BLOG 2026 AUGUST 2026 2025 2024 2023
AI blog APT blog Attack blog BigBrother blog BotNet blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blog
2026 January(89) February(123) March(106) April(119) May(126) June(97) July(101) August(348) September(0) October(0) November(0) December(0)
DATE |
NAME |
Info |
CATEG. |
WEB |
|
31.8.26 |
Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack | Recently, we've been interested in how AI is impacting the attack surface, so we started researching AI-assisted vulnerability discovery and AI-targeted technologies for our 1H-2026 State of Exploitation report. | AI blog | VULNCHECK |
|
31.8.26 |
45% of American Research Universities Expose Computing Infrastructure | The standard story about higher education cybersecurity is that it’s target-rich and cyber-poor: a sprawling, underfunded sector where the weakest links are the community colleges and cash-strapped campuses without the budget for a real security program. This study finds the opposite pattern. | Incident blog | FLARE.IO |
|
31.8.26 |
Anthropic Links Claude Session Theft to Infostealer Malware | An affected Claude user has shared a warning from Anthropic stating that infostealer malware can steal active Claude login sessions from infected computers. Attackers can reuse these sessions to access accounts and consume available usage without completing the normal sign-in process again. | Malware blog | |
|
31.8.26 |
Finnish Kennel Club, Shell Access, UK Iframe, Salt Mobile, and Brazil SERPRO Claims | SOCRadar Dark Web Team identified several new underground posts, including an alleged Finnish Kennel Club and Showlink dog-show database leak, and a separate initial access listing offering shell and WordPress access to websites in Indonesia and Romania. | CyberCrime blog | |
|
31.8.26 |
ServiceNow Patches Multiple CVSS 10.0 Flaws | ServiceNow disclosed four vulnerabilities affecting its AI Platform and related Now Platform components on August 27, 2026. Three received vendor-assigned CVSS v4.0 scores of 10.0, while a fourth was rated 8.7 High. | Vulnerebility blog | |
|
31.8.26 |
PaperCut RCE Chain: CVE-2026-82078 Exploited | PaperCut disclosed two vulnerabilities in PaperCut NG and PaperCut MF that can be chained into a pre-authentication Remote Code Execution (RCE) path against vulnerable Application Servers. | Vulnerebility blog | SOCRADAR |
|
31.8.26 |
Introducing the Aur0ra Ransomware Group | During a recent incident response engagement for an external organization, the BHIS ActiveSOC team investigated activity attributed to the Aur0ra ransomware group. In this incident, initial access was gained through vishing following aggressive email bombing. This foothold was followed up by the deployment of a unique C2 mechanism with noisy lateral movement & ransomware attempts. | Ransom blog | BLACKHILLS |
|
31.8.26 |
Carry-On Compromise: TA4922 Packs PackClient | Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is being used by at least one threat actor, Chinese-speaking TA4922, and appears to be actively sold on Telegram. | APT blog | PROOFPOINT |
|
31.8.26 |
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem | Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets. | Malware blog | GROUP-IB |
|
31.8.26 |
Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation | Gambit Security’s Threat Intelligence team investigates emerging attacker tradecraft and the evolving ways threat actors disrupt organizations. As part of this research, we track threat actors and their operations to identify new techniques, tooling, and approaches to disruption. | Ransom blog | GAMBIT SECURITY |
|
30.8.26 |
TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. | Malware blog | Microsoft blog |
|
29.8.26 |
ZeroTokens: Phishing Platform Gives Operators Real-Time Control of Attack Flow |
ZeroTokens supports impersonation of 53 financial institution brands to collect credentials, identity data, payment details, and verification codes. |
||
|
29.8.26 |
CRPx0 is a ClickFix-delivered ransomware-as-a-service operation whose lures impersonate Windows and macOS update prompts and reCAPTCHA checks to trick victims into running a copied command. |
|||
|
29.8.26 |
|
LLM security testing for pentesters: map attacks to the OWASP LLM Top 10, break a vulnerable MCP server locally, and turn what you find into regression tests. Including solutions for enterprise scale. |
||
|
29.8.26 |
The August 2026 security release is now available. Upgrade to 16.3.3 (Active LTS) or 15.5.24 (Maintenance LTS) now to address two Critical severity vulnerabilities. |
|||
|
29.8.26 |
Next.js is moving the August security release forward to August 25, 2026. |
|||
|
29.8.26 |
The AI CVE exploitation evidence story: Headlines are scarier than reality |
Expel's vulnerability intel team is currently monitoring 1,250+ CVEs related to 50 unique AI vendors; here's what we think you should know. |
||
|
29.8.26 |
Security teams have more data than ever before, but less time to act on it. Over the past several years, Cymulate has continued to evolve continuous exposure validation beyond attack simulation. We've expanded the platform to help organizations continuously validate their security controls, prioritize vulnerabilities to support continuous threat exposure management (CTEM), auto-mitigate with vendor-specific remediation and accelerate security operations with agentic AI. |
|||
|
29.8.26 |
When Monitored Content Strikes Back: Account Takeover in Microsoft Purview |
Microsoft Purview is built to catch dangerous messages. But what happens when the message fights back? Cymulate Research Labs found that a single external Teams message, email or Copilot prompt could carry stored malicious code into a Purview reviewer’s authenticated browser - turning a routine compliance check into a path to token theft and account takeover. |
||
|
29.8.26 |
What is new is the speed at which AI can discover, test and help weaponize those vulnerabilities. Frontier cyber models such as Mythos mark a shift in attacker economics. The limiting factor is no longer only expertise. It is orchestration. |
|||
|
29.8.26 |
Cymulate Cowork: Engineering Cyber Defenses at Machine Speed |
Security teams feel the squeeze of AI across threats, CVE discovery and weaponization. It’s time for AI to give cyber defenders an advantage by integrating validation into automated workflows that filter out the noise and build stronger defenses. |
||
|
29.8.26 |
Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More |
TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms. |
||
|
29.8.26 |
TrendAI™ Advances Threat Hunting to Dynamic, Real-World Exploitation of AI Infrastructure |
The new threat hunting component of the TrendAI™ agentic exploit-remediation engine, code name AESIR, extends visibility beyond vulnerability disclosure. Its first published |
||
|
29.8.26 |
The TrendAI™ agentic exploit-remediation engine, code name AESIR, ranks first on CyberGym at 97% — more than 12 points ahead of both GPT-5.6 Sol and Claude Mythos 5. |
|||
|
29.8.26 |
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft. |
|||
|
29.8.26 |
Mobile Fraud in 2026: Malware is Actively Targeting Mobile Banking Apps in LATAM |
Our most recent malware threat research from Zimperium’s zLabs research team revealed 34 malware families targeting 1,243 mobile banking and fintech apps across 90 countries globally. |
||
|
29.8.26 |
Video Call Exploit Chain Exposes Android Devices to Kernel-Level Access |
In a story recently reported by Dark Reading, researchers demonstrated how two vulnerabilities in Unisoc T612 modem firmware can be chained to gain privileged access to the Android kernel. The attack involves delivering a malicious payload to the modem and placing a video call that, if answered, triggers the exploit, highlighting how cellular modems can provide a remotely reachable attack surface for mobile devices. |
||
|
29.8.26 |
WindRelay Combines NFC Relay Malware and Remote Access for Mobile Fraud |
A recent analysis reveals WindRelay, a new Android NFC relay malware deployed alongside the SpyNote remote access trojan to enable sophisticated mobile fraud. Attackers use live social engineering calls to convince victims to install a personalized RAT, then remotely deploy WindRelay without additional user interaction. |
||
|
29.8.26 |
That's becoming increasingly important as AI coding assistants and agents accelerate development. More code can move into review, testing, security, integration, and deployment faster than those processes can absorb it, leading to more output but not necessarily more delivery. |
|||
|
29.8.26 |
A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. |
|||
|
29.8.26 |
Cambodia-focused cluster uses multistage infection chain with localized lures |
Acronis’ Threat Research Unit (TRU) identified a recent campaign focused on Cambodia. The analyzed archives, discovered while hunting for related activity, use several lure themes, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers. |
||
|
29.8.26 |
The first in CloudSEK's "Caught in 4K" series, where we pull ransomware operations out of the shadows and show exactly how they work. A misconfigured server opened a window straight into an Aurora ransomware operator's playbook: attacker tools, AI-assisted planning, and a look inside the actual negotiation panel where a victims and the operator settled on payment. |
|||
|
29.8.26 |
Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database |
Active Directory Certificate Services (ADCS) has emerged as one of the most significant and under-monitored attack surfaces in enterprise Windows environments, as documented by SpecterOps. After observing certificate-based privilege escalation techniques being actively exploited in several cases that the GuidePoint |
||
|
29.8.26 |
Making AI/ML-driven Active Cyber Defense Work in OT Environments |
You already have the data. That’s not the problem. Yet unified visibility implementations often fail before they even get off the ground. Before reaching for AI/ML-driven Active Cyber Defense to solve Operational Technology (OT) visibility and monitoring challenges, it’s critical to pause and make sure you’re not repeating the mistakes of the past. |
||
|
29.8.26 |
TL;DR – Play (aka PlayCrypt) is a successful threat actor that employs double extortion techniques against its victims in North and South America and Europe. Understand what it does and why its techniques have been successful thus far. |
|||
|
29.8.26 |
On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. |
|||
|
29.8.26 |
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs |
Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. |
||
|
29.8.26 |
In part 1 of this series, on discovering and mapping Copilot Studio agents in the wild, we took a close look at how active discovery and capability mapping for agents could play out. |
|||
|
29.8.26 |
It's Always DNS in Claude’s Sandbox: From Data Exfiltration to a Bidirectional DNS Shell |
In this blog, we’ll showcase how we were able to exploit a DNS functionality in Claude’s sandbox to create both a data exfiltration channel, and bidirectional shell. This whole attack chain rests on the overlooked DNS channel: although HTTP and HTTPS traffic are correctly blocked by egress filters, DNS resolution happens before those filters can intervene. |
||
|
29.8.26 |
Indirect prompt injection: How attackers manipulate AI agents through untrusted data |
An employee asks an AI agent to analyze a document. Hidden inside that content is an instruction written for the agent rather than the user. |
||
|
29.8.26 |
How Nokian Tyres found a cybersecurity partner it could trust |
Learn how Nokian Tyres improved email security, gained threat visibility and built a trusted cybersecurity partnership with Barracuda. |
||
|
29.8.26 |
Barracuda Research highlights recent SOC findings on GlobalProtect scanning, credential harvesting, firewall misconfigurations, and abuse of trusted remote access software. |
|||
|
29.8.26 |
Ransomware leak sites have become a prominent feature of modern cyber extortion campaigns, publishing claims about breached organizations and stolen data. This article explains how leak sites work and how to use them to assess risk, monitor threat activity and make better-informed security decisions. |
