pwnsy
News
·
Data
·
Blog
·
Events
·
Tools
News
EN
CN
Main
Social
Enterprise
Research
AI Security
Offensive
Privacy
Vendors
Tools
BLEEPINGCOMPUTER
Hackers arrested over €30M bank fraud exploiting service provider flaw
1h
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
4h
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
5h
MORE
···
DARK READING
Amid AI-Driven Bug Tsunami, NIST Looks to…AI
1h
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
3h
What Boards Need to Know About Tech Risk
5h
MORE
···
THE HACKER NEWS
Unpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
1d
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
2d
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
2d
MORE
···
CYBERSCOOP
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
21h
Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack
21h
AI’s ‘middle class’ has gotten dramatically better at hacking
1d
MORE
···
TLDR INFOSEC
Attacks Target Salesforce and ServiceNow 🚨, VMware vCenter RCE Flaw 🖥️, Trezor data breach 💿
19h
Ceva Cyberattack 💻, LiteLLM Supply Chain attack ⛓️💥, Kimwolf botnet 🤖
1d
SharePoint AI Exploit 🤖, Zoom "Zoomsday" RCE 📹, Project CAV3RN C2 🦇
2d
MORE
···
THE RECORD
France investigates tax authority breach after hacker claims 600,000 victims
6h
Flock tightens privacy controls amid scandals over officer abuse
1d
New Mirai variant adds stealth capabilities to notorious botnet code
1d
MORE
···
INFOSECURITY
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
4h
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
6h
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
8h
MORE
···
SECURITYWEEK
In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
7h
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
7h
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
8h
MORE
···
HELP NET SECURITY
The hardest part of agentic AI may be rebuilding the business
13h
New infosec products of the week: August 14, 2026
15h
153GB of stolen credentials surface after LiteLLM supply chain attack
1d
MORE
···
INDICATOR
Briefing: US backtracks on company ownership transparency
8h
AI generators are now required to offer detection tools. We tested them (and they need work)
2d
How TikTok bots turned a cancer patient's story into engagement bait
4d
MORE
···
GRAHAM CLULEY
Smashing Security podcast #480: This is the AI service you should never sign up to
1d
Beware cut-price AI services that read your every word
7d
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
8d
MORE
···
SOPHOS
ClickFix campaign abuses Deno runtime for infostealer delivery
3d
Abuse of alternative runtime environments Deno-tes defender headaches
3d
Sophos Working with OpenAI on security from AI, with AI, and for AI
4d
MORE
···
KREBS ON SECURITY
Who’s Tracking You? Use This New Service to Find Out
7h
Canadian Man Pleads Guilty in Snowflake Extortions
8d
SOCIAL
R/CYBERSECURITY
French taxpayers' data stolen in cyber attack, French Finance Ministry says
38min
💬 2
▲ 5
What's one cybersecurity habit you wish more people actually followed?
48min
💬 29
▲ 9
SOC L1 responsibilities
2h
💬 7
▲ 8
MORE
···
R/PRIVACY
Data and Privacy
55min
💬 1
▲ 5
Is Apple really a privacy focused option?
2h
💬 26
▲ 9
Opinion: Flock debate is not facts versus feelings
3h
💬 10
▲ 116
MORE
···
R/NETSEC
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs
12h
💬 1
▲ 28
Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam
14h
💬 2
▲ 22
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg
22h
💬 3
▲ 44
MORE
···
R/REVERSEENGINEERING
Modern Reverse Engineering IDE Built For AI Based RE
12h
💬 0
▲ 15
From P-Code to GNN: extract binary code semantics
19h
💬 0
▲ 8
I reverse engineered an anti-detect (Stealth) browser to find out exactly how their hooks work. I wrote a detailed breakdown + detector for it.
1d
💬 0
▲ 7
MORE
···
R/HACKING
In a first, US will allow some private firms to carry out cyberattacks | TechCrunch
21h
💬 8
▲ 135
University hostel Wi-Fi is heavily restricting websites and video calls — VPNs, WARP, DoH, and DPI bypasses all fail. Is there a way around this?
23h
💬 68
▲ 67
How to access wifi only camera without the app?
1d
💬 5
▲ 9
MORE
···
R/ASKNETSEC
Palo Alto firewall malicious dns requests
1d
💬 4
▲ 8
Question the value of vpn in modern or last 15 years corporate infrastructure.
