CFToday Curated security signals.

Daily edition · 2026-08-14

Friday, 14 August 2026

48 items across 9 sections, selected from 6029 candidates over 6 runs. 105 carried the panel unanimously.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel (opens in a new tab)

    Cybersecurity News ·Threat Intel & Breaches ·Tushar Subhra Dutta ·fetched 14 Aug 2026, 11:38 UTC agreed2/3

    Why readGives you three new malware family names and a C2 channel, GitHub Gists, that most egress policies and proxy allowlists let through untouched.

    Acronis researchers documented a framework they call HACKERAI C2 Agent that reads operator commands from and exfiltrates data to GitHub Gists, alongside two related families named PATCHCORD and SHEETCORD. The campaign targeted telecom, government, defense, energy, and critical infrastructure in South Asia using lures posing as telecom services, government updates, and software installers, and is tied with moderate confidence to APT36 or a closely related Pakistan-linked actor. This is a rewrite of the Acronis report rather than primary research, so treat the vendor writeup as the source for indicators; the useful takeaway is that gist.github.com traffic from workstations deserves the same scrutiny as any other cloud C2 fronting service.

    Indicators4
    Hashes
    74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2 cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6 1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94 378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668
  1. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit (opens in a new tab)

    Securelist ·Fareed Radzi ·fetched 14 Aug 2026, 11:38 UTC Must read Research agreed3/3

    Why readHoneyMyte's CoolClient backdoor now loads a signed kernel-mode driver as a Windows service and drives it over IOCTLs to hide its process, files and registry keys from inspection.

    The latest CoolClient variant, attributed to HoneyMyte (Mustang Panda), adds a signed kernel-mode rootkit deployed as a Windows service, with the user-mode component communicating through IOCTL requests. The driver hides the CoolClient process and protects its files and registry entries against inspection or modification, a step up from the 2025 variant that added clipboard theft and HTTP interception for credential harvesting. Targeting remains espionage against organisations in Asia and Russia; the signed-driver angle means detection has to move to driver load and service creation telemetry rather than process inspection.

  2. Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain (opens in a new tab)

    Truesec ·Hjalmar Desmond ·fetched 14 Aug 2026, 11:38 UTC Must read agreed3/3

    Why readEvidence that Russian pressure on Europe's Ukraine defence supply chain has moved past sabotage to physical surveillance of named executives and their families.

    Truesec pulls together reporting on German investigations into surveillance of the CEO of drone manufacturer Donaustahl and his family in late 2025 and early 2026, and sets it against the wider sabotage, arson and assassination-plot campaign Western officials described from 2024 onward. It notes that Russia's Ministry of Defence published addresses of European drone manufacturers supporting Ukraine in April 2026, with Dmitry Medvedev describing such sites as legitimate targets. The synthesis is drawn from open sources rather than original investigation, but the threat model shift it describes should reach personnel and physical security teams at defence suppliers, not just their SOCs.

  3. New Mirai variant adds stealth capabilities to notorious botnet code (opens in a new tab)

    The Record ·fetched 14 Aug 2026, 03:39 UTC agreed3/3

    Why readNames the device vendors a previously undocumented Mirai derivative, Evooo1Bot, has been exploiting for at least a month: Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare.

    FortiGuard Labs report a Linux-based Mirai variant spreading through unpatched bugs in internet-facing routers and embedded hardware, active for around a month and not previously documented. Beyond the usual DDoS functions it adds encrypted command-and-control communications and a scanner that fingerprints SSH and skips already-compromised devices. Telemetry shows activity across North and South America, Europe, India, China and Japan; no compromise count is given. This is a write-up of Fortinet's research, so go to the original for indicators.

  4. New Android malware relays bank cards to fraudsters while victims still hold them (opens in a new tab)

    Help Net Security ·Sinisa Markovic ·fetched 14 Aug 2026, 15:40 UTC agreed3/3

    Why readGroup-IB's WindRelay Android malware captures live NFC payment card data and relays it to a mule terminal in real time while the victim is still on the phone with the fake bank caller.

    WindRelay is an Android relay tool paired with the SpyNote RAT for remote device access. The chain begins with a vishing call impersonating the victim's bank; the victim is induced to tap their card against the infected phone, and the NFC transaction data is relayed to an attacker-controlled device for a card-present transaction elsewhere. This is second-hand coverage of Group-IB's research, so go to the original for indicators, but the relay-plus-RAT pairing is the detail worth carrying into mobile fraud detection logic.

  5. Investigation of banking hack leads to arrests in Germany, Brazil (opens in a new tab)

    The Record ·fetched 14 Aug 2026, 23:39 UTC agreed3/3

    Why readSeven arrests across Germany and Brazil close out a November 2023 operation that drained roughly 30 million euros by exploiting a payment provider rather than the bank itself.

    Germany's BKA charged three suspects in Europe and Brazil's federal police arrested four more under Operação Klonen, which ran 21 search and seizure warrants nationwide. Over four days in November 2023 the group made unauthorised withdrawals from German online banking accounts by exploiting a vulnerability at a payment provider, with Brazilian investigators describing cloned payment cards, and then laundered the proceeds through Brazil and four European countries. Neither agency named the bank, though Brazilian reporting points at Commerzbank; the supplier as the point of entry is the part worth carrying forward.