|||
|
29.8.26 |
On 26 August 2026, the Australian Federal Police charged two West Australian men over their alleged roles in a cybercrime syndicate that inserted malicious code into open-source software used by thousands of organizations worldwide. Both men appeared in Perth Magistrates Court the following day. |
|||
|
29.8.26 |
OpenAI is calling for a global surge in cyber defense as AI-enabled attacks become more widespread and sophisticated. The call to action raises a practical question for defenders: if attackers gain more capable AI, how can organizations, governments, security providers, and frontier AI companies make sure defensive tools, verified fixes, and threat intelligence reach the teams that need them most? |
|||
|
29.8.26 |
WhatsApp Says One Billion Users Are Now Protected by Passkeys |
The milestone signals that phishing-resistant authentication has moved into the consumer mainstream, while new controls target registration code theft and scam calls. |
||
|
29.8.26 |
GTA VI has been slipping out from behind Rockstar’s usually airtight walls in daily doses. An anonymous figure calling itself CyberLeek has been releasing gameplay clips, map images, and increasingly bold demands, turning what should have been a tightly controlled marketing rollout into one of the messiest leak sagas gaming has seen in years. |
|||
|
29.8.26 |
A critical vulnerability chain tracked as CVE-2026-18431 affects the Avada WordPress theme and its required Fusion Builder plugin, now branded as Avada Builder. The flaw carries a CVSS score of 9.8 and can allow an unauthenticated attacker to write and execute arbitrary PHP files, potentially leading to complete site compromise. |
|||
|
29.8.26 |
The Qilin Ransomware group listed the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) on its Dark Web leak site on August 26, 2026, the same day the agency publicly confirmed a cybersecurity “major incident” affecting a standalone system. |
|||
|
29.8.26 |
On 26 August 2026, the Australian Federal Police charged two West Australian men over their alleged roles in a cybercrime syndicate that inserted malicious code into open-source software used by thousands of organizations worldwide. Both men appeared in Perth Magistrates Court the following day. |
|||
|
29.8.26 |
Imobiliare.ro, Klark.ai, Fortinet VPN, E-Commerce Skimming, and Solimut SQLi |
SOCRadar Dark Web Team identified several new underground posts involving alleged database leaks, exposed remote access, and access-for-sale activity. The findings include an alleged Imobiliare.ro user database sale, administrative Fortinet SSL-VPN access tied to a UAE hotel reservation firm, an alleged Klark.ai data leak, a U.S. e-commerce iframe skimming operation, and alleged SQL injection access affecting Solimut Mutuelle de France. |
||
|
29.8.26 |
Cisco released security updates for Cisco Crosswork and Cisco Secure Workload, addressing nine vulnerabilities across the two product families. |
|||
|
29.8.26 |
GitLab has patched CVE-2026-19478, a critical code injection vulnerability affecting self-managed Community Edition (CE) and Enterprise Edition (EE) instances. Under certain conditions, an unauthenticated remote attacker could leverage a GraphQL directive to modify or delete public projects and user data. |
|||
|
29.8.26 |
Microsoft recently disclosed CVE-2026-69836, a critical Remote Code Execution (RCE) vulnerability in Microsoft Entra ID (formerly Azure Active Directory). Because this issue affected a Microsoft-hosted cloud service, remediation was applied on the backend rather than through a traditional customer patch. |
|||
|
29.8.26 |
A ShinyHunters-associated leak site listed ReliaQuest on August 23, 2026, raising questions about a potential data extortion attempt against the cybersecurity provider. |
|||
|
29.8.26 |
The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosystem specifically engineered to disable Apple’s Activation Lock on stolen devices. |
|||
|
29.8.26 |
How to build an exposure management program the business trusts: Lessons from Tenable’s CSO |
Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand. |
||
|
29.8.26 |
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. |
|||
|
29.8.26 |
The implant beacons hit the sinkhole as soon as we stood it up. Hundreds of routers, almost all in China, beaconing home to a forgotten domain. We found the domain obfuscated in the firmware of a router we bought on Amazon from a small company in New York. Now, we own the domain. We own the implants. |
|||
|
29.8.26 |
What CISA's FY2024-2025 Vulnerability Review Means for Runtime Security |
CISA's new Vulnerability Review for Fiscal Years 2024 and 2025 opens by correcting a widely held assumption. Cybersecurity conversations naturally gravitate toward nation-state adversaries and novel zero-days, but most compromises have not relied on advanced techniques. |
||
|
29.8.26 |
ERMAC and HookBot are two branches of one Android banking trojan sold as a service. They forked from a shared code base and each evolved in the direction its developers took it, but the core they run is close enough that a single constant in the source decides which name the panel shows. |
|||
|
29.8.26 |
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption |
A misconfigured open directory on 86.53.111[.]212:8080 exposed critical details of active cybercrime operator, including Moobot botnet source code, other denial of service (DOS) tools with attack records, and a fraudulent identity verification service – providing a rare view of a malicious operation in progress. |
||
|
29.8.26 |
For five days in March 2026, a single stolen token let one group poison five software ecosystems including a package downloaded 95 million times a month. The attack started with a misconfigured GitHub Actions workflow, and ended with backdoored code sitting inside CI/CD pipelines around the world. |
|||
| 29.8.26 | July 2026 Threat Trend Report on APT Attacks (South Korea) | Overview AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the classification, statistics, and functional characteristics for each type of domestic APT attacks identified during the month of July 2026. | APT blog | Zscaler |
| 29.8.26 | Gryxa: The AI-Built Toolkit That Watches How You Remove It | ReliaQuest has identified a new toolkit, dubbed “Gryxa,” used by a financially motivated threat actor across 324 listed hosts. We assess that substantial portions were almost certainly built with a commercial AI coding agent, which appears as co-author on most commits in the actor's public repository. This marks the first time ReliaQuest has observed a threat actor use AI to help build and execute an entire operation to this extent. | Malware blog | RELIAQUEST |
| 29.8.26 | Insights into Suspected DPRK Workers: Red Flags to Look Out For | North Korean (DPRK) remote IT workers (sometimes referred to as FAMOUS CHOMILLA) continue to pose a prolific threat to global organisations. DPRK-aligned operatives use fake or stolen identities to get hired at companies before sending their wages back to North Korea's regime, stealing data, or planting malware. | APT blog | Huntress |
| 29.8.26 | The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms | As more people use AI models such as Claude, ChatGPT, Grok, and Gemini, threat actors are abusing trusted AI platforms in a variety of ways to trick users into downloading malware. | AI blog | Huntress |
| 29.8.26 | BlueDelta Targets Defense and Diplomacy with HOOKEDGE | Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. | APT blog | Recorded Futures |
| 29.8.26 | Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy | Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now clear most alerts with a single click in Slack. | AI blog | ELASTIC |
| 29.8.26 | Not another Log4Shell: inside the Log4j 2 deserialization allowlist bypass | We reproduced this java deserialization vulnerability against official Log4j 2.26.1 JARs. Getting to command execution took two more things that Log4j itself does not ship. Here is how the bypass works, which versions carry it, and what to hunt for. | Vulnerebility blog | ELASTIC |
| 29.8.26 | Carry-On Compromise: TA4922 Packs PackClient | Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is being used by at least one threat actor, Chinese-speaking TA4922, and appears to be actively sold on Telegram. PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads. | APT blog | PROOFPOINT |
| 29.8.26 | TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. | APT blog | PROOFPOINT |
| 29.8.26 | Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 | The Russia-aligned threat actor TA458, the group behind Operation RoundPress, continues to focus on webmail targeting using half-click exploits as a way to steal highly sensitive email data. | APT blog | PROOFPOINT |
| 29.8.26 | From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO | Learn how cyber risk quantification helps CFOs measure financial exposure, assess business impact, and prioritize security investments. | Cyber blog | Cyble |
| 29.8.26 | 9Router Tailscale Install Endpoint Unauthenticated OS Command Injection | SonicWall Capture Labs threat research team became aware of the threat CVE-2026-59800, assessed its impact, and developed mitigation measures. The flaw, also known as the 9Router Tailscale Install Endpoint Unauthenticated OS Command Injection, is a critical vulnerability affecting the 9Router AI request proxy (decolua/ | Hacking blog | SonicWall |
| 29.8.26 | Efimer Brings Its Own Tools to the Job | This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of Efimer malware. This is a Python-based executable compiled with PyInstaller and protected with PyArmor to obfuscate the many libraries and payloads that are packed within. | Malware blog | SonicWall |
| 29.8.26 | The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution | To assess the impact of AI-enabled malware, we collected and analyzed over 400 malware samples that integrate AI in some capacity, from brand impersonation and large language model (LLM)-generated code to agentic execution loops. Our central finding was that the AI malware space is currently overwhelmingly composed of proof-of-concept code, security validation testing and researcher submissions that have never reached a production environment. | AI blog | Palo Alto |
| 29.8.26 | The safety penalty: Reclaiming operational sovereignty in the age of AI | As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries. | AI blog | CISCO TALOS |
| 29.8.26 | “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend | In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage. | Hacking blog | CISCO TALOS |
| 29.8.26 | JavaScript obfuscation: From party trick to phishing kit | Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem. | Phishing blog | CISCO TALOS |
| 29.8.26 | Choose your fighter: Balancing competing requirements to select models for your AI SOC | Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose. | AI blog | CISCO TALOS |
| 29.8.26 | AI-driven OSINT in the wrong hands – and why everyone could be a target for fraud | It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control. | AI blog | Eset |
| 29.8.26 | No Privileges, No Lockout, No Trace: Kerberoasting with SPN Misconfigurations | This blog will walk through the complete kill chain: an attacker enumerates domain-wide SPNs, identifies a vulnerable user account, and silently requests a Kerberos Ticket Granting Service (TGS) ticket encrypted with the weak RC4-HMAC algorithm. | Hacking blog | TRELLIX |
| 27.8.26 | ASIC Sounded the Alarm. Mobile is Where the Attack Starts. | On May 8, Commissioner Simone Constant of the Australian Security Investments Commission (ASIC) sent an open letter directly to every bank, superannuation fund, insurer, and financial services licensee in Australia. Not a report. Not a consultation. A direct instruction to boards and risk committees demanding urgent action on AI and cyber risk. Here's the full threat picture every CISO needs to add to that conversation. | Security blog | ZIMPERIUM |