1d
💬 26
▲ 6
Best SASE platform for stopping data leaks into ChatGPT and Gemini
1d
💬 8
▲ 7
MORE
···
R/MALWARE
WhiteCobra Malware on VS Code: Cloudflare C2 to Telegram Infostealer
2d
💬 0
▲ 5
ICMP-Ghost: Fileless C2 with ICMP & DNS Tunneling in Pure x64 Assembly | Suricata Bypassed
6d
💬 0
▲ 9
R/INFOSECNEWS
RingCentral data breach exposed info of 16 million accounts
7h
💬 0
▲ 7
HACKER NEWS
💬
Google is making private AI practical with homomorphic encryption
3h
💬 69
▲ 107
💬
Covert CIA program said to be behind mysterious attacks on Galápagos boats
11h
💬 19
▲ 33
💬
GLM-5.3: Frontier coding with emergent cyber capabilities
13h
💬 477
▲ 954
💬
Rsync 3.5.0: a huge number of security fixes
16h
💬 1
▲ 22
💬
Terabytes of credentials leaked in supply-chain attack
22h
💬 1
▲ 46
MORE
···
ENTERPRISE
TECHCRUNCH SECURITY
What we know about the alleged Iranian hacks on U.S. water utilities
15min
US courts will start publishing how often the government uses spyware
5h
Flock says its new tool will help identify police abuse, but hasn’t explained how it works
21h
MORE
···
THE REGISTER SECURITY
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
1h
French tax authority admits data heist after crook touts 2M records
4h
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
6h
MORE
···
ZDNET SECURITY
Google Meet can take notes for your in-person meetings now - here's how it works
2h
I tested an Android app that lets anyone fight censorship - and shows your impact in real time
3h
Apple is warning users of new spyware attacks - what to do if you're a target
3h
MORE
···
CSO ONLINE
Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks
5h
Oracle’s new database security tool is free — for six months
6h
Akira ransomware reboots into Windows Safe Mode to knock EDR offline
10h
MORE
···
FEDERAL NEWS CYBER
BOD 26-04 isn’t a scoring upgrade. It’s an audit of whether you can actually fix things.
21h
DISA starting small in proving out Mission Partner Environment capabilities
22h
‘ICJobs:’ Intel community gets new classified jobs portal
1d
MORE
···
NEXTGOV CYBER
Trump admin empowers private US firms to go after transnational cybercriminals
1d
NIST wants to outfit the National Vulnerability Database with AI
2d
Federal systems increasingly likely to face accidental AI breach after Hugging Face, experts say
4d
MORE
···
CYBERSECURITY DIVE
Researchers confirm breach claims by data-extortion group
3h
Researchers find AI-powered hacking tools for sale in underground forums
1d
Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks
1d
MORE
···
RESEARCH
SCHNEIER ON SECURITY
Upcoming Speaking Engagements
3h
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
8h
Separating AI’s Technological Problems from Its Capitalism Problems
1d
MORE
···
ARXIV SECURITY
DCBA: Detection of Collaborative Black-Hole Attacks in Connected Dominated Set using Baiting Process
15h
The energetic cost of mitigating AI attacks in cellular networks
15h
Tracing Provenance and Detecting Tampering with Complementary LLM Watermarks
15h
MORE
···
SANS ISC
ISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)
17h
ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)
1d
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)
1d
MORE
···
MICROSOFT SECURITY
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
4d
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
4d
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
9d
MORE
···
NIST NEWS
NIST National Construction Safety Team Advisory Committee Meeting Scheduled for Sept. 23 and 24, 2026
1d
NIST Researchers Correct Common Error Confounding Nanotech Measurements
8d
‘Spooky’ Particles Transit DC Suburbs, a Step Toward a Quantum Network
9d
MORE
···
TROY HUNT
Weekly Update 516: Live From Vietnam
2d
NCSC UK
NCSC statement in response to recent incidents resulting from frontier AI evaluations
10d
AI SECURITY
SIMON WILLISON
llm-gemini 0.33
23h
DeepSeek V4 Pro 0813 (on OpenRouter)
1d
Quoting Florian Herrengt
2d
MORE
···
XBOW
Autonomous Agent Safety: Hard Scoping and Guardrails
2d
ADVERSA AI
Top MCP security resources — August 2026
8d
OFFENSIVE
SPECTEROPS
Return of the Cookie Monster
1d
Attack of The Extensions
1d
Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders
2d
MORE
···
TRUSTEDSEC
AI Offense is Not Noclip Mode
1d
A Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI
3d
The Art of Hunting Azure Cloud Secrets
8d
MDSEC
ARM64 stack internals and obfuscation on Apple Silicon
6h
0XDF
HTB: Helix
6d
HACKING ARTICLES
Impacket for Pentester: reg
9d
PRIVACY
EFF DEEPLINKS
Too Little, Too Late: Flock Admits Their Technology Needs Reforms
22h
Who (or What) Generates Images for EFF?
