CFToday Curated security signals.

Daily edition · 2026-08-12

Wednesday, 12 August 2026

54 items across 7 sections, selected from 6682 candidates over 7 runs. 107 carried the panel unanimously.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. SEBI sets up dedicated task force to tackle AI-driven cyber threats (opens in a new tab)

    Google News: enforcement · News On AIR ·Governance, Risk & Compliance ·fetched 12 Aug 2026, 16:07 UTC agreed2/3

    Why readTells you SEBI is building in-house capacity on AI-enabled attacks, which is where its next round of expectations for Indian market intermediaries will come from.

    India's securities regulator has constituted a dedicated task force to address cyber threats driven by AI. The report is a short announcement with no terms of reference or timelines, so the substance is the direction of travel rather than any new obligation. Brokers, exchanges and other SEBI-regulated intermediaries should expect AI-specific questions to surface in the next round of cyber resilience guidance.

  1. Terabytes of credentials leaked in massive supply-chain attack (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 12 Aug 2026, 23:39 UTC Must read agreed3/3

    Why readIf your developers pulled LiteLLM from PyPI in March, your cloud keys, SSH keys, Kubernetes secrets and package-publishing tokens may already be in someone else's dataset; this is a rotation job, not a reading job.

    CloudSEK and Hudson Rock report that trojanised LiteLLM packages served from PyPI harvested secrets during a roughly 40 minute window in March, with Hudson Rock working from a 195TB collection of exfiltrated data. The haul reportedly spans cloud credentials, repository tokens, SSH keys, Kubernetes secrets, environment variables and AI provider keys tied to more than 2,500 organisations, including Microsoft, Amazon, Cisco, Samsung and Salesforce. Neither firm has attributed the compromise or named the source of the dataset, so the immediate priority is scoping installs against that March window and rotating anything the build environment could reach.

  2. ClickFix campaign abuses Deno runtime for infostealer delivery (opens in a new tab)

    Sophos Threat Research ·fetched 12 Aug 2026, 16:07 UTC Must read Research agreed3/3

    Why readClickFix chain that installs the Deno JavaScript runtime as its execution engine, with injected-script URLs, MSI staging detail and a Python infostealer payload.

    Sophos CTU investigated a June 2026 campaign in which compromised WordPress sites served Cloudflare-themed ClickFix lures via injected JavaScript referencing columbnezhjdq[.]com/goolgetagmanager.js, which fingerprinted the browser before showing the clipboard-paste prompt. The pasted PowerShell kicked off an MSI-based stage that installed Deno, then used it to pull and run remote JavaScript for payload delivery, tasking and persistence. Deno as a living-off-the-installed-runtime execution host is worth adding to detection logic, since a signed, freshly installed developer runtime executing remote script is unlikely to be covered by existing script-host rules.

    Indicators4
    URLs
    hxxps://columbnezhjdq[.]com/goolgetagmanager[.]js hxxp://webstizkgao[.]com/v020def066f14754be9[.]js hxxps://ordinary-computer-analytical-spell[.]trycloudflare[.]com/c
    Addresses
    162[.]33[.]177[.]16
  3. Sandworm hackers target IT pros with trojanized WireGuard VPN client (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 12 Aug 2026, 07:41 UTC Must read agreed2/2

    Why readSandworm sub-cluster UAC-0145 is delivering a trojanized WireGuard VPN client to sysadmins through fake job interviews, impersonating Sopra Steria and running the whole lure over Telegram and Zoom.

    CERT-UA attributes a social engineering campaign running since at least May to UAC-0145, believed to be a sub-cluster of Sandworm (APT44). The actor mines resumes posted on job sites, contacts targets as recruiters, moves the conversation to Telegram and stages an English-language Zoom interview where the technical assignment requires connecting to a supposed corporate VPN using a trojanized WireGuard client. One observed case impersonated Sopra Steria using addresses resembling its Bulgarian office, with configuration instructions sent by email.

    Indicators1
    Domains
    soprasteria-bg[.]com
  4. Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme (opens in a new tab)

    Group-IB ·fetched 12 Aug 2026, 07:41 UTC Must read Research agreed2/2

    Why readNames a new NFC relay malware family, WindRelay, paired with SpyNote RAT to run live-call fraud with a physical cash-out at the ATM or terminal.

    Group-IB documents WindRelay, an NFC relay malware used alongside SpyNote RAT so an operator on a live call with the victim can relay card data to a mule for withdrawal or purchase. The combination joins remote device control with physical presence at the point of cash-out, which breaks the assumption that card-present fraud implies a stolen card. Fraud and mobile threat teams should treat NFC relay as a supported capability in commodity Android tooling rather than a research curiosity.

  5. Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 12 Aug 2026, 07:41 UTC agreed2/2

    Why readKimwolf/AISURU v7 floods over HTTP/2 with full synthetic browser fingerprints, and resolves C2 via Ethereum Name Service plus a hard-coded Tor .onion, which breaks both request-anomaly DDoS filtering and DNS-based takedown.

    Unit 42 found Kimwolf v7 in February 2026. The new DDoS module builds complete browser fingerprints over HTTP/2 so flood traffic is hard to separate from real browsing, and C2 resolution now runs through a tiered chain of ENS, a hard-coded Tor hidden service, and a local clearnet-to-Tor proxy. All scanning, exploitation and brute-force code has been stripped, which the researchers read as the operators splitting propagation off from the bot itself. This is The Hacker News writing up the Unit 42 report; the primary research is where the indicators will be.