| 27.8.26 | Mobile Banking Fraud 2026: Malware is Actively Targeting Mobile Banking Apps in Europe, Middle East & Africa | Our most recent malware threat research from Zimperium’s zLabs research team revealed 34 malware families targeting 1,243 mobile banking and fintech apps across 90 countries globally. | Malware blog | ZIMPERIUM |
| 27.8.26 | TrendAI™ Advances Threat Hunting to Dynamic, Real-World Exploitation of AI Infrastructure | The new threat hunting component of the TrendAI™ agentic exploit-remediation engine, code name AESIR, extends visibility beyond vulnerability disclosure. Its first published investigation links over a year of honeypot data to the LF3 loader framework. | Exploit blog | Trend Micro |
| 27.8.26 | Mapping AI detections to MITRE ATLAS: How Expel does it | AI-related detections in Expel Workbench™ carry MITRE ATLAS tactic and technique labels alongside the ATT&CK labels our analysts already use. | AI blog | Expel |
| 27.8.26 | Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident | Chinese cybercrime group, GoldenEyeDog, has been regularly updating their malware and tactics since 2015. We’ve observed them regularly leveraging code-signing certificates to bypass Windows’s SmartScreen since 2024. | APT blog | Expel |
| 27.8.26 | Inside China-nexus cyber espionage infrastructure | Black Lotus Labs and the FBI uncovered China-nexus infrastructure used to hide cyber espionage, showing how early detection helps protect customers. | APT blog | LUMEN |
| 27.8.26 | LLM security testing: how to pentest LLMs and MCP servers | LLM security testing for pentesters: map attacks to the OWASP LLM Top 10, break a vulnerable MCP server locally, and turn what you find into regression tests. Including solutions for enterprise scale. | AI blog | ESCAPE.TECH |
| 27.8.26 | Cambodia-focused cluster uses multistage infection chain with localized lures | Acronis’ Threat Research Unit (TRU) identified a recent campaign focused on Cambodia. The analyzed archives, discovered while hunting for related activity, use several lure themes, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers. | Hacking blog | ACRONIS |
| 27.8.26 | Making AI/ML-driven Active Cyber Defense Work in OT Environments | You already have the data. That’s not the problem. Yet unified visibility implementations often fail before they even get off the ground. Before reaching for AI/ML-driven Active Cyber Defense to solve Operational Technology (OT) visibility and monitoring challenges, it’s critical to pause and make sure you’re not repeating the mistakes of the past. | AI blog | GUIDESECURITY |
| 27.8.26 | The roqueue-tools DevFlow campaign: 2 fake project-flow extensions that fetch JavaScript from a DuckDNS host and run it | Two project-flow extensions sit quietly for five minutes after you open your editor. The Kanban board renders, the webview loads, everything looks like a normal project-management tool. Then, once the IDE has settled and the developer has moved on to something else, a setTimeout fires. The extension reaches out to a free DuckDNS subdomain over plain HTTP, grabs a JavaScript file, and runs it with new Function. | Hacking blog | YEETH SECURITY |
| 27.8.26 | How Play Achieves Encryption | GuidePoint Security analysts are often called to support and consult on Digital Forensics and Incident Response (DFIR) efforts in remediation, recovery and forensic analysis of ransomware events. Play (also tracked as PlayCrypt) is a ransomware group that has been active since June 2022. Thus far, Play has claimed hundreds of victims across North America, South America and Europe. | Ransom blog | GUIDESECURITY |
| 27.8.26 | Exploiting SMTP with Unicode Bidi Override Spoofing: The Gap Between Auth & Render | Security Joes researchers, led by Red Team Lead Anna Breeva, discovered a new email spoofing technique that abuses Unicode bidirectional (Bidi) controls together with SMTPUTF8 to make an attacker-controlled email address visually appear to belong to a trusted domain. | Exploit blog | Security Joes |
| 27.8.26 | Why Financial Services Is the Canary in the Code Mine | Organizations have long known that attackers publish malicious packages to public open source registries. The more consequential question is if those packages are actually reaching enterprise development environments. | Security blog | SONATYPE |
| 27.8.26 | Email Bombing and Quick Assist: A New Ransomware Playbook | The email bomb was not just noise. It was the setup. The attacker manufactured the problem, waited for the frustration to become impossible to ignore, and then arrived as the person who could "fix" it. | Ransom blog | ZEROBEC BLOG |
| 27.8.26 | Lookalike Domains Are an Identity Problem | Powerful brands elicit a feeling of trust, a promise of service delivered, and an expectation of what you will get. Adversaries take advantage of that powerful connection as a means to collect username and password pairs for account takeover and payment card information for financial fraud. With AI and pre-built phishing kits, little technical skill is needed, which compresses the time between registering a lookalike domain and launching it as an active impersonation of your legitimate one. | AI blog | FLARE.IO |
| 27.8.26 | NHI Security: Is an Agent Just a Bot with PR? | I’ve recently spent time at identity-focused conferences and couldn’t miss all the messaging about agentic solutions. It got me thinking: agents are just bots with a better PR team. For over a decade, “bot” has been a dirty word. Botnets. Credential-stuffing bots. Bot traffic you pay to filter out. There is an entire security category designed to mitigate the impact of bots. And now, bot traffic now outnumbers human traffic. | Security blog | FLARE.IO |
| 27.8.26 | What the ERMAC Source Leak Says About HookBot | One code base, two names, and the panel artifacts that outlast a rebrand | Spam blog | CENSYS |
| 27.8.26 | Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | VulnCheck’s Initial Access Intelligence team shipped an exploit last week chaining two recently disclosed Microsoft SharePoint CVEs that, when used together, allow a remote unauthenticated adversary to bypass authentication and execute code on vulnerable target SharePoint servers. | Vulnerebility blog | VULNCHECK |
| 27.8.26 | Tenable & SentinelOne: 93 CVEs Expose Edge Risk | A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. | Vulnerebility blog | TENABLE |
| 27.8.26 | Response Orchestration: Automated Action on Your Terms | The security industry has spent years working on better detection. Threat intelligence is richer than it has ever been. Signals are correlated faster. AI is solving the discovery problem in a way that doesn't require hours from senior analysts to deliver insight. Detection has genuinely improved. | AI blog | ESENTIRE |
| 27.8.26 | Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities | Disclosure note: Hunt.io disclosed these findings to CERT-PH under TLP:AMBER and, following responsible disclosure, held publication until August 25, 2026. CERT-PH coordinated notification to the affected organizations. | APT blog | HUNT.IO |
| 27.8.26 | Agentic SOC alert triage: 60% to 92% AI accuracy | Elastic's InfoSec team runs three agents that read the detection rule's investigation guide and the closure reasons on 30 days of past cases. Analysts now clear most alerts with a single click in Slack. | Security blog | ELASTIC |
| 27.8.26 | Tortoiseshell: New Toolset and Operational Infrastructure Exposed | Group-IB Threat Intelligence performed enrichment and APT hunting based on recent public data about the Tortoiseshell APT group, leading to the discovery of new samples sharing similarities with known Tortoiseshell malware and additional operational infrastructure. | APT blog | GROUP-IB |
| 26.8.26 | A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign | As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States. | CyberCrime | ANYRUN BLOG |
| 26.8.26 | US Finance Under Phishing Pressure: What the SOC Data Reveals? | With modern campaigns such as Vercel-hosted RMM attacks, the scale and security impact of phishing in US finance should not be understated. As threats get increasingly harder to detect, the phishing challenge raises the stakes in the industry. | Phishing | ANYRUN BLOG |
| 26.8.26 | How a Google Search for Claude Led to MacSync | Picture this: You've just unboxed a shiny new Macbook, and now you're downloading all of your favorite apps. You type "How to install Claude Code on a Mac" in Google and click on the first link at the top of the page. | AI | ANYRUN BLOG |
| 26.8.26 | Response Orchestration: Automated Action on Your Terms | The security industry has spent years working on better detection. Threat intelligence is richer than it has ever been. Signals are correlated faster. AI is solving the discovery problem in a way that doesn't require hours from senior analysts to deliver insight. Detection has genuinely improved. | Cyber | ESENTIRE |
| 26.8.26 | TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. | APT | PROOFPOINT |
| 26.8.26 | Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking | Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities. | Phishing | GROUP-IB |
| 26.8.26 | UK Power Facility Cyberattack Shutdown: What Critical-Infrastructure Operators and Defenders Need to Know | A reported cyberattack on a UK power-generation facility in July 2026 shows that even disruptions at a single site can raise broader questions about critical infrastructure resilience. | BigBrother blog | Trend Micro |
| 26.8.26 | The Architecture Behind $1B: How Customers Run TrendAI Vision One™ on AWS, and Secure Their AI Workloads | TrendAI™ has surpassed $1 billion in AWS Marketplace sales, one of a select group of AWS independent software vendors (ISVs) ever to cross that line. Behind that number are more than 2,900 private offers, and thousands of security teams who closed real gaps faster because buying never slowed them down: | AI blog | Trend Micro |
| 26.8.26 | Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant | TrendAI™ Research provides a comprehensive analysis of the RedC2 Linux Implant, a sophisticated threat recently discovered in the npm open-source ecosystem. | AI blog | Trend Micro |
| 22.8.26 | Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns | Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios. | Hacking blog | WIZ.IO |
|
22.8.26 |
UNISOC T612 LPE | Summary UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme, | Security blog | SSD-DISCLOSURE |
|
22.8.26 |
Linux Bridge STP Timer Use-After-Free | Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, | OS Blog | SSD-DISCLOSURE |
| 22.8.26 | Device Code Phishing Up 1500% | In a story recently reported by Dark Reading, Crowdstrike researchers found that device code phishing and voice phishing (vishing) attacks have more than doubled as cybercriminals increasingly combine phone calls with mobile authentication workflows to trick users into approving fraudulent device authentication requests, enabling corporate network access. | Phishing blog | ZIMPERIUM |
|
22.8.26 |
The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile | The zLabs team recently identified an updated variant of ToxicPanda, the Android banking Trojan known to have primarily targeted Europe, that introduces significant enhancements, including a comprehensive command set of 167 remote commands and substantially expands its targets globally. | Malware blog | ZIMPERIUM |
|
22.8.26 |
GoldDigger Malware Demonstrates Advanced Mobile Banking Threats | A recent analysis highlights GoldDigger, an Android malware family designed to steal financial information and facilitate fraudulent activity on compromised devices. The malware abuses accessibility services to monitor user activity, capture credentials, and interact with banking applications while operating with limited visibility to the victim. | Malware blog | ZIMPERIUM |
| 22.8.26 | Mobile Ad Fraud Scheme Uses Automation to Mimic Human Behavior | A recent investigation uncovered Papyrus, a mobile ad fraud operation designed to generate fraudulent engagement by imitating legitimate user behavior. The scheme uses Android apps to produce automated clicks, scrolling, and other interactions that appear human, allowing fraudulent activity to blend into normal mobile traffic. By manipulating engagement signals rather than relying on obvious malicious actions, these techniques can make detection more difficult. | Malware blog | ZIMPERIUM |