2d
Dismiss Church’s Trademark Lawsuit Against “Mormon Stories” Podcast, EFF Urges Court
3d
MORE
···
CITIZEN LAB
Inside the Fake Copyright Racket Silencing News Outlets
7d
Immigration Policy: The Backdoor to Transnational Repression
9d
A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology
10d
FLOCK SAFETY
5 Places Your Community May Need Better Coverage
2d
Independent Grand Jury Report Highlights Flock's Commitment to Responsible ALPR
3d
SIGNAL
Introducing Automatic Key Verification
3d
TOR PROJECT
New Release: Tails 7.10.1
9d
VENDORS
MANDIANT
$4.7T
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
8d
CISCO TALOS
$475B
Curiouser and Curiouser
1d
Dissecting the JWR phishing framework
1d
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
2d
MORE
···
UNIT 42
$228B
Kimwolf v7: An Evolution of the Kimwolf Botnet
3d
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
3d
Inside the Modern SOC: The Identity Front Door
6d
MORE
···
CROWDSTRIKE
$186B
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
3d
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
7d
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
8d
FORTINET
$101B
Multi-Functional Linux Botnet “Evooo1Bot”
1d
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
10d
CLOUDFLARE
$85B
How Cloudflare detects MCP traffic and helps secure it
6h
Secure all your internal vibe-coded applications — in one click
6h
Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal
23h
MORE
···
WIZ
$32B
Wiz on Wiz: How the Wiz FinOps Team Uses Wiz Cloud Cost
5h
Securing Data in the AI era
7h
How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
1d
MORE
···
ZSCALER
$23B
Project Glasswing and the Coming Inversion of Vulnerability Management
1d
Closing the Data Security Gap: How AHEAD Built a Full
1d
Introducing Zscaler Zero Trust Gateway for Google Cloud
1d
MORE
···
CHECK POINT RESEARCH
$14B
The State of Ransomware Q2 2026
1d
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
3d
10th August – Threat Intelligence Report
4d
SNYK
$7.4B
The Agent Baseline: 35 Controls, But Where Should You Start?
2d
Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS
4d
Continuous Offensive Security & AI Pentesting: 20 FAQs
9d
SENTINELONE
$6.2B
The Good, the Bad and the Ugly in Cybersecurity – Week 33
3h
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders
1d
From Input to Impact: Secure AI Where It Runs
10d
ELASTIC SECURITY
$5.7B
13 million tool calls: auditing every AI coding agent action with Elastic Agent
3d
Living off the coding agent: Two tales of tunnels and LaunchAgents
6d
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
7d
MORE
···
QUALYS
$3.85B
Why API Discovery Is Critical for Modern AppSec Programs
1d
Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation
1d
Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review
2d
MORE
···
TENABLE
$3.1B
Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
3d
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
7d
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
8d
MORE
···
RECORDED FUTURE
$2.65B
Malware Crypting Services and the Threat Actors Who Sell Them
1d
Mines, Minds, and Machines: The Journey of AI
3d
The Hugging Face Hack Was Cheap Persistence at Work
4d
MORE
···
EXPEL
$1B
The hidden cost of alert fatigue (and how agentic MDR fixes it)
2d
HACKERONE
$841M
How to Build a CTEM Program: A 90-Day Implementation Roadmap
23h
CTEM Metrics That Matter: What CISOs Should Report to the Board
9d
RAPID7
$440M
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
2d
Patch Tuesday - August 2026
2d
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
3d
MORE
···
KASPERSKY SECURELIST
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
10h
Armored Likho expands its cyber-espionage toolkit
1d
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
3d
MORE
···
REVERSINGLABS
AI worms are coming — and traditional controls won't stop them
1d
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
2d
Frontier AI agents: Only as safe as their containment
3d
MORE
···
OX SECURITY
Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP
4d
AI-SPM vs. ASPM (and Why AINAPP Is What Comes Next)
5d
Agentic AI Security: Risks and Best Practices for Autonomous Agents
8d
MORE
···
WELIVESECURITY
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
1d
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
1d
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
2d
MORE
···
TOOLS
ZERO DAY INITIATIVE
$4.9B
The August 2026 Security Update Review
3d
FULL DISCLOSURE
APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9
21h
APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9
21h
Dangling DNS record for bastion.certb.cdp.bethesda.net
7d
MORE
···
EXPLOIT-DB
[webapps] Apache Gravitino 1.2.1 - SSRF
3d
[webapps] Blocksy Companion 2.1.46 - RCE
3d
[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
3d
MORE
···
PORTSWIGGER RESEARCH
CRLF-Powered Desync Attacks: Beheading HTTP Streams
8d
Can AI do novel security research? Meet the HTTP Terminator
8d