CFToday Curated security signals.

Daily edition · 2026-08-17

Monday, 17 August 2026

46 items across 9 sections, selected from 5749 candidates over 6 runs. 97 carried the panel unanimously.

Show
Section

India

3

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. Fortune 500 Companies Hit in Azure Data Theft Campaign (opens in a new tab)

    SecurityWeek ·Business & Boardroom ·Ionut Arghire ·fetched 17 Aug 2026, 07:41 UTC Must read agreed3/3

    Why readTells you which named enterprises had Entra directory exports pulled with leaked credentials, and how many records each dump holds, so you can judge your own exposure or a supplier's.

    An actor going by TheHatman is advertising employee directory data said to come straight from the Azure and Entra tenants of McDonald's, TCS, Vodafone, HCL, IHG, Kyndryl, Gap, Hexaware and Wyndham, with the McDonald's set alone at over 1.7 million records. Hudson Rock reports the field names and email formats line up with genuine Azure directory exports, and the stated access route is simply stolen credentials rather than any product flaw. Nothing here is confirmed by the named companies, but three of the listed victims are large IT outsourcers, which makes the directory data useful raw material for targeted phishing against their clients.

    Also covered byThe Register Security (opens in a new tab),SQ Magazine (opens in a new tab).

  2. New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure (opens in a new tab)

    The Hacker News ·Threat Intel & Breaches ·The Hacker News ·fetched 17 Aug 2026, 11:35 UTC agreed2/2

    Why readNames PATCHCORD, a C/C++ implant delivered via fake Afghan Telecom VPN installers, and a second Go backdoor, SHEETCORD, that uses Google Sheets for C2.

    Acronis Threat Research Unit documents an undocumented backdoor, PATCHCORD, hitting Afghan telecom operators and South Asian critical infrastructure through sector-specific lures such as counterfeit AFTEL VPN installers and telecom management tooling. Pivoting on the actor's infrastructure surfaced SHEETCORD, a Go implant using Google Sheets as its C2 channel, distributed from a domain impersonating India's National Informatics Centre. The infrastructure resolves to a single C2 server fronted by multiple domains, including a hijacked legitimate healthcare domain. This is a secondhand write-up; the Acronis report is where the indicators live.

    Indicators2
    Addresses
    46[.]30[.]188[.]13
    Domains
    nic-support[.]site
  3. Sebi launches portals to strengthen cybersecurity incident reporting (opens in a new tab)

    Google News: enforcement · Business Standard ·Governance, Risk & Compliance ·fetched 17 Aug 2026, 11:35 UTC agreed2/2

    Why readSEBI has stood up dedicated portals for cybersecurity incident reporting, changing how regulated entities in India's securities market file incidents.

    India's securities regulator launched portals to handle cybersecurity incident reporting across the securities market. For SEBI-regulated entities already under CSCRF obligations, this is a change to the reporting mechanism rather than to the underlying duty, and compliance teams will need to confirm registration and internal escalation routes point at the new channel. The feed text carries only the announcement, with no deadline or filing format detail.

    Also covered byFree Press Journal (opens in a new tab).

  1. C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 (opens in a new tab)

    Zscaler ThreatLabz ·ThreatLabz (Zscaler) ·fetched 17 Aug 2026, 15:37 UTC Must read Research agreed2/2

    Why readFirst technical analysis of C2Looper, a Rust backdoor using GitHub for command and control and likely delivered through a ClickFix chain ahead of ransomware.

    Zscaler ThreatLabz identified C2Looper in July 2026 and assesses with low to medium confidence that it arrives via a multi-stage ClickFix infection chain, acting as the foothold for lateral movement in ransomware operations. The malware supports remote shell execution, reconnaissance and second-stage payload deployment, resolves Windows APIs dynamically and encrypts its strings. Multiple variants with differing feature sets indicate active development, and the writeup covers the network protocols of each.

    Indicators3
    Hashes
    f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b 20675a659c338f7267fd09bacb431f4491f061d3acf42d07aca2dec3d25fa549 f59f32c9af4fa8a5dbd4668df8893593bc0c4324816cbf9b956acedcbfb8cdb6
  2. 17th August – Threat Intelligence Report (opens in a new tab)

    Check Point Research ·urias ·fetched 17 Aug 2026, 15:37 UTC agreed2/2

    Why readNames this week's incidents: ransomware at Colombia's Ministry of Justice, a claimed 2.5TB breach of Poland's MyDr health platform affecting nearly 19 million people, and a social-engineering compromise at Levi Strauss.

    The Colombian Ministry of Justice reports encrypted files affecting illicit-drug monitoring and legal case processing, with no data theft detected so far. Attackers claim 2.5TB from MyDr, Poland's national appointments and prescription platform, and published a senior politician's ID details and prescription records as proof. Levi Strauss says three employee devices were compromised via social engineering with corporate information stolen but no consumer data touched. It is a weekly roundup, so treat it as the index rather than the source.

  1. CVE-2025-62593: Ray-Project Ray, Ray-Project Ray Code Injection Vulnerability (opens in a new tab)

    CISA KEV ·fetched 17 Aug 2026, 15:37 UTC Must read CVE-2025-62593 Exploited in the wild · patch by 2026-08-21 EPSS 0.4% agreed2/2

    Why readRay code injection (CVE-2025-62593) is now on CISA KEV with a federal remediation deadline of 21 August 2026.