|
22.8.26 |
Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. | CloudSEK has published the victim list from Team PCP's supply chain campaign: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations over five days in March 2026. StepSecurity's research team has tracked this threat actor across the Trivy, telnyx, and LiteLLM compromises. | Hacking blog | STEPSECURITY |
|
22.8.26 |
Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper | A compromised maintainer account and a same-day impersonator of one of Rust's best-known authors turned a routine cargo update into silent remote code execution. Three crates from the same owner were poisoned in 23 minutes (arrayref, internment, and append-only-vec), alongside six attacker-owned crates now deleted from crates.io. | Security blog | STEPSECURITY |
| 22.8.26 | AI-Agent-Driven Offensive Operation : Exposed Adversary Open Directory Reveals Autonomous Crypto-Theft Campaign Leading to Mass Wallet and Credential Compromise | CloudSEK uncovered a Chinese-speaking threat operator using autonomous AI coding agents to scale cyberattacks, including mass WordPress compromise, cryptocurrency wallet theft, credential harvesting and cryptojacking. The exposed infrastructure also revealed a developing blockchain-based command-and-control system designed to make future operations more resilient to takedowns. | AI blog | CloudSEK |
|
22.8.26 |
BRIDGEHEAD : An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer | CloudSEK’s BRIDGEHEAD investigation exposes a 40-package npm typosquatting campaign that abuses WSL to reach Windows hosts and deploy a concealed Rust-based stealer. The malware targets cryptocurrency wallets, browser credentials, cookies and Telegram sessions, while executing largely in memory and using public infrastructure for reconnaissance and exfiltration, making detection and takedown significantly harder. | Cryptocurrency blog | CloudSEK |
|
22.8.26 |
PWNBench-v0.1: Evaluating frontier models for web application pentesting | We benchmarked 11 frontier LLMs on real-world web app pentesting. See which AI models lead in recall, precision, and cost efficiency in PWNBench-v0.1. | AI blog | NOVEE |
| 22.8.26 | Bird Watching: Characterizing the Infrastructure and Behavior of Falcon-branded Extortion Operations | Increased attention has been called to a sustained adversary-in-the-middle (AitM) phishing and vishing operation targeting financial services, professional services, energy and technology organizations since at least April 2026. This activity aligns with the threat cluster publicly designated UNC6671 by Google Threat Intelligence Group and O-UNC-045 / CORDIAL SPIDER by Okta Threat Intelligence, operating under extortion brands including Falcon, Helix, Pink and Redact (formerly BlackFile). | APT blog | GUIDESECURITY |
|
22.8.26 |
Beware the Ransomware Rescuer: Ransom Busters | The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” | Ransom blog | GUIDESECURITY |
| 22.8.26 | CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway | On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. | Vulnerebility blog | RAPID7 |
|
22.8.26 |
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America | Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces. | Cyber blog | RAPID7 |
| 22.8.26 | New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles | The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. Success going forward can’t be about patching as much as possible - it has to be about understanding what matters most and reducing the exposures attackers can actually reach. | AI blog | RAPID7 |
|
22.8.26 |
Copilot for KeyBank — a 3 KB VSIX that beacons through github-cdn.net and waits for eval | A new VS Code extension called “Copilot for KeyBank” went live on the Microsoft Visual Studio Marketplace in August 2026. The publisher is verified, the display name on the marketplace is “Deep Seek”, and the package name is verified.pypi-keyBank. None of those brand names — GitHub Copilot, DeepSeek, PyPI, KeyBank — have anything to do with this extension. They are all cover. | AI blog | YEETH SECURITY |
|
22.8.26 |
The heyheyhey campaign: 6 fake Roblox VS Code extensions that fetch and run a remote script from GitHub | A Kanban board for Roblox developers sounds harmless enough. Six of them hit the Microsoft VS Code Marketplace over three days in June 2026, all from different publishers, all with names like RoFlow, RoPilot, and ManageBlox. The boards work — they render a webview, they show columns, they look like a project tool. That is the cover. | Hacking blog | YEETH SECURITY |
| 22.8.26 | SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon | Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click. | AI blog | VARONIS |
|
22.8.26 |
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower | See how meta-hacking got Microsoft Copilot to snitch on itself, exposing CoSnitch, a one-click flaw that silently exfiltrates data. | AI blog | VARONIS |
|
22.8.26 |
Critical infrastructure security Is back in the headlines | Recent cyber threats affecting water infrastructure and industrial control systems have renewed attention on the cybersecurity challenges facing critical infrastructure across the United States. This article examines emerging risks to water utilities, proposed legislation aimed at improving resilience and the ongoing debate over how critical infrastructure security should be funded and managed. | Vulnerebility blog | BARRACUDA |
| 22.8.26 | Threat Spotlight: The average web application has 20 security vulnerabilities | Barracuda research finds the average web application has 20 security vulnerabilities. Learn the seven most common flaw types and how to reduce risk. | Vulnerebility blog | BARRACUDA |
|
22.8.26 |
The Gentlemen ransomware: Inside one of the fastest-growing extortion operations | The Gentlemen has emerged as one of the fastest-growing ransomware-as-a-service operations. This threat profile examines the group's origins, affiliate model, attack chain, infrastructure, known tactics, techniques and procedures (TTPs), and the operational-security failures that exposed its internal workings. | Ransom blog | BARRACUDA |
|
22.8.26 |
CVE-2026-19490: NetScaler Auth Bypass Patched | CVE-2026-19490: NetScaler Auth Bypass Patched Cloud Software Group released a critical security bulletin for customer-managed NetScaler ADC and NetScaler Gateway deployments, fixing two vulnerabilitie... | Vulnerebility blog | SOCRADAR |
| 22.8.26 | SOCRadar Ranks No. 542 on the 2026 Inc. 5000 List of America's Fastest... | SOCRadar Ranks No. 542 on the 2026 Inc. 5000 List of America’s Fastest-Growing Private Companies SOCRadar Is Recognized for 645% Three-Year Revenue Growth, Marking Its Second Consecutive Year on the L... | Cyber blog | SOCRADAR |
|
22.8.26 |
CVE-2026-69836: Microsoft Entra ID RCE Exploited | CVE-2026-69836: Microsoft Entra ID RCE Exploited Microsoft has disclosed CVE-2026-69836, a maximum-severity Remote Code Execution (RCE) vulnerability in Microsoft Entra ID, the cloud identity and acce... | Vulnerebility blog | SOCRADAR |
| 22.8.26 | FTP Banners: The New Dead Drop Resolver Delivering Novel RATs | FTP Banners: The New Dead Drop Resolver Delivering Novel RATs STRU found threat actors using FTP banners as Dead Drop Resolvers – legitimate services or protocols abused to host C2 addresses and comma... | Malware blog | SOCRADAR |
|
22.8.26 |
Windows IKE CVE-2026-33824 Added to CISA KEV | Windows IKE CVE-2026-33824 Added to CISA KEV Windows IKE CVE-2026-33824 is now in CISA’s Known Exploited Vulnerabilities catalog, giving defenders a short deadline to verify patching and exposure. CIS... | Vulnerebility blog | SOCRADAR |
|
22.8.26 |
July 2026: OpenAI Agent Incident, KDDI Breach | July 2026: OpenAI Agent Incident, KDDI Breach July 2026 brought a mix of large scale data exposures, supply chain access risks, credential-driven activity, and a new kind of AI-related incident respon... | Vulnerebility blog | SOCRADAR |
| 22.8.26 | Telegram Applied for .gram: What It Means for the Threat Landscape | Telegram Applied for .gram: What It Means for the Threat Landscape ... | Social blog | SOCRADAR |
|
22.8.26 |
Can NVD Modernization Keep Pace With AI? | Can NVD Modernization Keep Pace With AI? AI can help security teams find vulnerabilities faster. That sounds entirely positive until we consider what happens after those vulnerabilities are found. Eve... | Vulnerebility blog | SOCRADAR |
|
22.8.26 |
Italy RDWeb Access, GBCSA Data Sale, SCHUFA Claim, and FLY Firebase Ex... | Italy RDWeb Access, GBCSA Data Sale, SCHUFA Claim, and FLY Firebase Exposure SOCRadar Dark Web Team identified several new underground posts involving alleged initial access sales and large-scale data... | Cyber blog | SOCRADAR |
| 22.8.26 | From Blackwater to Cyber-Privateers: When States Outsource Force | From Blackwater to Cyber-Privateers: When States Outsource Force On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat ... | Cyber blog | SOCRADAR |
|
22.8.26 |
Frequently asked questions about the active threat to Siemens S7 Series PLCs | A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. | ICS blog | TENABLE |
|
22.8.26 |
Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities | Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts. | Ransom blog | TENABLE |
|
22.8.26 |
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs | Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. | Vulnerebility blog | TENABLE |
| 22.8.26 | Death By 20,000 PoCs | VulnCheck researchers curated 20K+ public exploits and vulnerability analyses in 2025. As of mid-August 2026, we’ve already reviewed 17,800+ PoCs and write-ups, putting us 87% of the way to 2025’s numbers with another 4.5 months left to go in the year. | Exploit blog | VULNCHECK |
|
22.8.26 |
FileRun: When Your File Manager Runs Your Files | Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy. FileRun’s thumbnail extractors build shell commands by pasting the uploaded file path into a double-quoted string and handing it to exec(), and the filename sanitizer lets $() through, so a file named $(payload).mp4 runs its payload the moment a thumbnail is generated. | Vulnerebility blog | VULNCHECK |
|
22.8.26 |
Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive | Two flaws in GitLab’s GraphQL API: one lets any user wipe or alter public projects and user data, the other quietly runs changes using a logged-in user’s own permissions. Self-managed instances from 18.2 through 19.2 need to upgrade now. | Vulnerebility blog | OX |
|
22.8.26 |
Critical vm2 Vulnerability Allows Host DNS Hijacking and Information Disclosure | vm2’s sandbox denylist forgot two modules: “os” and “dns.” Under the wildcard config vm2’s own docs recommend, that gap lets sandboxed code read the host process owner’s identity and hijack the host’s DNS with a single call — a change that outlives the sandbox run and never notifies the embedder. Patched in 3.11.6. | Vulnerebility blog | OX |
| 22.8.26 | 1 in 20 Stealer Log Victims are Threat Actors | When analysts examine stealer logs, the underlying assumption is that each infected device belongs to a victim. However, cybercriminals are not immune to the same operational mistakes as everyone else. | Malware blog | FLARE.IO |
|
22.8.26 |
July 2026 Threat Trend Report on APT Groups | The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub and development environments, VPN and remote access systems, mobile devices, and credentials stored in browsers. | APT blog | AHNLAB |
|
22.8.26 |
Clop Returns with Custom Implant in Mass-Extortion Campaign | This is external threat intelligence from the ReliaQuest Threat Research team. The findings describe threats, vulnerabilities, and attacker activity affecting third parties and the broader threat landscape—not ReliaQuest's own environment. Nothing in this report should be interpreted as a vulnerability in ReliaQuest's systems or data. | Ransom blog | RELIAQUEST |
|
22.8.26 |
