Cloud Security Office Hours Banner

Cloud Security News

Latest news, vulnerabilities, and developments in cloud security. Stay informed about the rapidly evolving cloud threat landscape.

RSS Feed
Cloud security news velocity is high; signal-to-noise is low. This page is the curated middle. - what this feed is for
Adult reading a newspaper with breakfast in modern kitchen, morning sunlight
Photo by cottonbro studio on Pexels

August 12, 2026 · 37 articles

ReversingLabs Blog

OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise

While prompt injection and data disclosure remain concerns, excessive agency climbed the list - not surprising with recent security incidents. (ReversingLabs Blog)

AI
SecurityWeek

WhatsApp Unveils New Scam Alert Feature

Signal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appe... (SecurityWeek)

Scam
The Register - Security

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

Gives a whole new meaning to Safe Mode (The Register - Security)

Ransomware
Dark Reading

Walmart Leaders Transform Security Operations Without Going Bananas

The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency and team spirit are key factors. (Dark Reading)

Cloud Security
The Record

Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery

This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold. (The Record)

Azure Vulnerability AI
Infosecurity Magazine

NIST Seeks Public Input on AI-Ready NVD Modernization

The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research (Infosecurity Magazine)

Vulnerability AI
BleepingComputer

Hackers leverage new Microsoft SharePoint exploit in attacks

Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...] (BleepingComputer)

Azure Vulnerability
The Record

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process. (The Record)

Azure CISA Vulnerability
Help Net Security

Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point resea... (Help Net Security)

Vulnerability Jobs
SecurityWeek

Ceva Logistics Operations Disrupted by Cyberattack

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupt... (SecurityWeek)

Cloud Security
StepSecurity Blog

Control Which Package Registries Your CI Jobs and Developer Machines Use

Two StepSecurity controls show every CI job and developer machine that still installs from public registries. Once you can see them, you can block public registries in CI and ce... (StepSecurity Blog)

Jobs
Orca Security Blog

Tools to Scan Workloads and Containers: Detecting Threats Agents Miss

Security teams running containerized workloads across EKS, GKE, and AKS clusters face a persistent coverage problem. Agents protect the hosts they’re installed on, but ephemeral... (Orca Security Blog)

Cloud Security
The Hacker News

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could resul... (The Hacker News)

Vulnerability Threat Research
BleepingComputer

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...] (BleepingComputer)

Azure Vulnerability
SecurityWeek

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Dis... (SecurityWeek)

Cloud Security
SecurityWeek

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks a... (SecurityWeek)

Vulnerability
Schneier on Security

Prompt Injections for Defense

This seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amaz... (Schneier on Security)

Cloud Security
SecurityWeek

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply C... (SecurityWeek)

Supply Chain
The Hacker News

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in qu... (The Hacker News)

Vulnerability Threat Research
Help Net Security

ConnectSecure helps MSPs automate Microsoft 365 security remediation

ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed ser... (Help Net Security)

Azure AI
Help Net Security

CBTS brings continuous penetration testing to enterprise security

CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploita... (Help Net Security)

Vulnerability
SecurityWeek

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattack... (SecurityWeek)

Vulnerability
Help Net Security

Crytica’s RDAi detects OT device tampering from within

Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and conne... (Help Net Security)

Cloud Security
Help Net Security

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping redu... (Help Net Security)

Cloud Security
Security Affairs

Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum

Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while... (Security Affairs)

Cloud Security
Infosecurity Magazine

Microsoft Fixes 400 Flaws on August Patch Tuesday

Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday (Infosecurity Magazine)

Azure
The Hacker News

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, databas... (The Hacker News)

Kubernetes Breach Scam
SecurityWeek

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact

CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoe... (SecurityWeek)

CISA
Help Net Security

Split-second deepfake glitch blows digital certificate fraudster’s cover

Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signature... (Help Net Security)