  1. You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) (opens in a new tab)

    watchTowr Labs ·Sina Kheirkhah (@SinSinology) ·fetched 14 Aug 2026, 11:38 UTC Must read Research CVE-2026-8452 EPSS 0.5% agreed3/3

    Why readThe first public pre-authentication RCE writeup against Citrix NetScaler in three years, from a team whose NetScaler research has historically preceded mass exploitation by days.

    watchTowr Labs walks through a pre-auth remote code execution flaw in Citrix NetScaler, tracked provisionally as CVE-2026-8452, on an appliance class that sits at the network edge and terminates SSLVPN sessions. The writeup is primary exploit research rather than advisory coverage, so it carries the reachability details and code path needed to judge whether your configuration is exposed and to build detection while you patch. NetScaler pre-auth bugs have a consistent history of moving from public writeup to opportunistic scanning quickly, and EPSS at the 40th percentile reflects only what has been seen so far, not what this becomes once the technique circulates.

  2. Vulnerability giving attackers full control of Macs is under active exploitation (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 14 Aug 2026, 19:43 UTC Must read CVE-2026-65400 EPSS 0.3% agreed3/3

    Why readCVE-2026-65400 in macOS screen sharing is being exploited in the wild for root access and Monero mining on hosts with TCP/5900 exposed.

    The Dutch NCSC reports active abuse across multiple systems reachable on port 5900, in each case ending with root and a Monero miner installed. The bug is a state-management flaw in macOS screen sharing, rated 7.1, patched by Apple last week for Tahoe, Sequoia and Sonoma. EPSS is still low at 0.0031, which reflects lag rather than safety here: patch, and check whether screen sharing is listening at the perimeter.

  3. Adobe Commerce Bug Targeted Immediately After Disclosure (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 14 Aug 2026, 11:38 UTC Must read CVE-2026-71362 EPSS 0.5% agreed3/3

    Why readCVE-2026-71362 in Adobe Commerce (CVSS 9.1) is being exploited within days of disclosure, letting unauthenticated attackers switch a session to another customer's account.

    Sansec blocked exploitation attempts shortly after Adobe's August 2026 Patch Tuesday advisory, which had stated no evidence of in-the-wild abuse. The incorrect authorization flaw lets a remote unauthenticated attacker pivot a customer session onto another customer account, exposing that account and its private data; Adobe fixed it by changing how Commerce handles the session switch. EPSS is still low at 0.005 (39th percentile) because the data lags, so treat the confirmed blocking telemetry as the signal and patch Commerce storefronts now.

  4. CVE-2026-26035 (CVSS 9.8): An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4. (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 19:43 UTC Must read CVE-2026-26035 CVSS 9.8 EPSS 0.5% agreed3/3

    Why readAn improper authentication bug lets an unauthenticated attacker log into the FortiWeb GUI or CLI with a random username and password across every supported branch from 7.0 to 8.0.2.

    CVE-2026-26035 affects FortiWeb 8.0.0-8.0.2, 7.6.0-7.6.6, 7.4.0-7.4.11, 7.2.0-7.2.12 and 7.0.0-7.0.12, and the described behaviour is full administrative authentication bypass with arbitrary credentials, not a narrow privilege issue. CVSS 9.8, no confirmed exploitation in the SSVC record yet, rated automatable with total technical impact. FortiWeb management interfaces are frequently internet-reachable and Fortinet auth bypasses have a short history between disclosure and mass scanning, so patch and pull management off the public interface now.

  5. CVE-2026-48362 (CVSS 10.0): ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resul (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 15:40 UTC CVE-2026-48362 CVSS 10.0 EPSS 2.1% agreed3/3

    Why readA pre-authentication command injection in ColdFusion rated CVSS 10.0 belongs at the top of the patch queue for any internet facing install.

    Adobe's APSB26-90 advisory fixes an OS command injection flaw in ColdFusion that NVD scores at 10.0, reachable over the network with no authentication, no user interaction, and a changed scope, meaning code runs past the vulnerable component's own boundary. EPSS still sits near two percent and the CISA ADP record shows no observed exploitation, but ColdFusion's history of fast mass exploitation after disclosure means that gap usually closes within days. Affected build numbers live in Adobe's bulletin rather than in the NVD entry.

  6. CVE-2026-58076 (CVSS 8.8): Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and ins (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 23:39 UTC CVE-2026-58076 CVSS 8.8 EPSS 0.3% agreed3/3

    Why readA second deserialization sink in Apache Airflow gives a Dag author code execution in the Scheduler and API server, and patching CVE-2026-33264 did not close it.

    The serialization layer reconstructs exception nodes by calling import_string() on a class name from the serialized blob and instantiating it with arguments from the same blob, with no allowlist. An operator's executor_config reaches that branch, so a Dag author can cause an arbitrary callable such as subprocess.check_output, or builtins.eval via the builtins-prefixed variant, to run in the Scheduler during its normal loop and in the API server on any authenticated GET /api/v2/dags/{dag_id}/details. Both components hold the metadata database credentials and the JWT signing secret, both are specified never to run Dag-author code, and no non-default configuration is needed. The earlier advisory covered only the trigger branch of the same deserializer, so deployments that upgraded for CVE-2026-33264 are still exposed.

  7. CVE-2026-11325 (CVSS 8.8): Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execut (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 19:43 UTC CVE-2026-11325 CVSS 8.8 EPSS 0.5% agreed3/3

    Why readcloudflare/pages-action has an unpatchable RCE that exposes CLOUDFLARE_API_TOKEN and GITHUB_TOKEN from workflow runs, and the repository disappears on 18 September 2026.