North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs | The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated operation that bypasses traditional security perimeters. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders. | APT blog | ANYRUN BLOG |
| 22.8.26 | Hunt Malware & Phishing Threats with ANY.RUN for Proactive Enterprise Security | One of the biggest challenges for every threat hunter is navigating endless alerts, scattered indicators, behavioral evidence, and infrastructural context. Data collection is just the first step – but how do you turn it into findings that lead to proactive protection against malware and phishing? | Malware blog | ANYRUN BLOG |
|
22.8.26 |
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US | Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. | Phishing blog | ANYRUN BLOG |
|
22.8.26 |
Post-DEF CON Phishing Uses Google Doc Apps Script to Deliver Malware | Following Black Hat/DEF CON, a Huntress researcher was targeted by a threat actor who used X DMs and fake security conference planning as a pretext to establish trust before attempting to deploy malware. The researcher recognized the lure as a scam and did not fall for it, but continued engaging with the actor to better understand the tactics they were using. | Phishing blog | Huntress |
| 22.8.26 | PurpleDelta's Fraudulent Employment Operations | Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. | APT blog | Recorded Futures |
|
22.8.26 |
Don’t Break the Agent: Lessons in Token Optimization | Measuring a token optimizer when your users are 1,000 engineers and your test suite is production | Security blog | JFROG |
|
22.8.26 |
Frontier AI Application Security: Every Second Counts | A look at how AppSec processes must change to manage the ever increasing volume of CVEs resulting from today's cyber-capable AI models | AI blog | JFROG |
|
22.8.26 |
13 million tool calls: auditing every AI coding agent action with Elastic Agent | We gave hundreds of developers an AI agent that can run shell commands, edit files, and call Model Context Protocol (MCP) servers on their laptops, then realized we had no record of what it actually did. So we built one. One 280-line dependency-free bash script, fired by Cursor's hooks, records every tool call as JSONL, and the Elastic Agent already on each endpoint ships it to Elasticsearch. Since the May rollout we have logged over 13 million tool-call events from more than 1,100 machines. | AI blog | ELASTIC |
| 22.8.26 | Every detection needs a next step: Why runbooks solve the investigation problem | An alert appears in the security operations center. It reports a suspicious sign-in from an unusual location, involving an account that matters. The analyst opens it and reviews the information provided by the detection. | Security blog | SEKOIA |
|
22.8.26 |
AI SOC integrations: 6 capabilities worth connecting | Explore six AI SOC integrations that bring identity, cloud, vulnerability, phishing, incident and network context into one investigation workflow. | AI blog | SEKOIA |
|
22.8.26 |
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia | Disclosure note: The relevant national CERTs were notified on 10 August 2026, and Dahua's PSIRT was notified regarding the issues that affect devices in all countries observed in this campaign. We appreciate Dahua PSIRT's engagement in reviewing parts of this research ahead of publication. Publication was held until 18 August 2026 under TLP:AMBER. | BigBrother blog | HUNT.IO |
| 22.8.26 | Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra - Killing Your EDR Since 2025 | In late July 2026, eSentire's Threat Response Unit (TRU) identified several ErrTraffic-generated ClickFix campaigns attempting to deliver Cruciferra - a malware loader marketed on underground forums that boasts EDR-killing capabilities. TRU found Cruciferra using a vulnerable driver to fulfill this behavior. | Malware blog | ESENTIRE |
|
22.8.26 |
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 | In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance, and deploying second-stage payloads. | Malware blog | Zscaler |
| 22.8.26 | How Grok unknowingly powers cybercrime | Kriminal isn’t a custom-built criminal AI model: it’s Grok in a trench coat. The proof sits in its own code. | AI blog | THREATDOWN |
|
22.8.26 |
CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms | Falcon Cloud Security earns the highest scores in both Innovation and Growth by connecting risk, adversary intelligence, and real-time protection to stop attacks. | Security blog | CROWDSTRIKE |
|
22.8.26 |
Benchmaxxing: When the Benchmark Becomes the Target | In AI and cybersecurity, optimizing to meet benchmarks can have significant consequences. This is how CrowdStrike approaches benchmarks and evaluations. | AI blog | CROWDSTRIKE |
| 22.8.26 | Teaching AI to Reason Through Detection Triage | New CrowdStrike research shows how step-by-step reasoning can improve detection triage accuracy, transparency, and safe automation. | AI blog | CROWDSTRIKE |
|
22.8.26 |
Fake AI, real malware: Attackers impersonating AI brands | A year of MDR casework shows attackers repeatedly exploiting demand for AI tools | AI blog | SOPHOS |
|
22.8.26 |
Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. | APT blog | GTI | |
| 22.8.26 | Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. | AI blog | GTI | |
|
22.8.26 |
CVE-2026-20349: Someone Is Crashing Cisco Firewalls. We Need to Talk About Why. | If you run a Cisco Adaptive Security Appliance or a Firepower Threat Defense device with Remote Access SSL VPN enabled, you are exposed to CVE-2026-20349. On August 11, 2026, Cisco published an advisory, scoring the vulnerability as “high” with a CVSS 3.1 score of 8.6. The flaw affects the Remote Access SSL VPN service on most ASA and FTD devices. | Vulnerebility blog | Eclypsium |
| 22.8.26 | Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Campaign Timeline Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 | CyberCrime blog | Seqrite |
|
22.8.26 |
Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates | Discover ransomware attack vectors hiding in endpoint blind spots, including remote access tools, credentials, vendors, OT systems and phishing. | Hacking blog | Cyble |
|
22.8.26 |
When the Attacker Wears Your Logo: Detecting and Taking Down Impersonation at AI Speed | AI-powered impersonation can damage brands in minutes. Learn how monitoring and rapid takedowns help detect threats and protect customer trust. | Hacking blog | Cyble |
| 22.8.26 | Brand Impersonation Takedown: From Whack-a-Mole to Managed Response | Manual brand impersonation takedowns fail because attackers move faster than ticket-based abuse reports can resolve. Solution? Managed takedowns. | Security blog | Cyble |
|
22.8.26 |
Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actors | The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026 with 2,188 attacks. | Ransom blog | Cyble |
| 22.8.26 | A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace | We found a custom Windows backdoor on a single corporate workstation while hunting for unusual WMI persistence. The malware was small, had a limited command set and disguised itself as legitimate Realtek software. Its most unusual feature was its configuration: the address of its command-and-control server was not stored as readable text or encrypted data, but encoded in the number of spaces on each line of a Windows `desktop.ini` file. | Malware blog | GENDIGITAL |
|
22.8.26 |
WordlistLoader Delivering Amatera via ClearFake Campaigns | Over the past few months, Amatera Stealer (also often referred to as ACR Stealer) has been actively developed and has gradually become one of the most prevalent infostealer in our user base. Most recently, we've been observing Amatera being distributed via ClearFake campaigns leveraging FakeCaptchas. | Malware blog | GENDIGITAL |
|
22.8.26 |
9Router Tailscale Install Endpoint Unauthenticated OS Command Injection | SonicWall Capture Labs threat research team became aware of the threat CVE-2026-59800, assessed its impact, and developed mitigation measures. The flaw, also known as the 9Router Tailscale Install Endpoint Unauthenticated OS Command Injection, is a critical vulnerability affecting the 9Router AI request proxy (decolua/9router, distributed on npm as 9router) in all versions up to and including 0.4.39, which NVD expresses as any version before 0.4.44. | Hacking blog | SonicWall |
| 22.8.26 | Efimer Brings Its Own Tools to the Job | This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of Efimer malware. This is a Python-based executable compiled with PyInstaller and protected with PyArmor to obfuscate the many libraries and payloads that are packed within. Efimer has extensive anti-analysis capabilities and, when executed, uses geo-IP information to identify Tor network connections for data exfiltration. | Cyber blog | SonicWall |
|
22.8.26 |
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) | Identity has effectively become the new perimeter, where cybercriminals are increasingly choosing to log in rather than break in. To accomplish this, attackers frequently gather previously leaked username and password pairs. Gathering these credentials can then allow them to pivot to password spraying against services exposed to the internet, gaining credentials for other products and services. | Hacking blog | Palo Alto |
| 22.8.26 | Identity Abuse Through Trusted Communication Channels | Identity has become a primary security boundary for most organizations, reducing the ability to solely trust other boundaries once associated with corporate networks. Users authenticate to cloud services using enterprise identities that provide access to collaboration platforms, business applications and sensitive data. With the adoption of software-as-a-service (SaaS) on the rise, people are shifting to platforms for communication and collaboration. | Cyber blog | Palo Alto |
|
22.8.26 |
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect | StopAndProtect is a newly identified operation that combines file encryption with data theft. The criminals abuse thousands of hacked WordPress websites as their infrastructure – using them to spread the malware, control infected machines, and store stolen documents, screenshots, and activity logs (records created by malware to track its actions, progress, or status during execution). | Cyber blog | CHECKPOINT |
| 22.8.26 | BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive | What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? | Cyber blog | CHECKPOINT |
|
22.8.26 |
Describing attacks with crime script analysis | Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted. | Cyber blog | CISCO TALOS |
| 22.8.26 | Is Cyber missing the Marque? | In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations. | Cyber blog | CISCO TALOS |
|
22.8.26 |
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities | The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality. | APT blog | CISCO TALOS |
| 22.8.26 | UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations | Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics. | APT blog | CISCO TALOS |
| 22.8.26 | How QR-code phishing can slip past corporate security measures | Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap. | Phishing blog | Eset |
|
22.8.26 |
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? | And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer? | AI blog | Eset |
| 22.8.26 | Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility | The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less | AI blog | Eset |
|
22.8.26 |
Black Hat USA 2026: AI is racing ahead of cybersecurity controls | AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong | AI blog | Eset |
| 22.8.26 | Are AI tutors safe for your kids? | AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child. | AI blog | Eset |
|
22.8.26 |
When Agents Go Rogue: The OpenClaw Supply Chain Crisis | This comprehensive technical report provides an in-depth analysis of some of these attack vectors, the supply chain poisoning, profiles the threat actors involved, details about the NovaStealer payload, maps the attacks to the MITRE ATT&CK framework, and provides actionable, enterprise grade mitigation strategies. | Hacking blog | TRELLIX |