  6. CERT Polska exposes multi-stage cyberattack on energy infrastructure involving VPN, private APN, OT network tunneling (opens in a new tab)

    Google News: incidents · Industrial Cyber ·fetched 12 Aug 2026, 15:39 UTC agreed3/3

    Why readCERT Polska's account of a multi-stage intrusion into energy infrastructure that moved from VPN access through a private APN into tunnelled OT networks.

    The reported chain runs from remote access via VPN, through a private mobile APN, to tunnelling that reached operational technology segments, which is a route many utilities assume is isolated by the carrier. The item reaching us is Industrial Cyber's coverage rather than the CERT Polska report itself, so the indicator detail sits in the original; worth pulling for anyone running private APN links into OT.

  7. A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months (opens in a new tab)

    Help Net Security ·Mirko Zorz ·fetched 12 Aug 2026, 23:39 UTC agreed3/3

    Why readDetails Reco's City-Forum campaign: 17 months of record extraction from Salesforce and ServiceNow portals using legitimate access paths rather than an exploit.

    Reco tracks a still-active campaign named for a domain registered in 2002, abandoned, and now resolving to a rented server at a German hosting provider. From that host, an operator has been pulling records out of Salesforce and ServiceNow portals worldwide, with the activity relying on features working as designed rather than a vulnerability. Useful as a prompt to audit guest and portal access on both SaaS platforms; the underlying Reco writeup is the primary source.

  8. Social media platforms crack down on drone factory recruiting game (opens in a new tab)

    Malwarebytes Labs ·fetched 12 Aug 2026, 03:37 UTC agreed2/2

    Why readDocuments a recruitment funnel that starts with a mobile game, Drone Battle: Ukraine, and ends at drone assembly work in Russia's Alabuga Special Economic Zone.

    Investigators tie the game, published in English, Russian and Chinese, to the Alabuga SEZ in Tatarstan, a site linked to production of attack drones used against Ukraine. The game acts as the top of a funnel run across YouTube, TikTok, Instagram and X that markets education, careers and travel to young people before steering some toward factory jobs. The reporting is built on a Straight Arrow News investigation rather than original collection, and the security relevance is platform-based influence and data collection rather than malware.

  9. Risky Bulletin: Russian hackers jump on the fake job interview train (opens in a new tab)

    Risky Business News ·fetched 12 Aug 2026, 07:41 UTC agreed2/2

    Why readRussian state crews have picked up the fake-job-interview lure previously associated with North Korean operators, alongside the first prosecution of a malicious AI chatbot developer.

    Daily bulletin covering Russian state hackers adopting fake job interview social engineering, a Portuguese man heading to trial over a malicious AI chatbot he built, an AI assistant used to compromise an Australian gym, and OpenAI shipping models aimed at blue teams. Roundup format, so each item is a pointer rather than an analysis. Useful for the lure shift: recruitment-themed interview flows now need to be treated as a Russian TTP too, not just a DPRK one.

  10. Sexual predators targeting online accounts for intimate images, FBI warns (opens in a new tab)

    Malwarebytes Labs ·fetched 12 Aug 2026, 11:41 UTC agreed2/2

    Why readFBI PSA breaks down the specific account-takeover chain used to steal intimate images: credential guessing from breach data, then fake support texts harvesting the legitimate reset code.

    The FBI warns that criminals are compromising social media and personal accounts to steal and distribute non-consensual intimate images, then posting or selling them alongside victims' names, phone numbers, email addresses and handles. The tradecraft is ordinary but documented: high-volume login attempts seeded with breach dumps, public profile data, leak sites and predictable personal details such as name variations and birth dates, plus texts claiming imminent account lockout where the criminal triggers a real password reset and talks the victim into reading back the code. Useful for security awareness content and for anyone supporting harassment or sextortion victims, though the techniques will be familiar.

  11. FBI: Hackers using social engineering to breach accounts and steal explicit content (opens in a new tab)

    The Record ·fetched 12 Aug 2026, 19:40 UTC agreed2/3

    Why readSets out the specific account takeover tradecraft behind explicit content theft, which is useful material for consumer and family-facing awareness guidance.

    An FBI alert describes attackers breaking into the social media accounts of adults and children to steal explicit content, resell it on criminal marketplaces and post it alongside the victim's personal details. The access methods are unglamorous but effective: password and PIN reuse harvested from leak sites, and, where the attacker knows the victim, guesses built from name and birthday variations. A second pattern has the attacker posing as platform support staff, claiming the account has been compromised and pressuring the victim over text into handing over credentials or codes.

  12. Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot (opens in a new tab)

    Hacker News ·gavinhking ·fetched 12 Aug 2026, 16:07 UTC 72 points agreed2/3

    Why readIf you allowlisted ClaudeBot or similar crawlers by user-agent string, this is the reason that control no longer means anything.

    The report describes vulnerability scanning traffic arriving with the user-agent strings of well known AI crawlers, ClaudeBot among them, apparently to inherit the trust operators extend to those bots. The evidence is observational, with no source addresses or request signatures to pivot on, so hold the attribution loosely. The operational conclusion stands on its own: verify crawler identity against published IP ranges or reverse DNS, never against the string the client sends.

  1. CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign (opens in a new tab)

    The Record ·fetched 12 Aug 2026, 15:39 UTC Must read agreed3/3

    Why readCVE-2026-68820 in Winsock is confirmed exploited by North Korean operators against defence and aerospace job applicants, and CISA has set a federal deadline of August 25.

    Microsoft and CISA confirmed active exploitation of CVE-2026-68820, a Windows Winsock flaw carrying a 7.0 severity score and the only bug in August's Patch Tuesday flagged as exploited in the wild. The campaign targeted people applying for jobs in defence and aerospace, consistent with long-running DPRK social-engineering operations. There is no workaround and the fix requires a device restart, so the KEV deadline of August 25 means a reboot window, not just a patch push.