    CVE-2026-11325 (CVSS 8.8) is a remote code execution issue in src/index.ts of the archived cloudflare/pages-action, reachable from certain GitHub Actions workflow configurations and capable of surfacing workflow secrets to an attacker. All published versions are affected, including anything pinned to the v1 moving tag, and Cloudflare will not patch because the action was deprecated in 2024. The only fix is migrating to cloudflare/wrangler-action, and the sunset date of 2026-09-18 means unmigrated pipelines break as well as leak. Grep your workflow files for pages-action now.

  8. CVE-2026-66147 (CVSS 9.4): An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 19:43 UTC CVE-2026-66147 CVSS 9.4 EPSS 1.0% agreed3/3

    Why readUnauthenticated command injection in the SonicWall GMS Dispatcher Service, affecting GMS 9.5.1 and every earlier version.

    A crafted request to the GMS Dispatcher Service gives remote code execution with no authentication, tracked by SonicWall as SNWLID-2026-0011 and scored CVSS 9.4. SSVC records no confirmed exploitation yet but rates it automatable with total technical impact, and EPSS already sits in the 61st percentile. GMS is a central management server for SonicWall firewall estates, so a compromise there reaches the devices it administers.

  9. It took $58 to break Microsoft’s SCCM, but a patch made it harder (opens in a new tab)

    CSO Online ·fetched 14 Aug 2026, 07:39 UTC CVE-2026-47301 EPSS 0.5% agreed3/3

    Why readAn unprivileged domain user can chain four SCCM flaws, including CVE-2026-47301, to run code as SYSTEM on the primary site server and inherit every managed client.

    XM Cyber chained a broken authorization check in the SCCM AdminService upload endpoint, a path traversal dubbed CabSlip, weak code-signing validation defeated with a $58 commercial certificate, and an unsigned DLL load in the SMS Executive service. The result is domain user to NT AUTHORITY\SYSTEM on the primary site server, which compromises the whole managed Windows fleet beneath it. Microsoft patched the initial authorization flaw as CVE-2026-47301 (EPSS 0.005), which raises the bar without dismantling the rest of the chain, so patch state and network reachability of the site server both matter.

  10. CVE-2026-5917 (CVSS 9.4): libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allo (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 19:43 UTC CVE-2026-5917 CVSS 9.4 EPSS 0.9% agreed3/3

    Why readA malicious .gitmodules submodule URL executes shell commands on the remote SSH server during a recursive clone, in every libgit2 from v0.27.0 to v1.9.0 built with the libssh2 backend.

    gen_proto() in ssh_libssh2.c splices the repository path straight into a shell command string passed to libssh2_channel_exec() without escaping quotes, semicolons or pipes. An attacker crafts a submodule URL containing metacharacters, and a recursive clone makes the server's shell run the injected commands under the victim's SSH account. CVSS 4.0 at 9.4 requiring only user interaction; the exposure follows libgit2 into every application that embeds it for SSH git operations, so check what your build links rather than what you install.

  11. CVE-2026-70468 (CVSS 8.1): A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManage (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 19:43 UTC CVE-2026-70468 CVSS 8.1 EPSS 0.6% agreed3/3

    Why readFortiManager holds the configuration and credentials for an entire Fortinet estate, and this is a pre-authentication bypass reachable over the network.

    Fortinet disclosed an authentication bypass via an alternate path or channel affecting FortiManager 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9, plus the equivalent FortiManager Cloud builds. The vector is network reachable with no privileges or user interaction and yields full confidentiality, integrity, and availability impact, though attack complexity is rated high. The advisory text is unfinished and still contains a placeholder where the attack vector should be, so treat the version list as the actionable part: inventory your management appliances and upgrade, given FortiManager's track record as an attacker target.

  12. CVE-2026-71290 (CVSS 9.1): Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effec (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 19:43 UTC CVE-2026-71290 CVSS 9.1 EPSS 0.2% agreed3/3

    Why readHostnameVerificationPolicy#BUILTIN silently does nothing on the async Apache HttpClient, so any Java service using it accepts a valid certificate for the wrong domain.

    CVE-2026-71290 affects Apache HttpComponents Client 5.4 and newer: the BUILTIN hostname verification policy has no effect on the async client, letting an attacker who can intercept and modify traffic impersonate a server with a certificate issued for a different name. The classic HttpClient is not affected, which narrows the search but also makes the exposure easy to miss in a dependency audit. Upgrade to 5.6.4 or later, and note the failure is silent: nothing in normal operation reveals that verification was skipped.

  1. Metasploit Wrap Up: Lot of summer shells and fit http profiles (opens in a new tab)

    Rapid7 ·Rapid7 Labs ·fetched 14 Aug 2026, 23:39 UTC Must read Research CVE-2026-46300 EPSS 7.0% agreed3/3

    Why readThirteen new Metasploit modules including SonicWall SMA1000 and Langflow RCE plus the Fragnesia Linux kernel LPE (CVE-2026-46300), and Framework 6.5 adds malleable HTTP profiles and AArch64 reverse TCP payloads.

    Thirteen modules landed, with RCEs for WordPress, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard and Pix-for-WooCommerce, alongside a local privilege escalation for the Fragnesia Linux kernel bug CVE-2026-46300 and a Ray Dashboard logs API path traversal. Framework 6.5 adds malleable HTTP profiles for C2 traffic shaping, MCP functionality, Linux multi-fetch payloads and both inline and staged AArch64 reverse TCP shells for Windows on ARM. Defenders should treat the SonicWall SMA1000 and Ray Dashboard modules as raising the commodity exploitation floor for those products.

