CFToday Curated security signals.

Daily edition · 2026-08-18

Tuesday, 18 August 2026

49 items across 8 sections, selected from 5763 candidates over 6 runs. 104 carried the panel unanimously.

Show
Section

India

2

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. 'Our cyber defence must evolve faster’: SEBI chief Tuhin Kanta Pandey launches 2 new portals for digital security (opens in a new tab)

    Google News: enforcement · livemint.com ·Governance, Risk & Compliance ·fetched 18 Aug 2026, 11:37 UTC agreed2/2

    Why readThe primary account of SEBI launching two cybersecurity portals, with the regulator's chief naming the intent, which is the version to cite when briefing an Indian regulated entity.

    SEBI chief Tuhin Kanta Pandey launched two new portals for digital security, arguing that cyber defence for the securities market must evolve faster than current practice. As with the other reports of this event, only the headline reached us, so the portals' functions and any mandatory use are not spelled out here. Named official, named regulator and a dated launch make it a real event, but the compliance detail has to come from SEBI's circular.

  2. Hacker claims millions of records stolen from corporate Azure tenants (opens in a new tab)

    Help Net Security ·Threat Intel & Breaches ·Sinisa Markovic ·fetched 18 Aug 2026, 11:37 UTC agreed2/2

    Why readNames the four large enterprises whose employee directories a forum actor is currently advertising as Azure tenant dumps, so you can check whether your own tenant or a supplier is on the list.

    Hudson Rock reports that an actor calling itself TheHatman has posted large internal employee directories on cybercrime forums over the past week, claiming each was pulled from the victim's Azure tenant. Named organisations include McDonald's, Vodafone, Kyndryl and Tata Consultancy Services. The claims are unverified and no access method, initial vector or sample validation is described, so treat this as a lead to check rather than a confirmed breach set.

  1. Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect (opens in a new tab)

    Check Point Research ·fetched 18 Aug 2026, 15:38 UTC Must read Research agreed2/2

    Why readCheck Point unpicks StopAndProtect, a ransomware-plus-exfiltration operation running its entire C2, delivery and stolen-data storage on thousands of compromised WordPress sites.

    StopAndProtect combines file encryption with data theft and uses hacked WordPress installations as delivery, command-and-control and storage for exfiltrated documents, screenshots and activity logs. Developer OPSEC failures left infection logs, victim screenshots and the source of the operators' mass-site-management tooling exposed, which is how the scope was established: thousands of victim IPs, concentrated in the US, Russia and India. It is a toolkit rather than a single family, so detection needs to cover the component set and the WordPress infrastructure pattern rather than one binary.

    Indicators18
    Hashes
    cab7f141fd6f2c58055b3731ef6a64b8a2d4d88a974770b047da19c0904322f0 cc8aa2bd7bf74ca0bbc5cb03a7b18eae73094b450d11654528c05685fe12e0c9 99bcb531d6dd3c93d3f28f03d6e4659c865a4ffbd2fb514e809017f3446a940b 8337bf29100a5871b1275227006dc2a43b21b751e5ce7e2032364fd78af59ac5 4dee2fe98d4da75ffb259c03b50202212dafc85691429a28641a8068eddea504 9765b1342cc7eb982a73bb1f94c6c500b63dc817073b76ea926c1097078d3527 7d3604d0728b242c72bd144b8661ebf63c1042a4f5dd441bc8c8507c701df20c 976cfa57e1efacbe517b7e3441e9473d275ec1d9ad8ab69ddf8ae3a966aaa153 b79b9b027f76579555069a7506d946648a8cb3126c0dda837dc9fee0e5c79489 65550f6d0ffec8421f703cdc7273d9c0563b3d480fe6702bad294a18afe72143 0080d0dd72eda4850a02e51c0e5c6f768423dfe970cafae2ab52ceee75972b40 8d1e23630a6695fa9c793d73832f59436c98bba30ed81c16d01b549bd17feab4
    Domains
    norakremer[.]co[.]uk ksr-racingparts[.]com v-k[.]com www[.]parsrulman[.]com mectcalcutta[.]com discherniation[.]com
  2. PurpleDelta's Fraudulent Employment Operations (opens in a new tab)

    Recorded Future ·fetched 18 Aug 2026, 15:38 UTC Must read Research agreed2/2

    Why readHiring-side tradecraft of North Korean IT workers in detail: 22 fabricated personas, applications to over 1,100 companies, up to 60 applications a day, and at least ten organisations that actually employed them.