Identity Scam
Help Net Security

Post-quantum migration gets harder when every user holds a key

In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and... (Help Net Security)

Cloud Security
Help Net Security

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then wal... (Help Net Security)

Vulnerability
Help Net Security

338 million attack simulations reveal the state of enterprise defense

First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have b... (Help Net Security)

Cloud Security
Help Net Security

Ready-made $500 kit puts a crypto scam within anyone’s reach

A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates... (Help Net Security)

Scam
Help Net Security

AI deployments are stretching enterprise security to its limits

CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and... (Help Net Security)

AI
Risky Business News

Risky Bulletin: Russian hackers adopt the fake job interview tactics

In other news: Portuguese to face trial for developing WormGPT; AI assistant hacks gym website; OpenAI releases cyber models for blue teams. (Risky Business News)

AI Jobs
SANS ISC

ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th)

(SANS ISC)

Cloud Security

Kimwolf botnet rebuilt to survive takedowns, researchers say

Months after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from... (CyberScoop)

Cloud Security

August 11, 2026 · 57 articles

Cisco Talos

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "crit... (Cisco Talos)

Azure
BleepingComputer

DeadLock ransomware uses blockchain to resist infrastructure takedown

The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activ... (BleepingComputer)

Ransomware
Dark Reading

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances. (Dark Reading)

Vulnerability Ransomware
BleepingComputer

Windows 11 KB5121003 & KB5120240 cumulative updates released

Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...] (BleepingComputer)

Azure
ReversingLabs Blog

Frontier AI agents: Only as safe as their containment

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model. (ReversingLabs Blog)

AI
The Hacker News

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "... (The Hacker News)

Vulnerability
Cloudflare Blog

Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection ve... (Cloudflare Blog)

Cloud Security
Rapid7 Blog

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achie... (Rapid7 Blog)

Azure Vulnerability
Infosecurity Magazine

Only Half of UK Manufacturers Have a Cyber Incident Response Plan

Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents (Infosecurity Magazine)

Cloud Security
Security Affairs

Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs

Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV v... (Security Affairs)

Cloud Security
The Register - Security

Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code (The Register - Security)

Cloud Security
The Hacker News

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers... (The Hacker News)

Cloud Security
Zscaler ThreatLabz

CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

IntroductionOn July 31, Microsoft Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch. Microsoft attributes this activity to Storm-2945, a... (Zscaler ThreatLabz)

Azure Scam Threat Research
AWS Security Blog

Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact

Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020)... (AWS Security Blog)

AWS
The Register - Security

Signal adds an extra layer of security to make sure you're actually chatting with the right person

One big caveat, though: You need your contact's phone number (The Register - Security)

Cloud Security
The Register - Security

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

Sysadmins, welcome to your new norm (The Register - Security)

Azure
Zscaler ThreatLabz

Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

IntroductionOn August 4, 2026, a self-propagating worm called ChainDrop entered the npm ecosystem through a compromised maintainer account. ChainDrop is a variant of Mini Shai-H... (Zscaler ThreatLabz)

Cloud Security
Rapid7 Blog

Patch Tuesday - August 2026

Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behem... (Rapid7 Blog)

Azure
BleepingComputer

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. [...] (BleepingComputer)

Jobs
Malwarebytes Labs

Fake CCleaner installs GhostDesk Chrome spyware

A convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome. (Malwarebytes Labs)

Cloud Security
The Record

NSA installs DHS lawyer as new general counsel

Kerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News. (The Record)

Cloud Security
The Record

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout

The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and s... (The Record)

Ransomware
The Hacker News

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local gri... (The Hacker News)

Breach
AWS Security Blog

Summer 2026 SOC 1 report is now available with 185 services in scope

Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 1... (AWS Security Blog)

AWS
The Hacker News

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting... (The Hacker News)

Jobs Scam Threat Research
Check Point Research

Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack

Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide,... (Check Point Research)

