52minBleepingComputerHackers arrested over €30M bank fraud exploiting service provider flaw1hThe Register Security1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack1hDark ReadingAmid AI-Driven Bug Tsunami, NIST Looks to…AI2hZDNet SecurityGoogle Meet can take notes for your in-person meetings now - here's how it works2hZDNet SecurityI tested an Android app that lets anyone fight censorship - and shows your impact in real time2hZDNet SecurityApple is warning users of new spyware attacks - what to do if you're a target2hSchneier on SecurityUpcoming Speaking Engagements2hZDNet SecurityChatGPT's new Computer History tracks your Mac activity to create a timeline - but should you let it?2hZDNet SecurityDell XPS 13 review: The first budget laptop to rival Neo raises the bar for all PCs2hDark ReadingScottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office3hCybersecurity DiveResearchers confirm breach claims by data-extortion group3hSentinelOneThe Good, the Bad and the Ugly in Cybersecurity – Week 333hBleepingComputerHackers exploit macOS Screen Sharing flaw to deploy Monero miner4hInfosecurityResearchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations4hThe Register SecurityFrench tax authority admits data heist after crook touts 2M records4hWizWiz on Wiz: How the Wiz FinOps Team Uses Wiz Cloud Cost4hBleepingComputerThe Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI4hDark ReadingWhat Boards Need to Know About Tech Risk5hBleepingComputerMax severity SAP Commerce Cloud flaw now targeted in attacks5hCSO OnlineSalesforce, ServiceNow data targeted in ‘City-Forum’ attacks5hTechCrunch SecurityUS courts will start publishing how often the government uses spyware5hThe RecordFrance investigates tax authority breach after hacker claims 600,000 victims5hCloudflareHow Cloudflare detects MCP traffic and helps secure it5hCSO OnlineOracle’s new database security tool is free — for six months5hThe Register SecurityAutonomous AI attacks pose 'clear and present danger' to critical infrastructure5hInfosecurityNew Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies5hCloudflareSecure all your internal vibe-coded applications — in one click6hMDSecARM64 stack internals and obfuscation on Apple Silicon6hWizSecuring Data in the AI era6hDark ReadingCyera's Oasis Security Buy Is All About AI Agent Control6hSecurityWeekIn Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities7hBleepingComputerShell investigates 'potential incident' after Clop data theft claims7hZDNet SecurityI used OpenFactory to build my own Linux distro overnight - this AI tool is going to be big7hSecurityWeekTrivy, Not LiteLLM Behind the 2,500 Org Compromise7hKrebs on SecurityWho’s Tracking You? Use This New Service to Find Out7hSchneier on SecurityIf the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them7hSecurityWeekGoogle Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal8hBleepingComputerRingCentral data breach exposed info of 1.6 million accounts8hInfosecurityNovel macOS Infostealer AmnesiaStealer Spread via ClickFix8hIndicatorBriefing: US backtracks on company ownership transparency8hThe Register SecurityCrypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach8hSecurityWeek1.6 Million Likely Impacted by RingCentral Data Breach9hSecurityWeekOver 1,000 Charities Hit by Beacon CRM Data Breach9hCSO OnlineAkira ransomware reboots into Windows Safe Mode to knock EDR offline9hKaspersky SecurelistAPT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit9hCSO OnlineThe cybersecurity backlog is not a security problem10hThe Register SecurityScottish prosecutors cast eye over leaky supplier after staff data exposed10hBleepingComputerData analyst sent to prison for stealing data, extorting employer10hCSO OnlineHow CSOs can turn cybersecurity into a business growth strategy10hSecurityWeek14,000 Trezor Customers Impacted by Data Breach at ShipMonk11hInfosecurityResearchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations11hSecurityWeekHackers Exploiting Unpatched GeoServer Zero-Day12hSecurityWeekAmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions13hHelp