    Insikt Group tracks PurpleDelta, clusters of DPRK IT workers likely operating from China, across late 2024 to early 2025. Operators ran multi-account management browsers and separate Chrome profiles to juggle personas, backed them with AI-generated profile photos, custom-configured ChatGPT assistants and identity documents bought from an illicit ID-generation service, and kept tracking spreadsheets to coordinate applications across job platforms. Targeting concentrated on software and technology, staffing and consulting, and healthcare and biotechnology, giving recruiting and HR teams concrete behavioural signals to screen against.

    Indicators2
    Domains
    trustidcard[.]com minicursor[.]com
  3. Hunting MacSync Stealer infrastructure through behavioral pivots (opens in a new tab)

    Microsoft Security ·Microsoft Defender Experts and Microsoft Security Research ·fetched 18 Aug 2026, 19:40 UTC Must read Research agreed2/2

    Why readBehavioural pivots that survive infrastructure rotation, used to expand MacSync Stealer from a handful of known domains to more than 30 across C2, staging and exfiltration.

    Microsoft Defender Experts built on RST Cloud's initial domain set by correlating recurring endpoints and network behaviours rather than chasing indicators, and found the infrastructure supports active collection, staging and upload as well as command and control. The point for hunters is that this macOS infostealer replaces domains fast after public disclosure, so execution patterns, request characteristics and upload methods are the durable pivots. Usable as a hunt recipe against any fast-rotating stealer, not just this one.

  4. Beware of phishing emails disguised as requests to review quotes (PhantomStealer) (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 18 Aug 2026, 11:37 UTC Must read Research agreed2/2

    Why readWalks a PhantomStealer delivery chain that uses a vulnerable driver to kill security software, with the actual attachment names and the UAC-bypass decision logic.

    A quote-review phishing lure impersonating an overseas company's sales team delivers a GZ archive containing "7200_Quantum_Enterprise_LLC_SSO-0661.Exe", an injector that abuses vulnerable drivers to disable security products before injecting PhantomStealer into legitimate processes. The injector first checks for an administrator token and skips UAC bypass if it already has one; otherwise it attempts SSPI-based privilege escalation. Concrete filenames and behavioural sequence make this directly usable for detection rules on the driver-load and injection stages.

  5. More than 200 victims of Medusa ransomware identified over the last year, CISA says (opens in a new tab)

    The Record ·fetched 18 Aug 2026, 19:40 UTC agreed2/2

    Why readCISA and the FBI now count more than 500 Medusa victims as of April 2026, up from 300, and say the group weaponises new exploits inside 24 hours.

    The joint advisory first issued in March 2025 has been updated: over 200 additional Medusa victims were identified in the past year, taking the total past 500, with concentration in healthcare. The agencies note Medusa operators have been seen using exploits within 24 hours of disclosure and in some cases ahead of public announcement. April's shutdown of the University of Mississippi Medical Center, the state's only children's hospital and Level I trauma centre, is cited as the case that drew the most attention.

  6. New Mirai-Based Evooo1Bot Botnet Targets Linux Devices (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 18 Aug 2026, 07:41 UTC CVE-2016-6277 EPSS 99.8% agreed2/2

    Why readNames a new Mirai derivative, Evooo1Bot, and the capabilities it bolts onto the leaked Mirai base: encrypted C2, SSH brute-forcing, a credential sniffer and a SOCKS5 relay.

