18minZDNet SecurityHow I sorted 22,000 digital photos without getting overwhelmed: 4 easy tricks27minReversingLabsShai-Hulud worm arrests: What you need to know35minZDNet Security3 surveys deliver the same uncomfortable truth about adopting agentic AI50minBleepingComputer68-year-old imprisoned after making $1.3 million by pirating IPTV services57minThe RecordPaperCut warns of hackers using printer management software flaw in attacks1hNextgov CyberTrump admin moves to block risky foreign technology from US power grid1hSentinelOneThe Good, the Bad and the Ugly in Cybersecurity – Week 351hTechCrunch SecurityMore Americans oppose police license plate cameras than support them: survey1hSecurityWeekIn Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions2hZDNet SecurityThe best early Labor Day Costco deals 2026: TVs, smartwatches, Apple devices, and more2hCybersecurity DiveFrontier AI tipping the scales toward cyber adversaries2hThe Register SecurityUS government snitch-finder pleads guilty to leaking state secrets to foreign spies2hRapid7Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!2hZDNet SecurityThis Linux and Windows app makes managing all your documents easier3hTenableWhy a cryptographic inventory is key for addressing the quantum computing threat3hBleepingComputerAI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?3hDark ReadingYou Need Cyber Deception for OT3hSecurityWeekATF Confirms Cyber Incident After Ransomware Group Claims Attack3hZDNet Security91% of professionals say their firm still falls short on AI - how to fix that3hDark ReadingDefining an AI Kill Switch Is Hard, but Necessary4hZDNet SecurityI've tested dozens of robot vacuums - this new $599 Roborock has all the features I need4hInfosecurityFake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign4hDark ReadingThe Vulnpocalypse Is Repricing the Bug Bounty Economy4hCloudflareBotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agents4hBleepingComputerOver 8,300 Gitea servers vulnerable to code execution attacks4hSecurityWeekOpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems5hCybersecurity DiveCISA identifies security hurdles that led to very different results in two red-team engagements5hBleepingComputerToy-making giant Hasbro disclose data breach affecting employees5hThe Register SecurityCISA: Most exploited vulnerabilities should have been eradicated decades ago6hIndicatorBriefing: “Every woman on earth should live in fear of a camera.”6hSchneier on SecurityAI Doesn’t Mean the End of Mathematics—at Least Not Yet6hSecurityWeekTech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge6hThe Register SecurityIndustry that built the problem offers to sell you the solution6hSecurityWeekThink You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says6hBleepingComputerServiceNow warns of three max severity security vulnerabilities7hGraham CluleyShai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more7hRapid7PaperCut NG/MF Critical Zero-Day Exploited in the Wild7hCSO OnlineThe first 24 hours of an AI agent security incident7hInfosecurityWindow to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn8hBleepingComputerWindows 11 KB5120998 update released with 35 changes and fixes8hCSO OnlineBeyond compliance: Designing systems that earn customer trust8hMDSecWhen it Snows it Pours – Anatomy of a ServiceNow Red Team8hSecurityWeekPaperCut Releases Emergency Patch for Exploited Zero-Day9hThe Hacker NewsPaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions9hCSO OnlineCTEM can give your security team a contextual edge9hInfosecurityThreat Actors Abuse Cursor Agent AI to Assist Ransomware Operations10hSANS ISCSome Malicious PE Stats, (Thu, Aug 27th)11hThe Register SecurityPrint management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood13hHelp Net SecurityNew infosec products of the month: August 202613harXiv SecurityHow Do LLM Agents Actually Get the Flag? Trace-Level Provenance for Agentic Offensive Security Evaluation13harXiv SecuritySILK: Closing the Time-of-Check-to-Time-of-Use Gap in RoT-Protected AI Systems13harXiv SecurityIoMT-SecAlarmBench: A Counterfactual Benchmark for Integrity Attacks in IoMT13harXiv SecurityUnsaid, Unsafe? Implicit Security Obligations in LLM-Based RTL Code Generation13harXiv SecurityBeyond Vector Hiding: Breaking and Mitigating Shared-Direction Weight Obfuscation in TEE-Offloaded Large