    CISA added CVE-2025-62593, a code injection flaw in Ray-Project Ray allowing remote code execution, to the Known Exploited Vulnerabilities catalogue with a due date of 2026-08-21. KEV listing means exploitation is confirmed, and the entry notes exposure for developers running Ray as a development tool, reachable via Firefox and Safari. EPSS is low at 0.004, but agencies must apply vendor mitigations under BOD 26-04 or discontinue use; anyone running Ray clusters or dashboards should treat this as the same priority.

  2. Critical flaw in SAP Commerce Cloud faces initial exploitation attempts (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 17 Aug 2026, 19:37 UTC Must read agreed2/2

    Why readCVE-2026-58231 in SAP Commerce Cloud is being exploited in the wild three days after the patch, with no public PoC in circulation.

    Defused reported exploitation attempts against CVE-2026-58231 hitting its honeypots three days after SAP shipped the fix, with one actor involved so far and no prior public proof of concept. The bug abuses a default authentication client and can lead to arbitrary code execution and internal access. Single-actor activity means this is early rather than widespread, which is precisely the window in which patching still gets ahead of it.

  3. CVE-2026-15341 (CVSS 9.8): The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and inclu (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 07:41 UTC Must read CVE-2026-15341 CVSS 9.8 EPSS 0.3% agreed3/3

    Why readWordPress User Session Synchronizer up to 1.4.0 hands out admin sessions to anyone who knows an email address, because the AES key silently degrades to md5('') when the key slot is unregistered.

    synchronize_session() is hooked on init so it runs on every request, and it validates no nonce, capability or shared secret against the attacker-supplied ussync-key, ussync-token and ussync-ref parameters. When ussync-key names an unregistered slot, get_option() returns false for both the secret and the domain allowlist, so the AES-256-CBC key becomes the predictable md5('') and the referer check collapses to an empty-string match, while the IV is hard-coded as md5('another-secret'). An unauthenticated attacker encrypts any known user email in ussync-ref and the handler calls wp_set_auth_cookie() for that account, administrators included. Fixed above 1.4.0; assume mass scanning follows publication.

  4. CVE-2026-15965 (CVSS 8.8): The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 07:41 UTC Must read CVE-2026-15965 CVSS 8.8 EPSS 0.6% agreed2/2

    Why readUnauthenticated arbitrary file upload to RCE in the WordPress Big File Uploads / MaxUpload plugin up to 1.4.0, via a chunked-upload filename mismatch.

    The handle_upload function applies extension and MIME checks to the uploaded chunk filename but not to the final assembled name derived from the resumableFilename parameter, so an attacker can land an executable file. Affects all versions through 1.4.0 and is reachable without authentication, making remote code execution possible. WordPress plugin file-upload bugs of this shape get mass-scanned quickly, so treat EPSS 0.006 as a floor rather than a ceiling.

  5. Apple Patches iOS and macOS, (Mon, Aug 17th) (opens in a new tab)

    SANS ISC Diary ·fetched 17 Aug 2026, 23:38 UTC CVE-2026-28990 EPSS 0.3% agreed2/2

    Why readApple shipped 108 fixes across iOS/iPadOS 26.6.1 and 18.7.10 and macOS Tahoe 26.6.2, including a libc sandbox escape (CVE-2026-28973) and six shared WebKit bugs.

    87 of the 108 vulnerabilities affect iOS 18 only, making this predominantly an iOS 18 maintenance release; just six affect all three operating systems and all six are in WebKit. Named issues include CVE-2026-28958 (sensitive data access via WebKit) and CVE-2026-28973 (malicious app breaking out of its sandbox, in libc). None are reported exploited, and there is no standalone Safari patch for older releases; VisionOS CVEs will be enumerated later.

  6. CERT-FR Weekly News Bulletin CERTFR-2026-ACT-035 (opens in a new tab)

    translated Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)

    CERT-FR (ANSSI) ·fetched 17 Aug 2026, 15:37 UTC agreed2/2

    Why readFlags a SharePoint Server flaw marked as actively exploited, alongside the week's SAP, Cisco ASA/FTD and ClamAV fixes.

    CERT-FR's weekly roundup for 17 August 2026 prioritises the significant vulnerabilities of the preceding week and marks a SharePoint issue affecting Server 2019, Server Subscription Edition and Enterprise Server 2016 as exploited. It also points to SAP's August 2026 security notes, a Cisco ASA/FTD VPN denial of service (cisco-sa-asaftd-vpn-dos-dzv4mQFF), Microsoft CVE-2026-68820 and the ClamAV 1.5.4 and 1.4.6 security patches. The exploited SharePoint entry is the reason to open it; the rest is a patch-priority checklist.

  7. CVE-2026-72819 (CVSS 8.7): Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users t (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 07:41 UTC CVE-2026-72819 CVSS 8.7 EPSS 0.5% agreed2/2

    Why readAuthenticated RCE in Grav CMS before 2.0.13: array notation bypasses routine-name validation in Flex Objects settings and lets a ZIP of PHP unpack into the web root.

