Aug 2026

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of […]

01Aug 2026

AMGEN reports breach to SEC

From Amgen’s filing on July 29 to the Securities and Exchange Commission: Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the “Company”) identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged… […]

01Aug 2026

CHARLES SCHWAB & CO., INC.

CHARLES SCHWAB & CO., INC. fnrw-backend Fri, 07/31/2026 – 20:52 MC ID CHAS MC Reporter Type Broker-Dealer MC Paragraph MC Link https://schwab.com/legal/sec-605 MC Last Updated Fri, 07/31/2026 – 20:52