| 22.8.26 | Stitching the Kill Chain: Detecting NTDS.dit Exfiltration with Trellix Helix Correlation | This blog continues the series exploring NTDS.dit credential theft, building on our earlier work. In this analysis, we examine the underlying methodologies used in these attacks and how Trellix Helix identifies them. We will highlight the Advanced Correlation Engine (ACE)'s capability to consolidate telemetry from policy, network, and endpoint sources. | Exploit blog | TRELLIX |
|
15.8.26 |
NightmareEclipse releases new PoC, ShieldBreak, exploits same weakness as RoguePlanet | NightmareEclipse claims Microsoft did not properly patch RoguePlanet vulnerability | Vulnerebility blog | THREATLOCKER |
|
15.8.26 |
AI-related software vulnerabilities: 2025–2026 | Why AI software vulnerabilities are increasing faster than the rest of the CVE landscape—and what defenders should do about it | AI blog | BARRACUDA |
|
15.8.26 |
From Blackwater to Cyber-Privateers: When States Outsource Force | On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” | Cyber blog | SOCRADAR |
|
15.8.26 |
LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies | New in this update: SOCRadar’s row-level analysis found that 95% of affected organizations were exposed before the well-known 40-minute PyPI window opened. That window marked the end of a five-day collection run, not the beginning. | AI blog | SOCRADAR |
|
15.8.26 |
FileRun: When Your File Manager Runs Your Files | Today VulnCheck is disclosing CVE-2026-14863, an OS command injection to remote code execution in FileRun, a commercial self-hosted file manager. It is being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy. FileRun’s thumbnail extractors build shell commands by pasting the uploaded file path into a double-quoted string and handing it to exec(), and the filename sanitizer lets $() through, so a file named $(payload).mp4 runs its payload the moment a thumbnail is generated. | Vulnerebility blog | VULNCHECK |
|
15.8.26 |
Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays | BotNet blog | FORTINET BLOG |
|
15.8.26 |
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs | Microsoft has addressed 415 vulnerabilities in its August 2026 security update release. This month's patches include fixes for one exploited zero-day vulnerability, three disclosed zero-day vulnerabilities, and 62 Critical vulnerabilities, along with 349 additional vulnerabilities of varying severity levels. | OS Blog | CROWDSTRIKE |
|
15.8.26 |
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery | The conversation about AI in cybersecurity has recently centered on capabilities like vulnerability discovery, exploit generation, and automated proof-of-concept development. It’s easy to see why: These tasks produce binary outcomes; a vulnerability either exists or it doesn't. That makes them useful for measuring model progress and demonstrating increasingly sophisticated cybersecurity capabilities. | AI blog | CROWDSTRIKE |
|
15.8.26 |
ClickFix campaign abuses Deno runtime for infostealer delivery | Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealer | Malware blog | SOPHOS |
|
15.8.26 |
Abuse of alternative runtime environments Deno-tes defender headaches | Attack TTPs combine fileless execution, wide LOLBin use | Hacking blog | SOPHOS |
|
15.8.26 |
When Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk | A recent ransomware incident at Coca-cola owned dairy company Fairlife provides a potent example of network edge devices being targeted for exploitation, and of the scale of outcomes attackers can achieve by exploiting them. | Ransom blog | Eclypsium |
|
15.8.26 |
Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams | Ransomware now drives nearly half of breaches. Explore a practical survival playbook for lean security teams, from prevention to recovery in 2026.! | Ransom blog | Cyble |
|
15.8.26 |
A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace | A hand-written Windows backdoor stored its command-and-control domain as the number of trailing spaces in a fake desktop.ini, and we found it on exactly one machine. | Malware blog | GENDIGITAL |
|
15.8.26 |
The phishing link that died on purpose | A single expired URL exposed a phishing campaign built around Mailer-Go, Cloudflare Workers and an EvilTokens OneDrive lure. | Phishing blog | GENDIGITAL |
|
15.8.26 |
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side | China-based hackers-for-hire group is breaking into government ministries across the Middle East and Asia from the same control panel it uses to run an industrial-scale cryptocurrency fraud business. | APT blog | SECURITY.COM |
|
15.8.26 |
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. | Ransom blog | Microsoft blog |
|
15.8.26 |
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. | Malware blog | Microsoft blog |
|
15.8.26 |
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates | Malware blog | Microsoft blog |
|
15.8.26 |
A Deep-Dive into the Multi-Stage .NET Loader Chain Delivering LokiBot | Recently, the SonicWall Capture Labs Threat Research Team discovered a sophisticated multi-stage .NET malware campaign that delivers the LokiBot information stealer via a heavily obfuscated infection chain. The malware uses multiple .NET loader stages, layered decryption, and process hollowing to evade detection before executing the final native LokiBot payload. | Malware blog | SonicWall |
|
15.8.26 |
Microsoft Security Bulletin Coverage for August 2026 | Microsoft’s August 2026 Patch Tuesday has 422 vulnerabilities, of which 177 are Elevation of Privilege. SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of August 2026 and has produced coverage for 24 of the reported vulnerabilities. | OS Blog | SonicWall |
|
15.8.26 |
Kimwolf v7: An Evolution of the Kimwolf Botnet | We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. | BotNet blog | Palo Alto |
|
15.8.26 |
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications | Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts. A smart contract is a self-executing program stored on a blockchain that automatically runs when specific conditions are met. | BotNet blog | Palo Alto |
|
15.8.26 |
Inside the Modern SOC: The Identity Front Door | In The 72-Minute Race, we explored how attackers are compressing the time between initial access and business impact. But as attacks continue to accelerate, another trend has emerged: Attackers are increasingly gaining access through compromised identities rather than exploiting technology vulnerabilities. | Security blog | Palo Alto |
|
15.8.26 |
The State of Ransomware Q2 2026 | For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but the road to joining them has gotten a great deal shorter. | Ransom blog | CHECKPOINT |
|
15.8.26 |
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack | Check Point Research is tracking a long‑running campaign called Operation Dream Job, targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked Lazarus group and its latest wave focuses on the defense sector in Europe and India. | APT blog | CHECKPOINT |
|
15.8.26 |
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers | Check Point Research analyzed Cloudflare Code Mode, a technique that changes how AI agents use MCP by turning tools into a TypeScript API the model can write code against. | AI blog | CHECKPOINT |
|
15.8.26 |
Curiouser and Curiouser | In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers. | Cyber blog | CISCO TALOS |
|
15.8.26 |
Dissecting the JWR phishing framework | Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. | Phishing blog | CISCO TALOS |
|
15.8.26 |
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities | Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." | OS Blog | CISCO TALOS |
|
15.8.26 |
Why metaphor may dictate your security strategy | In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat. | Security blog | CISCO TALOS |
|
15.8.26 |
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? | And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer? | AI blog | Eset |
|
15.8.26 |
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility | The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less | Security blog | Eset |
|
15.8.26 |
Black Hat USA 2026: AI is racing ahead of cybersecurity controls | AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong | AI blog | Eset |
|
15.8.26 |
Are AI tutors safe for your kids? | AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child. | AI blog | Eset |
|
15.8.26 |
This month in security with Tony Anscombe – July 2026 edition | OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup | Cyber blog | Eset |
|
15.8.26 |
Signed, sealed, injected: The mechanics of DCRat in 2026 | This DCRat campaign shows how attackers combine phishing lures, DLL sideloading, and process hollowing to attempt to slip past defenses and gain full remote access. | Malware blog | TRELLIX |
|
15.8.26 |
Weaponized AI: The Commoditization of Cybercrime | This highlights emerging threats tied to artificial intelligence (AI), from autonomous kill-chain planning engines to uncensored AI-as-a-service platforms. | AI blog | TRELLIX |
|
8.8.26 |
XSS2Shell (CVE-2026-64638): Patch WordPress Now | XSS2Shell (CVE-2026-64638): Patch WordPress Now A new WordPress Core vulnerability chain called XSS2Shell turns a login page XSS bug into a much more serious risk for exposed WordPress sites. The issu... | Vulnerebility blog | SOCRADAR |
|
8.8.26 |
Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Tools | Infostealers are a rapidly evolving threat, enabling various adversaries, ranging from ransomware groups and hacktivists to nation-state actors, to exploit stolen credentials for unauthorized access to sensitive resources. In today’s threat landscape, identity is a primary target, with attackers seeking diverse credentials including usernames, passwords, tokens, and seed phrases. | Malware blog | SOCRADAR |
|
8.8.26 |
Snowflake Hacker Pleads Guilty, Faces 32 Years | Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count tied to the 2024 breaches of Snowflake customer accounts. | CyberCrime blog | SOCRADAR |
|
8.8.26 |
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) | AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. | Malware blog | AHNLAB |
|
8.8.26 |
CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions | Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints. | Vulnerebility blog | OX |
|
8.8.26 |
IBM report sees deep fakes emerging as top AI attack threat | IBM study finds deepfake attacks now account for nearly half of AI-enabled breaches as organizations grapple with rising costs and expanding cyber risks. | AI blog | BARRACUDA |
|
8.8.26 |
Malware signing: When trust becomes an attack surface | How cybercriminals use stolen, fraudulent, and commercialized code-signing certificates to make malware appear legitimate and bypass traditional trust controls. | Malware blog | BARRACUDA |
|
8.8.26 |
Dark Web Market: Vortex Market | Vortex Market describes itself as a “classic wallet escrow market,” and that self-description is accurate. It is a general-purpose Dark Web marketplace built around anonymous trade, vendor reputation levels, and cryptocurrency payments held in market-controlled wallets. Reporting on mirror directories places the launch of the Vortex darknet market in October 2023 with full public access during 2024. | CyberCrime blog | SOCRADAR |
|
8.8.26 |
Formula 1 Phishing Campaign & Kit Analysis | SOCRadar Threat Research Unit (STRU) has identified and analyzed a sophisticated, multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets. The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. | Phishing blog | SOCRADAR |
|
8.8.26 |
Free tokens for sale: How fake signups drive AI fraud | As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability hunting. | AI blog | OKTA |
|
8.8.26 |
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant | Hacking blog | FORTINET BLOG |
|
8.8.26 |
Inside Greatness: Telegram-Distributed M365 AiTM PhaaS | ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. | Social blog | ZEROBEC BLOG |