  1. TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies (opens in a new tab)

    arXiv cs.CR (all) ·Xiaokang Qu, Jianliang Ma, Zao Fan, Tianshu Chu ·fetched 14 Aug 2026, 11:38 UTC Research agreed3/3

    Why readA system that compiles natural-language security intent into network topologies checked against CIS Controls v8.1.2 and exported as Mininet scripts with iptables ACLs.

    TopoIntent constrains LLM generation with a schema contract, retrieves reference architectures from a template library via dense-vector search, and applies staged fusion to align intent with templates before completing security gaps. Generated topologies are validated against topology-layer CIS Controls v8.1.2 safeguards, with unresolved cases flagged for manual review and structural gaps repaired by additive schema-preserving edits. Output runs as Mininet scripts with kernel-level iptables ACLs, so reachability and allow/deny claims are actually testable.

  2. Open Season: CZDS (opens in a new tab)

    Thor Collective ·Josh Rickard ·fetched 14 Aug 2026, 03:39 UTC agreed3/3

    Why readShows how to use ICANN's Centralized Zone Data Service as a free newly-registered-domain feed to catch phishing infrastructure at registration, before the certificate or the campaign shows up.

    Maps the phishing setup sequence (register domain, deploy infra, configure DNS, obtain a TLS certificate, launch) to the telemetry each stage leaves behind, then argues CZDS zone files catch the earliest stage that certificate transparency logs miss. Positions CZDS as a complement to CT monitoring rather than a replacement, since a domain appears in the zone file before it appears in a CT log. Practical enrichment source for hunt teams already running CT feeds.

  3. Who’s Tracking You? Use This New Service to Find Out (opens in a new tab)

    Krebs on Security ·BrianKrebs ·fetched 14 Aug 2026, 15:40 UTC agreed3/3

    Why readA free service, decryptads.com, that scrapes and correlates ads.txt, app-ads.txt, buyers.json and sellers.json so you can enumerate who is permitted to run ads on or harvest data from a given site or app.

    DecryptAds continuously collects the disclosure files that publishers and app developers are required to expose, then joins them into a searchable map of adtech relationships, including the sample it renders for espn.com. The data was always semi-public but has been hard to parse and largely locked inside large ad platforms, and the correlation is what makes it usable. Useful for third-party risk work, data-broker exposure assessments and privacy investigations where the question is which entities sit behind a given property.

    Indicators1
    Domains
    giacoloredstones[.]com
  4. TeleGapper: On the (un)reliability of Privacy Policies in Telegram Mini apps (opens in a new tab)

    arXiv cs.CR (all) ·Luca Ferrari, Mariano Ceccato, Luca Verderame ·fetched 14 Aug 2026, 07:39 UTC Research agreed3/3

    Why readExamines whether Telegram Mini App privacy policies match actual data flows, in an ecosystem where apps run in a WebView with unrestricted outbound networking and platform-supplied user context.

    Telegram Mini Apps differ from WeChat's tightly controlled proprietary framework: they are ordinary web applications in a WebView that combine Telegram-provided context with standard web capabilities, so sensitive data can be shipped to analytics, ad and tracking endpoints through normal requests. Developers may either write an app-specific policy or fall back on Telegram's platform default, and the authors argue the default produces generic statements that do not reflect real practice. Useful for anyone assessing messaging-platform mini-app ecosystems as a third-party data risk rather than as an app store.

  5. Slow and Steady: Preventing MEV with Verifiable Delays (opens in a new tab)

    arXiv cs.CR (all) ·Zeta Avarikioti, Dimitris Karakostas, Karl Kreder, Shreekara Shastry ·fetched 14 Aug 2026, 23:39 UTC Research agreed3/3

    Why readProposes enforcing a verifiable delay on transaction generation so a block producer cannot react to an MEV opportunity without breaking liveness, with bounds on where the defence stops working.

    The mechanism forces a verifiable delay into transaction creation, which removes the block creator's ability to observe and front-run an opportunity in time. The authors give positive results in both a Byzantine setting and a game-theoretic rational-participant model, plus negative bounds marking the limits of the approach, and back it with an evaluation against historical MEV data suggesting most existing MEV threats would be prevented. Narrow relevance outside distributed ledger work, but the delay-as-liveness-constraint construction is worth the read if you touch transaction ordering.

  6. VR-Themis: A Scalable Framework for Virtual Reality Application Clone Detection (opens in a new tab)

    arXiv cs.CR (all) ·Gengyang Xu, Hanyang Guo, Hong-Ning Dai, Weizhi Meng ·fetched 14 Aug 2026, 15:40 UTC Research agreed3/3

    Why readA two-stage clone-detection framework for VR apps that found 307 cloned applications in the wild, where Android-oriented repackaging detectors do not transfer.

    VR-Themis detects repackaged VR applications using a Hierarchy-Object-Behaviour model: a coarse stage clusters apps on cheap statistical features so the approach scales across large VR app sets, then a fine-grained stage scores similarity between suspicious pairs using the HOB metrics. The authors report 307 cloned VR apps detected, arguing existing mobile-platform clone detectors miss the scene-graph and behavioural structure that characterises VR builds. Relevant if you are responsible for app-store integrity or IP protection on Quest-class platforms; the technique is the contribution, not the dataset.