Language Models13harXiv SecurityKubeCap: A Framework for Capability Minimization in Kubernetes via Static Analysis and LLM-Assisted Rule Inference13hEFF DeeplinksEFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity13hThe Register SecurityAustralian cops cuff alleged TeamPCP masterminds15hSANS ISCISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)17hTLDR InfoSecCyber Agent VM Escapes 🤖, Medical Device Disruptions 🩺, Redact Local Agent Secrets 🤐18hSimon WillisonBreaking Claude Code Opus 5 Auto Mode19hFederal News CyberArmy overhauls software acquisition to speed delivery20hThe Register SecurityCRPx0 hacking service for dummies claims victim count more than quintupled21hExpelThe AI CVE exploitation evidence story: Headlines are scarier than reality21hThe RecordWhite House bans foreign-made equipment for power generation over cyber backdoor concerns21hFederal News CyberGetting help to disaster survivors takes more than good weather forecasts21hDark ReadingChinese Routers Sold Worldwide Contain Backdoors22hCyberScoopUnit 42 warns AI has shifted balance of power from defenders to attackers22hCyberScoop100-plus companies call for ‘global surge’ in AI-powered cyber defense23hCisco Talos“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend23hTechCrunch SecurityATF declares ‘major incident’ as ransomware gang claims hack23hQualysPCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 202623hSpecterOpsWhy SpecterOps Signed OpenAI’s Call for Collective Cyber Defense1dDark ReadingAgentic AI Risks, CVE Program Concerns Permeate Black Hat USA 20261dCyberScoopFormer sexual abuse victims say Grok used their images, videos to train deepfake capabilities1dCloudflareHow we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache1dWizInside 90 days of attacks on AI infrastructure1dZscalerIt No Longer Takes an Expert to Attack a Factory1dReversingLabsExtend CrowdStrike Falcon with Permanent Intelligence1dMicrosoft SecurityWhat’s new in Microsoft Security: August 20261dGitHub SecurityOpenClaw went viral. Meet the maintainers building and securing it.1dSpecterOpsCleartext Credential Recovery in ServiceNow1dWizFrom Concept to Context Engine: How Wiz Built AI-Powered Data Discovery1dCybersecurity DiveHundreds of agents went rogue in lead up to Hugging Face breach1dThe RecordFinland appeals court revives case against Eagle S Officers over cable breaks1dThe Hacker NewsNext.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE1dThe RecordChinese and Russian spies stepping up cyberattacks, German companies report1dTenableHow to build an exposure management program the business trusts: Lessons from Tenable’s CSO1dTechCrunch SecurityAustralian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others1dXBOWContinuous Attack Surface Testing vs Penetration Testing: Key Differences1dNextgov CyberATF investigating ‘major’ cyber incident after ransomware group claim1dTechCrunch SecurityHere’s all the times AI has gone rogue and hacked other companies1dHelp Net SecurityTwo alleged TeamPCP hackers arrested over global supply chain attacks1dRapid7Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs1dThe Hacker NewsAmazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers1dThe RecordCyberattack on Manchester Airports Group exposes data of 8.7 million customers1dInfosecurityManchester Airports Group Hit by Cyber Incident1dCybersecurity DiveFederal authorities disrupt China-backed hacking operation targeting US critical infrastructure1dNCSC UKDisruptive cyber activity highlights risk from internet-exposed systems and edge devices1dXBOWSuperhuman: Continuous Security Testing at Release Speed1dWizVersion Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps1dInfosecurityChinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns1dCSO OnlineAI can be made to read an email much differently than you do1dDark ReadingRussian Hackers Phish EU Officials Over Messaging Apps1dThe Hacker NewsSpark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools1dInfosecurityCISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products1dKaspersky SecurelistThreat landscape for industrial automation systems. Q2 20261dCisco TalosJavaScript obfuscation: From party trick to phishing kit1dSANS ISCA polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)1dSchneier on SecurityLLM-Based Social Engineering Scams1dGraham CluleyUS Navy tells sailors and