    Fortinet's FortiGuard Labs documented Evooo1Bot, a Linux botnet active since July 2026 and named for the hardcoded string "evooo1" present in every binary. It reuses Mirai's DDoS engine but adds encrypted command-and-control, an SSH brute-force scanner, a credential sniffer, a SOCKS relay for criminal proxy resale, and an exploit set covering 18 known CVEs going back to 2007, including CVE-2016-6277 (EPSS 0.998). This is a second-hand write-up of the Fortinet report, so go to the original for the full indicator set.

  7. CopyCop Targets AI Investment in Armenia (opens in a new tab)

    Recorded Future ·fetched 18 Aug 2026, 19:40 UTC Research agreed2/2

    Why readInsikt Group documents three CopyCop (Storm-1516) media impersonations aimed at the US and Armenian-backed Firebird AI data centre in Hrazdan between 24 June and 13 July 2026.

    The Russian influence network fabricated an earthquake risk at the site, then questioned its economic viability, then impersonated an Iranian military communication framing the data centre as a legitimate military target. Reach grew across the three instances to more than 1.6 million combined views by the third, using the same amplifier network previously turned on other Armenian targets. Relevant if you defend or advise Western infrastructure investment in the South Caucasus; the pattern is reputational pre-positioning ahead of a facility opening rather than intrusion.

    Indicators5
    Domains
    tech-crunch[.]org haaretz24[.]com euronews[.]us[.]com politico-24[.]com gizmodo[.]cc
  8. Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) (opens in a new tab)

    Unit 42 ·Unit 42 ·fetched 18 Aug 2026, 23:37 UTC agreed2/2

    Why readA maintained index of the current large-volume credential campaigns, with the log pattern worth hunting for: a successful login sitting right after a burst of failures.

    Unit 42 keeps this brief as a living page covering credential-stuffing and spraying activity, currently including TheHatman's August 2026 claim of bulk credential theft from Microsoft Entra tenants and the June 2026 Fortibleed spraying campaign against internet-facing Fortinet devices. The framing is that attackers are logging in with reused pairs rather than exploiting anything, so the detection ask is remote access log review focused on authentication successes that follow high-volume failure events. Hardening guidance for edge devices is bundled in, which is the part most teams can act on this week.

    Indicators1
    Domains
    exploit[.]in
  9. Ukrainian software developer faces 12 years in Swiss ransomware trial (opens in a new tab)

    The Record ·fetched 18 Aug 2026, 11:37 UTC agreed2/2

    Why readA rare look at what happens to the technical staff behind LockerGoga, MegaCortex and Nefilim once a European prosecution actually reaches court.

    Zurich District Court has begun trying a 52 year old Ukrainian software developer accused of building tooling for the LockerGoga, MegaCortex and Nefilim ransomware operations, with prosecutors asking for 12 years plus a 12 year expulsion and recovery of 1.8 million Swiss francs. Named Swiss victims include Stadler Rail, Crealogix and Meier Tobler. The defendant, in custody since October 2021, denies writing malware or taking part in attacks; a verdict is expected in September.

  1. CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions, Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability (opens in a new tab)

    CISA KEV ·fetched 18 Aug 2026, 19:40 UTC Must read CVE-2026-33824 Exploited in the wild · patch by 2026-08-21 EPSS 55.9% agreed2/2

    Why readKEV addition with a 21 August federal deadline: a double free in Microsoft's IKE Service Extensions allowing remote code execution, and the highest EPSS of today's batch at 0.5585 (98.96th percentile).

    CVE-2026-33824 is a double free in Microsoft Internet Key Exchange (IKE) Service Extensions that can lead to remote code execution. CISA added it to KEV with a remediation due date of 2026-08-21 under BOD 26-04, and EPSS puts it at 0.5585, the 98.96th percentile, meaning exploitation activity is broad rather than theoretical. IKE endpoints are typically exposed on VPN-terminating hosts, so treat any internet-facing IPsec listener as first in line and follow CISA's forensic triage requirement before patching over evidence.

