Cybersecurity and other IT news aggregator
LATEST FEEDS
-
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks 2026-08-12 at 11:45 By Ionut Arghire The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source
-
Crytica’s RDAi detects OT device tampering from within
Crytica’s RDAi detects OT device tampering from within 2026-08-12 at 11:40 By Industry News Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrupting operations. The need is becoming increasingly urgent…
-
Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily 2026-08-12 at 11:36 By Anamarija Pogorelec Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) Chrome revokes notification permissions for websites users…
-
Ivanti EPM Update Patches Remotely Exploitable Flaws
Ivanti EPM Update Patches Remotely Exploitable Flaws 2026-08-12 at 11:14 By Ionut Arghire The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source
-
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations 2026-08-12 at 11:04 By Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK…
-
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact 2026-08-12 at 10:51 By Eduard Kovacs CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original…
-
Split-second deepfake glitch blows digital certificate fraudster’s cover
Split-second deepfake glitch blows digital certificate fraudster’s cover 2026-08-12 at 10:50 By Sinisa Markovic Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made…
-
Inside the fake crypto startup that fooled North Korean IT workers
Inside the fake crypto startup that fooled North Korean IT workers 2026-08-12 at 10:34 By Cointelegraph by Yohan Yun Suspected North Koreans IT workers joined a fake crypto startup — without realizing their every move was being tracked to extract valuable intel. This article is an excerpt from Cointelegraph.com News View Original Source
-
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code 2026-08-12 at 10:31 By SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has…
-
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform 2026-08-12 at 10:31 By Ionut Arghire The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source
-
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access 2026-08-12 at 09:41 By The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for…
-
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS 2026-08-12 at 09:15 By Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is…
-
Harmony considers rollback after suspected exploit inflates ONE supply
Harmony considers rollback after suspected exploit inflates ONE supply 2026-08-12 at 09:02 By Cointelegraph by Ezra Reguerra Harmony is working with exchanges to freeze funds and is preparing a patch after claims that 2.8 billion unauthorized ONE hit trading platforms. This article is an excerpt from Cointelegraph.com News View Original Source
-
Post-quantum migration gets harder when every user holds a key
Post-quantum migration gets harder when every user holds a key 2026-08-12 at 09:00 By Mirko Zorz In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break…
-
PentestGPT: Open-source automated penetration testing agentic framework
PentestGPT: Open-source automated penetration testing agentic framework 2026-08-12 at 08:30 By Anamarija Pogorelec PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and…
-
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks 2026-08-12 at 08:10 By Eduard Kovacs CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source
-
CFTC invokes emergency powers to keep Kalshi operating in New York fight
CFTC invokes emergency powers to keep Kalshi operating in New York fight 2026-08-12 at 07:53 By Cointelegraph by Ezra Reguerra The order escalates a jurisdictional fight over whether states may treat federally regulated event contracts as illegal gambling. This article is an excerpt from Cointelegraph.com News View Original Source
-
Ravencoin hits record low as network exploit puts transactions at risk
Ravencoin hits record low as network exploit puts transactions at risk 2026-08-12 at 04:11 By Cointelegraph by Ezra Reguerra Mining pools controlling most of Ravencoin’s hash rate are building a competing chain that could trigger a three-day reorganization. This article is an excerpt from Cointelegraph.com News View Original Source
-
SEC, CFTC sue Goliath Ventures over $400M crypto Ponzi scheme
SEC, CFTC sue Goliath Ventures over $400M crypto Ponzi scheme 2026-08-12 at 03:07 By Cointelegraph by Ezra Reguerra Regulators allege Goliath promised crypto liquidity-pool returns but instead paid earlier investors and funded its founder’s luxury spending. This article is an excerpt from Cointelegraph.com News View Original Source
-
You Can’t Patch Your Way Out of AI
You Can’t Patch Your Way Out of AI 2026-08-12 at 00:27 By Dominic Djannesari, Eric Chien The goal isn’t patching faster. It’s making vulnerabilities irrelevant. This article is an excerpt from SECURITY.COM View Original Source
-
Wisconsin store owner, Nintendo superfan discovers dozens of ultra rare vintage Mario Bros. game cartridges: ‘Holy Grail’
Wisconsin store owner, Nintendo superfan discovers dozens of ultra rare vintage Mario Bros. game cartridges: ‘Holy Grail’ 2026-08-12 at 00:00 By Associated Press Most of the cartridges will go up for sale Friday in an online auction that will run until Sept. 9. This article is an excerpt from Latest Technology News | New York…
-
SEC to address crypto regulations in absence of CLARITY passage
SEC to address crypto regulations in absence of CLARITY passage 2026-08-11 at 23:59 By Cointelegraph by Turner Wright The US securities regulator scheduled a meeting this week with the potential to step up on digital asset policies without congressional action. This article is an excerpt from Cointelegraph.com News View Original Source
-
Itaú joins Brazil tokenization pilot with OpenAssets
Itaú joins Brazil tokenization pilot with OpenAssets 2026-08-11 at 23:55 By Cointelegraph by Nate Kostar The bank will test tokenized fixed-income securities and investment funds as part of an ANBIMA-led industry pilot. This article is an excerpt from Cointelegraph.com News View Original Source
-
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack 2026-08-11 at 23:10 By Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code…
-
California data center war takes vile turn as racist slurs fly at powerful union
California data center war takes vile turn as racist slurs fly at powerful union 2026-08-11 at 22:59 By Titus Wu The North Coast States Carpenters Union accused anti-data-center protesters of hurling racist and homophobic slurs. This article is an excerpt from Latest Technology News | New York Post View Original Source
-
MoneyGram expands crypto cash ramps to Solana
