Cloud Security Office Hours Banner

Cloud Security News

Latest news, vulnerabilities, and developments in cloud security. Stay informed about the rapidly evolving cloud threat landscape.

RSS Feed
Cloud security news velocity is high; signal-to-noise is low. This page is the curated middle. - what this feed is for
Adult reading a newspaper with breakfast in modern kitchen, morning sunlight
Photo by cottonbro studio on Pexels

August 18, 2026 · 56 articles

AWS Security Bulletins

CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route

Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source... (AWS Security Bulletins)

AWS Vulnerability
Qualys Blog

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as su... (Qualys Blog)

CISA Vulnerability
The Record

More than 200 victims of Medusa ransomware identified over the last year, CISA says

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 - writing that as of April 2026, Medusa act... (The Record)

CISA Ransomware
The Hacker News

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connec... (The Hacker News)

Azure
The Hacker News

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operation... (The Hacker News)

Vulnerability AI Scam
BleepingComputer

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials,... (BleepingComputer)

Ransomware Scam
Microsoft Security Blog

Hunting MacSync Stealer infrastructure through behavioral pivots

MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots.... (Microsoft Security Blog)

Azure
Security Affairs

Project noRecognition: Teaching AI to Fool Surveillance Cameras

Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cyber... (Security Affairs)

AI
AWS Security Blog

Security Hub Extended adds Supply Chain Security as its tenth category

Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were a... (AWS Security Blog)

AWS Supply Chain
The Hacker News

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups'... (The Hacker News)

Ransomware
The Record

Berlin cuts two state ministries off government network after security breach

The affected ministries - one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment - have b... (The Record)

Breach
The Record

University of Texas forced to take systems offline in San Antonio after cyberattack

The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and... (The Record)

Cloud Security
Infosecurity Magazine

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher (Infosecurity Magazine)

AI
Help Net Security

Download: 2026 Credential Risk Report

85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate expos... (Help Net Security)

Scam
Wiz Blog

Announcing the 2026 Wiz Partner Alliance Award Winners

Recognizing the partners, integrators, and visionaries driving cloud security transformation, AI risk management, and SOC modernization across AMER, EMEA, and ANZ. (Wiz Blog)

AI
Help Net Security

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect G... (Help Net Security)

Vulnerability
The Hacker News

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the ac... (The Hacker News)

Scam Threat Research
SecurityWeek

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hac... (SecurityWeek)

Vulnerability Breach
Malwarebytes Labs

Heights Finance data breach: What customers need to know

Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing. (Malwarebytes Labs)

Breach Phishing Identity
Security Affairs

GitLab Patches Critical Unauthenticated GraphQL Vulnerability

GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch... (Security Affairs)

Vulnerability
GitGuardian Blog

Why Secrets Slip Through Every Layer of Your Security Stack

Your security stack is a set of specialists, each guarding one territory. Exposed credentials don't respect the boundaries between them, and 64% of the ones found valid in 2022... (GitGuardian Blog)

Breach Scam
The Register - Security

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Phishing, malvertising attacks could target devs to gain access to private corporate networks (The Register - Security)

CISA Vulnerability Phishing
SecurityWeek

Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks

Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. The post Webina... (SecurityWeek)

AI
Infosecurity Magazine

Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities

Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds (Infosecurity Magazine)

Vulnerability
ReversingLabs Blog

Black Hat 2026: AI rewrites the rules of cybersecurity

The annual cybersecurity conference focused on frontier AI agents - and what they mean for cyber. Here are three key takeaways. (ReversingLabs Blog)

AI
The Register - Security

Apple plugs image-processing hole ripe for spyware abuse

Patch batch spans current kit, older iGadgets, Macs, and Vision Pro (The Register - Security)

Cloud Security
SecurityWeek

CISO Conversations: Nico Waisman - From Self-Taught Hacker to AI-Driven Offensive Security at XBOW

With no formal training and no career plan, Waisman built a path from Argentina's early hacking scene to leading security at an AI-powered offensive security firm. The post CISO... (SecurityWeek)

AI Jobs
Google Threat Intelligence

Staying Ahead of Adversarial AI Through Agentic Source Code Review

Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code... (Google Threat Intelligence)