    Passing the routine name as an array rather than a string evades validation and reaches the unZip routine, which writes attacker-supplied PHP files into a web-served path for execution. Requires an authenticated account but no administrative privilege. Patched in 2.0.13, one of a cluster of Grav and Flex Objects authorization and injection bugs disclosed the same day.

  8. CVE-2026-72827 (CVSS 8.7): Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to e (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 07:41 UTC CVE-2026-72827 CVSS 8.7 EPSS 0.5% agreed2/2

    Why readTwig server-side template injection in Grav CMS before 2.0.13 lets a low-privileged page editor reach OS command execution through a form's email action.

    Payloads injected into the subject, body, to, or from fields of an email action are evaluated with the unsandboxed find filter, giving arbitrary command execution when the form is submitted. The privilege requirement is only page-editor level, so any site with delegated content authors is exposed. Fixed in Grav 2.0.13; GitHub advisory GHSA-xx48-97m4-h7qm has the detail.

  9. CVE-2026-72830 (CVSS 9.3): Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write schedul (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 03:42 UTC CVE-2026-72830 CVSS 9.3 EPSS 0.4% agreed3/3

    Why readScoped api.config.write keys in Grav API plugin can inject commands into scheduler.custom_jobs for RCE, and CISA's SSVC record already marks it PoC and automatable.

    Versions before 1.0.13 do not enforce API key scope caps in ConfigController's super-scope gates, letting a key scoped only to api.config.write write scheduler configuration. Arbitrary commands placed in scheduler.custom_jobs are then executed through Symfony Process. The CISA ADP entry lists exploitation as poc and automatable as yes, with a GitHub security advisory (GHSA-2x29-3mjq-2pvx) and a VulnCheck writeup behind it, which makes this the most actionable of the six Grav CVEs.

  10. CVE-2026-15001 (CVSS 8.8): The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78 (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 03:42 UTC CVE-2026-15001 CVSS 8.8 EPSS 0.4% agreed3/3

    Why readA Subscriber account on any site running bLoyal Loyalty & Promotions up to 3.1.611.78 can repoint the plugin's API URL and then log in as Administrator.

    The AJAX actions save_bloyal_configuration_data and save_bloyal_accesskeyverification_data are registered with no capability or nonce checks, letting a low-privileged user overwrite bloyal_custom_loyaltyengine_api_url. Hitting the unauthenticated /cart REST route then makes bloyal_customer_auto_login fetch a Customer.ExternalId from the attacker's endpoint and pass it straight to wp_set_auth_cookie(). The chain is fully documented, so a working exploit is trivial to reconstruct; EPSS is still only 0.004.

  11. CVE-2026-19188 (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 07:41 UTC CVE-2026-19188 CVSS 10.0 EPSS 1.9% agreed3/3

    Why readGives the exact reachable path for unauthenticated root command execution on a Haiwell industrial gateway, precise enough to hunt for in logs before a patch lands.

    CVE-2026-19188 sits in the Net Check feature of the Haiwell IoT Cloud HMI Gateway, where the cmdPing Socket.io event on the /setting endpoint passes user input to the shell without sanitisation. It scores 10.0 under CVSS 4.0 with no privileges or interaction required and root-level execution on success. EPSS is still modest at 0.019, but this is an OT-facing gateway class that tends to be internet reachable, so exposure review matters more than the probability number.

  12. CVE-2026-72831 (CVSS 8.7): The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiCon (opens in a new tab)

    NVD ·fetched 17 Aug 2026, 07:41 UTC CVE-2026-72831 CVSS 8.7 EPSS 0.3% agreed2/2

    Why readGrav Flex Objects up to 1.4.6 lets a non-super account with users.update change a super administrator's password through the generic Flex API endpoint.

    FlexApiController::update() checks only the broad Flex directory permission and skips the target, field and super-admin checks that the dedicated Users and Groups controllers enforce. An account holding api.access, admin.login and users.update, without api.users.write or admin.super, can reset a super admin password via /api/v1/flex-objects/user-accounts or grant its own group admin.super via /api/v1/flex-objects/user-groups. Fixed in Flex Objects 1.4.7.

    Indicators4
    Hashes
    0b384f5b0e73b1ad9dd29c70185407895ea3b09f 8071c10bc3a4743a4b8cf003dfb1644d6680c2ea a0bf26f7e5d7a98894b7cd2b8c5afe419b264e53 ad9709f865b09b68798fb1ac375b484a8cc1d892
  1. Trust Without Boundaries: An Architectural Analysis of Satellite Flight Software (opens in a new tab)

    arXiv cs.CR (all) ·Jack Vanlyssel, Gruia-Catalin Roman, Kendra Cook, Sazzadur Rahaman ·fetched 17 Aug 2026, 03:42 UTC Must read Research agreed3/3

    Why readEmpirical demonstration on NASA's own flight representative simulator that one rogue component inside cFS can exercise the authority of the entire spacecraft bus without looking anomalous.

