August 2026

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers 2026-08-08 at 11:54 By Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of […]

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers Read More »

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens 2026-08-08 at 11:03 By New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens Read More »

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication 2026-08-08 at 09:58 By Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Read More »

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist 2026-08-08 at 09:57 By N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist Read More »

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts 2026-08-08 at 09:52 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts Read More »

Domestic stablecoins could boost demand for dollar-backed tokens: IMF

Domestic stablecoins could boost demand for dollar-backed tokens: IMF 2026-08-08 at 09:21 By Cointelegraph by Ezra Reguerra IMF first deputy managing director Dan Katz says users may favor digital dollars for their liquidity, network effects and cross-border acceptance. This article is an excerpt from Cointelegraph.com News View Original Source

Domestic stablecoins could boost demand for dollar-backed tokens: IMF Read More »

US court backs Bybit’s bid to trace funds from $1.5B North Korea hack

US court backs Bybit’s bid to trace funds from $1.5B North Korea hack 2026-08-08 at 07:11 By Cointelegraph by Ezra Reguerra Expedited discovery allows the exchange to seek account identities, balances and transaction histories from platforms with US operations. This article is an excerpt from Cointelegraph.com News View Original Source

US court backs Bybit’s bid to trace funds from $1.5B North Korea hack Read More »

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets 2026-08-08 at 04:49 By ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets Read More »

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data 2026-08-08 at 04:49 By A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data Read More »

Donald Trump’s media company to terminate Crypto.com deal

Donald Trump’s media company to terminate Crypto.com deal 2026-08-08 at 00:39 By Cointelegraph by Turner Wright The president’s company will unwind an agreement with Crypto.com to create a multibillion-dollar CRO treasury and reportedly not integrate prediction markets onto Truth Social. This article is an excerpt from Cointelegraph.com News View Original Source

Donald Trump’s media company to terminate Crypto.com deal Read More »

US Treasury’s OFAC sanctions 2 Iran-linked crypto exchanges

US Treasury’s OFAC sanctions 2 Iran-linked crypto exchanges 2026-08-07 at 23:02 By Cointelegraph by Turner Wright The US government sanctioned an individual and two crypto exchanges it said facilitated money laundering for a combined $5 million in digital assets linked to Iran. This article is an excerpt from Cointelegraph.com News View Original Source

US Treasury’s OFAC sanctions 2 Iran-linked crypto exchanges Read More »

Yahoo News’ AI-powered tool drew just 3% of its articles from conservative outlets: study

Yahoo News’ AI-powered tool drew just 3% of its articles from conservative outlets: study 2026-08-07 at 22:46 By Thomas Barrabi Media Research Center – a conservative watchdog that has previously called out Apple News, Google and other aggregators for alleged bias – conducted a review of the “Yahoo 100” feed. The tool “uses AI to

Yahoo News’ AI-powered tool drew just 3% of its articles from conservative outlets: study Read More »

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer 2026-08-07 at 21:48 By A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer Read More »

This new ‘AI’ chatbot is actually just one very tired guy

This new ‘AI’ chatbot is actually just one very tired guy 2026-08-07 at 21:43 By Bianca Zalben The tongue-in-cheek project is advertised on a $6,000 San Francisco billboard, and was launched as a commentary on society’s increasingly automatic reliance on artificial intelligence. This article is an excerpt from Latest Technology News | New York Post

This new ‘AI’ chatbot is actually just one very tired guy Read More »

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street 2026-08-07 at 17:26 By SecurityWeek News Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Read More »

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect 2026-08-07 at 16:10 By King Orande and Cris Tomboc The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign leveraging a new social engineering method to deploy unauthorized ConnectWise ScreenConnect clients. Rather than relying on conventional phishing pages, the campaign recreates convincing software

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect Read More »

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP 2026-08-07 at 15:56 By WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP Read More »

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

200 accounts compromised in Swiss government’s Microsoft SharePoint breach 2026-08-07 at 15:29 By Sinisa Markovic Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers.

200 accounts compromised in Swiss government’s Microsoft SharePoint breach Read More »

Scroll to Top