Cybersecurity News Today: breaches, vulnerabilities and threat intel from 40+ sources
pwnsy
News
·
Data
·
Blog
·
Events
·
Tools
News
EN
CN
Main
Social
Enterprise
Research
AI Security
Offensive
Privacy
Vendors
Tools
BLEEPINGCOMPUTER
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
3h
PaperCut warns of NG, MF flaw exploited in zero-day attacks
8h
Manchester Airports Group says hackers stole travelers' data
9h
MORE
···
DARK READING
Chinese Routers Sold Worldwide Contain Backdoors
5h
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
7h
Russian Hackers Phish EU Officials Over Messaging Apps
14h
MORE
···
CYBERSCOOP
Unit 42 warns AI has shifted balance of power from defenders to attackers
6h
100-plus companies call for ‘global surge’ in AI-powered cyber defense
6h
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
8h
MORE
···
TLDR INFOSEC
Critical Ubiquti Vulnerabilities 🛜, Security Needs a New Control Plane 🤖, Debunking Carhartt Breach Claims 👕
1d
Critical Keycloak ATO 🔑, AI Bug Bounty Hunter 🐞, Global Telecom Exploitation 📞
2d
Does Plan Mode Help Code Security 📝, OWASP Agent Skills Top 10 🔟, Bypassing macOS SIP 🍎
3d
MORE
···
THE HACKER NEWS
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
1d
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
1d
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
1d
MORE
···
THE RECORD
White House bans foreign-made equipment for power generation over cyber backdoor concerns
5h
Finland appeals court revives case against Eagle S Officers over cable breaks
9h
Chinese and Russian spies stepping up cyberattacks, German companies report
10h
MORE
···
SECURITYWEEK
Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
11h
Australia Arrests 2 Alleged TeamPCP Hackers
12h
OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
13h
MORE
···
HELP NET SECURITY
Two alleged TeamPCP hackers arrested over global supply chain attacks
11h
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
1d
RightCrowd Pass unifies mobile, physical, and biometric credentials
1d
MORE
···
INFOSECURITY
Manchester Airports Group Hit by Cyber Incident
12h
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns
13h
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
14h
MORE
···
GRAHAM CLULEY
US Navy tells sailors and their families: scrub your social media, enemies are watching
15h
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
1d
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
3d
MORE
···
SOPHOS
A call for collective action on cyber defense
1d
The State of Ransomware in Education 2026
1d
Sophos Ranked #1 Overall in Endpoint, XDR, MDR, and Firewall in the G2 Fall 2026 Reports
3d
MORE
···
INDICATOR
AI-generated Costco employees got over 100 million views on Facebook and Instagram
1d
OSINT Tool Radar: 14 new and 72 updated
2d
The Indicator guide to vibecoding for OSINT
3d
MORE
···
KREBS ON SECURITY
Who’s Tracking You? Use This New Service to Find Out
13d
Microsoft Plugs Nearly 400 Security Holes
16d
Canadian Man Pleads Guilty in Snowflake Extortions
21d
MORE
···
SOCIAL
R/PRIVACY
Bank to Bank transfers
3h
💬 11
▲ 17
West Yorkshire Police to deploy facial recognition at Leeds Festival for first time
4h
💬 5
▲ 29
Is looking for privacy make you more of a target.
5h
💬 14
▲ 32
MORE
···
R/CYBERSECURITY
Are you worried that everyone is getting into cybersecurity that it will be like computer science?
3h
💬 181
▲ 90
Best Varonis alternatives for an on-prem environment?
4h
💬 30
▲ 11
how does an IAM department actually work inside a company?
7h
💬 22
▲ 39
MORE
···
R/HACKING
I pwned OpenClaw with just email and a new injection escalation technique: prompt laundering
3h
💬 4
▲ 39
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
12h
💬 1
▲ 13
I Turned a $400 Enterprise AP Into a Fully Emulated Root Shell — Here's the Whole Story, Bugs and All
12h
💬 0
▲ 5
MORE
···
R/NETSEC
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range
4h
💬 1
▲ 9
A fake resume invoked China’s defence tech elite, then installed VShell
9h
💬 3
▲ 9
LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation
10h
💬 0
▲ 10
MORE
···
R/ASKNETSEC
Best runtime security platform for AI agents that actually deploys without proxies or SDK changes?
11h
💬 2
▲ 5
Best risk based vulnerability management solution? tired of guessing.
12h
💬 3
▲ 10
What's your guardrail for an AI coding assistant reading files outside the repo
18h
💬 9
▲ 20
MORE
···
R/REVERSEENGINEERING
HexWalk 2.2.0 Hex analyzer new release, added multi-encoding support: ASCII, UTF8, UTF16, Latin1... works both on Windows, Linux and MacOs, give it a try!