AI Threat Research
Help Net Security

NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation

NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic.... (Help Net Security)

Cloud Security
JFrog Security Research

Frontier AI Application Security: Every Second Counts

Somewhere in the last few months, the math of application security quietly broke. Anthropic’s Claude Mythos Preview didn’t just analyze code, it found a 27-year-old vulnerabilit... (JFrog Security Research)

AI
Check Point Research

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of... (Check Point Research)

Ransomware
SecurityWeek

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severit... (SecurityWeek)

Vulnerability AI
Dark Reading

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence. (Dark Reading)

Azure Scam
The Register - Security

Copilot tricked into telling reseachers how to hack itself

How to social engineer an AI's reasoning engine (The Register - Security)

AI
Rapid7 Blog

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers. The latest Quarterly Threat Landscape Report from Rapid7 Labs shows v... (Rapid7 Blog)

AI
The Hacker News

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next thro... (The Hacker News)

AI
SecurityWeek

Xpander Raises $7.5 Million for AI Management and Governance

Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million f... (SecurityWeek)

AI
SecurityWeek

Fortinet Acquires AI Security Company Virtue AI

Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security C... (SecurityWeek)

AI
Help Net Security

Google’s $10,000 refund test shows why AI agents need zero trust

Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust securi... (Help Net Security)

Zero Trust AI
Infosecurity Magazine

Cyber Incident Disrupts Student Services at UT San Antonio

UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume (Infosecurity Magazine)

Cloud Security
Schneier on Security

LLMs and Contextual Integrity

I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “ CIMemories: A Compositional Benchmark for Co... (Schneier on Security)

AI
Infosecurity Magazine

Three-quarters of Ransomware Attacks Target Mid-Market Firms

Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit (Infosecurity Magazine)

Ransomware
Help Net Security

OpenAI tightens defenses after AI agents breach research environment

Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructu... (Help Net Security)

Breach AI
The Hacker News

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of appr... (The Hacker News)

Breach
Help Net Security

Hacker claims millions of records stolen from corporate Azure tenants

A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Voda... (Help Net Security)

Azure Threat Research
Infosecurity Magazine

UK Legal Regulator Raises AI Misuse Concerns

Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks (Infosecurity Magazine)

Breach AI
Help Net Security

Synthesized builds Test Data Agent to validate AI agents with production-like data

Synthesized has announced its Test Data Agent, a new agentic infrastructure capability being developed to create and provision the realistic data, business context, and system s... (Help Net Security)

AI
Security Affairs

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed... (Security Affairs)

Scam
Cloud Security Alliance

Downwind of the Labs

One of the first things they teach you in hazmat response is to stage uphill and upwind. (And the rule of thumb: if you can’t cover the scene with your thumb, you’re too close).... (Cloud Security Alliance)

Cloud Security
SecurityWeek

Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates

The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data. The post Dozens of WebKit Vulnerabilities Patched With... (SecurityWeek)

Vulnerability
Help Net Security

Google’s open-source HEIR lets AI work with data it can’t see

Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development pl... (Help Net Security)

AI
Help Net Security

A hollowed out data layer is making CISOs fly blind into AI attacks

The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not... (Help Net Security)

AI
Help Net Security

Cybersecurity jobs available right now: August 18, 2026

CISO ADI Global Distribution | USA | Hybrid - View job details As a CISO, you will develop and lead ADI’s global security strategy to protect information assets, digital platfor... (Help Net Security)

Jobs
SANS ISC

ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th)

(SANS ISC)

Cloud Security
Recorded Future

PurpleDelta's Fraudulent Employment Operations

Learn how North Korean IT worker threat cluster "PurpleDelta" uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to infiltrate organizations. Di... (Recorded Future)

AI Scam
Recorded Future

CopyCop Targets AI Investment in Armenia

The Russian influence network CopyCop is targeting Western-backed AI and infrastructure projects in Armenia, including the Firebird AI data center, to undermine the country’s we... (Recorded Future)

AI

August 17, 2026 · 48 articles

Check Point Research

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justi... (Check Point Research)

Breach Threat Research
The Hacker News

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through... (The Hacker News)

Vulnerability
BleepingComputer

French tax authority data breach affects 678,000 individuals

The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data b... (BleepingComputer)