their families: scrub your social media, enemies are watching1dWeLiveSecurityAI-assisted reconnaissance: Why everyone could be a viable target for fraud1dCSO OnlineCritical infrastructure’s long, undefended tail exposed by UK energy attack1dSANS ISCISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)1dZscalerZscaler WebMCP Security Controls: Bringing Zero Trust to the Agentic Web1dSophosA call for collective action on cyber defense1dRecorded FutureBlueDelta Targets Defense and Diplomacy with HOOKEDGE1dTor ProjectNew Alpha Release: Tor Browser 16.0a101dTLDR InfoSecCritical Ubiquti Vulnerabilities 🛜, Security Needs a New Control Plane 🤖, Debunking Carhartt Breach Claims 👕1dSophosThe State of Ransomware in Education 20261dXBOWElliot Hyun (현종석)1dSimon WillisonQwen3.8-Flash-Next1dGraham CluleySmashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency1dZscalerHuman + AI: How Our Product Managers Innovate with AI1dCyberScoopCyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure1dEFF DeeplinksA List of ICE Subpoenas to Tech Companies1dExpelMapping AI detections to MITRE ATLAS: How Expel does it1dCyberScoopOfficials disrupt Chinese espionage operation that hit multiple federal agencies1dXBOWNOAuth, No Problem: Authentication in Security Testing1dCyberScoopOpenAI: Agent behavior that led to Hugging Face intrusion formed in May1dTechCrunch SecurityMedical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations1dNextgov CyberWhite House to soon launch water provider cyber protection program1dEFF DeeplinksEFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms2dFederal News CyberCommercial aviation depends on a growing network of connected systems. GAO found gaps in cybersecurity.2dZscalerWhat to Look for in a Deception Technology Solution2dTechCrunch SecurityUS seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate2dFull DisclosureFD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)2dFull Disclosure[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File2dFull Disclosure[NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Records2dFull Disclosure[NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service2dFull Disclosure[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM2dFull Disclosure[NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Write2dMicrosoft SecurityWhen AI infrastructure becomes the target: Securing gateways and control points2dThe Hacker NewsFBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations2dEFF DeeplinksEFF Statement on Meta Settlement2dNextgov CyberFBI disables China-linked hacking tools used against US agencies2dWizDemocratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service Catalog2dSANS ISCWho Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)2dWizThe State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities2dQualysBeyond Patching: What IT Teams Need to Know About Unpatchable Exposures2dReversingLabsInfostealers highlight malware-as-a-service trend2dQualysWhen an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion2dEFF DeeplinksFrench Top Court Gets It Right, Strikes Down Social Media Ban For Youths2dCybersecurity DiveBoston Scientific says cyberattack disrupted order processing, shipping2dThe Hacker NewsCISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing2dTenableEdge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter2dSchneier on SecuritySpyware for Babies2dXBOWXBOW Product Demo: How to Run an Autonomous Penetration Test2dCybersecurity DiveTreasury to help financial firms transition to quantum-resistant encryption2dCSO OnlineNemoClaw’s AI can be poisoned through a browser tab2dIndicatorAI-generated Costco employees got over 100 million views on Facebook and Instagram2dHelp Net SecurityCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)2dCisco TalosChoose your fighter: Balancing competing requirements to select models for your AI SOC2dKaspersky SecurelistExploits and vulnerabilities in Q2 20262dZscalerWhat’s New in GovCloud: August 2026 Zscaler Product Updates2dSimon WillisonQuoting Paul Dix2dHelp Net SecurityMeta adds three new features to keep WhatsApp accounts secure2dHelp Net SecurityAI vulnerability discovery scores the highest impact of 20 emerging risks2dSnykWhy Your AI Application Is Exposed Snyk2dSANS ISCISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)2dRecorded FutureRecorded Future Launches AI Alert