SecurityTicks

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs 2026-08-31 at 14:24 By Ionut Arghire Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs Read More »

Hyperliquid, Pump.fun account for nearly 90% of record $638M crypto buybacks: FT

Hyperliquid, Pump.fun account for nearly 90% of record $638M crypto buybacks: FT 2026-08-31 at 14:21 By Cointelegraph by Zoltan Vardai Crypto projects spent a record $638 million on token buybacks so far in 2026, as more protocols are turning their revenue into buybacks to return more value to token holders. This article is an excerpt

Hyperliquid, Pump.fun account for nearly 90% of record $638M crypto buybacks: FT Read More »

Markets pivot to September Fed rate hike: Five things to know in Bitcoin this week

Markets pivot to September Fed rate hike: Five things to know in Bitcoin this week 2026-08-31 at 13:51 By Cointelegraph by William Suberg Bitcoin approached the August monthly close below key resistance with markets once again pricing in a Federal Reserve interest-rate hike in September. This article is an excerpt from Cointelegraph.com News View Original

Markets pivot to September Fed rate hike: Five things to know in Bitcoin this week Read More »

Boston Scientific Still Recovering From Cyberattack

Boston Scientific Still Recovering From Cyberattack 2026-08-31 at 13:50 By Eduard Kovacs The company has called in CrowdStrike and others to investigate the attack that caused global network disruption. The post Boston Scientific Still Recovering From Cyberattack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Boston Scientific Still Recovering From Cyberattack Read More »

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs 2026-08-31 at 13:44 By A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate,

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs Read More »

Extortion Group Claims Manchester Airports Group Data Breach

Extortion Group Claims Manchester Airports Group Data Breach 2026-08-31 at 13:29 By Ionut Arghire FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online. The post Extortion Group Claims Manchester Airports Group Data Breach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Extortion Group Claims Manchester Airports Group Data Breach Read More »

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails 2026-08-31 at 12:45 By Sinisa Markovic Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails Read More »

Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’

Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ 2026-08-31 at 12:07 By Associated Press The ruling is part of Anthropic’s legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year. The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ appeared first

Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ Read More »

More Markets lending reserve drained for $9.3M: Blockaid

More Markets lending reserve drained for $9.3M: Blockaid 2026-08-31 at 11:57 By Cointelegraph by Zoltan Vardai Blockaid said an attacker used an Ankr liquid staking token and E-mode to overborrow from More Markets and drain about $9.3 million in WFLOW from a lending reserve. This article is an excerpt from Cointelegraph.com News View Original Source

More Markets lending reserve drained for $9.3M: Blockaid Read More »

Berlin Won’t Pay Extortion Group Claiming Data Theft

Berlin Won’t Pay Extortion Group Claiming Data Theft 2026-08-31 at 11:49 By Ionut Arghire The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials. The post Berlin Won’t Pay Extortion Group Claiming Data Theft appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Berlin Won’t Pay Extortion Group Claiming Data Theft Read More »

Debian developers rejected an LLM ban and left disclosure voluntary

Debian developers rejected an LLM ban and left disclosure voluntary 2026-08-31 at 11:08 By Anamarija Pogorelec A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result:

Debian developers rejected an LLM ban and left disclosure voluntary Read More »

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims 2026-08-31 at 10:56 By The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted.

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims Read More »

More Details Emerge on Exploited PaperCut Vulnerabilities

More Details Emerge on Exploited PaperCut Vulnerabilities 2026-08-31 at 09:51 By Eduard Kovacs PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578. The post More Details Emerge on Exploited PaperCut Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Details Emerge on Exploited PaperCut Vulnerabilities Read More »

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 2026-08-31 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity,

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree Read More »

Halo-record: Open-source audit trails for AI agents

Halo-record: Open-source audit trails for AI agents 2026-08-31 at 08:30 By Mirko Zorz Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to,

Halo-record: Open-source audit trails for AI agents Read More »

AI AppSec tools agree on just 5% of security findings

AI AppSec tools agree on just 5% of security findings 2026-08-31 at 08:23 By Sinisa Markovic Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of viable application attacks (Source: Contrast Security) Contrast Security’s AppSec Overflow 2026 report draws on telemetry collected from

AI AppSec tools agree on just 5% of security findings Read More »

Scroll to Top