|
8.8.26 |
Sorting the Agentic AI Hype From Black Hat 2026: 4 Things to Look For | At the Mandalay Bay Convention Center, you could measure how fast the market is moving by counting the signs that read "Agentic AI" over the booth. The label was everywhere. What it actually meant changed booth to booth—and that is the problem you carry home. | AI blog | RELIAQUEST |
|
8.8.26 |
There is a diagram most security teams still carry in their heads when they think about AI. A user talks to a chatbot. The chatbot talks to a large language model. The model talks back. Put an inspection point in the middle, and the problem is solved. | AI blog | IMPERVA | |
|
8.8.26 |
Wallet-depleting macOS malware wants your crypto | During a retrospective threat hunt in June 2026, a Huntress analyst found components of a Mac-specific stealer malware on a monitored system that had been infected three months earlier. | Malware blog | Huntress |
|
8.8.26 |
Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead | We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to. | Phishing blog | Huntress |
|
8.8.26 |
Toolkit Installation via SQL Injection Shows the Classics Still Hit | Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution | Hacking blog | Huntress |
|
8.8.26 |
Living off the coding agent: Two tales of tunnels and LaunchAgents | Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware. | AI blog | ELASTIC |
|
8.8.26 |
Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows | Public leaderboards can't tell you which LLM to trust in your SOC, so Elastic built an evaluation framework that grades models on the work (tool calls, execution traces, blind judging) across Agent Builder, Attack Discovery, and automatic migration. | Security blog | ELASTIC |
|
8.8.26 |
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages | Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads. | Malware blog | ELASTIC |
|
8.8.26 |
Payroll Pirates: Strange New Tides in Business Email Compromise | Key Takeaways Arctic Wolf is tracking an active, widespread email-driven phishing campaign that uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts, identify personnel involved | Phishing blog | ARTICWOLF |
|
8.8.26 |
Ransomware Moves up the Org Chart: Managers Are Prime Targets | When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. | Ransom blog | Zscaler |
|
8.8.26 |
Targeted Attack on Government Entities in the Middle East | Part 2 | This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. After ThreatLabz published Part 1 on the TELESHIM backdoor and MIXEDKEY loader, Kaspersky highlighted a related campaign in recent reporting. | Hacking blog | Zscaler |
|
8.8.26 |
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness | It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his Director of Security Operations, and authenticated through a trust chain that never questioned traffic originating from VPN infrastructure. | AI blog | Zscaler |
|
8.8.26 |
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery | The conversation about AI in cybersecurity has recently centered on capabilities like vulnerability discovery, exploit generation, and automated proof-of-concept development. It’s easy to see why: These tasks produce binary outcomes; a vulnerability either exists or it doesn't. That makes them useful for measuring model progress and demonstrating increasingly sophisticated cybersecurity capabilities. | AI blog | CROWDSTRIKE |
|
8.8.26 |
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates | Real-world case studies and observations demonstrate an increase in attacks on trusted relationships and adversarial use of AI. | Exploit blog | CROWDSTRIKE |
|
8.8.26 |
Secure Agent Harness Execution: Preventing Escape | CrowdStrike uses a defense-in-depth architecture, consisting of seven independent control layers, to prevent autonomous AI agents from taking unintended actions. | Vulnerebility blog | CROWDSTRIKE |
|
8.8.26 |
N-able N-central exploitation results in RMM tool deployment | After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access | Vulnerebility blog | SOPHOS |
|
8.8.26 |
Interlock ransomware gang creates volatile situation | Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists | Ransom blog | SOPHOS |
|
8.8.26 |
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the following developments: | AI blog | GTI |
|
8.8.26 |
Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. | Cyber blog | GTI | |
|
8.8.26 |
Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors | Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced 866 documented… | Ransom blog | Cyble |
|
8.8.26 |
From Stolen Credentials to Full Breach: The 72-Hour Timeline | The 72-hour Timeline reveals how stolen credentials can escalate into a cyberattack, showing key attack stages and detection opportunities. | CyberCrime blog | Cyble |
|
8.8.26 |
The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem | Discover why continuous asset discovery is the foundation of attack surface management and how visibility helps reduce cyber risk and exposure. | Hacking blog | Cyble |
|
8.8.26 |
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. | Malware blog | Microsoft blog |
|
8.8.26 |
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. | Malware blog | Microsoft blog |
|
8.8.26 |
MythStealer: Browser and Discord Credential Theft with HTTPS Exfiltration to Operator-Notified C2 | The Sonicwall Threats research team have recently been tracking an information-stealer malware family known as Myth. The sample we analyzed is a 43.8 MB Windows executable combining browser credential theft, Discord session token extraction, Firefox cookie harvesting, and HTTPS exfiltration into a single binary. | Malware blog | SonicWall |
|
8.8.26 |
AI Meets Ransomware : Open‑Weight AI Models Fueling Ransomware Evolution | This week, the SonicWall Capture Labs Threat Research team analyzed an interesting ransomware sample discovered about an year ago, that leverages AI capabilities in its attack workflow. Unlike conventional ransomware that embeds its malicious logic directly within the binary, PromptLock adopts a fundamentally different approach. | Ransom blog | SonicWall |
|
8.8.26 |
No File, No Trace: How a Fake Invoice Hides a Formbook Loader in Plain Sight | This week, the SonicWall Capture Labs Threat Research Team identified an ongoing campaign distributing Formbook malware through phishing emails disguised as routine business documents, purchase orders, shipping notices, and request-for-quote attachments targeting unsuspecting users and businesses. | Cyber blog | SonicWall |
|
8.8.26 |
Langflow AI Untrusted Control Sphere Remote Code Execution | The SonicWall Capture Labs threat research team became aware of an unauthenticated remote code execution vulnerability in Langflow AI, assessed its impact and developed mitigation measures. Langflow AI is a Python-based web application that provides a visual interface to build AI-driven agents and workflows. | AI blog | SonicWall |
|
8.8.26 |
ChainDrop: Inside a Self-Propagating npm Worm | A self-propagating npm worm nicknamed ChainDrop infected over 400 packages that are collectively downloaded hundreds of millions of times each week. This includes malicious versions of widely used packages such as keyv and cacheable-request. Unit 42 has unique observations of this attack. | Malware blog | Palo Alto |
|
8.8.26 |
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software | Frontier AI is fundamentally shifting the dynamics of cybersecurity — accelerating both how vulnerabilities are discovered and how quickly they can be exploited. | AI blog | Palo Alto |
|
8.8.26 |
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources | It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. | AI blog | Palo Alto |
|
8.8.26 |
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI | Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI. | AI blog | CISCO TALOS |
|
8.8.26 |
Why metaphor may dictate your security strategy | In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat. | Cyber blog | CISCO TALOS |
|
8.8.26 |
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents | Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2. | Incident blog | CISCO TALOS |
|
1.8.26 |
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) | This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI). | Ransom blog | AHNLAB |
|
1.8.26 |
Not Every Fox is Silver: Inside an AtlasRAT loader chain | AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes. | Malware blog | AHNLAB |
|
1.8.26 |
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN | While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the infected system and also installed SoftEther to use it as a VPN server. | Hacking blog | AHNLAB |
|
1.8.26 |
June 2026 Threat Trend Report on APT Attacks (South Korea) | AhnLab monitored domestic APT (Advanced Persistent Threat) attacks—which are conducted covertly and persistently—using its own infrastructure. This report summarizes the classification and statistics on domestic APT attacks identified in June 2026 and describes the capabilities of each type of APT attack. | APT blog | AHNLAB |
|
1.8.26 |
Bitdefender Threat Debrief | July 2026 | This edition of the Bitdefender Threat Debrief covers the latest developments in the ransomware threat landscape, including Qilin’s fall from the number one rank in Top Groups. Other events featured in this release include the arrest of a Scattered Spider operator, the criminal act of ransom negotiation, and an update on the FortiBleed campaign. | Cyber blog | BITDEFENDER |
|
1.8.26 |
Operation BlueDash: Multi-RMM Workplace Phishing | ZeroBEC investigated a live Microsoft Teams-themed phishing operation that began with a "secure document" email and ended with the silent enrollment of the victim endpoint into attacker-controlled remote monitoring and management environments. | Phishing blog | ZEROBEC BLOG |
|
1.8.26 |
Kali365 Ringer: Targeting Financial and Insurance Sectors | ZeroBEC prevented a Kali365 device-code phishing attack targeting a financial, regulated customer environment. The lure used a missed-call notification and a trusted Google Sites wrapper before redirecting through Google redirector, OCI API Gateway, and a Cloudflare-protected Kali365 host. The campaign targeted multiple organizations on the same day, including financial and insurance services customers, using the same Google Sites landing page, sender subdomain, subject pattern, and fake internal reference ID. | Phishing blog | ZEROBEC BLOG |
|
1.8.26 |
Inside JIVS PhishKit: A Domain-Adaptive Credential Harvester | ZeroBEC prevented a coordinated mailbox credential-harvesting campaign targeting multiple users within the same Microsoft 365 organization. The messages used an authenticated but unrelated external sender, warned that each recipient mailbox had violated policy, and directed users to a live PHP phishing page on corychase[.]org. | Phishing blog | ZEROBEC BLOG |
|
1.8.26 |
Apple Libnotify/notifyd Stack Overflow (CVE-2026-64739) — Discovered by ThreatBook XGPT | On July 27, 2026, Apple released security updates for iOS 26.6 and iPadOS 26.6, fixing vulnerabilities across several components — Accessibility, Kernel, Libnotify, and WebKit. Among them is CVE-2026-64739, a stack-based buffer overflow in Libnotify/notifyd found and reported to Apple by ThreatBook XGPT. | Vulnerebility blog | THREATBOOK |
|
1.8.26 |
Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation | A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. ThreatBook TDP® (Threat Detection Platform) has already captured this vulnerability being exploited in the wild, so if you run an affected version without SafeMode enabled, treat remediation as urgent. | Exploit blog | THREATBOOK |
|
1.8.26 |
Threat Coverage Digest: New TI Report, Threat Research and 750+ Detection Rules | July brought another set of threat coverage updates designed to help security teams work faster and with more confidence. ANY.RUN added 42 behavior signatures, 11 YARA rules, and 703 Suricata rules, giving SOCs broader visibility across files, malware behavior, and network activity. | Security blog | ANYRUN BLOG |
|