  7. Vulnerability response in the AI-discovery era (opens in a new tab)

    Sysdig ·fetched 14 Aug 2026, 11:38 UTC agreed2/3

    Why readMakes the case that remediation windows now have to close before a patch exists, citing Mandiant's average time to exploit of negative seven days.

    A Sysdig post arguing that AI-accelerated discovery breaks the assumptions behind current vulnerability management SLAs. The load-bearing figure is from Mandiant M-Trends, which puts average time to exploit at negative seven days, meaning exploitation is beginning before vendors ship fixes, so risk acceptance becomes a choice teams must defend to boards and auditors rather than a resource constraint. The tempering point is worth keeping: for any fixed codebase this is a surge rather than an endless flood, since most AI-found flaws fall into known classes with known fixes. Vendor content, so read the argument and skip the product framing.

DFIR

1
  1. AI in DFIR 101: Why You Should Use AI for Planning (opens in a new tab)

    Cyber Triage ·Brian Carrier ·fetched 14 Aug 2026, 03:39 UTC agreed3/3

    Why readDraws a line between where a deterministic playbook is sufficient in investigation planning and where GenAI adds value, using concrete question-to-data-source mappings.

    Breaks the planning phase into three stages and argues that turning investigative questions into data sources is where a model supplements analyst knowledge, while routine collection steps should stay deterministic. Worked example: answering 'was data exfiltrated, was persistence installed, were credentials stolen' maps to process and browser history, firewall logs, and triggered tasks. Written by Brian Carrier, so the methodology is credible even though the reasoning is introductory and the venue sells a triage product.

  1. Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair (opens in a new tab)

    arXiv cs.CR (AI) ·Benjamin Agyekum, Fabio Santos ·fetched 14 Aug 2026, 07:39 UTC Research agreed3/3

    Why readMeasures how often iterative LLM repair of Terraform silently breaks a previously-passing CIS check, across 5,968 IaC-Eval scenario timelines and 4,440 iteration transitions with Checkov on both sides.

    Prior IaC work reported cumulative-best metrics, which are non-decreasing by construction and therefore hide per-iteration regressions; this study tracks the raw trajectory instead. It covers 15 configurations (six model-specific RAG, nine model-aggregated non-RAG, three temperatures each), follows 30 individual CIS check IDs, and classifies root causes from the code diffs under inclusive and strict detection modes. The practical consequence: if your pipeline feeds Checkov errors back to an LLM and accepts the last iteration, you need a per-iteration gate rather than a best-of-N score.

  2. LLM-Assisted Dynamic Threat Analysis for Attacker-Reachable Software Weaknesses in Autonomous Vehicles (opens in a new tab)

    arXiv cs.CR (AI) ·Md Wasiul Haque, Sagar Dasgupta, Mizanur Rahman, Md Rayhanur Rahman ·fetched 14 Aug 2026, 03:39 UTC Research agreed3/3

    Why readMeasures how far two local open-weight LLMs actually get at turning static analysis hits into compiling, fuzzable exploit artefacts against the Autoware autonomous-driving stack, and where they fail.

    The authors ran compiler-precise static analysis over 185 Autoware packages, extracting 1,375 decision rules, 2,274 validation checks and 482 input-to-safety-output flows, then sampled 740 reachable weakness sites. Two local open-weight models plus a no-static-context ablation and a template baseline produced 3,700 artefact sets, compiled against the real build under sanitizers with compiler-in-the-loop repair. The headline result is a failure taxonomy rather than a win: 80% of first-shot compilation failures come from dependency wiring, which is a concrete limit on LLM-driven exploitability confirmation in large C++ codebases.

  3. Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility (opens in a new tab)

    ESET WeLiveSecurity ·fetched 14 Aug 2026, 15:40 UTC agreed2/3

    Why readOpenAI's late addition to the Black Hat agenda gave a timeline for the Hugging Face breach that contradicts the prevailing assumption that agent driven attacks move too fast to interrupt.

    Writing up a Black Hat USA 2026 session, ESET reports that OpenAI presented its own account of the Hugging Face incident, tracing it back to a next generation model training exercise begun on 7 May. The key correction is pace: the attack did not unfold at machine speed, and there were windows in which human operators could have intervened and did not. The framing that follows, that this was a failure of human control over agents rather than a rogue agent acting alone, is opinion, but the timeline detail is new and reshapes how the incident should be used in tabletop exercises and agent oversight design.

  4. Beyond Visual Evidence: Revealing and Mitigating Relational Privacy Leakage in Document MLLMs (opens in a new tab)

    arXiv cs.CR (AI) ·Beining Xu, Hairui Wang, Jiaxin Wang, Changsheng Chen ·fetched 14 Aug 2026, 19:43 UTC Research agreed3/3

    Why readShows that document-understanding MLLMs will hallucinate missing identity-document fields from memorised training-data field relations, leaking correlated personal data when the image does not actually contain it.

    Testing key information extraction on identity documents, the authors find that when visual evidence is absent or degraded the model falls back on memorised relationships between fields and emits multiple correlated sensitive values it never saw. They release DocPrivacyBench to measure susceptibility under minimal-evidence conditions and propose the Dynamic Relational Unlearning Framework, which decouples high-risk field pairs while preserving extraction accuracy. Relevant to anyone putting a document MLLM in front of KYC or onboarding data.

