August 2026

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks 2026-08-18 at 15:38 By Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. “TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared […]

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Read More »

Xpander Raises $7.5 Million for AI Management and Governance

Xpander Raises $7.5 Million for AI Management and Governance 2026-08-18 at 15:29 By Ionut Arghire Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on SecurityWeek. This article is an excerpt

Xpander Raises $7.5 Million for AI Management and Governance Read More »

Fortinet Acquires AI Security Company Virtue AI

Fortinet Acquires AI Security Company Virtue AI 2026-08-18 at 15:06 By Eduard Kovacs Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Fortinet Acquires AI Security Company Virtue AI Read More »

Download: 2026 Credential Risk Report

Download: 2026 Credential Risk Report 2026-08-18 at 15:03 By Help Net Security 85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move toward Continuous Credential

Download: 2026 Credential Risk Report Read More »

Google’s $10,000 refund test shows why AI agents need zero trust

Google’s $10,000 refund test shows why AI agents need zero trust 2026-08-18 at 14:49 By Anamarija Pogorelec Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The

Google’s $10,000 refund test shows why AI agents need zero trust Read More »

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) 2026-08-18 at 14:38 By Sinisa Markovic GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) Read More »

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 2026-08-18 at 14:30 By A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 Read More »

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets 2026-08-18 at 14:20 By Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets Read More »

OpenAI tightens defenses after AI agents breach research environment

OpenAI tightens defenses after AI agents breach research environment 2026-08-18 at 12:41 By Anamarija Pogorelec Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked

OpenAI tightens defenses after AI agents breach research environment Read More »

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers 2026-08-18 at 12:10 By SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Read More »

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response 2026-08-18 at 05:23 By Mihir Bagwe Manual brand impersonation takedowns fail because attackers move faster than ticket-based abuse reports can resolve — phishing pages and fake executive profiles often do their damage within hours of going live, while manual removal can take days. A managed takedown program

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response Read More »

‘Fabricated rumors’ about BitMart founder, Binance bStocks dominate: Asia Express

‘Fabricated rumors’ about BitMart founder, Binance bStocks dominate: Asia Express 2026-08-18 at 04:28 By Cointelegraph by Andrew Fenton Binance’s bStocks are the second largest tokenized stock issuer just two months after launch, and BitMart’s internal feud erupts into the spotlight ahead of its closure This article is an excerpt from Cointelegraph.com News View Original Source

‘Fabricated rumors’ about BitMart founder, Binance bStocks dominate: Asia Express Read More »

OCC approves Trump family crypto company for trust charter

OCC approves Trump family crypto company for trust charter 2026-08-18 at 00:17 By Cointelegraph by Turner Wright The US financial regulator gave conditional approval for World Liberty Financial’s charter bid as ten Democrats signed onto a bill to “prevent corruption in banking applications.“ This article is an excerpt from Cointelegraph.com News View Original Source

OCC approves Trump family crypto company for trust charter Read More »

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects 2026-08-18 at 00:03 By GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects Read More »

Nvidia provides $105B in financing toward OpenAI’s massive Ohio data center — will be one of biggest in world

Nvidia provides $105B in financing toward OpenAI’s massive Ohio data center — will be one of biggest in world 2026-08-17 at 22:05 By Thomas Barrabi OpenAI has inked a 20-year deal for the site, which will ultimately provide about eight gigawatts of computing capacity that will help support products like ChatGPT. In energy terms, a

Nvidia provides $105B in financing toward OpenAI’s massive Ohio data center — will be one of biggest in world Read More »

Binance to plan UK relaunch with FCA license application: Report

Binance to plan UK relaunch with FCA license application: Report 2026-08-17 at 21:45 By Cointelegraph by Turner Wright Binance’s UK arm has been barred from offering regulated activities in the country since June 2021, but the company will reportedly move to secure licensing under new crypto rules. This article is an excerpt from Cointelegraph.com News

Binance to plan UK relaunch with FCA license application: Report Read More »

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection 2026-08-17 at 21:44 By Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection Read More »

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads 2026-08-17 at 21:22 By A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads Read More »

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic 2026-08-17 at 20:41 By Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Read More »

Scroll to Top