17h
💬 0
▲ 18
drakoarmy/datadome-rs: High-end Rust DataDome deobfuscator & solver with VM disassembly — all 3 challenge types (tags, interstitial, slider).
1d
💬 2
▲ 5
binviz – a binary visualiser with calibrated thresholds instead of magic numbers
1d
💬 6
▲ 8
MORE
···
R/INFOSECNEWS
Police Arrest Two Alleged TeamPCP Members Linked to Shai-Hulud Attacks
5h
💬 0
▲ 6
Account Takeover Flaw Hits TranslatePress Plugin Used on 400K WordPress Sites
14h
💬 0
▲ 5
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
1d
💬 1
▲ 20
MORE
···
R/MALWARE
I open-sourced a categorized catalog of 2,800+ malware families (Mapped to NIST/CISA & MITRE)
2d
💬 2
▲ 15
E4del and PINHOLE two new RATs abusing FTP banners, Pinterest, and SurveyMonkey for C2
6d
💬 1
▲ 11
HACKER NEWS
💬
Three UK airports hit by cyber-attack with data of 8.7M customers accessed
2h
💬 1
▲ 7
💬
Show HN: Beating GPT5.5-xhigh for Coding agent security with SLMs and IRM
2h
💬 3
▲ 6
💬
Carhartt data breach exposes information of 12.9 million accounts
10h
💬 1
▲ 6
💬
Government admits water system cyberattacks were worse than first reported
11h
💬 2
▲ 9
💬
AC2 Protocol: The missing security layer for AI agents
11h
💬 14
▲ 16
MORE
···
ENTERPRISE
FEDERAL NEWS CYBER
Army overhauls software acquisition to speed delivery
3h
Getting help to disaster survivors takes more than good weather forecasts
5h
Commercial aviation depends on a growing network of connected systems. GAO found gaps in cybersecurity.
1d
MORE
···
THE REGISTER SECURITY
CRPx0 hacking service for dummies claims victim count more than quintupled
3h
AI girlfriend review site's secrets were exposed to the world for three weeks
6h
Omarchy distro gains serious backing
8h
MORE
···
ZDNET SECURITY
Lawsuit says Oura sleep tracking has 'a coin flip's chance of being correct'
4h
Galaxy Z Fold 8 camera trouble? 4 settings I recommend changing now
6h
This excellent HP laptop is nearly 50% off at Best Buy - and comes with a cheap TV
8h
MORE
···
TECHCRUNCH SECURITY
ATF declares ‘major incident’ as ransomware gang claims hack
7h
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
10h
Here’s all the times AI has gone rogue and hacked other companies
11h
MORE
···
CYBERSECURITY DIVE
Hundreds of agents went rogue in lead up to Hugging Face breach
9h
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
12h
Boston Scientific says cyberattack disrupted order processing, shipping
1d
MORE
···
NEXTGOV CYBER
ATF investigating ‘major’ cyber incident after ransomware group claim
11h
White House to soon launch water provider cyber protection program
1d
FBI disables China-linked hacking tools used against US agencies
1d
MORE
···
CSO ONLINE
AI can be made to read an email much differently than you do
13h
Critical infrastructure’s long, undefended tail exposed by UK energy attack
16h
NemoClaw’s AI can be poisoned through a browser tab
1d
MORE
···
ARS TECHNICA SECURITY
Claude published malicious code to the Internet and attacked 3 real companies
27d
Chrome may get faster updates with no restart required
28d
Microsoft unveils AI security tools it says outperform competing platforms
1mo
MORE
···
RESEARCH
MICROSOFT SECURITY
What’s new in Microsoft Security: August 2026
9h
When AI infrastructure becomes the target: Securing gateways and control points
1d
The patch window is collapsing: Why security needs a new control plane
2d
MORE
···
NCSC UK
Disruptive cyber activity highlights risk from internet-exposed systems and edge devices
13h
NCSC statement in response to recent incidents resulting from frontier AI evaluations
23d
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations
1mo
MORE
···
SANS ISC