  5. Beyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Jiajun Ruan, Peiyang Li, Yukun Chen, Fengting Li ·fetched 14 Aug 2026, 15:40 UTC Research agreed3/3

    Why readHARD formalises LLM agent runtime defence at the harness level and then evolves the interventions automatically from observed failure traces, instead of hand-writing guardrails.

    The paper gives a harness-level formulation of runtime defence for LLM agents, describing how harness mechanisms enable interventions and unifying existing runtime defences under that view. Building on it, HARD selects intervention strategies automatically and iteratively refines defence artefacts using traces of failures it observes, turning guardrail authoring into an evolution loop. Useful mainly as a design frame for anyone maintaining agent guardrails by hand; the experimental results are asserted here rather than detailed.

  6. InterSAGE: The Secure and Verifiable Interoperability Protocol for An Internet of Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Zhenhua Zou, Sheng Guo, Qiuyang Zhan, Lepeng Zhao ·fetched 14 Aug 2026, 11:38 UTC Research agreed3/3

    Why readProposes the authorisation and accountability layer that MCP, A2A and ANP leave out, using Agent Identity Cards bound to developer, code package, operator and deployment context.

    InterSAGE is a four-layer protocol suite (Persistent Identity, Discovery, Trust Negotiation, Accountability) intended to sit alongside existing agent communication protocols rather than replace them. Its concrete primitives are identity cards binding code and operator provenance, DID-bound verifiable credential manifests for capability discovery, monotonic capability attenuation with two-tier access control, and kernel-mediated cryptographic audit trails that tie delegation and execution back to an agent identity without a consensus ledger. It is a design paper, so treat it as a checklist of the properties your own agent deployments currently lack rather than something to install.

  7. Tracing Provenance and Detecting Tampering with Complementary LLM Watermarks (opens in a new tab)

    arXiv cs.CR (AI) ·Xiaoyan Feng, Yanjun Zhang, He Zhang, Leo Yu Zhang ·fetched 14 Aug 2026, 23:39 UTC Research agreed3/3

    Why readA watermarking scheme that co-embeds a robust and a fragile signal per token, so detection can distinguish Intact, Tampered and No-Watermark rather than only proving provenance.

    Existing LLM watermarks survive editing, which is exactly what enables piggyback spoofing: an adversary rewrites the substance while the attribution signal persists. The proposed scheme embeds two signals through the same mechanism but with independent keys and different seeding windows over normalised text, using multiple rounds of unbiased tournament reweighting to preserve the generation distribution and a periodic round-allocation pattern to tune the trade-off. Evaluated across two models and two prompt datasets, it reports the highest tamper-detection rate among the compared methods.

  8. Google is making private AI practical with homomorphic encryption (opens in a new tab)

    Hacker News ·u1hcw9nx ·fetched 14 Aug 2026, 23:39 UTC Research 239 points agreed2/3

    Why readGoogle has open sourced HEIR, an MLIR-based compiler that targets fully homomorphic encryption backends, which is the tooling layer that has been missing from encrypted inference.

    HEIR joins Google's Private Computing Toolkit and compiles models down to FHE circuits so a provider can run inference over ciphertext without seeing the input or shipping the model to the device. The pitch is aimed at healthcare and finance, where regulation blocks the data sharing that server-side features normally require. Treat this as infrastructure maturing rather than a deployable answer: the compiler removes a real engineering barrier, but the performance gap between encrypted and plaintext inference is still the thing that decides whether any of it ships.

  9. CVE-2026-72922 (CVSS 8.2): AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 03:39 UTC CVE-2026-72922 CVSS 8.2 EPSS 0.3% agreed3/3

    Why readA client controlled URL segment selects which webhook manager validates the request, so an attacker can route through a class whose signature check does nothing and execute someone else's agent graph as them.

    AutoGPT before 0.6.70 passed the provider segment of the request URL to get_webhook_manager() instead of using the provider recorded on the webhook itself, so a request to /compass/webhooks/{webhook_id}/ingress resolved to CompassWebhookManager and inherited the no-op verify_signature from BaseWebhooksManager. That bypasses the X-Webhook-Secret check that protects generic webhooks and lets an unauthenticated caller trigger a victim's graph, running with the victim's credentials and integrations. Version 0.6.70 fixes it; the broader pattern, letting an untrusted key choose which security handler runs, is worth auditing in any agent platform that dispatches on provider names.

    Indicators1
    Hashes
    646dd5b8cfad1206e92ec7bcc3b8312657e2a92e
  10. CVE-2026-73032 (CVSS 9.4): PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious (opens in a new tab)

    NVD ·fetched 14 Aug 2026, 19:43 UTC CVE-2026-73032 CVSS 9.4 EPSS 0.4% agreed3/3

    Why readA concrete case of LLM output flowing straight into window.eval() inside a chrome-privileged context, triggerable by prompt injection in a PDF.

    PapersGPT for Zotero 0.6.1 passes text returned from the configured LLM endpoint unsanitised to window.eval() in views.ts, giving arbitrary JavaScript execution with Zotero's chrome privileges: file read and write, process execution, and access to the whole library. Three delivery routes are listed: prompt injection embedded in a PDF the user asks about, MITM of the API request, or pointing the plugin at an attacker-controlled custom endpoint. CVSS 9.4, EPSS 0.004, and the deployment base is small, but the pattern is the one to take away for any tool that renders model output in a privileged runtime.