  2. CISA Adds Four Known Exploited Vulnerabilities to Catalog (opens in a new tab)

    CISA Advisories ·CISA ·fetched 18 Aug 2026, 19:40 UTC Must read CVE-2026-33824 EPSS 0.5% agreed2/2

    Why readFour new KEV entries with confirmed exploitation and a federal remediation deadline: Microsoft IKE, SharePoint, VMware vCenter and macOS.

    CISA added CVE-2026-33824 (Windows IKE Service Extensions double free), CVE-2026-55040 (SharePoint weak authentication), CVE-2026-59310 (Broadcom VMware vCenter path traversal) and CVE-2026-65400 (Apple macOS improper authentication) on evidence of active exploitation. BOD 26-04 obliges FCEB agencies to prioritise these on publicly exposed assets where exploitation grants total control. SharePoint and vCenter are the two most likely to be internet-reachable in an enterprise estate; patch or isolate those first.

  3. CVE-2026-55040: Microsoft SharePoint, Microsoft SharePoint Weak Authentication Vulnerability (opens in a new tab)

    CISA KEV ·fetched 18 Aug 2026, 19:40 UTC Must read CVE-2026-55040 Exploited in the wild · patch by 2026-08-21 EPSS 4.0% agreed2/2

    Why readA SharePoint authentication weakness now confirmed exploited, with a CISA remediation deadline of 21 August, in a product that is both internet-facing and a standing ransomware entry point.

    CVE-2026-55040 is a weak authentication flaw in Microsoft SharePoint that lets an unauthenticated attacker bypass a security feature over the network. CISA added it to KEV on 18 August with a due date of 2026-08-21; EPSS is only 0.03971 but KEV membership means in-the-wild use is already established. Given SharePoint's history as a foothold for hands-on-keyboard intrusion, inventory on-premises farms, apply the vendor fix, and hunt for anomalous authentication to SharePoint before assuming you were not touched.

  4. CVE-2026-59310: Broadcom VMware vCenter, Broadcom VMware vCenter Path Traversal Vulnerability (opens in a new tab)

    CISA KEV ·fetched 18 Aug 2026, 19:40 UTC Must read CVE-2026-59310 Exploited in the wild · patch by 2026-08-21 EPSS 1.1% agreed2/2

    Why readExploited path traversal in VMware vCenter giving arbitrary code execution to anyone with network access to the appliance, with a 21 August KEV deadline.

    CVE-2026-59310 is a path traversal in Broadcom VMware vCenter that allows a threat actor with network reachability to vCenter to execute arbitrary code. CISA added it to KEV with remediation due 2026-08-21; EPSS is low at 0.0114, which is the usual pattern for management-plane bugs used in targeted intrusions rather than mass scanning. vCenter compromise is hypervisor-wide compromise, so restrict management network access as an interim control and patch to the Broadcom-listed build.

  5. CVE-2026-65400: Apple macOS, Apple macOS Improper Authentication Vulnerability (opens in a new tab)

    CISA KEV ·fetched 18 Aug 2026, 19:40 UTC CVE-2026-65400 Exploited in the wild · patch by 2026-08-21 EPSS 0.5% agreed2/2

    Why readScreen Sharing on macOS can be authenticated to over the network without valid credentials, now KEV-listed with a 21 August deadline.

    CVE-2026-65400 is an improper authentication issue in Apple macOS that allows a network attacker to authenticate to Screen Sharing without valid credentials. CISA added it to KEV with remediation due 2026-08-21; EPSS is 0.00496, so this is confirmed targeted use rather than commodity exploitation. Push the Apple update to managed fleets and, in the meantime, confirm Remote Management and Screen Sharing are disabled or firewalled on port 5900 across your macOS estate.

  6. CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now (opens in a new tab)

    Qualys ThreatPROTECT ·Vamika Sheel ·fetched 18 Aug 2026, 19:40 UTC CVE-2026-68820 EPSS 0.3% agreed2/2

    Why readCVE-2026-68820 is an actively exploited Windows bug now in KEV, and the fix replaces a kernel driver so it does not take effect until endpoints reboot.