  2. Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 12 Aug 2026, 16:07 UTC Must read CVE-2026-59310 EPSS 1.1% agreed3/3

    Why readCVE-2026-59310 in VMware vCenter (CVSS 9.8) is being exploited in the wild, with 361 victim IPs across 47 countries and cron plus reverse_ssh used for persistence.

    QUIRSO found active exploitation of the directory-traversal-to-RCE flaw Broadcom patched in late July, surfacing it during an incident response engagement. Compromised hosts began contacting attacker domains on 3 August, five days after public disclosure, with path traversal followed by a malicious cron job running reverse_ssh to hold an outbound SSH channel to attacker infrastructure. EPSS is still low at 0.011, which is exactly the case where confirmed in-the-wild activity should override the model: patch vCenter now and hunt for unexpected cron entries and outbound SSH from management hosts.

  3. Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 12 Aug 2026, 23:39 UTC CVE-2026-20349 EPSS 1.0% agreed3/3

    Why readCVE-2026-20349 is being exploited in the wild against Cisco ASA and FTD Remote Access SSL VPN, there are no workarounds, and the advisory lists the exact vulnerable configurations.

    Insufficient error checking when processing HTTP requests lets an unauthenticated remote attacker send a crafted request to the Remote Access SSL VPN service and force the device to reload, causing denial of service (CVSS 8.6). Cisco confirms exploitation in the wild and states that no workarounds address the flaw, so patching is the only path. Exposure depends on configuration, including IKEv2 remote access VPN with client services enabled on an interface, which gives teams a concrete way to scope affected devices before the maintenance window.

  4. Cisco says software vulnerability could let hackers crash firewalls (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 12 Aug 2026, 15:39 UTC Must read agreed3/3

    Why readCVE-2026-20349 lets an unauthenticated remote attacker reload Cisco ASA and FTD firewalls via malformed HTTP requests to the remote-access interface, and CISA added it to KEV on release day.

    Cisco's advisory describes improper error handling when processing HTTP requests in Secure Firewall ASA and FTD software, allowing an unauthenticated attacker to trigger an unexpected device reload and a denial of service. The attack path is the remote-access connection, which on most deployments is internet-facing by design. CISA added the flaw to the Known Exploited Vulnerabilities catalog immediately, and fixed versions are available for multiple ASA and FTD trains.

    Also covered byCERT-FR (ANSSI) (opens in a new tab).

  5. Lazarus hackers exploited Windows zero-day to target defense firms (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 12 Aug 2026, 16:07 UTC CVE-2026-68820 EPSS 0.4% agreed3/3

    Why readAn actively exploited local privilege escalation in AFD.sys that shipped a fix this Patch Tuesday, with confirmed nation state use against defense and aerospace targets.

    CVE-2026-68820 is a use after free in the Windows Ancillary Function Driver for WinSock that lets a locally authenticated user win a race condition and reach SYSTEM with no user interaction. Microsoft flagged it as exploited in the wild in this month's release, and researchers tie the exploitation to Lazarus operating the long running Operation Dream Job campaign against defense, aerospace, and aviation firms in Europe and India, in one case pivoting from a compromised French organisation into spear phishing others. The low EPSS score is noise here; confirmed in the wild use by a capable actor should drive the patch priority, and the recruitment lure pattern gives detection teams something to hunt on immediately.

  6. Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 12 Aug 2026, 23:39 UTC CVE-2026-68820 EPSS 0.4% agreed3/3

    Why readCVE-2026-68820, a use-after-free in afd.sys (the WinSock kernel driver), is under active exploitation for SYSTEM-level code execution, and this month also ships a wormable DNS RCE.

    Microsoft's August 2026 Patch Tuesday covers 398 CVEs across Windows, Office, Azure, Exchange, SharePoint, Teams, GitHub Copilot and .NET, 62 of them Critical. CVE-2026-68820, a use-after-free in the Ancillary Function Driver for WinSock, is confirmed exploited in the wild despite Microsoft's own exploit maturity rating of Unproven and an EPSS of just 0.004. A wormable DNS remote code execution flaw is the other bug to prioritise in the rollout.

    Also covered byHelp Net Security (opens in a new tab),CSO Online (opens in a new tab),CrowdStrike (opens in a new tab),The Register Security (opens in a new tab),Qualys ThreatPROTECT (opens in a new tab).

  7. Hackers exploit critical Adobe Commerce flaw to hijack customer accounts (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 12 Aug 2026, 23:39 UTC CVE-2026-71362 EPSS 0.5% agreed3/3

    Why readExploitation attempts are already hitting CVE-2026-71362 in Adobe Commerce and Magento, and the bug allows unauthenticated takeover of customer accounts by switching a session to another customer.

    Adobe patched seven issues this week and said it knew of no in-the-wild exploitation, but Sansec reports its Shield WAF is already blocking attempts against CVE-2026-71362, an incorrect authorization flaw. Sansec's review of the patch traced it to Magento mishandling customer identity in an account session, letting an attacker switch a customer session to another customer with no existing account, admin privileges or user interaction. Merchants running Commerce or Magento should treat this as an immediate patch and review sessions and order data for signs of account hijacking.

  8. Metabase SQLi exploit grants attackers total access (opens in a new tab)

    CSO Online ·fetched 12 Aug 2026, 03:37 UTC CVE-2026-72898 EPSS 0.7% agreed2/2

    Why readCVE-2026-72898 is a CVSS 10 SQL injection in Metabase 1.58 and later with public proof-of-concept code, exposing the database credentials, tokens and API keys the platform stores.