    Indicators1
    Hashes
    094134172ce4a344a31e4b196cc75d1806383658
  11. Concept Drift Detection and Adaptive Retraining of Malware Classification Models (opens in a new tab)

    arXiv cs.CR (all) ·Christofer Washington Berruz Chungata, Martin Jurecek, Katerina Potika, William B. Andreopoulos ·fetched 14 Aug 2026, 03:39 UTC Research agreed3/3

    Why readMeasures whether drift-triggered retraining of a malware classifier actually beats retraining on a fixed schedule, using three different drift detectors across four model families.

    The authors compare a novel One-Class SVM drift detector against Minibatch K-Means and Maximum Mean Discrepancy, then run each against Multilayer Perceptron, Random Forest, SVM and XGBoost malware classifiers under three regimes: never retrain, retrain periodically regardless of drift, and retrain only when a detector fires. The value here is the cost comparison, since periodic retraining is the default in most production detection pipelines and it is rarely tested against a triggered alternative. It reads as a book chapter rather than a novel-result paper, so expect a careful comparison of known techniques rather than a new detection capability.

  12. Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? (opens in a new tab)

    ESET WeLiveSecurity ·fetched 14 Aug 2026, 11:38 UTC agreed2/3

    Why readPuts hard patch volume numbers behind the AI vulnerability discovery story: 169 Microsoft CVEs in April rising to 622 in July.

    An ESET writeup of a Black Hat USA 2026 keynote covering Arizona State research by Yan Shoshitaishvili and his students on how machine-assisted bug hunting is scaling. It tracks the Patch Tuesday load across four months, from 169 CVEs in April to 118 in May, 571 in June and 622 in July including exploited zero days, and notes the US government stood up a coordination body called Gold Eagle for discovery and fix workflows. The open question it poses is whether the current surge eventually exhausts the finite bug supply in a given codebase and leaves software safer, or simply outruns the people who have to ship patches.

  1. Trump taps cyber firms to go on offensive against criminals (opens in a new tab)

    The Record ·fetched 14 Aug 2026, 11:38 UTC Must read agreed3/3

    Why readThe legal footing under private-sector hack back is moving, and this memorandum is the document that moves it.

    A presidential memorandum released on 12 August 2026 permits vetted US companies to run offensive cyber operations and surveillance against transnational cybercrime and fraud groups, working in partnership with the Justice and Homeland Security departments. Each operation requires advance approval from DOJ and DHS officials, placing the activity under federal direction rather than leaving it to firms acting alone. Congressional reaction is already forming, with Representative Bennie Thompson quoted in the piece, and the oversight and liability questions around collateral damage remain unresolved.

  2. Going Dark, and the era of law enforcement hacking (opens in a new tab)

    Hacker News ·vslira ·fetched 14 Aug 2026, 23:39 UTC Must read 130 points agreed2/3

    Why readMatthew Green's argument that AI-driven bug finding will dry up the exploit supply that Western law enforcement quietly relies on, and that the political bill for that lands on encryption policy.

    The essay traces how agencies moved from wiretaps to endpoint exploitation as traffic went encrypted, then argues that AI systems finding and fixing memory safety bugs at scale will shrink the pool of cheap, reliable implants. Green's concern is not that policing gets harder in isolation; it is that a genuine capability collapse creates political pressure for mandated lawful access, which is the outcome he considers worse for everyone. Read it as a forecast of where the next crypto policy fight comes from, not as a claim that software is about to become secure.

  3. Risky Bulletin: US will let private companies carry out offensive cyber ops (opens in a new tab)

    Risky Business News ·fetched 14 Aug 2026, 07:39 UTC Must read agreed3/3

    Why readThe White House is preparing to let private companies run offensive cyber operations, which changes the legal and liability questions every security leader has been answering for a decade.

    Risky Business News reports a coming policy shift in which the US government would authorize private firms to conduct offensive cyber operations, reversing the long standing position that active response belongs to government alone. The same bulletin carries an AI driven intrusion campaign against Taiwanese government targets, internet facing exploitation of a macOS bug to deploy cryptominers, and a Kenyan order requiring internet cafes to retain logs. The offensive ops item is the one to read closely: it reopens hack back questions around authorization scope, attribution error, and who carries liability when a contracted operation hits the wrong host.

  4. FinCEN ends beneficial ownership reporting for most small businesses (opens in a new tab)

    Compliance Week ·Adrianne Appel ·fetched 14 Aug 2026, 23:39 UTC agreed3/3

    Why readFinCEN has finalised the decision killing beneficial ownership information reporting for tens of millions of US small businesses.

    The final rule removes the BOI reporting obligation under the Corporate Transparency Act for most US small businesses. For compliance, KYC and third-party risk teams this cuts off a data source that due diligence workflows had begun to assume would exist. Coverage is brief and carries no effective date detail, so check the rule text before adjusting any onboarding process built on BOI availability.

  5. Sovereign by necessity? Frontier AI export controls, cyber security, and the limits of national AI capability (opens in a new tab)

    arXiv cs.CR (all) ·Alan Woodward, Andrew Rogoyski ·fetched 14 Aug 2026, 19:43 UTC agreed3/3

    Why readArgues that access to frontier AI is now part of national cyber defence and can be revoked at short notice, using the June 2026 US licensing requirement that pulled a leading developer's top models worldwide.