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
15h
ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)
23h
Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)
1d
MORE
···
SCHNEIER ON SECURITY
LLM-Based Social Engineering Scams
15h
Spyware for Babies
1d
Black Hat State of Security Vendors
2d
MORE
···
ARXIV SECURITY
ToolMinimize: Auditing and Rewriting LLM Agent Tool Calls to Minimize Privacy Exposure
21h
Retrieved But Not Reliable: A Survey on Attacks, and Defenses in Retrieval-Augmented Generation
21h
Static Detection of Post-Quantum Cryptographic Algorithms in Stripped Binaries for Digital Forensic Examination and Migration Assurance
21h
MORE
···
TROY HUNT
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
2d
Weekly Update 518: IoT Doorlock Nirvana with UniFi
3d
Welcoming the Sri Lankan Government to Have I Been Pwned
4d
MORE
···
NIST NEWS
NIST Researchers Supersize Quantum Technology to Help Detect Faint Photons
3d
NIST National Construction Safety Team Advisory Committee Meeting Scheduled for Sept. 23 and 24, 2026
14d
NIST Researchers Correct Common Error Confounding Nanotech Measurements
21d
MORE
···
AI SECURITY
SIMON WILLISON
Breaking Claude Code Opus 5 Auto Mode
2h
Qwen3.8-Flash-Next
1d
Quoting Paul Dix
1d
MORE
···
XBOW
Continuous Attack Surface Testing vs Penetration Testing: Key Differences
10h
Superhuman: Continuous Security Testing at Release Speed
13h
Elliot Hyun (현종석)
1d
MORE
···
ADVERSA AI
OWASP Agentic Skills Top 10 explained: the ten agent skill risks, and which to fix first
2d
Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories
7d
Top 10 zero-click attacks against AI agents
9d
MORE
···
EMBRACE THE RED
Recovering Encrypted LLM Reasoning Traces
10d
LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
24d
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)
28d
MORE
···
OFFENSIVE
SPECTEROPS
Why SpecterOps Signed OpenAI’s Call for Collective Cyber Defense
7h
Cleartext Credential Recovery in ServiceNow
9h
AWSHound: An OpenSource AWS OpenGraph Collector
8d
MORE
···
TRUSTEDSEC
SpooNMAP Grows Up: Findings, Local LLM Detection, and a Whole Lot Less Waiting
2d
We've Seen This Movie: The OT/IT Technology Divide
9d
AI Offense is Not Noclip Mode
14d
MORE
···
0XDF
HTB: Cobblestone
12d
HTB: Helix
19d
HTB: Kobold
26d
MORE
···
HACKING ARTICLES
Impacket for Pentester: SMBExec
12d
Impacket for Pentester: reg
22d
Impacket for Pentester: atexec
26d
MORE
···
PRAETORIAN
Bluetooth Low Energy Security Testing, Consolidated: Introducing Caeruleus
1mo
FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 2 of 2)
1mo
Knossos: Procedurally Generated Decoy Environments
1mo
MORE
···
MDSEC
ARM64 stack internals and obfuscation on Apple Silicon
13d
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
1mo
PRIVACY
EFF DEEPLINKS
A List of ICE Subpoenas to Tech Companies
1d
EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms
1d
EFF Statement on Meta Settlement
1d
MORE
···
FLOCK SAFETY
Independent Study: Vehicle Thefts Fell 11% After Flock Cameras Went Live
4d
Building on Trust: Updates to Flock’s Terms and Conditions
7d
Flock Updates Privacy, Accountability, Security, and Transparency Safeguards
15d
MORE
···
CITIZEN LAB
‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert
7d
Call for Applications: Information Controls Research Program 2026
10d
Inside the Fake Copyright Racket Silencing News Outlets
20d
MORE
···
TOR PROJECT
New Release: Tails 7.11
9d
New Release: Tor Browser 15.0.20
10d
Funding internet freedom together: results from our first participatory funding round
11d
MORE
···
THE MARKUP
Brazil gives parents social media controls for their kids. Should the US?