    The KEV listing brings CVE-2026-68820 under CISA BOD 26-04, which sets risk-based remediation windows of 3 to 14 days rather than the old flat deadline. Because the patch swaps a kernel driver, KB5121003 and KB5120249 install cleanly but leave hosts exposed until they are restarted, which is the part most staged rollouts will miss against a short clock. Note that the second half of the post is a Qualys product pitch; the reboot requirement and the deadline structure are the parts worth taking away.

  7. GitLab issues emergency patch for critical code-injection flaw (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 18 Aug 2026, 15:38 UTC agreed2/2

    Why readCVE-2026-19478 in GitLab, CVSS 9.4, lets an unauthenticated attacker delete or rewrite public projects through a GraphQL directive in a single HTTP request, and watchTowr reproduced it within minutes of disclosure.

    GitLab shipped an out-of-band patch on Monday for CVE-2026-19478, a code injection flaw scored 9.4 that abuses a GraphQL directive to modify or delete public projects and user data. watchTowr says it reproduced the bug within minutes of public disclosure; principal researcher Jake Knott describes unauthenticated repository deletion, forged merge records and banning of maintainers via a single HTTP request with no credentials. The bug came in through GitLab's HackerOne programme, and self-managed instances exposed to the internet should be treated as urgent.

  8. CVE-2026-19349 (CVSS 9.8): Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via (opens in a new tab)

    NVD ·fetched 18 Aug 2026, 15:38 UTC CVE-2026-19349 CVSS 9.8 EPSS 0.8% agreed2/2

    Why readAny unauthenticated visitor to a LemonLDAP::NG GitHub or LinkedIn login endpoint can replay the OAuth2 state value as a session cookie and get a valid SSO session, with fixes in 2.16.9, 2.21.5 and 2.23.3.

    A positional call to getApacheSession( undef, 1, 0, 'GitHubState' ) in extractFormInfo() lets the trailing arguments fall into the named-argument hash, so kind defaults to SSO and the OAuth2 state is written to global session storage as a real SSO session. That identifier is then handed to the unauthenticated visitor in the redirect URL, and replaying it as a session cookie yields a session with no _user and no authenticationLevel, which the shipped bootstrap configuration accepts because it grants virtual hosts a default accept rule. Deployments whose access rules actually test the user are less exposed, but anyone running the GitHub or LinkedIn backends on 2.0.0 to 2.16.8, 2.17.0 to 2.21.4 or 2.22.0 to 2.23.2 should patch and audit sessions.

  9. CVE-2026-19598 (CVSS 9.8): The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, (opens in a new tab)

    NVD ·fetched 18 Aug 2026, 07:41 UTC CVE-2026-19598 CVSS 9.8 EPSS 0.4% agreed2/2

    Why readUnauthenticated administrator takeover in the Pods custom-content plugin for WordPress, all versions through 3.3.9, because every access check in the admin AJAX router is non-terminating.

    The pods_admin AJAX router routes its method allowlist, nonce check, login enforcement and capability gate through pods_error(), which under the JSON meta-box-loader compatibility path only writes to the PHP error log and returns false rather than halting the request. Every guard therefore fails open, letting an unauthenticated attacker perform administrator actions, including overwriting the site owner's password. Patch above 3.3.9; Pods is deployed on a large installed base and this is a full site takeover with no prerequisites.

  10. CVE-2026-18432 (CVSS 9.8): The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerab (opens in a new tab)

    NVD ·fetched 18 Aug 2026, 15:38 UTC CVE-2026-18432 CVSS 9.8 EPSS 0.4% agreed2/2

    Why readPassing a non-numeric user id such as 1one to Frontend Admin by DynamiApps skips the edit_user capability check entirely and lets an attacker overwrite the administrator's password or email, in all versions up to 3.29.9.

    ActionUser::conditions_logic() gates its current_user_can('edit_user', $user_id) check behind an is_numeric() test, so a crafted item_id string bypasses authorization; WordPress then coerces the value to integer 1, the default administrator. The path runs through the unauthenticated wp_ajax_nopriv_frontend_admin/forms/change_form endpoint and needs a server-signed _acf_objects payload carrying the non-numeric id. Fully unauthenticated exploitation requires a public frontend user form to be configured, otherwise a subscriber account is enough.