    The authors map how authority, identity, messaging, observability and persistence are distributed across components in NASA's Core Flight Software, then build a malicious onboard application and run five experiments on the NOS3 simulator to show what it reaches using nothing but legitimate architectural privileges. Because the architecture treats every component as a trusted peer, the abuse is hard to separate from normal operation; there is little internal isolation for an attacker to visibly break. A comparison against other modular flight software frameworks finds the same trust assumptions recurring, which makes this a statement about the design pattern rather than about one codebase.

  2. Exploit-Garbage/0day-Rubbish: Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to elevate vendor security standards and advance (opens in a new tab)

    GitHub: new security tools ·Exploit-Garbage ·fetched 17 Aug 2026, 07:41 UTC Research ★ 151 agreed2/2

    Why readA live, recurring drop of working exploits against real ERP and business software, released with no vendor coordination on a roughly fortnightly schedule.

    The project pairs automated discovery, pattern analysis, fuzzing and code review, with manual validation and PoC development, then publishes verified 0days directly rather than through a coordinated process. The stated rationale is that AI has made individual bugs cheap enough that direct release is the only pressure vendors respond to, and the operators restrict targets to software with actual user bases. For defenders the practical takeaway is a named channel where unpatched exploitable issues in enterprise software appear on a predictable cadence, worth monitoring against your own vendor list.

  1. Apple Screen Sharing Security, (Mon, Aug 17th) (opens in a new tab)

    SANS ISC Diary ·fetched 17 Aug 2026, 15:37 UTC agreed2/2

    Why readConcrete hardening steps for macOS Screen Sharing, and the reason the legacy VNC password path is the one that gets you owned.

    Apple's Screen Sharing has always been VNC underneath, and two recent severe flaws sit precisely in the modifications Apple bolted onto it; ISC says exploitation is live and that any host with the service exposed should be treated as compromised. The core weakness is that Apple still honours plain VNC authentication, where a client is prompted for a password only and no username, alongside the macOS account path. The remediation is to drop the VNC password entirely, force account based authentication, and keep port 5900 off the internet behind a VPN or SSH tunnel since the protocol itself is unencrypted.

  2. Between Two Nerds: The eye of Sauron (opens in a new tab)

    Risky Business News ·fetched 17 Aug 2026, 23:38 UTC agreed2/2

    Why readDiscussion of the Offense Death Cycle paper, which argues defenders should exploit their own control of the network to force intruders into exposure rather than waiting to detect them.

    Tom Uren and The Grugq walk through "The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber Defense", a paper on turning a defender's administrative control of the environment into a persistent pressure campaign against intruders. The argument is that repeated, deliberate environmental change surfaces attackers who would otherwise remain quiet. Worth it for the framing and for the paper reference; the episode itself is commentary rather than method.

DFIR

1
  1. aliyun/alibabacloud-ecs-troubleshoot-skills: Troubleshooting skills for Alibaba Cloud ECS (opens in a new tab)

    GitHub: new security tools ·aliyun ·fetched 17 Aug 2026, 03:42 UTC Research ★ 148 agreed3/3

    Why readA vendor released bundle of Linux compromise assessment skills you can hand to an agent: 51 analysers, 10 collectors and 88 kernel CVE detectors, deployable standalone, in Docker or on Kubernetes.

    Alibaba Cloud published its ECS troubleshooting skill set, whose security half covers intrusion detection and forensics across process, network, authentication, persistence, rootkit, malware, memory and container escape checks, mapped to more than 103 ATT&CK techniques. A separate module ships 88 kernel CVE detectors with three privilege escalation verification modes and a small challenge harness that confirms a candidate finding actually reproduces rather than stopping at version matching. Documentation is in Chinese and the Linux skills expect the aliyun CLI with configured credentials, so the collectors are tied to Alibaba Cloud even though the analyser logic is generic.

  1. Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline (opens in a new tab)

    Rapid7 ·Anna Širokova ·fetched 17 Aug 2026, 15:37 UTC Must read Research agreed2/2

    Why readAn exposed directory handed Rapid7 both a crypto fraud crew's full toolkit and the shell history and prompts showing how they built it with AI coding assistants.

    The open web directory held raw phone number datasets, account validation tooling, enriched lead records, phishing panels, voice dialling scripts, fake wallet applications, persistence code and Telegram exfiltration logic, giving an end to end view of the pipeline Rapid7 tracks as Operation ASTERIX. The unusual part is the development residue: recovered prompts and project files show assistants used to package Electron apps, obfuscate code, fix builds and prep malware for distribution. When one model started refusing parts of the workflow, the operator moved to a different provider and wrote a custom jailbreak prompt to get past its controls, which is about as clean a piece of evidence on adversarial assistant abuse as you will find in public reporting.