1mo
Kaiser Permanente nurses say technology is making their jobs — and patient care — worse
1mo
Californians can protect their personal data with one click. Help us test if it works
1mo
MORE
···
SIGNAL
Introducing Automatic Key Verification
17d
More linked devices are on the table (and the Android tablet)
24d
VENDORS
MANDIANT
$4.7T
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia
7d
Staying Ahead of Adversarial AI Through Agentic Source Code Review
9d
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
21d
MORE
···
CISCO TALOS
$475B
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
7h
JavaScript obfuscation: From party trick to phishing kit
15h
Choose your fighter: Balancing competing requirements to select models for your AI SOC
1d
MORE
···
UNIT 42
$228B
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
2d
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
6d
Identity Abuse Through Trusted Communication Channels
7d
MORE
···
CROWDSTRIKE
$186B
CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms
7d
Benchmaxxing: When the Benchmark Becomes the Target
8d
Teaching AI to Reason Through Detection Triage
10d
MORE
···
CLOUDFLARE
$85B
How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache
8h
The Cloudflare Blog – Brought to you by EmDash
3d
Say it once: introducing Bot Preference Sync
6d
MORE
···
DATADOG SECURITY LABS
$85B
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it
8d
Putting models to the secure coding test: Plan vs default mode
9d
Worm compromises hundreds of popular npm packages
24d
MORE
···
WIZ
$32B
Inside 90 days of attacks on AI infrastructure
8h
From Concept to Context Engine: How Wiz Built AI-Powered Data Discovery
9h
Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
13h
MORE
···
ZSCALER
$23B
It No Longer Takes an Expert to Attack a Factory
8h
Zscaler WebMCP Security Controls: Bringing Zero Trust to the Agentic Web
1d
Human + AI: How Our Product Managers Innovate with AI
1d
MORE
···
CHECK POINT RESEARCH
$14B
24th August – Threat Intelligence Report
3d
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
7d
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
9d
MORE
···
SNYK
$7.4B
Why Your AI Application Is Exposed Snyk
1d
Remediation Agents, Demystified: Why Fixing Beats Finding
9d
Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%
9d
MORE
···
SENTINELONE
$6.2B
The Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity
2d
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders
14d
From Input to Impact: Secure AI Where It Runs
23d
MORE
···
ELASTIC SECURITY
$5.7B
Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy
3d
How a team of entity maintainers monitors, connects and scores entities in Elastic Security
4d
13 million tool calls: auditing every AI coding agent action with Elastic Agent
17d
MORE
···
QUALYS
$3.85B
PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026
7h
Beyond Patching: What IT Teams Need to Know About Unpatchable Exposures
1d
When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion
1d
MORE
···
TENABLE
$3.1B
How to build an exposure management program the business trusts: Lessons from Tenable’s CSO
10h
Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
1d
Frequently asked questions about the active threat to Siemens S7 Series PLCs
7d
MORE
···
RECORDED FUTURE
$2.65B
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
1d
Recorded Future Launches AI Alert Filtering
2d
Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
3d
MORE
···
EXPEL
$1B
The AI CVE exploitation evidence story: Headlines are scarier than reality
5h
Mapping AI detections to MITRE ATLAS: How Expel does it
1d
New Ruxie AI power-up: Meet RTA, the AI agent bringing self-challenging logic to identity and cloud alert triage
3d
MORE
···
HACKERONE
$841M
CIRCIA Cyber Incident Reporting: HackerOne's Recommendations
7d
How to Build a CTEM Program: A 90-Day Implementation Roadmap
14d
CTEM Metrics That Matter: What CISOs Should Report to the Board
22d
MORE
···
RAPID7
$440M
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs
11h
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
3d
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
8d
MORE
···
REVERSINGLABS
Extend CrowdStrike Falcon with Permanent Intelligence
8h
Infostealers highlight malware-as-a-service trend
1d
Agentic AI scales semiautonomous server attacks
2d
MORE
···
KASPERSKY SECURELIST
Threat landscape for industrial automation systems. Q2 2026
15h
Exploits and vulnerabilities in Q2 2026
1d
The invisible passenger in your car
6d
MORE
···
OX SECURITY
ClickFix Phishing Pages Discovered in 24 npm Packages
2d
PBOM vs SBOM: What’s the Difference, and Why Does It Matter in 2026?
8d
Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive
9d
MORE
···
WELIVESECURITY
How QR-code phishing can slip past corporate security measures
10d
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
14d
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
14d
MORE
···
BITDEFENDER
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
24d
Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
2mo
Inside APAC's malvertising ecosystem: How scams spread through social media ads
2mo
TOOLS
GITHUB SECURITY
$3.3T
OpenClaw went viral. Meet the maintainers building and securing it.
9h
Disrupting supply chain attacks on npm and GitHub Actions
1mo
Next chapter: Restructuring GitHub’s bug bounty program
1mo
MORE
···
ZERO DAY INITIATIVE
$4.9B
The August 2026 Security Update Review
16d
The July 2026 Apple Security Update Review
28d
Pwn2Own Ireland 2026 – New Targets and Categories
1mo
MORE
···
FULL DISCLOSURE
FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)
1d
[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File
1d
[NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Records
1d
MORE
···
EXPLOIT-DB
[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
3d
[remote] PCMan 2.0.7 - Buffer Overflow
10d
[dos] NanaZip 6.5 - DoS
10d
MORE
···
PROJECTDISCOVERY
Supply Chain Security Analysis of a 9.5M-Install VS Code Extension
11d
Watching Agents Work: A Behavioral Audit of Offensive-Security LLM Runs
24d
Oh My Rogue Agent
1mo
MORE
···
PORTSWIGGER RESEARCH
What's in a tag name? JavaScript, apparently
2d
CSS:the bomb inside your inbox
21d
CRLF-Powered Desync Attacks: Beheading HTTP Streams
22d
MORE
···
DOYENSEC
Introducing Session Switcher. Swap Burp Sessions with One Click!
2mo