Filtering2dTLDR InfoSecCritical Keycloak ATO 🔑, AI Bug Bounty Hunter 🐞, Global Telecom Exploitation 📞2dFederal News CyberArmy moves cloud management under its Cyber Command2dTroy HuntA Cautionary Tale About Data Breach Claims, Verification and Carhartt2dZscalerZero Trust or Bust: Winning Compliance in an AI-Driven Multicloud World2dFederal News CyberCISA wants agencies to maximize ‘insight’ from cyber data logging3dMicrosoft SecurityThe patch window is collapsing: Why security needs a new control plane3dReversingLabsAgentic AI scales semiautonomous server attacks3dNextgov CyberTreasury sanctions Iranian hackers tied to critical infrastructure breaches3dSentinelOneThe Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity3dPortSwigger ResearchWhat's in a tag name? JavaScript, apparently3dHelp Net SecurityINTERPOL crackdown on West African crime rings uncovers troubling new trend3dSchneier on SecurityBlack Hat State of Security Vendors3dUnit 42The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution3dCisco TalosThe safety penalty: Reclaiming operational sovereignty in the age of AI3dOX SecurityClickFix Phishing Pages Discovered in 24 npm Packages3dIndicatorOSINT Tool Radar: 14 new and 72 updated3dAdversa AIOWASP Agentic Skills Top 10 explained: the ten agent skill risks, and which to fix first3dTrustedSecSpooNMAP Grows Up: Findings, Local LLM Detection, and a Whole Lot Less Waiting3dQualysCVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days3dElastic SecurityInside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy3dExploit-DB[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE3dSophosSophos Ranked #1 Overall in Endpoint, XDR, MDR, and Firewall in the G2 Fall 2026 Reports3dRecorded FutureMexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense3dTLDR InfoSecDoes Plan Mode Help Code Security 📝, OWASP Agent Skills Top 10 🔟, Bypassing macOS SIP 🍎3dFederal News CyberGSA, Treasury kick off post-quantum initiatives to protect against cyber threats3dNextgov CyberTreasury launches task force to prepare financial sector for quantum cyber threats3dCloudflareThe Cloudflare Blog – Brought to you by EmDash4dRapid7Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)4dGraham CluleyMalicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials4dCheck Point Research24th August – Threat Intelligence Report4dGraham CluleyGunra ransomware: what you need to know4dNIST NewsNIST Researchers Supersize Quantum Technology to Help Detect Faint Photons4dXBOWThreat Hunting with AI & Autonomous Pentesting4dIndicatorThe Indicator guide to vibecoding for OSINT4dSchneier on SecurityCriminal Deception in Silicon Valley4dExpelNew Ruxie AI power-up: Meet RTA, the AI agent bringing self-challenging logic to identity and cloud alert triage4dTroy HuntWeekly Update 518: IoT Doorlock Nirvana with UniFi4dFlock SafetyIndependent Study: Vehicle Thefts Fell 11% After Flock Cameras Went Live4dElastic SecurityHow a team of entity maintainers monitors, connects and scores entities in Elastic Security4dTLDR InfoSecAnthropic Expands Defender Access to Mythos 🛡️, Leaked AWS Keys 🔑, Auditing AI Coding Agent Actions 🤖4dSimon WillisonAnthropic’s best AI model struggles to attract users as cheaper tools thrive4dSimon WillisonQuoting Drew Breunig5dTroy HuntWelcoming the Sri Lankan Government to Have I Been Pwned5dSimon WillisonQuoting Linus Torvalds6dCloudflareSay it once: introducing Bot Preference Sync6dUnit 42Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain6dSchneier on SecurityFriday Squid Blogging: Neon Flying Squid7dEFF DeeplinksEFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition7dIndicatorBriefing: New web search tools to cut through the slop7dKaspersky SecurelistThe invisible passenger in your car7dFlock SafetyBuilding on Trust: Updates to Flock’s Terms and Conditions7dTLDR InfoSecGLM-5.3 Release 🤖, Hacking SAML 👾, Hunting Malware in K8S Memory ⚓️7dExpelSynkLoader: when you throw in everything but the kitchen sink7dCisco TalosIs Cyber missing the Marque?7dCitizen Lab‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert8dCloudflareFrom all-or-nothing to task-based OAuth consent8dWizRust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns8dHackerOneCIRCIA Cyber Incident Reporting: HackerOne's Recommendations8dTenableFrequently asked questions about the active threat to Siemens S7 Series PLCs8dMandiantGoing