Vulnerability Jobs Threat Research
Trail of Bits Blog

How Trail of Bits helps verify the integrity of your Signal chats

Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you... (Trail of Bits Blog)

Cloud Security
Security Affairs

ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activ... (Security Affairs)

Vulnerability
Malwarebytes Labs

Valve warns Steam hardware buyers: Expect fake delivery scams

The warning affects recent buyers of Steam hardware, including the hugely popular Steam Deck. (Malwarebytes Labs)

Scam
Security Affairs

The inconvenient truth about AI pentesting: someone has to check all the work

AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentic... (Security Affairs)

AI
Orca Security Blog

5 Key Takeaways from Black Hat USA 2026

Black Hat USA 2026 ran August 1 through 6 in Las Vegas this year, days of training, briefings, presentations, and of course, the vendor showroom, that drew cybersecurity profess... (Orca Security Blog)

Cloud Security
AWS Security Blog

AWS successfully completed its 2025-26 NHS DSPT assessment

Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a st... (AWS Security Blog)

AWS
Malwarebytes Labs

Social media platforms crack down on drone factory recruiting game

Researchers found that games and major US social media platforms were used to lure young people into jobs in Russia's drone industry. (Malwarebytes Labs)

Jobs
Google Cloud Blog

PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap

Securing infrastructure and services against a future cryptographically-relevant quantum computer has been a goal for Google for a decade, and we’ve dedicated ourselves to help... (Google Cloud Blog)

GCP
BleepingComputer

Wesco confirms security incident after ExfilSquad claims data theft

Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...] (BleepingComputer)

Supply Chain
Schneier on Security

AI Genie in the Wild

When I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked OpenClaw to book gym c... (Schneier on Security)

AI
SecurityWeek

The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It

Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t... (SecurityWeek)

AI
Infosecurity Magazine

Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification

Cursor fixed a pre-trust code execution path in three days then closed the report as informative (Infosecurity Magazine)

Cloud Security
SecurityWeek

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vul... (SecurityWeek)

Cloud Security
SecurityWeek

US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senat... (SecurityWeek)

Cloud Security
BleepingComputer

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to de... (BleepingComputer)

AI
Help Net Security

Arctera enhances Unified Platform for evidence-driven compliance workflows

Arctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and respo... (Help Net Security)

Cloud Security
The Register - On-Prem

Building up the US power grid won't be wasted, even if the AI bubble bursts

The bigger risk is underinvestment, claims consulting biz McKinsey (The Register - On-Prem)

AI
Malwarebytes Labs

Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trust

The same technology making our lives easier is also making it harder. How are young people navigating this new world? (Malwarebytes Labs)

AI
SecurityWeek

Corma Raises $60 Million for Defensive Cybersecurity AI Model

Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue. The post Corma Raises $60 Million for Defensive Cybersecurity AI Model appeared f... (SecurityWeek)

AI
The Hacker News

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the co... (The Hacker News)

Jobs
Schneier on Security

AI for Military Support

Interesting empirical research: “ Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI .” Abstract: How is AI transforming decision-making in modern c... (Schneier on Security)

AI
SecurityWeek

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store,... (SecurityWeek)

AI
The Hacker News

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM... (The Hacker News)

Cloud Security
Infosecurity Magazine

Logistics Giant Ceva Suffers Data Breach Impacting European Clients

Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius (Infosecurity Magazine)

Breach Supply Chain
Orca Security Blog

Cloud Compliance Solutions for Enterprises: The Automation Checklist

Enterprise teams managing cloud environments across multiple providers and regions know the pain of tracking compliance manually. Spreadsheets fall out of date within hours, evi... (Orca Security Blog)

Cloud Security
The Hacker News

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obvi... (The Hacker News)

AI
Palo Alto Networks Unit 42

Kimwolf v7: An Evolution of the Kimwolf Botnet

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the... (Palo Alto Networks Unit 42)