Net SecurityThe hardest part of agentic AI may be rebuilding the business14hHelp Net SecurityNew infosec products of the week: August 14, 202614harXiv SecurityDCBA: Detection of Collaborative Black-Hole Attacks in Connected Dominated Set using Baiting Process14harXiv SecurityThe energetic cost of mitigating AI attacks in cellular networks14harXiv SecurityTracing Provenance and Detecting Tampering with Complementary LLM Watermarks14harXiv SecurityDiscovering Persistent Behavioural Patterns for Interpretable Blockchain Forensics14harXiv SecurityAdversarial Robustness in Smishing Detection: A Comparative Analysis of Adversarial Fragility in Classical vs. Transformer-Based Detection Systems14harXiv SecurityBeyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents14harXiv SecurityATOBench: Tracing How Autonomous Penetration-Testing Agents Verify Vulnerabilities When Target Evidence Lies14harXiv SecurityInterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents14harXiv SecurityOperationalizing Cyber Threat Intelligence with GraphRAG14harXiv SecurityA Commitment-Based Hybrid Post-Quantum Cryptographic Model for Multi-File Cloud Storage15hThe Register SecurityNew Zealand says China tried using space investments to spy on local affairs16hCSO Online5 key takeaways from Black Hat USA 202616hSANS ISCISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)18hThe Register SecurityOpenAI ditches Recall-style screenshot surveillance for friendly keylogging18hZDNet SecurityThis free Android assistant fixes my biggest Gemini frustration - and keeps my data private18hTLDR InfoSecAttacks Target Salesforce and ServiceNow 🚨, VMware vCenter RCE Flaw 🖥️, Trezor data breach 💿20hCyberScoopA bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.20hTechCrunch SecurityFlock says its new tool will help identify police abuse, but hasn’t explained how it works20hCyberScoopTech contractor for Brightly Software sentenced to 2 years in prison for insider attack21hFull DisclosureAPPLE-SA-08-06-2026-2 macOS Sequoia 15.7.921hFull DisclosureAPPLE-SA-08-06-2026-3 macOS Sonoma 14.8.921hTechCrunch SecurityIf Apple sends you a push notification alerting you to a spyware attack, take it seriously21hFederal News CyberBOD 26-04 isn’t a scoring upgrade. It’s an audit of whether you can actually fix things.21hBleepingComputerUkraine shuts down 94 fraudulent call centers, seize millions in cash22hEFF DeeplinksToo Little, Too Late: Flock Admits Their Technology Needs Reforms22hFederal News CyberDISA starting small in proving out Mission Partner Environment capabilities22hBleepingComputerAkira hackers disable EDR with Safe Mode, steal data but fail to encrypt22hZDNet SecurityI tried the new ChatGPT Desktop App for Linux - but I'll stick to my browser for now22hDark ReadingGlobal Threat Campaign Hits Critical VMware vCenter Flaw22hCSO OnlineAttackers target zero-day vulnerability in geospatial data platform GeoServer22hCloudflareTotal eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal23hSimon Willisonllm-gemini 0.3323hHackerOneHow to Build a CTEM Program: A 90-Day Implementation Roadmap1dThe Hacker NewsUnpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE1dTechCrunch SecurityAnthropic set AI agents loose on the same task. They started a turf war.1dBleepingComputerHackers breach govt webmail while running parallel crypto fraud1dCisco TalosCuriouser and Curiouser1dZDNet SecurityGemini voice calling on Android Auto keeps failing me - and Google has until September to fix it1dQualysWhy API Discovery Is Critical for Modern AppSec Programs1dCyberScoopAI’s ‘middle class’ has gotten dramatically better at hacking1dThe RecordFlock tightens privacy controls amid scandals over officer abuse1dNextgov CyberTrump admin empowers private US firms to go after transnational cybercriminals1dZscalerProject Glasswing and the Coming Inversion of Vulnerability Management1dZDNet SecurityThis Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on sale1dSpecterOpsReturn of the Cookie Monster1dSpecterOpsAttack of The Extensions1dThe