with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia8dCheck Point ResearchBTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive8dCisco TalosUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities8dUnit 42Identity Abuse Through Trusted Communication Channels8dAdversa AIZero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories8dCrowdStrikeCrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms8dDatadog Security LabsN4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it8dGraham CluleySmashing Security podcast #481: Never say this to a robot dog8dMicrosoft SecurityMicrosoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 20269dRapid7CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway9dCloudflareA revisit of remote Spectre attacks on Cloudflare Workers9dSpecterOpsAWSHound: An OpenSource AWS OpenGraph Collector9dReversingLabsWhy shadow AI is far riskier than shadow IT9dReversingLabsWhy software delivery cannot depend on trust alone9dOX SecurityPBOM vs SBOM: What’s the Difference, and Why Does It Matter in 2026?9dQualysOracle Critical Patch Update, August 2026 Security Update Review9dRapid7Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America9dIndicatorShow & Tell: How WSJ reporters caught Polymarket faking its own site9dCrowdStrikeBenchmaxxing: When the Benchmark Becomes the Target9dTenableOracle August 2026 Critical Security Patch Update Addresses 925 CVEs9dTor ProjectNew Release: Tails 7.119dSnykRemediation Agents, Demystified: Why Fixing Beats Finding9dDatadog Security LabsPutting models to the secure coding test: Plan vs default mode9dSophosFake AI, real malware: Attackers impersonating AI brands9dRecorded FutureRecorded Future Launches 6 New Capabilities for Third-Party Risk9dExpelNew Ruxie AI power-up: Phishing classification AI turns benign inbox noise into SOC focus9dHackerOneBoard Cybersecurity Accountability: What NIS2 Requires9dUnit 42Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)9dQualysCVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now10dMicrosoft SecurityHunting MacSync Stealer infrastructure through behavioral pivots10dOX SecurityCritical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive10dOX SecurityCritical vm2 Vulnerability Allows Host DNS Hijacking and Information Disclosure10dMandiantStaying Ahead of Adversarial AI Through Agentic Source Code Review10dCheck Point ResearchThousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect10dAdversa AITop 10 zero-click attacks against AI agents10dTrustedSecWe've Seen This Movie: The OT/IT Technology Divide10dSnykBenchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%10dTroy HuntWeekly Update 517: Cyber Ransoms10dExploit-DB[remote] PCMan 2.0.7 - Buffer Overflow10dTor ProjectNew Release: Tor Browser 15.0.2010dExploit-DB[dos] NanaZip 6.5 - DoS10dExploit-DB[webapps] flyto-core 2.26.7 - Arbitrary File Write10dRecorded FuturePurpleDelta's Fraudulent Employment Operations10dExploit-DB[webapps] Nodemailer 9.0.0 - File Read/ SSRF10dRecorded FutureCopyCop Targets AI Investment in Armenia10dExploit-DB[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF10dCitizen LabCall for Applications: Information Controls Research Program 202611dTenableDetecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities11dCheck Point Research17th August – Threat Intelligence Report11dWeLiveSecurityHow QR-code phishing can slip past corporate security measures11dCrowdStrikeTeaching AI to Reason Through Detection Triage11dEmbrace The RedRecovering Encrypted LLM Reasoning Traces11dTor ProjectFunding internet freedom together: results from our first participatory funding round11dSophosA heap of overflow in August’s Patch Tuesday haul11dSophosHunting the Undead: Accelerating NetNTLMv1 Lookups Without GPUs12dProjectDiscoverySupply Chain Security Analysis of a 9.5M-Install VS Code Extension13d0xdfHTB: Cobblestone13dHacking ArticlesImpacket for Pentester: SMBExec14dMDSecARM64 stack internals and obfuscation on Apple Silicon14dKrebs on SecurityWho’s Tracking You? Use This New Service to Find Out14dKaspersky SecurelistAPT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit14dExpelPatch Tuesday: August 2026 (Expel’s version)15dSpecterOpsReturn of the Cookie Monster15dSpecterOpsAttack of The Extensions15dWeLiveSecurityBlack Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?15dSentinelOneThe Model Is the Malware | What Four