    Metabase disclosed a zero-day SQL injection on 6 August affecting versions 1.58 and up, rated 10.0, with working exploit code already public. Because Metabase brokers connections to Databricks, MongoDB, Oracle, Snowflake and BigQuery among others, a successful exploit reaches stored credentials and gives raw database access rather than just the BI layer. Shodan tracks roughly 2,500 exposed instances and Wiz reports Metabase present in about 13% of cloud environments; EPSS is still low at 0.007, so this is patch-before-it-turns rather than confirmed mass exploitation.

  9. ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 12 Aug 2026, 15:39 UTC CVE-2026-50656 EPSS 10.7% agreed3/3

    Why readA public PoC bypasses Microsoft's July patch for CVE-2026-50656, giving SYSTEM on fully updated Windows 11 25H2 and Server 2025 with a claimed 100 percent success rate.

    Researcher Chaotic Eclipse has released ShieldBreak, a proof of concept that defeats the fix for RoguePlanet (CVE-2026-50656), a Microsoft Defender race condition that spawns a SYSTEM shell. The author says it was tested on Windows 11 25H2 including the Canary channel and on Windows Server 2025, and that Windows 10 and its server editions are vulnerable but unsupported by the PoC. There is no patch for the bypass, so the practical response is detection on Defender process-spawning behaviour rather than patching. EPSS on the original CVE sits at 0.107, 95th percentile.

    Also covered byThe Hacker News (opens in a new tab).

  10. Zoom Zero-Click RCE Flaws Allow Any Meeting Attendee to Compromise All Participants (opens in a new tab)

    Orca Security ·The Orca Research Pod ·fetched 12 Aug 2026, 23:39 UTC Research CVE-2026-53415 EPSS 0.4% agreed3/3

    Why readMemory corruption in Zoom Workplace annotation message handling gives zero-click RCE against every participant in a meeting, on all platforms.

    CVE-2026-53413 and CVE-2026-53415 (CVSS 8.3 and 9.0) are critical memory corruption bugs in Zoom Workplace clients, reachable through malicious annotation messages sent inside a meeting. Any attendee can use them to compromise all other participants without user interaction, putting full device compromise one meeting invitation away. Client patching should be pushed on managed fleets rather than left to user-initiated updates, given how much of the install base sits on personal machines.

  11. CVE-2026-19429 (CVSS 9.4): Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for CVE-2026-33001 and CVE-2026-704 (opens in a new tab)

    NVD ·fetched 12 Aug 2026, 11:41 UTC CVE-2026-19429 CVSS 9.4 EPSS 0.2% agreed2/2

    Why readA full Jenkins controller compromise chain: TAR symlink extraction reads the secrets directory, the remember-me signing key forges an admin cookie, and the Script Console gives RCE, all in versions already patched for two earlier CVEs.

    CVE-2026-19429 shows FilePath.untarFrom() still does not validate symlink targets in extracted TAR archives, even after the fixes for CVE-2026-33001 and CVE-2026-70427. An attacker with job configuration rights plants an archive whose extraction creates workspace symlinks to arbitrary controller files, reads the secrets directory, forges a signed remember-me cookie for an administrator, and reaches the Script Console. Jenkins 2.576 additionally lets the CVE-2026-70427 blank-name check be bypassed with zero-width characters (U+200B, U+200C, U+200D, U+2060, U+00AD) that Java's String.isBlank() does not treat as whitespace.

  12. ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability (opens in a new tab)

    ZDI Published Advisories ·fetched 12 Aug 2026, 03:37 UTC Research CVE-2026-62911 agreed2/2

    Why readPwn2Own Exchange bug that yields code execution as SYSTEM via an unvalidated user-supplied file path, with the required authentication bypassable.

    CVE-2026-62911 in Microsoft Exchange stems from missing validation of a user-supplied path before it is used in file operations, giving a remote attacker arbitrary code execution as SYSTEM. Authentication is nominally required but ZDI notes the existing mechanism can be bypassed, which pairs it with the capture-replay auth bypass filed the same day. Microsoft has shipped an update; on-premises Exchange operators should treat this as priority patching given the product's exposure.

  1. Signal adds new security feature to thwart man-in-the-middle attacks (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 12 Aug 2026, 11:41 UTC Must read agreed2/2

    Why readSignal's Automatic Key Verification replaces manual safety-number comparison with a key transparency log audited by Cloudflare and Trail of Bits, removing the out-of-band step nobody performed.

    Signal shipped Automatic Key Verification, built on a key transparency system in which the user, their contacts and third-party auditors independently verify that the mapping between a phone number or username and its public key is globally consistent. The stated threat model is a key silently swapped out without the owner's knowledge, including by an attacker who has compromised Signal itself. For teams that mandate Signal for sensitive comms, this changes the verification guidance in the runbook: the in-person safety-number check is no longer the only assurance available.

  2. Linux Kernel Process Accounting, (Wed, Aug 12th) (opens in a new tab)

    SANS ISC Diary ·fetched 12 Aug 2026, 15:39 UTC agreed3/3

    Why readA working introduction to Linux kernel process accounting as an execution telemetry source that survives everything a user can do to their shell history.

    The diary walks through enabling process accounting with `accton`, which makes the kernel write a binary record for every terminated process to /var/log/account/pacct. Because the collection happens in the kernel rather than in the shell, it captures commands regardless of interpreter, wrapper, or history tampering, at the cost of some extra disk writes. Useful as a cheap fallback where you cannot deploy auditd or an EDR agent, and as a corroborating source when reconstructing activity on a host.