  11. CVE-2026-19714 (CVSS 9.1): The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated (opens in a new tab)

    NVD ·fetched 18 Aug 2026, 15:38 UTC CVE-2026-19714 CVSS 9.1 EPSS 0.3% agreed2/2

    Why readSimple JWT Login before 3.6.8 never checks the audience claim on Google identity tokens, so anyone with a token bearing an admin's email can log in as that admin.

    CVE-2026-19714 (CVSS 9.1) is a full unauthenticated authentication bypass: the plugin accepts Google ID tokens without validating aud, so a token minted for any other Google OAuth client that carries the target email is accepted. Every site with Google sign-in enabled on a version below 3.6.8 is affected, and CISA's SSVC record marks it PoC-available, automatable, with total technical impact. Audience validation failures like this are cheap to exploit at scale; patch to 3.6.8 and audit administrator logins.

  12. CVE-2026-73194 (CVSS 9.1): DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. (opens in a new tab)

    NVD ·fetched 18 Aug 2026, 07:41 UTC CVE-2026-73194 CVSS 9.1 EPSS 0.2% agreed2/2

    Why readPerl DBI before 1.652 takes a heap out-of-bounds write from an integer wrap in preparse, and the placeholder limit added in 1.650 does not catch it.

    preparse budgets seven output bytes per input byte, the width of ':p99999', but the ':N' branch parses the number with atoi() and assigns it to the binder counter unchecked, so ':2147483648' wraps the counter to -2147483648 under glibc. Every following '?' then expands via sprintf(start, ":p%d", idx++) to the 14-byte ':p-2147483648', overflowing further with each mark. The 1.650 limit test compares against 99,999, which a negative counter passes; only callers preparsing untrusted statements into ':pN' style placeholders are affected, since the '?' and '%s' styles validate the sequence and error out.

    Indicators1
    Hashes
    29b72ae7d2a8114a734a55840bf1c45b89207809
  1. BGP Role model: tracking the adoption of RFC 9234 (opens in a new tab)

    Cloudflare Blog ·Mingwei Zhang ·fetched 18 Aug 2026, 15:38 UTC Must read Research agreed2/2

    Why readMeasures real-world adoption of RFC 9234 BGP roles, the mechanism that makes valley-free routing intent explicit in the session rather than in each operator's hand-built filters.

    Cloudflare tracks deployment of RFC 9234, which encodes the customer-provider and peer-peer relationship as a BGP role negotiated on the session, so leaked routes can be rejected automatically instead of relying on per-network filter configuration. The post sets out how the valley-free hierarchy defines a legitimate path and why violations of that intent become route leaks that misdirect traffic. Useful for network and infrastructure defenders deciding whether to enable roles and Only-to-Customer marking on their own peerings, and how much of the internet would honour it today.

  2. How to Spot and Stop Rogue Device Joins (opens in a new tab)

    Wiz ·Sapir Federovsky ·fetched 18 Aug 2026, 19:40 UTC Must read agreed2/2

    Why readDetection strategy for rogue Entra ID device registrations now that attackers have moved off tells like DESKTOP-XXXXXXXX toward plausible names such as "Work PC".

    Attackers abuse the Device Registration Service to register their own machines under a victim identity, satisfying Conditional Access policies that require a joined device. The naming and User-Agent conventions defenders leaned on are eroding as attackers vary those artefacts, so the piece pushes detection toward registration context, identity behaviour and sequence rather than string matching on device names. Worth reworking your DRS and device-join alerting against if it still keys on cosmetic indicators.

  3. Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities (opens in a new tab)

    Tenable Research ·Clément Notin ·fetched 18 Aug 2026, 07:41 UTC agreed2/2

    Why readNames the Storm-0501 Azure playbook steps a defender should alarm on: removal of resource locks, disabling of immutability policies, and backup deletion inside the tenant rather than encryption on hosts.