MoneyGram expands crypto cash ramps to Solana 2026-08-11 at 22:53 By Cointelegraph by Nate Kostar MoneyGram’s Ramps service now connects Solana wallets and applications to its global cash network, with Rift becoming the first wallet to integrate the service. This article is an excerpt from Cointelegraph.com News View Original Source
-
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing 2026-08-11 at 22:36 By Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf…
-
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client 2026-08-11 at 22:08 By Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter’s. The flaw sat in the annotation tool, the feature that lets participants draw…
-
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day 2026-08-11 at 21:46 By Ionut Arghire A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from…
-
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands 2026-08-11 at 21:36 By The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing…
-
AI assistant goes rogue, hacks Australian gym website in stunning breach: report
AI assistant goes rogue, hacks Australian gym website in stunning breach: report 2026-08-11 at 20:30 By Thomas Barrabi An Australian man asked his OpenClaw AI assistant – an open-source software whose AI agents can perform real-world tasks — to book him a spot in a morning class, Australian outlet ABC reported. Instead of just following…
-
FlightAware sues Kalshi over flight cancellation data
FlightAware sues Kalshi over flight cancellation data 2026-08-11 at 19:55 By Cointelegraph by Turner Wright The legal action against Kalshi focused on trademark infringement and injury to its reputation in addition to citing state authorities comparing the company’s contracts to gambling. This article is an excerpt from Cointelegraph.com News View Original Source
-
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws 2026-08-11 at 19:50 By Ionut Arghire The security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source
-
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE 2026-08-11 at 19:47 By Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint…
-
Coinbase-backed Flowdesk secures full broker-dealer license in Dubai
Coinbase-backed Flowdesk secures full broker-dealer license in Dubai 2026-08-11 at 19:39 By Cointelegraph by Sam Bourgi Flowdesk’s VARA approval follows its MiCA authorization in France as crypto firms build regulated operations across major global markets. This article is an excerpt from Cointelegraph.com News View Original Source
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt 2026-08-11 at 19:35 By The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. “Its recovery ecosystem combines the Session messaging network with blockchain-backed services…
-
Nasdaq to acquire LeveL Markets in push toward ‘always-on’ markets
Nasdaq to acquire LeveL Markets in push toward ‘always-on’ markets 2026-08-11 at 19:34 By Cointelegraph by Nate Kostar Nasdaq’s acquisition of the third-largest US alternative trading system comes as the exchange operator expands into tokenized securities and longer trading hours. This article is an excerpt from Cointelegraph.com News View Original Source
-
Film Festival Data Leak Exposes A-List Directors, Actors, Celebrities
Film Festival Data Leak Exposes A-List Directors, Actors, Celebrities 2026-08-11 at 19:00 By Records associated with Tribeca Film Festival were exposed. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source
-
Zoom Patches Zero-Click Code Execution Vulnerability
Zoom Patches Zero-Click Code Execution Vulnerability 2026-08-11 at 18:49 By Ionut Arghire Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source
-
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It 2026-08-11 at 18:00 By Steve Durbin Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It appeared first on SecurityWeek. This article is…
-
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities 2026-08-11 at 17:14 By Ionut Arghire SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source
-
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ 2026-08-11 at 17:03 By Eduard Kovacs The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared…
-
Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk
Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk 2026-08-11 at 17:00 By Nolen Johnson Recent cyberattacks against U.S. water and wastewater systems delivered an important reminder: disrupting operational technology (OT) does not always require sophisticated malware or a previously unknown vulnerability. In the July 2026 activity, internet-facing programmable logic controllers (PLCs),…
-
ADI Chain, Shipfinex partner to tokenize $500M vessel pipeline
ADI Chain, Shipfinex partner to tokenize $500M vessel pipeline 2026-08-11 at 16:59 By Cointelegraph by Nate Kostar Shipfinex plans to bring 35 vessels onchain through ADI Chain as tokenization expands into the multitrillion-dollar maritime industry. This article is an excerpt from Cointelegraph.com News View Original Source
-
SharpLink reports $394M in Q2 net loss fueled by ETH decline
SharpLink reports $394M in Q2 net loss fueled by ETH decline 2026-08-11 at 16:17 By Cointelegraph by Zoltan Vardai SharpLink reported a net loss of $394 million in the second quarter of 2026, largely driven by Ether’s 23% decline during the quarter. This article is an excerpt from Cointelegraph.com News View Original Source
-
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development 2026-08-11 at 16:11 By OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. “Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities…
-
Arctera enhances Unified Platform for evidence-driven compliance workflows
Arctera enhances Unified Platform for evidence-driven compliance workflows 2026-08-11 at 16:09 By Industry News Arctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and response workflows across the compliance lifecycle. These capabilities help organizations create a more complete and defensible record of compliance…
-
Citrix expands Platform Flex with observability and secure developer services
Citrix expands Platform Flex with observability and secure developer services 2026-08-11 at 15:39 By Industry News Citrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience Insights Flex, a Citrix-managed observability service powered by…
-
EToro to buy TradeZero as Q2 crypto revenue falls 30%
EToro to buy TradeZero as Q2 crypto revenue falls 30% 2026-08-11 at 15:35 By Cointelegraph by Zoltan Vardai Trading platform eToro will acquire TradeZero as part of its US expansion as it reported crypto-related revenue fell by about 30% compared to the second quarter of 2025. This article is an excerpt from Cointelegraph.com News View…
-
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G 2026-08-11 at 15:10 By Sinisa Markovic Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr…
Browse older archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023