Agentic Intrusions Tell Defenders15dCheck Point ResearchThe State of Ransomware Q2 202615dNIST NewsNIST National Construction Safety Team Advisory Committee Meeting Scheduled for Sept. 23 and 24, 202615dWeLiveSecurityBlack Hat USA 2026: What the Hugging Face hack tells us about human responsibility15dKaspersky SecurelistArmored Likho expands its cyber-espionage toolkit15dHackerOneHow to Build a CTEM Program: A 90-Day Implementation Roadmap15dTrustedSecAI Offense is Not Noclip Mode15dFlock SafetyFlock Updates Privacy, Accountability, Security, and Transparency Safeguards16dSpecterOpsBlacklight: Illuminating AI Agent Artifacts for Attackers and Defenders16dWeLiveSecurityBlack Hat USA 2026: AI is racing ahead of cybersecurity controls16dTroy HuntWeekly Update 516: Live From Vietnam16dSnykThe Agent Baseline: 35 Controls, But Where Should You Start?16dFlock Safety5 Places Your Community May Need Better Coverage16dKrebs on SecurityMicrosoft Plugs Nearly 400 Security Holes16dZero Day InitiativeThe August 2026 Security Update Review16dCheck Point ResearchShattering the Dream – When a Job Offer Becomes a Zero-Day Attack17dKaspersky SecurelistHead Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants17dUnit 42Kimwolf v7: An Evolution of the Kimwolf Botnet17dCrowdStrikeAugust 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs17dTrustedSecA Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI17dSignalIntroducing Automatic Key Verification17dElastic Security13 million tool calls: auditing every AI coding agent action with Elastic Agent17dFlock SafetyIndependent Grand Jury Report Highlights Flock's Commitment to Responsible ALPR17dUnit 42The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications18dMicrosoft SecurityMicrosoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise18dWeLiveSecurityAre AI tutors safe for your kids?18dSnykShow, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS18dOX SecurityShai-Hulud Outbreak Debrief: The Worm Evolves into MCP20d0xdfHTB: Helix21dCitizen LabInside the Fake Copyright Racket Silencing News Outlets21dCrowdStrikeCrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX21dElastic SecurityThe security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent21dPortSwigger ResearchCSS:the bomb inside your inbox22dKrebs on SecurityCanadian Man Pleads Guilty in Snowflake Extortions22dMandiantUNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments22dAdversa AITop MCP security resources — August 202622dNIST NewsNIST Researchers Correct Common Error Confounding Nanotech Measurements22dOX SecurityDid We Just Witness Step One of the Autonomous AI Arms Race?22dCrowdStrikeExpanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery22dTrustedSecThe Art of Hunting Azure Cloud Secrets22dPortSwigger ResearchCRLF-Powered Desync Attacks: Beheading HTTP Streams22dPortSwigger ResearchCan AI do novel security research? Meet the HTTP Terminator22dHacking ArticlesImpacket for Pentester: reg23dCitizen LabImmigration Policy: The Backdoor to Transnational Repression23dNIST News‘Spooky’ Particles Transit DC Suburbs, a Step Toward a Quantum Network23dHackerOneCTEM Metrics That Matter: What CISOs Should Report to the Board23dSnykContinuous Offensive Security & AI Pentesting: 20 FAQs23dTor ProjectNew Release: Tails 7.10.123dCitizen LabA Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology24dSentinelOneFrom Input to Impact: Secure AI Where It Runs24dNCSC UKNCSC statement in response to recent incidents resulting from frontier AI evaluations24dNIST NewsNIST Joins National Genesis Mission to Accelerate AI Innovation24dAdversa AINine AI coding agent incidents that ended with deleted data24dTrustedSecTLS Encryption and Compliance24dSignalMore linked devices are on the table (and the Android tablet)24dDatadog Security LabsWorm compromises hundreds of popular npm packages24dElastic SecurityAgents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human24dTor ProjectArti 2.5.1 released24dFlock SafetyFlock LPR vs. Fixed Video: Same Camera Body, Two Different Jobs25dProjectDiscoveryWatching Agents Work: A Behavioral Audit of Offensive-Security LLM Runs25dEmbrace The RedLLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection25dAdversa AITop AI Coding Agent security resources — August 202625dBitdefenderFake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums25dTroy HuntWelcoming the Nepalese