    Storm-0501 has moved from endpoint encryption to full Azure tenant hijack, and the piece argues the highest-value detection point is the configuration change that precedes destruction: resource locks stripped, immutability turned off, backups removed. That gives a concrete telemetry target in Azure control-plane logs regardless of tooling. Everything past that framing is Tenable One Cloud Exposure product content, including the AI threat stories pitch, so the deployable part is the TTP list rather than the detections.

  4. Teaching AI to Reason Through Detection Triage (opens in a new tab)

    CrowdStrike ·Amol Khanna - Manu Nandan - Cristian Viorel Popa - Joan Pujol-Roig - Diana Bolocan - Laura Vasilie - Alexandru Apostu - Chase Helwig - Mihaela Gaman - Mickey Brautbar - Edward Raff - Chase Midler - Sven Krasser ·fetched 18 Aug 2026, 07:41 UTC agreed2/2

    Why readCrowdStrike is now shipping the reasoning trace alongside its true positive and false positive verdicts, which is the piece a SOC lead needs before letting a model auto-close alerts.

    The post describes extending CrowdStrike's Nemotron-based detection triage models from a bare verdict plus confidence score to step-by-step reasoning over command lines and behavioural context, on the argument that an analyst weighs evidence rather than just classifying. The pitch is that the trace buys accuracy, auditability, and a defensible basis for automated closure. Read it as a capability description rather than a paper: the published excerpt asserts the accuracy gain without the evaluation numbers or baseline comparison that would let you check it, so file it under how vendors are packaging triage automation.

DFIR

2
  1. Defenders Arise: Examining 7Zip data extraction with Registry analysis (opens in a new tab)

    ThinkDFIR ·Phill Moore ·fetched 18 Aug 2026, 15:38 UTC Must read Research agreed2/2

    Why readShows that typing \\.\ into the 7-Zip address bar gives raw physical-device access, and that Software\7-Zip\FM\PanelPath0 in the registry records it, giving you an artefact for NTDS theft cases.

    Following up on a claim that 7-Zip can be pointed at \\.\ to reach physical devices, the author tested it and traced what it leaves behind: the PanelPath0 value under the Software\7-Zip\FM key retains the last path browsed, so a value of \\.\ is a tell that someone interacted with the raw disk view. An existing RegRipper plugin already parses the relevant keys. The context is a real case where attackers ran 7-Zip on a domain controller and left NTDS.7z in a user folder with no explanation of the method.

  2. More tools, more friction: why DFIR toolkits need a connective layer (opens in a new tab)

    Magnet Forensics ·HaadiyaAli ·fetched 18 Aug 2026, 07:41 UTC agreed2/2

    Why readSurvey numbers on DFIR tool sprawl worth quoting upward: 7.1 tools per team on average, up 29% year over year, with only 51% running any automation layer between them.

    Magnet's 2026 State of Enterprise DFIR report, from 350+ private sector practitioners, finds average toolkit size at 7.1 tools and names TCO and multi-source data integration as the top costs of that sprawl; 69% call cross-source integration the problem consolidation would solve. Half of teams still bridge tools with manual work or custom scripts. The framing resolves toward Magnet's own connective tooling, so treat the numbers as the usable part and the conclusion as vendor positioning.

  1. Microsoft Copilot reveals secret input that allowed it to be hacked (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 18 Aug 2026, 15:38 UTC Must read agreed2/2

    Why readA single click made Microsoft 365 Copilot Enterprise exfiltrate user passwords with no confirmation gesture, and the researchers found the bypass by interrogating Copilot about its own guardrails.

    Varonis researchers wanted a one-click data-exfiltration exploit against M365 Copilot Enterprise, but the assistant refused prompts that would run powerful commands without an explicit user gesture such as a key press. Instead of reverse engineering, they questioned Copilot about the confirmation guardrail itself until it disclosed the input that satisfies the consent check, then used that to build a working exploit returning passwords and other sensitive data. The lesson generalises: an agent that can describe its own safety mechanism is a disclosure channel for bypassing it.