Cloud Security
Infosecurity Magazine

OpenAI Pauses Some Development of Astra Model on Security Concerns

OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns (Infosecurity Magazine)

Cloud Security
FortiGuard Labs

Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack

What is the Attack? Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromis... (FortiGuard Labs)

Threat Research
Sysdig Blog

Vulnerability response in the AI-discovery era

(Sysdig Blog)

Vulnerability AI
Recorded Future

Mines, Minds, and Machines: The Journey of AI

Minerals become chips. Chips become data centers. Data centers become models, and models are acquiring arms and legs. From Earth to Embodied AI traces the supply chain of the fo... (Recorded Future)

Supply Chain AI

August 10, 2026 · 26 articles

NATO and an AI startup can now name and track software vulnerabilities

NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European... (CyberScoop)

AI
The Hacker News

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control ri... (The Hacker News)

AI
The Hacker News

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. Th... (The Hacker News)

Azure Ransomware Threat Research
Infosecurity Magazine

Go-Based macOS Malware Steals Crypto and Secrets

A macOS malware variant has been detected stealing crypto, passwords and more (Infosecurity Magazine)

Cloud Security
Malwarebytes Labs

A week in security (August 3 - August 9)

A list of topics we covered in the week of August 3 to August 9 of 2026 (Malwarebytes Labs)

Cloud Security
The Register - Security

Advertisers are trying to influence AI bots with secret ads

PLUS: Hiveminds are emerging to hack the planet, and open-weight models are the new new red scare (The Register - Security)

AI
ESET WeLiveSecurity

Are AI tutors safe for your kids?

AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child. (ESET WeLiveSecurity)

AI
Microsoft Security Blog

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The... (Microsoft Security Blog)

Azure AI Threat Research
Dark Reading

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. (Dark Reading)

Identity AI
Security Affairs

Gym Booking Task Turns Into Real-World AI Cyberattack

An AI agent hacked a gym booking system while trying to help a user, booking early and removing another person from the waitlist. An Australian man asked his AI assistant to boo... (Security Affairs)

AI

The FTC wants to regulate AI for ideological bias

The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. The post The FTC... (CyberScoop)

AI
The Register - Security

DEF CON hackers add new muscle to water utility protection

Franklin project adds new security providers, employs digital twins and AI (The Register - Security)

AI
Dark Reading

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users. (Dark Reading)

Vulnerability

OpenAI says Daybreak will expand to offer specialized cyber services

The company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors. The post OpenAI says Daybr... (CyberScoop)

Cloud Security
AWS Security Blog

AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)

We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitiv... (AWS Security Blog)

AWS
The Register - Security

North Korean spies are running local LLMs to cause AI mischief

Kimsuky's phishing attacks get an AI boost (The Register - Security)

Phishing AI
The Register - Security

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

What wouldst thou ask of the monkey's paw? (The Register - Security)

AI
The Register - Security

Attackers pick Levi's pockets in social engineering attack

Crims talked their way onto three employee PCs before trousering corporate data (The Register - Security)

Scam
Dark Reading

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets. (Dark Reading)

Cloud Security
Dark Reading

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups. (Dark Reading)

Vulnerability
Dark Reading

Outdated Cybercrime Laws Put Security Researchers at Risk

A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research. (Dark Reading)

Cloud Security
Security Affairs

Hackers Cross From IT to OT Through a Private APN in Poland

Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a... (Security Affairs)

Breach
The Record

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed... (The Record)

Cloud Security
Zscaler ThreatLabz

Abyssos: Technical Analysis of a New Modular RAT

Introduction In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in... (Zscaler ThreatLabz)

Cloud Security
Infosecurity Magazine

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data (Infosecurity Magazine)

Vulnerability AI
Malwarebytes Labs

New turnkey kit makes it easy for anyone to become a scammer

We discovered a kit that gave us an insight into how modern online scams are built, promoted, and potentially used to target everyday consumers. (Malwarebytes Labs)

Scam