1.8.26 |
The US CFO’s Playbook: How to Reduce Cyber Risk Without Scaling SOC Team in a Tight Labor Market | Cyber risk is increasing, but so is the cost of managing it. More than 514,000 cybersecurity job listings appeared in the US between May 2024 and April 2025, while the mean annual wage for an information security analyst reached $132,510. | Cyber blog | ANYRUN BLOG |
|
1.8.26 |
Building Resilience Against AiTM Phishing: What SOC Leaders Should Know | Email gateways, endpoint controls, and file-centric sandboxing remain essential layers of defense. But many of today’s phishing attacks unfold in ways they weren’t designed to fully expose. | Phishing blog | ANYRUN BLOG |
|
1.8.26 |
Infrastructure Health, Now Agentic: The IT Engineer Teammate Is Here | Technology and infrastructure health is the foundation of the SOC. Investigations, threat hunts, and detection engineering all assume the same thing: the tools underneath are up, generating telemetry, and functioning as intended. When that assumption breaks, the rest of the SOC breaks with it. | Security blog | RELIAQUEST |
|
1.8.26 |
DNS Poisoning Tactics Expand to Hospitality Wi-Fi | Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026. | Hacking blog | RELIAQUEST |
|
1.8.26 |
The Five Questions Every Security Team Should Be Asking After the OpenAI–Hugging Face Incident | On Tuesday, July 21, OpenAI reported that its own AI models were behind an unprecedented cyber incident against the open-source developer platform, Hugging Face. A combination of GPT-5.6 Sol, and a more capable, unreleased model broke out of a sandboxed testing environment, reached the public internet, and exploited a vulnerability to access Hugging Face's systems. | AI blog | RELIAQUEST |
|
1.8.26 |
Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker’s Servers | Huntress recently investigated an incident where the victim searched Google for how to install Claude on a Mac, clicked a sponsored result, and landed on a weaponised claude.ai/share conversation dressed up as an Apple Support install guide. It told them to open Terminal and paste a single curl command. | Malware blog | Huntress |
|
1.8.26 |
Huntress Threat Advisory: Widespread SonicWall Credential Stuffing Campaign | Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks. | Cyber blog | Huntress |
|
1.8.26 |
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT | Between July 21 and July 22, 2026, Huntress' Security Operations Center (SOC) lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe. The attacks had one common denominator: victims had searched for the Claude desktop app and were taken to a malicious public Claude Artifact on the actual Claude AI domain, which appeared to be a legitimate download link for the desktop app. | Malware blog | Huntress |
|
1.8.26 |
Iran War’s Secondary Effects Shape 2026 US Violent Extremism | Explore the 2026 US violent extremism threat landscape. This report analyzes rising risks from HVEs, DVEs, and Iran-nexus actors to public and | BigBrother blog | Recorded Futures |
|
1.8.26 |
Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend | Every stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection. | AI blog | ELASTIC |
|
1.8.26 |
Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas | Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth. | Cyber blog | ELASTIC |
|
1.8.26 |
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support | Elastic Defend automatically generates and instantly deploys vulnerable driver YARA rules from VirusTotal, LOLDrivers and Microsoft's blocklist, closing the gap BYOVD attacks depend on. Plus a new troubleshooting skill and ARM endpoint protection. | Safety blog | ELASTIC |
|
1.8.26 |
Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here | Elastic's first automatic migration from a modern SIEM. Translate your Sentinel detection rules into Elastic Security without rebuilding them. | Security blog | ELASTIC |
|
1.8.26 |
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called | While conducting routine open-source research, NetAskari identified a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170 servers running the framework, and uncovered a fractured criminal ecosystem built around its leaked codebase. | Malware blog | HUNT.IO |
|
1.8.26 |
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades | NGINX sits in front of a large share of the internet's web traffic and Ghost CMS powers well over 100,000 publishing sites. Within months of each other earlier this year, critical vulnerabilities were found in both: NGINX Rift (CVE-2026-42945), a long-standing heap overflow in the rewrite module, and a blind SQL injection in the Ghost Content API (CVE-2026-26980). Exploit code for both became public quickly. | AI blog | HUNT.IO |
|
1.8.26 |
Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Financ | Disclosure note: This research was conducted jointly by Hunt.io and Bob Diachenko, security researcher and journalist. Thailand's national CERT and NCSA were notified on July 15, 2026, and acknowledged receipt the same day. Publication was held for the standard 7-day disclosure window. | Exploit blog | HUNT.IO |
|
1.8.26 |
Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection | Summary Arctic Wolf Labs has been tracking a cluster of campaigns built around CastleLoader, a multi-stage shellcode loader that has served as the backbone of | Malware blog | ARTICWOLF |
|
1.8.26 |
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | On 22 July 2026 (the day prior to Proofpoint’s joint release with the NSA), TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyze, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity. | APT blog | PROOFPOINT |
|
1.8.26 |
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor | Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. | Malware blog | Zscaler |
|
1.8.26 |
The AI era of cybercrime has arrived: The 2026 Cybercrime in the age of AI report | New research reveals how AI is rewiring cybercrime today, and how you can prepare for what’s coming tomorrow. | AI blog | THREATDOWN |
|
1.8.26 |
XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens | Dive into a covert Linux XMRig campaign exploiting trusted access, weaponizing PAM to create forensic smokescreens, and deploying self-unlinking payloads. | Exploit blog | GROUP-IB |
|
1.8.26 |
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks | In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows. | AI blog | CROWDSTRIKE |
|
1.8.26 |
CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security | CrowdStrike is an inaugural partner in the Open Secure AI Alliance, a new industry coalition built on a simple premise: securing the AI era requires open models, shared tools, and a massively distributed community of defenders. | AI blog | CROWDSTRIKE |
|
1.8.26 |
Inside Astaroth's New Spambot Component | Operators of the Astaroth botnet introduced a new spambot component, a sign of their evolving operations and an expanding LATAM eCrime ecosystem. | BotNet blog | CROWDSTRIKE |
|
1.8.26 |
Falcon AIDR Now Protects Copilot Studio Agents and Claude Code | New feature releases extend AI visibility, detection, and response capabilities to Microsoft Copilot Studio and Claude Code. | AI blog | CROWDSTRIKE |
|
1.8.26 |
Chaos in Teams vishing | Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems. Between February and June 2026, Sophos analysts observed the threat actors targeting dozens of North American organizations. | Phishing blog | SOPHOS |
|
1.8.26 |
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise | For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. | APT blog | GTI |
|
1.8.26 |
Announcing InfraTrust, the source of intelligence on security risks across hardware infrastructure | Today we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated source of security advisories and risk data from major enterprise hardware infrastructure vendors. | Cyber blog | Eclypsium |
|
1.8.26 |
APTs Top the List of Most Active Threat Actors in H1 2026 | These are the most active threat actors in H1 2026 as APT groups lead global cyber operations, followed by ransomware and hacktivist campaigns. | APT blog | Cyble |
|
1.8.26 |
Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscape | Cyble breaks down how dark web ecosystems are evolving in 2026 with ransomware, initial access brokers, AI-driven attacks, and underground threat activity. | CyberCrime blog | Cyble |
|
1.8.26 |
Fake invoices are moving from inboxes to shopping apps | Scammers are using order-tracking apps to place fake receipts where users expect to see real purchases, then pushing them to call fake support numbers. | GENDIGITAL | |
|
1.8.26 |
Email threat landscape: Q2 2026 trends and insights | In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. | Cyber blog | Microsoft blog |
|
1.8.26 |
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility | TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense. | AI blog | Trend Micro |
|
1.8.26 |
Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave | Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan. | Hacking blog | Trend Micro |
|
1.8.26 |
The Signs Were There: What the First Autonomous Ransomware Case Confirms | An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior. | AI blog | Trend Micro |
|
1.8.26 |
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan | We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. | Spam blog | Trend Micro |
|
1.8.26 |
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It | OpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it’s contained, not just on how it’s trained. | AI blog | Trend Micro |
|
1.8.26 |
Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure | TrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves. | ICS blog | Trend Micro |
|
1.8.26 |
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass | Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement. | Phishing blog | Trend Micro |
|
1.8.26 |
DbGate JSON Script Runner Unauthenticated Remote Code Execution | SonicWall Capture Labs threat research team became aware of the threat CVE-2026-47668, assessed its impact, and developed mitigation measures. The flaw, also known as the DbGate JSON Script Runner Unauthenticated Remote Code Execution, is a critical vulnerability affecting the DbGate web-based database manager (dbgate/dbgate, distributed on npm as dbgate-serve) in all versions up to and including 7.1.8 | Vulnerebility blog | SonicWall |
|
1.8.26 |
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version | After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. This version’s advanced architecture hides its core logic in memory space, reducing its digital footprint. | Malware blog | Palo Alto |
|
1.8.26 |
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks | Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. | AI blog | Palo Alto |
|
1.8.26 |
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains | Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. | Cyber blog | CISCO TALOS |
|
1.8.26 |
Black Hat special: Rewind and revisit | Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence. | Cyber blog | CISCO TALOS |
|
1.8.26 |
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel | The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN. | Ransom blog | CISCO TALOS |
|
1.8.26 |
Preview: Cisco Talos at Black Hat USA 2026 | Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk. | Cyber blog | CISCO TALOS |
|
1.8.26 |
You were onto something with “It’s the Climb,” Miley | Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar. | Cyber blog | CISCO TALOS |
|
1.8.26 |
Don’t swing at everything | Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever. | Cyber blog | CISCO TALOS |
|
1.8.26 |
Begun, the Patch Wars have | Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story. | Cyber blog | CISCO TALOS |
|
1.8.26 |
The Hunter's Paradox: Is it time to embrace automated threat hunting? | Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like. | Cyber blog | CISCO TALOS |
|
1.8.26 |
Beyond the screenshot: Why you should verify what you see | The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine | Cyber blog | Eset |