RecordNew Mirai variant adds stealth capabilities to notorious botnet code1dInfosecurityExposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities1dCybersecurity DiveResearchers find AI-powered hacking tools for sale in underground forums1dWizHow to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign1dThe Register SecurityTrump wants to grant private cyber firms a license to hack back1dZscalerClosing the Data Security Gap: How AHEAD Built a Full1dInfosecurityGoogle Cloud Targets 2027 for First Major Post-Quantum Security Milestone1dThe Register SecurityThe backup Microsoft never promised you1dReversingLabsAI worms are coming — and traditional controls won't stop them1dCybersecurity DiveCisco security revenue jumps 14% as agentic AI sharpens cyberattacks1dSecurityWeekCybersecurity M&A Roundup: 21 Deals Announced in July 20261dWeLiveSecurityBlack Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?1dSecurityWeekAdobe Commerce Bug Targeted Immediately After Disclosure1dInfosecurityvCenter Flaw Exploited Just Five Days After Disclosure1dWizClosing the Blind Spot: Securing Personal Repositories in the Software Supply Chain1dThe RecordBrazil orders Discord to suspend livestreaming after teen suicide1dThe RecordTrump taps cyber firms to go on offensive against criminals1dCSO OnlineAI agents wage near-autonomous cyberattack on Asian government networks1dSentinelOneThe Model Is the Malware | What Four Agentic Intrusions Tell Defenders1dFortinetMulti-Functional Linux Botnet “Evooo1Bot”1dCloudflareCertificate Transparency Monitoring is now generally available1dCheck Point ResearchThe State of Ransomware Q2 20261dInfosecurityTrump Authorizes Private Sector Participation in Offensive Cyber Operations1dCSO OnlineTrump administration opens door to private-sector cyber offensives1dCSO OnlineIt took $58 to break Microsoft’s SCCM, but a patch made it harder1dNIST NewsNIST National Construction Safety Team Advisory Committee Meeting Scheduled for Sept. 23 and 24, 20261dThe Register SecurityAWS key exposed in JavaScript may have lit way to Beacon's charity data1dSchneier on SecuritySeparating AI’s Technological Problems from Its Capitalism Problems1dHelp Net Security153GB of stolen credentials surface after LiteLLM supply chain attack1dCisco TalosDissecting the JWR phishing framework1dDark Reading'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft1dInfosecurityAkira Affiliate Crashes Ransomware After Attempting EDR Evasion1dWeLiveSecurityBlack Hat USA 2026: What the Hugging Face hack tells us about human responsibility1dInfosecurityICO Reprimands Criminal Records Office After 2023 Breach1dKaspersky SecurelistArmored Likho expands its cyber-espionage toolkit1dDark ReadingBelgium's eID Authentication Opens Citizen Accounts to RCE1dHelp Net SecurityDDoS attacks hit record scale as 1 Tbps+ campaigns become more common1dTrustedSecAI Offense is Not Noclip Mode1dZscalerIntroducing Zscaler Zero Trust Gateway for Google Cloud1dSANS ISCISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)1dSANS ISCUsing Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)1dTLDR InfoSecCeva Cyberattack 💻, LiteLLM Supply Chain attack ⛓️💥, Kimwolf botnet 🤖1dRecorded FutureMalware Crypting Services and the Threat Actors Who Sell Them1dSimon WillisonDeepSeek V4 Pro 0813 (on OpenRouter)1dGraham CluleySmashing Security podcast #480: This is the AI service you should never sign up to1dFederal News Cyber‘ICJobs:’ Intel community gets new classified jobs portal1dFederal News CyberThe missing component of government AI deployment: Trust1dDark ReadingLong-running Data Theft Campaign Targeting Salesforce, ServiceNow1dQualysQualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation2dNextgov CyberNIST wants to outfit the National Vulnerability Database with AI2dZscalerHow Eaton Secured 100+ Manufacturing Facilities with Zscaler2dTechCrunch SecurityUber Freight reportedly investigating after hacking group claims data breach2dCyberScoopResearchers observe first ‘near-autonomous’ AI attack on government target in Taiwan2dDark ReadingWalmart Takes a 