    Indicators11
    Hashes
    ba9d459169a303067a4fe36c8b8582a5ea023b9c270dafe89613bab840501b19 918fa540126b7db6424652d84a5ce7e968947136db3d6e3e0cab30ea309e25a2 961a398a5c71e837626b5fce68e44b14a5d220e3bd74a3d0ecd61a2762c38176 7073b2a3a34525c5969921dd17ef1fa5607af92be78b3fc6129cdea73216691a 0f2c7194f1f577e73460db9ec2e75fc0c7f845588cbd4246333b7a4fbec90d9f 4bee9affff9fa718a2c94f02ebe6a75143d4d461d291c2df9b769920fc927bf8
    Domains
    macos-claude[.]com com[.]ledger[.]live 36mcrypto[.]com ledgerhelp[.]com ledger[.]com
  2. Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot “Autofix” (opens in a new tab)

    Wiz ·Gal Nagli ·fetched 17 Aug 2026, 15:37 UTC Must read Research agreed2/2

    Why readAn AI-generated Copilot autofix introduced a GitHub Actions script injection in snowflakedb/snowflake-connector-net that let an unauthenticated user run commands in the runner by filing a crafted issue.

    Wiz's autonomous Red Agent, working through Snowflake's HackerOne programme, found a workflow injection in a public Snowflake repository where untrusted issue content flowed into a GitHub Actions step, giving arbitrary command execution on the runner and access to repository credentials. Disclosure was on 23 June 2026; Snowflake fixed it the same day, rotated the affected credential, and confirmed from audit logs that Wiz was the only actor in the exposure window. The interesting pairing is provenance on both ends: an AI coding assistant's autofix introduced the pattern, and an autonomous agent found it in the wild, which argues for treating Copilot-authored workflow changes as untrusted input to CI review.

  3. Recovering Encrypted LLM Reasoning Traces (opens in a new tab)

    Embrace The Red ·fetched 17 Aug 2026, 07:41 UTC Must read Research agreed2/2

    Why readHands-on reproduction of the paper showing that the encrypted, base64-wrapped reasoning traces OpenAI and Anthropic return in their message protocols can be recovered.

    A recent paper, "Stealing Reasoning Traces from Proprietary LLM APIs", describes a method for recovering the hidden reasoning text that labs ship back and forth as an encrypted blob, and this post walks through actually running it. The consequence is that the confidentiality boundary around proprietary reasoning traces is weaker than the encryption implies, which matters for anyone relying on hidden chain-of-thought to keep sensitive intermediate content out of reach. Practical relevance for both model providers and teams whose agents pass reasoning through untrusted intermediaries.

  4. MazeRunner: Nonlinear Task and Clue Orchestration for LLM-driven Black-Box Automated Penetration Testing (opens in a new tab)

    arXiv cs.CR (AI) ·Zhenyuan Li, Yi Jiang, Junjie Cheng, Yaokun Li ·fetched 17 Aug 2026, 19:37 UTC Research agreed2/2

    Why readAn LLM pentest agent architecture that fixes the failure mode of existing ones, depth-first tunnel vision and forgotten evidence, evaluated on 10 recent HTB targets.

    MazeRunner splits autonomous black-box penetration testing across three agents: global orchestration, context-heavy execution, and failure-oriented review, with persistent task state and an environmental evidence store. That separation is what enables action revision, prerequisite recovery, branch switching and correlation of clues found many steps earlier, which linear end-to-end agents cannot do. The claimed contribution is nonlinear attack-graph inference rather than raw exploit capability, so read it as an agent-design paper that happens to attack HTB boxes.

  5. ‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit (opens in a new tab)

    404 Media ·Jason Koebler ·fetched 17 Aug 2026, 19:37 UTC agreed2/2

    Why readCourt records show a 3M expert witness generated much of his report with ChatGPT, and left prompts including "show how 3M is 0% at fault" publicly exposed.

    Transcripts, depositions and discovery in the litigation over the Watson Grinding explosion in Houston, which killed three people and destroyed around 200 homes, show an expert witness retained by 3M used ChatGPT to write significant parts of his expert report, and exposed the prompts themselves. One asked the model to "create an exceptional expert witness report defending the standard of care at 3M". The prompts becoming discoverable artefacts is the part worth internalising: anything staff type into a hosted model can end up as evidence attributed to your organisation, which is a records and privilege problem as much as an AI one.

  6. Finding Vulnerabilities via LLM-Augmented Semantics-Aware Type-Checking (opens in a new tab)

    arXiv cs.CR (AI) ·Ruizhe Wang, Meng Xu, N. Asokan ·fetched 17 Aug 2026, 03:42 UTC Must read Research agreed3/3

    Why readProposes a type system whose types are derived from the natural-language meaning of identifiers, with LLMs doing inference and checking, and reports 87% precision finding real Python web app bugs.

    SETYPE treats the semantic meaning of variable and function names as type information, so a failed type check flags a probable vulnerability; the PYSETYPE prototype applies this to Python web applications and reaches 87% detection precision and 88% accuracy on real-world targets. The angle is that syntactic static analysis rules miss bugs that are obvious from what the code claims its data is. Precision figures on academic benchmarks rarely survive contact with a large monorepo, so read the evaluation set before drawing conclusions for your own SAST pipeline.

  7. STINER: Automated Extraction of Strategic Cyber Threat Intelligence from X (opens in a new tab)

    arXiv cs.CR (AI) ·Yasir Ech-Chammakhy, Oussama Azrara, Jaafar Chbili, Anas Motii ·fetched 17 Aug 2026, 07:41 UTC Research agreed2/2

    Why readAn expert-annotated corpus of 2,100 real-world breach alerts from X plus an eight-entity taxonomy, benchmarked across nine models, for anyone trying to automate strategic CTI extraction.