  3. On the Sensitivity to Errors in Homomorphic Computing: Single Transient Bit-flip Client-side Error Characterization (opens in a new tab)

    arXiv cs.CR (all) ·Matías Mazzanti, Vattana Chan, Karthik Swaminathan, Augusto Vega ·fetched 12 Aug 2026, 23:39 UTC Research agreed3/3

    Why readShows that a single transient bit flip on the client side can silently corrupt homomorphic computation, which matters if you are planning to trust CKKS results in a production pipeline.

    The authors characterise how bit-level faults propagate through the CKKS approximate-arithmetic scheme and identify homomorphic multiplication as by far the most error-sensitive operation in practical HE pipelines. Because HE already relies on deliberate noise injection, injected or accidental faults blend into that noise and evade conventional integrity checks, producing silent data corruption rather than a visible failure. The paper is a robustness characterisation rather than an attack, but it sets up the obvious follow-on question of whether an adversary with fault-injection capability can steer the result.

  4. This Tool Unmasks the Shadowy World of Ads that Track Your Location (opens in a new tab)

    404 Media ·Joseph Cox ·fetched 12 Aug 2026, 16:07 UTC agreed3/3

    Why readDecryptAds lets you query which ad brokers operate on a given site and where else those same brokers appear, collapsing work that previously meant hand-reading obscure adtech files.

    The tool aggregates a large corpus of advertising and data-broker records so a researcher can pivot from one website to the brokers present on it, then out to every other property those brokers touch. That pivot is the new capability: location-data supply chains have been hard to map because the evidence sits in files nobody reads and cannot be searched together. Relevant to anyone assessing third-party tracking exposure on their own web properties or investigating location-data resale.

  5. dweep-desai/FaceGate-Mac: World's first Face Authentication enabled MacOS App-locker, completely free and open-source. Unlock your Mac apps using Face , TouchID or password. Completely local and encrypted - your data nev (opens in a new tab)

    GitHub: new security tools ·dweep-desai ·fetched 12 Aug 2026, 23:39 UTC Research ★ 425 agreed3/3

    Why readOpen-source macOS app-locker that gates individual application launches behind on-device face recognition, Touch ID or a password, with no telemetry.

    FaceGate intercepts app launches on macOS and blocks them until the user authenticates, using a face embedding pipeline that runs locally on the Apple Neural Engine. It supports up to three enrolled faces, external USB cameras and head-pose liveness challenges. Native Swift and free, but per-app locking on a shared workstation is a weak control against anyone with local admin, so treat it as convenience hardening rather than an enterprise measure.

  6. Statistically-Secure Bit Commitment and Coin Flipping Protocols Based on Quantum Hardware Assumptions (opens in a new tab)

    arXiv cs.CR (all) ·Roo Dunnill, Mina Doosti ·fetched 12 Aug 2026, 16:07 UTC Research agreed2/3

    Why readA genuine escape from the Mayers and Lo-Chau impossibility result for unconditionally secure bit commitment, achieved by adding a hardware assumption rather than a computational one.

    The authors build statistically hiding and binding bit commitment from hybrid locked physical unclonable functions, a primitive pairing classical hardware tokens with quantum communication, and derive the first hardware based coin flipping protocol from the same construction. The security proofs rest on stated assumptions about the HLPUF plus a purpose built challenge generation subroutine, so the result is only as strong as those hardware assumptions hold in practice. This is foundational two party cryptography for future quantum networks, not something that touches a current control set; the panel members who filed it under offense misread a protocol construction as attack work.

  7. Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse (opens in a new tab)

    BleepingComputer ·Mayank Parmar ·fetched 12 Aug 2026, 03:37 UTC agreed2/2

    Why readGoogle's own figure that Chrome suppressed 7 billion unwanted Android notifications a day in Q1 2026, with permissions auto-revoked from inactive and repeatedly flagged sites.

    Google describes a layered anti-abuse approach for Chrome notifications on Android, aimed at scam, malware, phishing and fraudulent payment prompts. Chrome now strips notification permissions from dormant sites and from sites that repeatedly trigger suspicious-notification warnings, unsubscribing users automatically, with the revocations reviewable and reversible in Safety Hub. The headline volume figure comes from Google with no published methodology, and nothing here is deployed by the reader.

DFIR

1
  1. AdvDebug/Brovan: Brovan is a user-mode x86_64 binary emulator for your malware analysis & reverse engineering. (opens in a new tab)

    GitHub: new security tools ·AdvDebug ·fetched 12 Aug 2026, 03:37 UTC Research ★ 155 agreed2/2

    Why readA user-mode x86_64 emulator that runs untrusted binaries without executing them on the host CPU, tracing API and syscall activity and capturing guest socket traffic for export.

    Brovan is a C# emulator for malware analysis and reverse engineering that loads and executes binaries inside the emulator, with hardware acceleration via Windows Hypervisor Platform on Windows and KVM on Linux. It exposes live inspection of the functions, DLLs and kernel calls a sample reaches, intercepts guest network traffic for export, and includes a Vulkan translation subsystem handling DXVK calls for graphical software. The author states it is early in development and not yet reliable, so treat it as a supplementary tracing option rather than a replacement for an established sandbox.

  1. Prompt Injections for Defense (opens in a new tab)

    Schneier on Security ·Bruce Schneier ·fetched 12 Aug 2026, 11:41 UTC Must read agreed2/2

    Why readTracebit's 'context bombing' inverts prompt injection into a defensive canary: seeding guardrail-tripping text next to AWS secrets makes attacking LLM agents halt.

    Tracebit found that placing prompt injections alongside stored credentials and keys in AWS was frequently enough to stop autonomous AI attack agents. The payload instructs the attacking model to do something its guardrails forbid, such as describing inhalable anthrax production, or for Chinese-developed models to reference Tank Man, at which point the model stops following its operator's instructions. Schneier's caveat is the operational limit: the technique only works against agents that have guardrails, so locally run unaligned models defeat it.

