August 2026

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC 2026-08-10 at 17:07 By Ionut Arghire Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Read More »

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain 2026-08-10 at 16:55 By Rodel Mendrez This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn’t expect. This article is an excerpt from LevelBlue SpiderLabs Blog View Original

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain Read More »

Sen. Bernie Sanders demands CEOs pause AI development ‘in the interest of humanity’

Sen. Bernie Sanders demands CEOs pause AI development ‘in the interest of humanity’ 2026-08-10 at 16:47 By Ryan King Sen. Bernie Sanders gave an ultimatum to the CEOs of Anthropic, Meta, and OpenAI, warning them to pause the development of artificial intelligence now or else have lawmakers do it for them. This article is an

Sen. Bernie Sanders demands CEOs pause AI development ‘in the interest of humanity’ Read More »

Metabase zero-day exploited to access Framework customer data

Metabase zero-day exploited to access Framework customer data 2026-08-10 at 16:42 By Zeljka Zorz Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers

Metabase zero-day exploited to access Framework customer data Read More »

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development 2026-08-10 at 16:19 By North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development Read More »

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users 2026-08-10 at 16:19 By Sinisa Markovic Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users Read More »

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad 2026-08-10 at 15:59 By Ionut Arghire An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek.

‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad Read More »

Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams

Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams 2026-08-10 at 15:44 By Ashish Khaitan Ransomware stopped being an isolated incident type in 2025. It became the dominant force behind the modern breach landscape, and the ransomware data breach statistics from Cyble’s own tracking make the shift

Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams Read More »

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA 2026-08-10 at 15:25 By Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA Read More »

New Jersey, Alabama Join States Targeted in Water Cyberattacks

New Jersey, Alabama Join States Targeted in Water Cyberattacks 2026-08-10 at 14:44 By Eduard Kovacs Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek. This article is an excerpt from

New Jersey, Alabama Join States Targeted in Water Cyberattacks Read More »

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 2026-08-10 at 14:34 By Zeljka Zorz To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix.

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 Read More »

Meta’s Mark Zuckerberg pushes positive AI message, calls for open-source approach to beat China

Meta’s Mark Zuckerberg pushes positive AI message, calls for open-source approach to beat China 2026-08-10 at 13:59 By Ariel Zilber Amid AI doomerism, Meta CEO Mark Zuckerberg is continuing his attempt at positive messaging about the tech in a new manifesto while calling on Washington to lower barriers for US open-source developers to help them

Meta’s Mark Zuckerberg pushes positive AI message, calls for open-source approach to beat China Read More »

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility 2026-08-10 at 13:01 By Eduard Kovacs CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek. This article

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Read More »

OpenAI risks White House relationship with hiring of ‘nuisance’ AI policy executive: sources

OpenAI risks White House relationship with hiring of ‘nuisance’ AI policy executive: sources 2026-08-10 at 13:00 By Thomas Barrabi Ball infuriated Trump AI officials last month after claiming that the White House should create “regulatory risk” — or new rules imposing consequences on US firms — to discourage use of Chinese AI models. This article

OpenAI risks White House relationship with hiring of ‘nuisance’ AI policy executive: sources Read More »

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability 2026-08-10 at 12:31 By Ionut Arghire The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Read More »

Anthropic to put AI in charge of reviewing Claude Code actions by default

Anthropic to put AI in charge of reviewing Claude Code actions by default 2026-08-10 at 12:13 By Anamarija Pogorelec Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether

Anthropic to put AI in charge of reviewing Claude Code actions by default Read More »

Corporate Data Stolen in Levi Strauss Cyberattack

Corporate Data Stolen in Levi Strauss Cyberattack 2026-08-10 at 11:55 By Ionut Arghire Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Corporate Data Stolen in Levi Strauss Cyberattack Read More »

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials 2026-08-10 at 10:38 By Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials Read More »

UK regulators to prepare tokenized gold framework: Report

UK regulators to prepare tokenized gold framework: Report 2026-08-10 at 10:25 By Cointelegraph by Zoltan Vardai The UK’s FCA is reportedly preparing a regulatory framework for tokenized gold and how these products may be used as collateral assets in wholesale markets. This article is an excerpt from Cointelegraph.com News View Original Source

UK regulators to prepare tokenized gold framework: Report Read More »

Scroll to Top