Breach
Infosecurity Magazine

SafePal Data Breach Hits Tens of Thousands of Customers

Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach (Infosecurity Magazine)

Breach
BleepingComputer

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-... (BleepingComputer)

Azure Vulnerability
Huntress Blog

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer

Huntress SOC analysts reverse engineer MacSync Stealer, a macOS infostealer spread through fake Claude Code download pages. Watch the full analysis. (Huntress Blog)

Cloud Security
Dark Reading

'Turf War' Between Claude Agents Leads to Self-Replicating Malware

Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic. (Dark Reading)

Cloud Security
Rapid7 Blog

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw ph... (Rapid7 Blog)

Breach Scam
The Record

Ukrainian software developer faces 12 years in Swiss ransomware trial

The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation. (The Record)

Ransomware
Security Affairs

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company thr... (Security Affairs)

Ransomware
Malwarebytes Labs

Update your Mac: Screen Sharing vulnerability exploited in the wild

Attackers are exploiting a Mac Screen Sharing vulnerability to gain root access and install Monero cryptominers. (Malwarebytes Labs)

Vulnerability
ESET WeLiveSecurity

How QR-code phishing can slip past corporate security measures

Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap. (ESET WeLiveSecurity)

Phishing

Irregular says ‘human oversight’ responsible for AI sandbox escape incidents

In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human... (CyberScoop)

AI
SANS ISC

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that ad... (SANS ISC)

Cloud Security
The Record

Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

The breach affected anyone who received a loan through the company or inquired about a loan product through a third party. (The Record)

Breach
Dark Reading

Adam Shostack Talks Hugging Face & PHANTOM-B

World-class threat modeler Adam Shostack shared he was "blown away" by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both... (Dark Reading)

Cloud Security
BleepingComputer

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information fr... (BleepingComputer)

Breach
The Register - On-Prem

Siemens and Reinhausen turn up the voltage for hungry AI racks

Not a German cop show, but a pair of engineering firms aiming to feed 800 VDC to next-gen kit (The Register - On-Prem)

AI
AWS Security Blog

Updates to your AWS Sign-In experience

Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will kn... (AWS Security Blog)

AWS
Security Affairs

LiteLLM Supply-Chain Attack - Technology, Banking and Healthcare the Most Affected

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated t... (Security Affairs)

Breach Scam
Cloud Security Alliance

When the Playbook Breaks: AI Incident Response for Systems That Don't Behave Like Anything Else

Three years after the explosion of GenAI in the enterprise, most organizations now have an inventory of their AI systems, an acceptable use policy, and - at best - a process for... (Cloud Security Alliance)

AI
The Register - Security

An AI broke Snowflake's code. Then another AI agent exploited it

Don't worry, this one was via a bug bounty program (The Register - Security)

Vulnerability AI
The Record

Irregular faces criticism over ‘spin’ in AI hacking postmortem

The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release o... (The Record)

AI
The Record

Poland probes MyDr healthcare software breach potentially affecting 19 million people

MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of... (The Record)

Breach
Tenable Blog

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable... (Tenable Blog)

Azure Ransomware Threat Research
SANS ISC

Apple Screen Sharing Security, (Mon, Aug 17th)

About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC prot... (SANS ISC)

Cloud Security
Zscaler ThreatLabz

C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor... (Zscaler ThreatLabz)

Ransomware Threat Research
BleepingComputer

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and tr... (BleepingComputer)

Vulnerability
The Hacker News

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, an... (The Hacker News)

Vulnerability Breach
CrowdStrike Blog

Teaching AI to Reason Through Detection Triage

(CrowdStrike Blog)

AI
Wiz Blog

The Closed Loop Remediation Playbook with Wiz

Start your path to a self-healing cloud today, with Wiz Workflows now GA and Remediation and Response in public preview. (Wiz Blog)

Cloud Security
The Hacker News

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server... (The Hacker News)

Cloud Security
Schneier on Security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices-at hotels, conference centers, and so on-around the world and changing their DNS settings. The goal is to redirect users to fake... (Schneier on Security)

Scam
Infosecurity Magazine

ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act

The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act (Infosecurity Magazine)