  2. A Gateway Architecture for Enterprise MCP Authentication: Unifying Heterogeneous Auth, Identity Delegation, and the User / Non-User Persona Problem (opens in a new tab)

    arXiv cs.CR (AI) ·Suraj Kumar, Amy Wang, Srinivasan Manoharan ·fetched 12 Aug 2026, 03:37 UTC Must read Research agreed2/2

    Why readA production MCP gateway design that fixes fragmented per-server auth, including the awkward case of automated non-user callers.

    The paper reports an enterprise deployment where dozens of internally built MCP servers each implemented authentication differently, from none at all to full OAuth, leaving no way to authorise callers, attribute actions or offboard a departing employee across the fleet. The answer is a single fronting gateway with a two-axis model crossing persona (interactive user versus automated non-user) against credential type (no-auth, static or dynamic API key, PKCE, client credentials, platform app-context), plus a layer supporting three enterprise SSO grants and three token types. Useful if you are standing up MCP internally and have not yet decided how identity delegation works.

  3. China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack (opens in a new tab)

    Google News: incidents · Financial Times ·fetched 12 Aug 2026, 16:07 UTC agreed3/3

    Why readThe first mainstream report of an intrusion campaign described as autonomously driven by AI rather than merely AI assisted, which is the line executives will ask about.

    The Financial Times reports a China linked campaign against Taiwanese targets characterised as an unprecedented autonomous AI cyber attack. Only the headline is available in this feed, so the operative claim, what autonomous means in the reporting and who made the assessment, is not verifiable from what is in front of us. Worth tracking because the framing marks a threshold rather than an increment, but hold the must read designation until the underlying technical account or the vendor report behind it lands.

  4. fu351/Doberman-Core: Doberman is an AI agent security framework for guardrails, prompt injection defense, runtime policy enforcement, tool-use permissions, agent monitoring, audit logs, LLM safety, autonomous workflow pr (opens in a new tab)

    GitHub: new security tools ·fu351 ·fetched 12 Aug 2026, 15:39 UTC Research ★ 203 agreed3/3

    Why readAn open-source MCP proxy that sits on the execution path between a coding agent and its tools, failing closed on every call and refusing to loosen policy silently.

    Doberman is a Python framework that intercepts AI coding agent tool calls as a transparent MCP proxy or host hook, issuing exactly one allow/deny verdict per call before execution and logging it for audit. Two design commitments are worth arguing with: it fails closed when uncertain, and policy is raise-only, so it can tighten automatically but never relax without a human. It works with Claude Code, Cursor, Codex and Copilot, and publishes an attack-block-rate versus false-positive benchmark, though the benchmark methodology is the part to check before trusting the numbers.

  5. On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models (opens in a new tab)

    arXiv cs.CR (AI) ·Md Jafrin Hossain, Mohammad Arif Hossain, Nirwan Ansari ·fetched 12 Aug 2026, 07:41 UTC agreed2/2

    Why readQuantifies where agentic LLM security research is concentrated and where it is not: 66% of papers cover prompt injection and jailbreaking, only 4.7% cover tool misuse, code injection and sandbox escape.

    A PRISMA 2020 systematic review screened 743 records across six databases and retained 85 papers on agentic LLM security from 2023 to 2025. Attack research outpaces defence work 3.9:1, perception-layer issues dominate at 66% of papers, and action-layer vulnerabilities appear in just 4.7% with code execution security at 3.5%. The authors argue this distribution is misaligned with the real risk profile of agents that call APIs, write files and query databases.

  6. Emergent Introspective Awareness in Large Language Models (opens in a new tab)

    Hacker News ·doener ·fetched 12 Aug 2026, 11:41 UTC Research 62 points agreed2/2

    Why readIt supplies an experimental method for checking whether a model's self-report actually tracks its internal state, which is the missing measurement underneath every claim that a model can be asked what it is doing.

    The authors inject representations of known concepts directly into a model's activations and then measure whether the model's self-reported states change in ways that match the injection, separating genuine introspection from plausible confabulation. Models sometimes notice and correctly name an injected concept, recall earlier internal representations, and use recalled intent to tell their own output apart from a prefill someone else wrote. Capability tracks model strength, with Claude Opus 4 and 4.1 performing best, and the results are conditional rather than reliable, so this reads as a first usable probe rather than a working evaluation.

  7. Exploring Claude/GPT Knowledge Cutoffs and Pre-Training Timelines (opens in a new tab)

    Hacker News ·sshh12 ·fetched 12 Aug 2026, 07:41 UTC Must read 156 points agreed2/2

    Why readDocuments three black-box probing methods that infer a closed model's parameter scale, training-data mixture and training cutoff from its outputs alone.

    The author probes GPT-5 and Opus with niche-fact recall ("incompressible knowledge probes") to approximate parameter count, inspects tokenizer behaviour to infer dataset mixture ("data mixture inference"), and uses date and self-identification questions to estimate pre-training timelines. The methods are stated clearly enough to reproduce, and the post is explicit that the conclusions are estimates with little public ground truth to check against. For anyone reasoning about model provenance or what a deployed model leaks about its own training, the techniques are the takeaway rather than the specific numbers.

  8. Defaulting on tech debt: When the bill comes due, AI is the collector (opens in a new tab)

    Sysdig ·fetched 12 Aug 2026, 16:07 UTC agreed3/3

    Why readEight publicly documented AI enabled operations, from state espionage through experimental malware to the first agentic ransomware, mapped as a set against MITRE ATT&CK and ATLAS.