'Trusted Agent' Approach to Purple Teaming2dSpecterOpsBlacklight: Illuminating AI Agent Artifacts for Attackers and Defenders2dZscalerHow an Unexpected Pivot Led to a Career at Zscaler2dExpelThe hidden cost of alert fatigue (and how agentic MDR fixes it)2dTechCrunch SecurityAfter Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug2dSimon WillisonQuoting Florian Herrengt2dCybersecurity DiveHackers abuse AI models to find new entry paths2dReversingLabsOWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise2dCybersecurity DiveCisco says software vulnerability could let hackers crash firewalls2dSANS ISCLinux Kernel Process Accounting, (Wed, Aug 12th)2dDark ReadingRansomware Hits Colombian Justice Ministry Days Before Presidential Transition2dHelp Net SecurityA stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months2dWeLiveSecurityBlack Hat USA 2026: AI is racing ahead of cybersecurity controls2dRapid7AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?2dXBOWAutonomous Agent Safety: Hard Scoping and Guardrails2dIndicatorAI generators are now required to offer detection tools. We tested them (and they need work)2dSchneier on SecurityPrompt Injections for Defense2dHelp Net SecurityMicrosoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)2dThe Hacker NewsAttackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access2dTroy HuntWeekly Update 516: Live From Vietnam2dThe Hacker NewsMalicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations2dThe Hacker NewsCisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS2dSnykThe Agent Baseline: 35 Controls, But Where Should You Start?2dSANS ISCISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)2dCyberScoopKimwolf botnet rebuilt to survive takedowns, researchers say2dFlock Safety5 Places Your Community May Need Better Coverage2dTLDR InfoSecSharePoint AI Exploit 🤖, Zoom "Zoomsday" RCE 📹, Project CAV3RN C2 🦇2dSimon WillisonThere are no lossless transformations of natural-language text2dCyberScoopFederal judge issues second order blocking Trump mail-in voting directive2dSimon WillisonStealing Reasoning Traces from Proprietary LLM APIs2dCisco TalosMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities2dZscalerCaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials2dFederal News CyberFour things agencies need to get right before AI outpaces their security programs2dQualysMicrosoft and Adobe Patch Tuesday, August 2026 Security Update Review2dZscalerTracking Shai-Hulud: Inside the ChainDrop NPM Worm2dRapid7Patch Tuesday - August 20262dEFF DeeplinksWho (or What) Generates Images for EFF?2dThe Hacker NewsMicrosoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack2dTechCrunch SecurityFBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures2dThe Hacker NewsZoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client3dTenableMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)3dCyberScoopDelta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas3dZero Day InitiativeThe August 2026 Security Update Review3dSANS ISCMicrosoft Patch Tuesday August 2026, (Tue, Aug 11th)3dCheck Point ResearchShattering the Dream – When a Job Offer Becomes a Zero-Day Attack3dZscalerWhen "Prepare to Disconnect" Becomes Official Guidance: What CI Fortify Means for OT Security3dSchneier on SecurityAI Genie in the Wild3dTechCrunch SecurityDelta investigating after someone set up fake Wi-Fi network mid-flight3dCyberScoopNIST wants to overhaul its vulnerability database for the AI age3dCybersecurity DiveFormer BlackFile affiliates linked to extortion campaign targeting private equity3dReversingLabsFrontier AI agents: Only as safe as their containment3dTechCrunch SecurityNorth Korean remote IT staffer worked for US government agency, says FBI3dThe Hacker NewsOpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development3dRapid7CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)3dRapid7Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)3dCloudflareCloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave3dKaspersky SecurelistHead Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants3dCybersecurity DiveCVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’3dThe Hacker NewsResearchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers3dSchneier on SecurityAI for Military Support3dKaspersky SecurelistProject CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection3dUnit 42Kimwolf v7: An Evolution of the Kimwolf Botnet3dZscalerThe Hidden Threat in Your Software Development Lifecycle: Why Self-Hosted Runners Need Zero Trust3dThe Hacker NewsHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine3dHelp Net SecurityAn AI tool found 84 flaws in 5G network software and 23 of them still have no fix3dCrowdStrikeAugust 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs3dTrustedSecA Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI3dSANS ISCISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)3dEFF DeeplinksDismiss Church’s Trademark Lawsuit Against “Mormon Stories” Podcast, EFF Urges Court3dFlock SafetyIndependent Grand Jury Report Highlights Flock's Commitment to Responsible ALPR3dSophosClickFix campaign abuses Deno runtime for infostealer delivery3dSophosAbuse of alternative runtime environments Deno-tes defender headaches3dTLDR InfoSecUK Navy Drone Data Leak 🛸, Belgian eID RCE 🇧🇪, Apple Private Cloud Bug 🍎3dElastic Security13 million tool calls: auditing every AI coding agent action with Elastic Agent3dRecorded FutureMines, Minds, and Machines: The Journey of AI3dExploit-DB[webapps] Apache Gravitino 1.2.1 - SSRF3dExploit-DB[webapps] Blocksy Companion 2.1.46 - RCE3dExploit-DB[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution3dExploit-DB[remote] mcp-server-kubernetes 3.8.x - Argument Injection3dExploit-DB[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting3dExploit-DB[webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF3dExploit-DB[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion3dSignalIntroducing Automatic Key Verification3dSimon WillisonIntroducing Muse Glimmer3dFederal News CyberFBI investigating North Korean remote IT staffer working for US agency3dUnit 42The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications3dCyberScoopThe FTC wants to regulate AI for ideological bias3dFederal News CyberHow operating reality shifts under NSPM-124dCloudflareEverything we launched during Agents Week4dEFF DeeplinksMeta Must Stop Silencing Reproductive Health Information4dZscalerZero Trust Connectivity for Private AI Apps/Models: Who Can Actually Reach Them?4dSANS ISCScans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)4dMicrosoft SecurityMicrosoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise4dNextgov CyberFederal systems increasingly likely to face accidental AI breach after Hugging Face, experts say4dMicrosoft SecurityDeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure4dCybersecurity DiveCivil-society initiative will pay cybersecurity vendors to protect rural water systems4dCybersecurity DiveSecure development can help turn the tables as AI alters cyber landscape4dTechCrunch SecurityA data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond4dCheck Point Research10th August – Threat Intelligence Report4dCloudflareServing the most critical missions: Cloudflare for Government achieves FedRAMP Class D (High) Certified status4dWizInside the Metabase SQLi: Exploited in the Wild4dQualysAudit Fix: Audit Readiness for the Post-Mythos Era4dSchneier on SecurityPython Now Has a Post-Quantum Encryption Library4dIndicatorHow TikTok bots turned a cancer patient's story into engagement bait4dKaspersky SecurelistIT threat evolution in Q2 2026. Non-mobile statistics4dKaspersky SecurelistIT threat evolution in Q2 2026. Mobile statistics4dIndicatorOSINT Tool Radar: 4 new and 2 updated4dWeLiveSecurityAre AI tutors safe for your kids?4dHelp Net SecurityOpenAI locks down Astra over potential critical cyber capabilities4dSimon WillisonQuoting OpenClaw (running Opus 4.6)4dSANS ISCISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)4dSophosSophos Working with OpenAI on security from AI, with AI, and for AI4dTLDR InfoSecKids