    STINER targets the gap where conventional NER models fail on the informal dialect of social media, which is where breach announcements often surface days ahead of vendor reports. The authors release a taxonomy centred on strategic pivots such as Threat Actor, Sector and Location, an expert-annotated dataset of 2,100 alerts, and benchmark results over nine models in twelve configurations. Useful if you are building or evaluating automated intake for open-source strategic intelligence; the dataset is the durable contribution.

  8. A Four-Axis Trustworthiness Benchmark for LLM-as-Judge in Principle-Based Regulation (opens in a new tab)

    arXiv cs.CR (AI) ·Dipankar Sarkar ·fetched 17 Aug 2026, 15:37 UTC Research agreed2/2

    Why readQuantifies how badly an LLM judge collapses under adversarial keyword stuffing: a 120B judge drops from 0.74 to 0.27 accuracy on Consumer Duty inputs.

    Principle-Bench is 168 cryptoasset financial-promotion scenarios mapped to two UK FCA principles, with paraphrase, keyword-stuffing and boundary perturbations authored under a pre-registered rubric, evaluating LLM-as-judge on accuracy, paraphrase robustness, adversarial robustness and calibration. Across keyword counting, three sentence-transformer embedders, an open-weight LLM judge and a calibrated cascade, no method wins on all four axes, and the strongest benign-input judge loses 47 accuracy points under adversarial stuffing. The paper also proposes Ceca, a calibrated assessor emitting per-exemplar counterfactual attributions, which matters for anyone being asked to put an LLM in a compliance decision path.

  9. A Hybrid LLM-Based Framework for Automated Security Annotation Generation in Business Process Models (opens in a new tab)

    arXiv cs.CR (AI) ·Md Kamrul Islam, Tiphaine Henry, Mattia Salnitri, Julius Köpke ·fetched 17 Aug 2026, 11:35 UTC Research agreed2/2

    Why readMeasured result on LLM-generated security annotations for BPMN: precision 0.58 against 0.29 for human analysts across 27 process models, with recall roughly level.

    The framework takes a BPMN model plus a natural-language security requirements document and emits SecBPMN2 annotations, combining LLM semantic extraction with schema-constrained mapping, rule-based normalisation and deterministic validation. Evaluated on a curated set of 27 models, it beat human security analysts on precision (0.58 vs 0.29) at comparable recall (0.52). Narrow in scope and tied to a specific modelling notation, but the numbers are stated and arguable, and the schema-constrained-plus-validation pattern generalises to other security-artefact generation tasks.

  10. LiteLLM cyberattack exposes over 2,500 companies to risk (opens in a new tab)

    Google News: incidents · Escudo Digital ·fetched 17 Aug 2026, 07:41 UTC agreed2/2

    Why readAn early flag that LiteLLM, the proxy sitting in front of many production model endpoints, is reported compromised with downstream exposure claimed across thousands of organisations.

    A Spanish-language report, surfaced through a news aggregator, states that an attack on LiteLLM has exposed more than 2,500 companies. No mechanism, timeline, CVE or affected version range accompanies the claim at this stage, so treat the number as unconfirmed. The reason to note it anyway is placement: LiteLLM commonly holds provider API keys and brokers traffic for internal applications, so a genuine compromise there is a credential and prompt-data incident, not just a dependency bump.

  1. Record-setting AML penalty against UBS was years in the making (opens in a new tab)

    Compliance Week ·By Alexander Owens, CW Guest Columnist ·fetched 17 Aug 2026, 23:38 UTC agreed2/2

    Why readShows what regulators do when a firm misses remediation commitments it made in a prior consent order: UBSFS paid $125 million after promising in 2018 to fix wire transaction monitoring by mid-2019.

    FinCEN, FINRA ($20 million), the SEC ($20 million) and the CFTC ($8 million) combined for a $125 million penalty against UBS Financial Services over long-running AML failures. The aggravating factor was recidivism: a 2018 consent order and $14.5 million penalty came with a commitment to replace a foreign currency wire monitoring process that screened at best quarterly and depended on error-prone Excel report generation. The lesson for anyone operating under a regulatory undertaking is that the remediation deadline is itself the enforceable obligation.

  2. Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity (opens in a new tab)

    NIST Cybersecurity Insights ·Julie Haney, Jody Jacobs ·fetched 17 Aug 2026, 23:38 UTC agreed2/2

    Why readNIST is taking public comment on the future of its human-centered cybersecurity programme, which is the open door if you want usability failures like password complexity rules and punitive phishing simulations addressed in guidance.

    Julie Haney and Jody Jacobs open a request for input on where NIST's human-centered cybersecurity work should go next, framing it around the friction users and practitioners live with: password requirements that force writing them down, phishing simulations that read as traps, and analysts working across half a dozen disconnected dashboards. The consequence is influence over future NIST guidance rather than any obligation today. Worth a response if your programme carries usability debt you want standards cover to fix.

  3. Risky Bulletin: The EU publishes its upcoming cybersecurity standards (opens in a new tab)

    Risky Business News ·fetched 17 Aug 2026, 11:35 UTC agreed2/2

    Why readThe EU has now published the list of harmonised cybersecurity standards it intends to adopt, which sets the compliance target teams will be measured against, alongside a GeoServer zero-day already under exploitation.