    Sysdig's threat research team aggregates incidents that have so far only been reported individually and normalises them onto ATT&CK for victim side tradecraft plus ATLAS for the AI specific layer, which is the part worth the read; a cross case mapping shows which stages attackers are actually automating rather than which ones vendors claim they are. The surrounding technical debt framing is house metaphor and the recommendations are the expected ones about attack surface created at deployment time. Read it as a consolidated reference on documented AI enabled operations to date, and discount the narrative around it.

  9. Hackers abuse AI models to find new entry paths (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 12 Aug 2026, 16:07 UTC agreed2/3

    Why readThe one durable point is directional: guardrails on frontier models are pushing serious actors toward open-weight ones, which moves AI abuse out of the places vendors can observe it.

    Accenture and Google Cloud researchers told a Black Hat media session that criminal and state-aligned groups are testing both frontier and open-weight models for exploit development, faster operations, and persistence via living-off-the-land tooling. The stated driver for the shift to open weights is oversight avoidance rather than raw capability, with Google Threat Intelligence Group framing it as a question of where an operator is willing to be watched. No new tradecraft, samples, or named campaigns are attached, so treat it as a read on the direction of travel and on the shrinking value of vendor-side telemetry for detecting AI-assisted operations.

  1. Three intrusions at UK criminal records office went undetected for two years (opens in a new tab)

    The Record ·fetched 12 Aug 2026, 15:39 UTC agreed3/3

    Why readThe ICO reprimand names the specific failures behind three breaches of a UK policing body: a Kentico portal frozen at its September 2019 version and a critical system unpatched for nearly four years.

    The Information Commissioner's Office has formally reprimanded ACRO Criminal Records Office after attackers compromised its public-facing customer portal three separate times between July 2021 and June 2023, exposing personal data including that of domestic violence victims. The portal ran on a Kentico CMS build unchanged since September 2019 with multiple known flaws, antivirus alerts went unread, and one critical system sat unpatched for close to four years. It is a clean example of a regulator treating patch and alert hygiene as the finding, which is the shape of enforcement peers should expect.

  2. Klue Security Incident and Impact on Recorded Future (opens in a new tab)

    translated KlueセキュリティインシデントとRecorded Futureへの影響

    Recorded Future ·fetched 12 Aug 2026, 23:39 UTC agreed3/3

    Why readRecorded Future discloses that a compromised OAuth token between Salesforce and marketing vendor Klue exposed customer contact data and some contract information, a concrete example of the third-party SaaS integration blast radius boards keep asking about.

    Klue notified Recorded Future's CSIRT on 13 June 2026 that its integration layer connecting Klue to marketing and sales SaaS platforms had been accessed without authorization, with activity starting 12 June and contained the same morning. Recorded Future's own log correlation confirmed that part of its Salesforce tenant was reached via a compromised OAuth token tied to the Salesforce-Klue integration, exposing business data fields such as customer contact names and email addresses and possibly some contract information. No access to Recorded Future's own systems, internal databases or customer platform data was found; the integrations connected to Klue were disconnected as part of the response, and the investigation is continuing.

  3. Health IT Vendor’s Data Breach Exposes Nearly 4M Patient Records (opens in a new tab)

    Google News: incidents · MedCity News ·fetched 12 Aug 2026, 07:41 UTC agreed2/2

    Why readRoughly 4 million patient records exposed through a health IT vendor, the kind of third-party healthcare breach that lands on a board agenda and in HHS reporting.

    A health IT vendor disclosed a data breach affecting close to 4 million patient records. The report available is brief and does not name the intrusion method or the downstream provider organisations affected. Relevant mainly as scale and as another supplier-side incident in healthcare.

  4. Credit unions win round against Snowflake in data breach case (opens in a new tab)

    Google News: incidents · American Banker ·fetched 12 Aug 2026, 11:41 UTC agreed2/2

    Why readCredit unions cleared a procedural hurdle in their breach litigation against Snowflake, a live test of whether a cloud data platform bears downstream liability for customer credential compromise.

    A court ruled in favour of credit union plaintiffs on an early stage of their data breach case against Snowflake, per American Banker. Only the headline reached us, so the specific motion, jurisdiction and reasoning are unstated. The direction matters well beyond banking: the 2024 Snowflake-tenant compromises were driven by customers' own stolen credentials and absent MFA, so any finding that the platform shares responsibility reshapes shared-responsibility arguments and vendor contract negotiations.

  5. Discord ordered to suspend livestreams in Brazil (opens in a new tab)

    BBC Technology ·fetched 12 Aug 2026, 19:40 UTC agreed3/3

    Why readBrazil's ANPD has ordered Discord to suspend Go Live streaming nationwide, on the finding that the company lacks real-time access to livestream content for moderation.

    The order follows an investigation opened 7 August into the death of a 13-year-old girl who was reportedly pressured to take her own life during a broadcast in an invite-only server. ANPD's stated rationale is that Discord cannot inspect livestreams in real time, which blocks automated intervention. A data protection authority regulating a product feature on child-safety grounds is a precedent any platform or consumer-facing service should have an answer for.

  6. 15M patients impacted by largest healthcare data breach of 2026 (opens in a new tab)

    Google News: incidents · HealthExec ·fetched 12 Aug 2026, 11:41 UTC agreed2/2

    Why readA 15 million patient breach now stands as the largest healthcare incident of 2026, the number a health-sector board will ask about this week.

    HealthExec reports a breach affecting roughly 15 million patients, the largest disclosed in healthcare so far in 2026. The item as received carries the scale figure and nothing further: no named covered entity, no attribution, no intrusion detail. Useful as a marker of sector exposure and a likely regulatory and litigation trigger; wait for the primary notification for anything actionable.