Smartwatch Bug ⌚, Metabase Zero-Day 🚨, Kimi K3 AI Escapes Sandbox 🤖4dSnykShow, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS4dRecorded FutureThe Hugging Face Hack Was Cheap Persistence at Work4dExploit-DB[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution4dExploit-DB[local] Microsoft Edge 150.0.4078.48 - RCE4dExploit-DB[webapps] CorgetGpsDget 2_3.2 - OS Command Injection4dSimon WillisonQuoting Claude Opus 5 system prompt4dSimon WillisonGitHub Models is now retired4dOX SecurityShai-Hulud Outbreak Debrief: The Worm Evolves into MCP5dNextgov CyberVoting machine researchers say federal work abruptly ended after Trump ally pushed back on their findings5dOX SecurityAI-SPM vs. ASPM (and Why AINAPP Is What Comes Next)5dSimon WillisonAuto mode is now the default in Claude Code for Pro, Max, and Team plans6d0xdfHTB: Helix6dThe Hacker NewsAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers6dElastic SecurityLiving off the coding agent: Two tales of tunnels and LaunchAgents6dUnit 42Inside the Modern SOC: The Identity Front Door6dSchneier on SecurityFriday Squid Blogging: Arctic Bobtail Squid Video7dFederal News CyberSome contractors got CMMC certified early. Now the implementation is on hold.7dNextgov CyberNew ‘Water Watch Center’ launched to help small utilities stop cyberattacks7dFederal News CyberRemote connections to monitor critical systems create opportunities for cyber attackers7dGraham CluleyBeware cut-price AI services that read your every word7dCitizen LabInside the Fake Copyright Racket Silencing News Outlets7dNextgov CyberCISA cautions against rigid rules for future of cyber vulnerability program7dRapid7Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)7dCloudflareUnveiling good and bad behaviors on the Agentic Internet7dCloudflareIntroducing Radar Researcher: An AI tool for exploring Internet data in plain language7dCloudflareAnnouncing Cloudflare Ambassadors, Community Engineers, and another $1M in open-source funding7dTenableAgentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 20267dIndicatorBriefing: Grokipedia's edit freeze7dSchneier on SecurityICE Is Buying Access to Credit Card Records7dSANS ISCLinux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)7dHelp Net SecurityAugust 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?7dCrowdStrikeCrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX7dTLDR InfoSec4,400 Rockwell PLCs Exposed 🏭, Swiss SharePoint Hack 🇨🇭, TONTOU Spectre v2 Bypass💻7dElastic SecurityThe security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent7dRecorded FutureJuly 2026 CVE Landscape7dUnit 42ChainDrop: Inside a Self-Propagating npm Worm7dFull DisclosureDangling DNS record for bastion.certb.cdp.bethesda.net7dFull DisclosureCL.0 desync in www.microsoft.com7dFull DisclosureCVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)7dFull Disclosure[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability7dFull Disclosure[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability7dFull Disclosure[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability7dFull Disclosure[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability7dFull Disclosure[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)8dNextgov CyberCISA still finds water system controls exposed online amid multistate hacks8dCisco TalosWhy metaphor may dictate your security strategy8dKrebs on SecurityCanadian Man Pleads Guilty in Snowflake Extortions8dIndicatorWelcome to the Indicator Lab pilot8dReversingLabsAI domain takeover takeaway: Focus on the harness not the model8dNextgov CyberAI advances are pushing governments to treat cyberattacks as routine, Western officials say8dWizCloud Threat Highlights: H1 20268dMandiantUNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments8dOX SecurityAgentic AI Security: Risks and Best Practices for Autonomous Agents8dAdversa AITop MCP security resources — August 20268dNIST NewsNIST Researchers Correct Common Error Confounding Nanotech Measurements8dWizWiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 