Government to Have I Been Pwned25dDatadog Security LabsBefore the first prompt: Code execution paths in trusted coding-agent projects25dElastic SecuritySOC case management and detection rule history in Elastic Security27d0xdfHTB: Kobold27dHacking ArticlesImpacket for Pentester: atexec27dHacking ArticlesActive Directory Enumeration with BloodHound-Python27dHacking ArticlesArsenal-NG: A Terminal Cheat-Sheet Launcher for Faster Penetration Testing27dArs Technica SecurityClaude published malicious code to the Internet and attacked 3 real companies27dCitizen LabKate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime Convention28dArs Technica SecurityChrome may get faster updates with no restart required29dKrebs on SecurityRead This Before You Buy That TV Streaming Stick29dEmbrace The RedEscaping Linux Sandboxes via PipeWire (CVE-2026-5674)29dZero Day InitiativeThe July 2026 Apple Security Update Review29dMandiantBatten Down Your Packages: Mitigation Guidance for Supply Chain Compromise29dHackerOneVulnerability Prioritization in the Age of AI Attack Chains1moGitHub SecurityDisrupting supply chain attacks on npm and GitHub Actions1moThe MarkupBrazil gives parents social media controls for their kids. Should the US?1moArs Technica SecurityMicrosoft unveils AI security tools it says outperform competing platforms1moDatadog Security LabsDetection primitives for eBPF rootkits1mo0xdfHTB: Fries1moMandiantUpdated Cyber Threat Actor Naming System1moArs Technica SecurityForgot your Google password? Now you can log in with a selfie.1moNCSC UKUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations1moProjectDiscoveryOh My Rogue Agent1moSentinelOneSol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?1moGitHub SecurityNext chapter: Restructuring GitHub’s bug bounty program1moSentinelOneFrom Triage Grind to Strategic Operator: The New AI SOC Career Path1moNIST NewsNIST Announces Funding Opportunity for 14 MEP Centers to Advance Small and Medium-Sized U.S. Manufacturers1moKrebs on SecurityLG to Ban Residential Proxies from Smart TV Apps1moProjectDiscoveryIntroducing Internal Network Scanning: see your network the way an attacker inside it would1moZero Day InitiativePwn2Own Ireland 2026 – New Targets and Categories1moHacking ArticlesWindows Privilege Escalation: SeRestorePrivilege1moEmbrace The RedAutonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise1mo0xdfHTB: Logging1moMandiantDemystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management1moEmbrace The RedFrom Indirect Prompt Injection to DNS Exfiltration in macOS Terminal1moKrebs on SecurityMicrosoft Patches a Record 570 Security Flaws1moZero Day InitiativeThe July 2026 Security Update Review1mo0xdfHTB: Orion1moDatadog Security LabsCompromised AsyncAPI npm packages: inside a CI supply-chain attack1moNCSC UKUK and Allies urge critical sectors to improve defences against Russian intelligence targeting1moProjectDiscoveryCommunity Spotlight: Rishi (@rxerium)1moPraetorianBluetooth Low Energy Security Testing, Consolidated: Introducing Caeruleus1moZero Day InitiativeCVE-2026-47291: Remote Code Execution in the Windows HTTP.sys1moMDSecDell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)1moThe MarkupKaiser Permanente nurses say technology is making their jobs — and patient care — worse1moPraetorianFreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 2 of 2)1moPraetorianKnossos: Procedurally Generated Decoy Environments1moThe MarkupCalifornians can protect their personal data with one click. Help us test if it works2moGitHub SecurityInside the Advisory Database and what happens when vulnerability volume breaks records2moEmbrace The RedComputer-Use and TOCTOU: What You Click Is Not What You Get!2moBitdefenderFake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams2moNCSC UKThe AI shift in cyber risk: why leaders must act now2moPraetorianGhostPack Necromancy: Reforging C# Tools with WasmForge2moProjectDiscoveryThe Vulnerability Curve Bent With the AI Curve2moNCSC UKAlert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways2moDoyensecIntroducing Session Switcher. Swap Burp Sessions with One Click!2moPraetorianSharing is Caring: SMB Secret Scanning with Sulla2moThe MarkupYour medical provider might be recording your mental health care visits2moHackerOneCTEM2moBitdefenderInside APAC's malvertising ecosystem: How scams spread through social media ads