    The paper takes the June 2026 US export-control action, which required licences before releasing the most advanced models to any foreign person including foreign nationals resident in the US and proved unadministrable enough that the models were withdrawn globally, and reads it alongside the first documented largely autonomous AI-run espionage campaign. It concludes that dependency on two states' frontier labs is a cyber-defence exposure, and examines why the obvious sovereign-capability remedy is constrained by the economics of frontier training. Useful for anyone writing AI risk or resilience policy.

  6. Brazil orders Discord to suspend livestreaming after teen suicide (opens in a new tab)

    The Record ·fetched 14 Aug 2026, 07:39 UTC agreed3/3

    Why readA data protection regulator ordered a specific product feature switched off nationwide pending proof of safeguards, which is a sharper enforcement tool than the fines platforms have learned to budget for.

    Brazil's ANPD has ordered Discord to keep its Go Live streaming feature disabled until the company can demonstrate effective protections for children and teenagers. The order follows the death of a 13 year old girl who authorities say was encouraged to harm herself during a roughly 45 minute livestream in July; five teenagers have been arrested and investigators found groups using Discord and Telegram to spread extremist material and recruit members. The precedent worth tracking is procedural rather than technical: a DPA using child safety grounds to compel a feature shutdown, which any platform operating in Brazil should factor into its regulatory risk model.

  1. France investigates tax authority breach after hacker claims 600,000 victims (opens in a new tab)

    The Record ·fetched 14 Aug 2026, 15:40 UTC Must read agreed3/3

    Why readFrance's tax authority, DGFiP, confirms attackers accessed and extracted individual and business data, with the intruder claiming 600,000 victims.

    The French Economy Ministry confirmed late on 13 August 2026 that an attacker reached DGFiP systems in late June by stealing or misusing an identity, then viewed and extracted data on individuals and businesses. Access was detected and cut off in late June, but the incident only became public after the hacker publicly claimed responsibility this week and DGFiP imposed further access restrictions. Scope is still being determined; the 600,000 figure is the attacker's claim, not a confirmed count, and notification of affected parties is pending.

    Also covered byReuters (opens in a new tab),Cybersecurity Dive (opens in a new tab).

  2. AnMed restores MyChart access after cyberattack disrupts services (opens in a new tab)

    Google News: incidents · Independent Mail ·fetched 14 Aug 2026, 03:39 UTC agreed3/3

    Why readAnMed has restored MyChart patient portal access after a cyberattack that disrupted clinical services, another named health system outage for peers to benchmark against.

    AnMed, the South Carolina health system, has brought MyChart back online following a cyberattack that interrupted services. Only the headline and outlet reached us, so there is no detail on intrusion vector, downtime duration or data exposure. Worth noting as a patient-portal recovery datapoint for healthcare security leaders; the substance will come from any later notification filing.

    Also covered byThe HIPAA Journal (opens in a new tab).

  3. Data breach notices have already blown past last year’s total — and AI is playing a growing role (opens in a new tab)

    Google News: incidents · CNBC ·fetched 14 Aug 2026, 19:43 UTC agreed2/3

    Why readA single number worth carrying into a board or risk committee conversation: breach notification volume this year has already passed all of last year.

    CNBC reports that US data breach notification filings for 2026 have already exceeded the full 2025 total, with AI cited as a growing contributor to the trend. The item is a headline aggregation with no accompanying figures, methodology, or notifying-body breakdown available here, so the specific counts and the causal weight assigned to AI need checking against the original piece before quoting. Useful as a directional indicator for disclosure exposure and notification workload, not as a citable statistic on its own.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
FERRARI MANGIMI SRL qilin Agriculture and Food Production IT 14 Aug 2026
granjarinya.com safepay Agriculture and Food Production ES 14 Aug 2026
Columbia University Information (Dental) Global Secret Group Healthcare US 14 Aug 2026 press coverage (opens in a new tab)
Connections qilin - BE 14 Aug 2026
Connell Enterprises LLC interlock - US 14 Aug 2026
Turner and Townsend coinbasecartel Professional Services GB 14 Aug 2026
Serruya private equity coinbasecartel Agriculture and Food Production US 14 Aug 2026
Sweet Water Holdings coinbasecartel Agriculture and Food Production US 14 Aug 2026
Keystops akira Technology US 14 Aug 2026
Cozad Asset Management akira Financial Services US 14 Aug 2026
FiferFox Minecraft Server BlueWhale Technology - 14 Aug 2026
Satellite Developer Server BlueWhale Technology - 14 Aug 2026
Aletex Group qilin Manufacturing ES 14 Aug 2026
Pierce Township rhysida Government & Defense US 14 Aug 2026
Radiant qilin - SG 14 Aug 2026
ZEBRA.COM clop Manufacturing US 14 Aug 2026
Lercher Werkzeugbau qilin Manufacturing AT 14 Aug 2026
3f qilin - DK 14 Aug 2026
PenLink qilin Government & Defense US 14 Aug 2026
Urban Worldwide qilin - NL 14 Aug 2026
tecnoabi.com m3rx Technology BR 14 Aug 2026
Hinman Straub Storm Professional Services US 14 Aug 2026
3-point Australia Storm - AU 14 Aug 2026
Rood & Riddle Equine Hospital Storm Healthcare US 14 Aug 2026
Canadian Mental Health Association Storm Healthcare CA 14 Aug 2026
How this edition was made
Candidates fetched
6029
New after deduplication
720
Kept by the panel
230
Published
112
Generated
14 Aug 2026, 23:39 UTC