  7. ‘Something Was Wrong.’ Hasbro’s Lessons From a Cyberattack. (opens in a new tab)

    Google News: incidents · WSJ ·fetched 12 Aug 2026, 03:37 UTC agreed2/2

    Why readA named consumer brand walking through what its own cyberattack response got right and wrong, in the outlet your board reads.

    WSJ covers Hasbro's account of a cyberattack and the lessons its leadership drew from the response. This is the retrospective framing an executive team asks about rather than technical campaign detail. Useful as a peer reference point for anyone briefing a board on incident readiness.

  8. After cyberattack on water system, Cape May mayor calls for more federal support (opens in a new tab)

    Google News: incidents · WNYC ·fetched 12 Aug 2026, 07:41 UTC agreed2/2

    Why readA water utility intrusion has a sitting mayor publicly asking for federal help, which is where the small-utility funding argument is now being made.

    Following a cyberattack on the Cape May water system, the mayor called for greater federal support for municipal utilities. No detail is given on the intrusion, the systems affected or whether operational technology was involved. It is worth tracking as pressure builds on federal water sector cybersecurity funding.

  9. Cyberattack shutters Suisun City Hall, prompts local state of emergency (opens in a new tab)

    Google News: incidents · nbcbayarea.com ·fetched 12 Aug 2026, 11:41 UTC agreed2/2

    Why readSuisun City declared a local state of emergency and closed City Hall over a cyberattack, a concrete data point for anyone briefing on municipal ransomware exposure.

    A cyberattack shut Suisun City Hall in California and prompted a local state of emergency declaration. Only the headline reached us, so the attack class, entry point and recovery status are unstated. The emergency declaration is the notable element: it is the mechanism small municipalities use to unlock mutual aid and emergency procurement, and peer local governments will be asked whether their own plans contemplate it.

  10. Slotkin reveals how water system cyberattack hit Michigan. What she said (opens in a new tab)

    Google News: incidents · Detroit Free Press ·fetched 12 Aug 2026, 19:40 UTC agreed2/3

    Why readA named US water utility intrusion described publicly by a sitting member of Congress, which is the form of this story executives and utility boards will be asked about.

    Detroit Free Press reports Senator Elissa Slotkin publicly describing how a cyberattack affected a Michigan water system. The item is thin on technical specifics, but it moves the water sector threat from generic warning into a named, officially acknowledged incident in a specific state. That distinction matters for anyone briefing utility leadership or regional government on operational technology exposure.

  11. Behind the Data Breach Targeting Clothing Giant Levi Strauss (opens in a new tab)

    Google News: incidents · cybermagazine.com ·fetched 12 Aug 2026, 03:37 UTC agreed2/2

    Why readLevi Strauss joins the run of named retail and apparel brands disclosing data breaches this year.

    Coverage of a data breach at Levi Strauss, framed around the consumer brand rather than the intrusion. The supplied text carries no detail on the intrusion vector, data types affected or scale. Worth logging as a sector data point for anyone tracking retail exposure, but wait for a primary disclosure for anything substantive.

  12. Weekly Update 516: Live From Vietnam (opens in a new tab)

    Troy Hunt ·Troy Hunt ·fetched 12 Aug 2026, 19:40 UTC agreed2/3

    Why readUses the Brinks Home breach FAQ as a worked example of incident communications that are legally cautious to the point of answering nothing.

    Troy Hunt walks through the Brinks Home breach FAQ and notes that the company authored its own questions and then declined to answer most of them, a pattern of lawyer-shaped language that leaves customers no better informed. He sketches the sequence these events now reliably follow: voice phishing into an OAuth grant, extortion demand, refusal, data dump, mass class action filings, then notification only where the law compels it. The value here is as a checklist of what not to publish when your own incident FAQ goes live.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Riker Danzig Scherer Hyland & Perretti SilentRansomGroup Professional Services - 12 Aug 2026
Hightech Signs kairos Manufacturing US 12 Aug 2026
Riker Danzig LLP SilentRansomGroup Professional Services US 12 Aug 2026
gamaus.com incransom Technology US 12 Aug 2026
Tianji Auto Care Service Company nightspire Transportation TR 12 Aug 2026
Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... blacknevas Agriculture and Food Production US 12 Aug 2026
Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... blacknevas Healthcare US 12 Aug 2026
Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... blacknevas Professional Services CA 12 Aug 2026
United Association Local Union 345 qilin - US 12 Aug 2026
BEDC.COM.AU incransom Energy & Utilities AU 12 Aug 2026
diabetesandmetabolism.com incransom Healthcare US 12 Aug 2026
AOL.COM clop Technology US 12 Aug 2026
GATE7LLC.COMGBBEV.COM clop - GB 12 Aug 2026
ENTERATEK.MXESBERBEVERAGE.COM clop Agriculture and Food Production MX 12 Aug 2026
NUVITIA.COM clop Technology FR 12 Aug 2026
IPMSOLUTIONS.SK clop Professional Services SK 12 Aug 2026
ECCELLENT.COM clop - IT 12 Aug 2026
STNET.IT clop Technology IT 12 Aug 2026
QCPL.IN clop Manufacturing IN 12 Aug 2026
FLUIDLOGIC.COM clop Technology US 12 Aug 2026
MIDLANDIND.COM.AU clop Manufacturing AU 12 Aug 2026
ITKHOLDING.HU clop Technology HU 12 Aug 2026
G3AEROSPACE.COM clop Government & Defense US 12 Aug 2026
ARCHERGREY.COM clop - US 12 Aug 2026
OMNITANKER.COM clop Transportation US 12 Aug 2026
How this edition was made
Candidates fetched
6682
New after deduplication
840
Kept by the panel
149
Published
118
Generated
12 Aug 2026, 23:39 UTC