Cloud Security
The Register - Security

Code fixers have fired up the AI warp drive. Strange new worlds await

With more patches per month than at a pirate convention, the bug must be an endangered species. Well, about that (The Register - Security)

AI
Malwarebytes Labs

Why Facebook’s war on ad blockers could help scammers

One ad blocker is giving up the fight against Facebook ads. The consequences could go beyond annoying advertising. (Malwarebytes Labs)

Scam
Security Affairs

Invisible AI Prompts Trigger Court Sanctions

A litigant hid AI prompt injections in a court filing to influence a ruling. The judge caught it and banned him from electronic filing. A man suing the New York Bariatric Group... (Security Affairs)

AI
SecurityWeek

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exp... (SecurityWeek)

Vulnerability
Help Net Security

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil a... (Help Net Security)

Scam
Infosecurity Magazine

Infostealers Harvest 1.7 Billion Credentials in Six Months

Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026 (Infosecurity Magazine)

Scam
The Register - Security

Black Hat and DEF CON are AI conferences now, too

On this week's episode of The Reg's Kettle podcast, we revisit 'hacker summer camp,' where the hottest topic was ... sigh... agentic AI (The Register - Security)

AI
Malwarebytes Labs

A week in security (August 10 - August 16)

A list of topics we covered in the week of August 10 to August 16 of 2026 (Malwarebytes Labs)

Cloud Security
The Register - Security

Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; South Korea to fine Apple, Google; India bans some rideshare tips; and more! (The Register - Security)

Breach AI
Help Net Security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or m... (Help Net Security)

Cloud Security
Risky Business News

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

In other news: Hackers breach France's tax agency; GeoServer zero-day exploited hours after disclosure; exploit unlocks old AMD CPUs with one instruction. (Risky Business News)

Vulnerability Breach
The Register - Security

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service (The Register - Security)

Azure AI
Chainguard Unchained

This Shit is Hard: Patching a vulnerability that has no fix

Generating an AI security patch is easy. Trusting it is hard. Learn how Chainguard proves zero-day fixes are safe before they ship. (Chainguard Unchained)

Vulnerability AI
Chainguard Unchained

Proven, not promised: Chainguard Containers achieves SLSA Build Level 3

Coalfire independently assessed Chainguard Containers at SLSA Build Level 3, validating hardened builds, provenance, and supply chain integrity. (Chainguard Unchained)

Supply Chain

August 16, 2026 · 8 articles

Security Affairs

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI in... (Security Affairs)

AI
BleepingComputer

Large-scale DDoS attacks disrupted Threema secure messaging service

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...] (BleepingComputer)

Cloud Security
Security Affairs

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mu... (Security Affairs)

Cloud Security
BleepingComputer

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively c... (BleepingComputer)

Cloud Security
The Register - Security

Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do

Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power' (The Register - Security)

AI
Security Affairs

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached Franc... (Security Affairs)

Breach Threat Research
Security Affairs

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just doc... (Security Affairs)

Threat Research
StepSecurity Blog

ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

ChainDrop npm worm: 444 packages and 2,212 versions poisoned, starting with keyv@6.0.0. Payload analysis, affected package list, IOCs, and remediation steps. (StepSecurity Blog)

Scam

August 15, 2026 · 4 articles

Security Affairs

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,00... (Security Affairs)

Vulnerability Scam
The Register - Security

ChainDrop worm crawls into npm supply chain, evades standard defenses

Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks (The Register - Security)

Supply Chain
Security Affairs

GeoServer Zero-Day Is Already Being Probed. That’s the Problem

GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already... (Security Affairs)

Vulnerability Breach
Tenable Blog

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed... (Tenable Blog)

AI

August 14, 2026 · 4 articles

Rapid7 Blog

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pte... (Rapid7 Blog)

Cloud Security
Schneier on Security

Friday Squid Blogging: Searching for the Colossal Squid

Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is mo... (Schneier on Security)

Cloud Security
Orca Security Blog

Agentic AI Security: Risks, Controls & Framework

Key Takeaways Agentic AI security is the practice of bounding what an autonomous AI system may do once it starts reasoning toward a goal, calling tools, reading the results, and... (Orca Security Blog)

AI
Dark Reading

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the... (Dark Reading)

Vulnerability AI