20258dTenableAI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing8dSchneier on SecurityAdversarial Clothing Designed to Fool Facial Recognition Systems8dHelp Net SecurityCritical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)8dOX SecurityDid We Just Witness Step One of the Autonomous AI Arms Race?8dGraham CluleyApple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits8dUnit 42Token Jacking: Cybercriminals Could Be Stealing Your AI Resources8dOX SecurityCVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions8dCrowdStrikeExpanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery8dTrustedSecThe Art of Hunting Azure Cloud Secrets8dTLDR InfoSecShai-Hulud NPM Worm Returns 🐛, Agentic IR Notebooks 📓, RingCentral Phish For M365 🎣8dElastic SecurityShai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages8dRecorded FutureEmerging Threats to Neurotechnology8dPortSwigger ResearchCRLF-Powered Desync Attacks: Beheading HTTP Streams8dGraham CluleySmashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency8dPortSwigger ResearchCan AI do novel security research? Meet the HTTP Terminator9dHacking ArticlesImpacket for Pentester: reg9dNextgov CyberHugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says9dSpecterOpsTurning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 19dSpecterOpsOf Course We Built a WSUS Ludus Lab9dSpecterOpsWeaponizing Windows Updates with NotWSUSpicious9dMicrosoft SecurityMicrosoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)9dMicrosoft SecurityFrom open lures to cloaked gates: How a macOS ClickFix campaign learned to hide9dReversingLabsHow to Leverage Spectra Analyze's Search for SVG Analysis9dCitizen LabImmigration Policy: The Backdoor to Transnational Repression9dHackerOneCTEM Metrics That Matter: What CISOs Should Report to the Board9dTenableTenable Hexa AI: Automating exposure remediation with agentic routines9dNIST News‘Spooky’ Particles Transit DC Suburbs, a Step Toward a Quantum Network9dIndicatorHow to red team an AI tool for safety9dSnykContinuous Offensive Security & AI Pentesting: 20 FAQs9dEFF DeeplinksTomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction9dSophosSophos DNS Protection update for GenAI9dTLDR InfoSecmacOS Root Access Bug 🖥️, Rusty UEFI Bootkit 🦀, DPRK NPM Attacks 📦9dRecorded FutureHype vs. Reality: What the Hugging Face Incident Means for AI Safety9dTor ProjectNew Release: Tails 7.10.19dElastic SecurityBenchmarking the Agentic SOC: How we evaluate LLMs for security workflows9dMicrosoft SecurityChainDrop supply chain compromise: Anatomy of a self-propagating worm9dEFF DeeplinksAppeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA9dFederal News CyberVA’s cloud security memo more mythbuster than new policy9dSpecterOpsMythic 4 Public Beta: More Than a New Coat of Paint9dEFF DeeplinksMobile Ad Software Encourages Location Data Sharing, EFF Report Finds9dEFF DeeplinksDevelopers: Beware of Ad Libraries that Betray Your Users’ Location Privacy10dMicrosoft SecurityAdvance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps10dCitizen LabA Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology10dMicrosoft Security128 Seconds to disruption: Microsoft Defender stops ransomware at QNET10dNextgov CyberChinese telecom firms kept footholds in US networks despite federal crackdowns, House probe finds10dReversingLabsWhy AI coding makes zero trust an AppSec requirement10dEFF DeeplinksTechnology's Power in the Hands of the People10dSentinelOneFrom Input to Impact: Secure AI Where It Runs10dWizWiz at Black Hat 2026: Driving AI Threat Readiness10dUnit 42The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software10dFortinetQuickFox Supply Chain Attack Used to Deploy FDMTP Implant10dUnit 42Almost Half of Malware Samples Communicate Direct to IP10dOX SecurityA Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads10dKaspersky SecurelistHow legitimate cloud platforms enable phishers to bypass MFA10dNIST NewsNIST Joins National Genesis Mission to Accelerate AI Innovation10dNCSC UKNCSC statement in response to recent incidents resulting from frontier AI evaluations