August 2026

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands 2026-08-25 at 14:33 By Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to […]

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Read More »

First Malware Built Specifically for Car Head Units Fuels Botnet

First Malware Built Specifically for Car Head Units Fuels Botnet 2026-08-25 at 14:18 By Eduard Kovacs Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

First Malware Built Specifically for Car Head Units Fuels Botnet Read More »

Frontier AI: Vulnerability Management’s Systemic Revolution

Frontier AI: Vulnerability Management’s Systemic Revolution 2026-08-25 at 14:14 By Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful […]

Frontier AI: Vulnerability Management’s Systemic Revolution Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over […]

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff 2026-08-25 at 13:01 By Associated Press AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China. The post Taiwan Charges 9 Over Illegal AI Server Exports to China, […]

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff Read More »

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access 2026-08-25 at 13:01 By Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as […]

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access Read More »

Silent Patches Don’t Stop Attackers—They Blind Defenders

Silent Patches Don’t Stop Attackers—They Blind Defenders 2026-08-25 at 13:00 By Tod Beardsley Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Silent Patches Don’t Stop Attackers—They Blind Defenders Read More »

Standard Chartered becomes first bank distributor of HKD stablecoin

Standard Chartered becomes first bank distributor of HKD stablecoin 2026-08-25 at 12:52 By Cointelegraph by Ezra Reguerra The bank plans tokenized money market fund settlements in the fourth quarter as HKDAP expands its phased rollout into conventional banking. This article is an excerpt from Cointelegraph.com News View Original Source

Standard Chartered becomes first bank distributor of HKD stablecoin Read More »

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack 2026-08-25 at 12:24 By Sinisa Markovic Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group […]

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack Read More »

Galaxy puts Coldcard hack losses at 1,789 BTC, with 87% unmoved

Galaxy puts Coldcard hack losses at 1,789 BTC, with 87% unmoved 2026-08-25 at 11:46 By Cointelegraph by Helen Partz Galaxy Research’s latest tally shows that more than half of 221 Coldcard hack victim reports involved individual losses exceeding 1 Bitcoin. This article is an excerpt from Cointelegraph.com News View Original Source

Galaxy puts Coldcard hack losses at 1,789 BTC, with 87% unmoved Read More »

Business owner faces up to 280 years over $24M crypto Ponzi scheme

Business owner faces up to 280 years over $24M crypto Ponzi scheme 2026-08-25 at 10:58 By Cointelegraph by Ezra Reguerra A federal jury convicted Brent Kovar of wire fraud, mail fraud and money laundering after he took $24 million from at least 400 investors. This article is an excerpt from Cointelegraph.com News View Original Source

Business owner faces up to 280 years over $24M crypto Ponzi scheme Read More »

CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA Warns of Exploited Oracle WebLogic Vulnerability 2026-08-25 at 10:46 By Eduard Kovacs The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Oracle WebLogic Vulnerability Read More »

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data 2026-08-25 at 09:12 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 […]

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data Read More »

AI supply chain risk is showing up in developer workflows first

AI supply chain risk is showing up in developer workflows first 2026-08-25 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and […]

AI supply chain risk is showing up in developer workflows first Read More »

TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials

TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials 2026-08-25 at 08:33 By Sinisa Markovic Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highlight permissions and access levels, so a security team can assess the risk and prioritize its response. TruffleHog Enterprise […]

TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials Read More »

HOL Guard: Open-source antivirus for AI agents

HOL Guard: Open-source antivirus for AI agents 2026-08-25 at 08:30 By Anamarija Pogorelec HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your […]

HOL Guard: Open-source antivirus for AI agents Read More »

The cybercrime supply chain has five stages, each with a price

The cybercrime supply chain has five stages, each with a price 2026-08-25 at 08:00 By Help Net Security In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five […]

The cybercrime supply chain has five stages, each with a price Read More »

New TCG guidance gives buyers a way to test PQC-ready TPM claims

New TCG guidance gives buyers a way to test PQC-ready TPM claims 2026-08-25 at 07:30 By Help Net Security The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements […]

New TCG guidance gives buyers a way to test PQC-ready TPM claims Read More »

Cybersecurity jobs available right now: August 25, 2026

Cybersecurity jobs available right now: August 25, 2026 2026-08-25 at 07:00 By Sinisa Markovic Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and […]

Cybersecurity jobs available right now: August 25, 2026 Read More »

Scroll to Top