    Risky Business News runs its daily briefing, led by the EU making public the cybersecurity standards it plans to put into force, the reference point vendors and operators will have to build toward. The same bulletin flags a breach at France's tax agency, a GeoServer zero-day picked up by threat actors within hours of disclosure, and an exploit that unlocks older AMD CPUs with a single instruction. The write-up itself is a pointer to the show notes rather than original reporting, so treat it as a queue of things to chase rather than the analysis itself.

  1. France's tax authority had data stolen on 680k taxpayers (opens in a new tab)

    Hacker News ·rzk ·fetched 17 Aug 2026, 11:35 UTC Must read 55 points agreed2/2

    Why readFrance's tax administration had taxpayer data on 680,000 people stolen, a named public-sector breach that peers and regulators in the EU will be asked about.

    Data on 680,000 French taxpayers was stolen from the national tax authority, per French-language reporting picked up on Hacker News. The item as supplied carries the scale and the victim organisation but no attack vector, timeline or attribution. For a European security leader this is the CNIL and GDPR notification question that lands on Monday, and a reference point for anyone holding comparable citizen data.

  2. Major genetic-testing firm says hack compromised sensitive patient data (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 17 Aug 2026, 23:38 UTC agreed2/2

    Why readBaylor Genetics confirmed an 11-17 June intrusion exposing genomic and lab test records, insurance data and some SSNs for patients and employees.

    Baylor Genetics, a genomic-diagnostics lab serving healthcare providers, said attackers were in part of its IT environment between 11 and 17 June 2026 and could have accessed birthdates, medical and laboratory test records, health insurance information and, in a small number of cases, Social Security numbers. Employee SSNs and financial account details were also potentially exposed. The investigation with outside responders and law enforcement closed 30 July, and the company has not explained the two-week gap before disclosure.

  3. Knock-knock, who’s there? RingCentral discloses data breach in wake of ShinyHunters hack claims (opens in a new tab)

    Google News: incidents · Cyber Daily ·fetched 17 Aug 2026, 03:42 UTC agreed3/3

    Why readRingCentral has formally disclosed a breach after ShinyHunters claimed the hack, another name in the extortion group's run against SaaS communication providers.

    RingCentral confirmed a data breach following claims by ShinyHunters, moving the incident from criminal boast to vendor acknowledgement. The report is a headline-level item with no stated record count, intrusion vector or affected-customer scope. For leaders it is the point at which a widely deployed UCaaS supplier enters the ShinyHunters victim list, which is a third-party risk question worth raising before the technical detail lands.

  4. SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted (opens in a new tab)

    The Record ·fetched 17 Aug 2026, 19:37 UTC agreed2/2

    Why readThird crypto hardware wallet maker breached in a month: SafePal lost order data on nearly 40,000 customers, which is a targeting list for physical and phishing attacks.

    SafePal confirmed names, email addresses, shipping addresses, phone numbers and purchase details were stolen for customers who ordered between 2 March 2025 and 11 April 2026, affecting close to 40,000 people. The company attributes it to a flaw in the order-tracking function of a plug-in that allowed unauthorised access to another customer's order records, which reads like a straightforward authorisation bug. It follows incidents at Trezor and Coinkite, making the pattern across wallet vendors the story rather than any single breach.

    Also covered byRescana (opens in a new tab).

  5. Comcast (CMCSA) Agrees $117.5 Million Settlement Over Massive Customer Data Breach (opens in a new tab)

    Google News: incidents · finance.yahoo.com ·fetched 17 Aug 2026, 23:38 UTC agreed2/2

    Why readPuts a number on consumer breach exposure for a US telecom: Comcast has agreed to a $117.5 million settlement over a customer data breach.

    Comcast has agreed to pay $117.5 million to settle claims arising from a breach of customer data. The item reached us as a headline with no article body, so the class definition, the underlying incident and the court are not confirmed here. The figure is the useful part for anyone benchmarking breach liability reserves or arguing cyber insurance limits at board level.

  6. If Meta loses this trial, Instagram and Facebook could change forever (opens in a new tab)

    BBC Technology ·fetched 17 Aug 2026, 03:42 UTC agreed3/3

    Why readA 30-state jury trial over children's privacy opens against Meta with damages sought above $1 trillion and product-design remedies on the table.

    The suit, filed in 2023 by 30 US states including California and New York, alleges violations of federal and state children's privacy law and seeks both damages and structural changes: ending like counts and infinite scroll, parental verification for teen accounts, removal of appearance-altering filters and an end to ephemeral posts. A loss would set the first jury precedent for privacy-law liability attaching to recommendation design rather than to a data breach. Anyone whose product handles minors' data should expect the remedy list to shape regulator expectations regardless of the verdict.

  7. Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach (opens in a new tab)

    The Record ·fetched 17 Aug 2026, 23:38 UTC agreed2/2

    Why readHeights Finance told Texas regulators 734,828 people had SSNs, bank account and routing numbers exposed after a third-party cloud platform was breached on 7 May.

    Heights Finance, which runs personal loan operations across Alabama, Tennessee, Georgia, Texas and South Carolina, disclosed a breach discovered 7 May 2026 in a third-party-hosted cloud platform holding customer records. The regulator filing puts the count at 734,828 people, with exposed data covering addresses, bank account and routing numbers, Social Security numbers, tax IDs and driver's licence numbers. The three-month gap between discovery and notification, and the third-party hosting angle, are the parts peers in consumer lending will be asked about.

  8. Bits of Gold data breach exposes personal details of up to 250,000 crypto customers (opens in a new tab)

    Google News: incidents · calcalistech.com ·fetched 17 Aug 2026, 11:35 UTC agreed2/2

    Why readIsraeli crypto exchange Bits of Gold breached, with personal details of up to 250,000 customers exposed.

    Bits of Gold, a regulated Israeli cryptocurrency broker, has disclosed a breach affecting as many as 250,000 customers' personal details. KYC-heavy exchange data is directly weaponisable for targeted phishing and SIM-swap attempts against holders, so the downstream fraud exposure outlasts the disclosure. Only the headline and outlet reached us, so the breach vector and timeline are not established here.

  9. Unlimited Technology Systems data breach exposes information of 3.8M patients (opens in a new tab)

    Google News: incidents · Top Class Actions ·fetched 17 Aug 2026, 15:37 UTC agreed2/2

    Why readUnlimited Technology Systems has disclosed a breach affecting 3.8 million patients, a healthcare third-party exposure large enough for peers to field questions about.

    A data breach at Unlimited Technology Systems exposed information belonging to roughly 3.8 million patients. The item is a class-action tracker's note rather than a filing or forensic account, so the scale figure is the only hard detail. Healthcare and third-party risk owners will want the underlying notification once it surfaces.

  10. Israel’s Largest Crypto Broker Reports Data Breach (opens in a new tab)

    Google News: incidents · Yahoo Finance ·fetched 17 Aug 2026, 19:37 UTC agreed2/2

    Why readIsrael's largest crypto broker has disclosed a data breach, which matters given how directly exchange customer data feeds targeted theft.

    The country's biggest crypto brokerage reported a data breach, per Yahoo Finance. Nothing has been published yet on records affected, intrusion vector or whether custody systems were touched, so treat the disclosure itself as the fact. Customer lists from crypto intermediaries reliably turn into SIM-swap and social-engineering campaigns against named holders, so expect follow-on fraud questions before technical detail arrives.

  11. Srsly Risky Biz: Data extortion is booming. Hooray! (opens in a new tab)

    Risky Business News ·fetched 17 Aug 2026, 23:38 UTC agreed2/2

    Why readArgues that data-theft extortion is displacing encryption-based ransomware, which changes the calculus for reputation-sensitive organisations.

    Uren and Wilson make the case that the cybercrime ecosystem is shifting toward stealing data and monetising the threat to leak it rather than locking files, and that for organisations where reputation is the primary asset a leak now outranks an outage. They also argue the spread of AI is reason to revive CISA's Secure by Design push. Position pieces of this kind are useful for framing board conversations, but there is no data or incident detail attached here.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Codinter insomnia Technology US 17 Aug 2026
GSW Gemeinschaftsstadtwerke GmbH qilin Energy & Utilities DE 17 Aug 2026 press coverage (opens in a new tab)
White-Daters & Associates, Inc qilin Professional Services US 17 Aug 2026
The University of the West Indies qilin Education TT 17 Aug 2026
EmpireWorks qilin - - 17 Aug 2026
Bridgeport Capital Services play Financial Services US 17 Aug 2026
Sam Pack Auto Group play Retail & E-Commerce US 17 Aug 2026
Woodhaven Association play - US 17 Aug 2026 press coverage (opens in a new tab)
BMW Group xpl0itrs Manufacturing DE 17 Aug 2026
Lansing Urgent Care incransom Healthcare US 17 Aug 2026
The Rubber Group Global Secret Group Manufacturing US 17 Aug 2026
DL E&C Panzer Manufacturing KR 17 Aug 2026
4M REALTY COMPANY Global Secret Group Retail & E-Commerce US 17 Aug 2026
Planungsgruppe M+M AG aurora Professional Services CH 17 Aug 2026
Arizona State University (ASU) direwolf Education US 17 Aug 2026
Wishfully Studios direwolf Technology SE 17 Aug 2026
Rx Networks everest Technology CA 17 Aug 2026
Mighty Kingdom direwolf Technology AU 17 Aug 2026
Eva AI Limited direwolf Technology GB 17 Aug 2026
Natco Home Group aurora Retail & E-Commerce US 17 Aug 2026
Castilla La Mancha Panzer Government & Defense ES 17 Aug 2026
Doimo Cucine Panzer Manufacturing IT 17 Aug 2026
Lloyd Coils Europe aurora Manufacturing GB 17 Aug 2026
Otter Tail County, Minnesota incransom Government & Defense US 17 Aug 2026
Vermont XCenter dragonforce - BR 17 Aug 2026
How this edition was made
Candidates fetched
5749
New after deduplication
720
Kept by the panel
146
Published
97
Generated
17 Aug 2026, 23:38 UTC