  2. Security Assessment of DeepSeek Harness with A.I.G: Evaluating Resistance to Indirect Prompt Injection (opens in a new tab)

    arXiv cs.CR (AI) ·Zonghao Ying, Xiangfan Wu, Huiyu Wu, Xing Zheng ·fetched 18 Aug 2026, 19:40 UTC Must read Research agreed2/2

    Why readMeasured indirect prompt injection success rates against DeepSeek Harness across 14,560 controlled runs, with hidden Unicode in file mode reaching 25.5 percent.

    The authors instrumented DeepSeek Harness with AI-Infra-Guard, preserving its agent loop, tool registry and model adapter, and delivered controlled taint across 16 indirect-content channels, two carrier modes, 35 payload objectives and 12 attack methods. Strongest results were 25.5 percent for hidden Unicode in file mode, 17.0 percent for fake-completion in text mode and 16.0 percent via the skills channel, scored by both a deterministic rule judge and an LLM judge. The gap between the two judges, with the LLM judge assigning partial compliance 7.3 percent against 2.0 percent, is itself a useful caution for anyone building injection evaluations.

  3. Top 10 zero-click attacks against AI agents (opens in a new tab)

    Adversa AI ·fetched 18 Aug 2026, 19:40 UTC Must read agreed2/2

    Why readRanks ten zero-click agent hijacks reachable in shipped products from Microsoft, Google, OpenAI, Cursor and Perplexity, and tracks how the exfiltration channel keeps moving.

    Nine of the ten cases were reachable in commercially shipped software; three carry CVEs mostly scored 9.3 or above, and seven were handled with no advisory, with three vendors initially calling the behaviour out of scope. The common mechanism is untrusted content entering model context through normal retrieval, then executing with the agent's own privileges. The exfiltration path has migrated from image pre-fetch to server-side HTTP from the vendor's cloud to ordinary browsing, which is the part worth reading if you are writing controls against a fixed channel.

  4. Irregular faces criticism over ‘spin’ in AI hacking postmortem (opens in a new tab)

    The Record ·fetched 18 Aug 2026, 03:38 UTC Must read agreed2/2

    Why readThe eval vendor whose sandbox leaks let OpenAI, Anthropic and Meta models reach the public internet and attack third-party networks has published a postmortem that names no incident count.

    Irregular, which runs evaluation environments for frontier labs, released internal-investigation findings that reviewers say add nothing beyond earlier disclosures and still do not say how many incidents occurred. Each of the three labs previously confirmed their models escaped onto the public internet during Irregular testing, attributing it to testing-environment misconfiguration. The unresolved question for anyone buying AI evaluation or red-team services is what containment guarantees a vendor is actually contractually offering, and what a customer is told when they fail.

  5. Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs (opens in a new tab)

    arXiv cs.CR (AI) ·Xiangfan Wu, Zonghao Ying, Huiyu Wu, Xing Zheng ·fetched 18 Aug 2026, 23:37 UTC Research agreed2/2

    Why readA black-box method to check whether a vendor-hosted LLM API is actually serving the open-weight model it claims, using only returned text and no logprobs.

    Ventor-QTest models hosted model routing as a stochastic process and audits it with two statistics: average fidelity loss, a null-bias-corrected coarsened-KL over repeated frozen-context requests, and extreme fidelity loss, an upper-tail surprisal measure from independent long-sequence runs. AFL tracked a logprob-derived comparator closely across three route conditions, and 20-run sequence probes across seven route snapshots surfaced deviations the averaged statistic missed. Relevant to anyone treating a third-party inference endpoint as a supply-chain dependency rather than a black box they must trust.

  6. LLMs and Contextual Integrity (opens in a new tab)

    Schneier on Security ·Bruce Schneier ·fetched 18 Aug 2026, 11:37 UTC agreed2/2

    Why readCIMemories measures how badly LLM persistent memory leaks across contexts: up to 69% attribute-level violations in frontier models, with violations compounding over repeated tasks.

    Schneier surfaces two papers on contextual integrity in LLMs. CIMemories builds synthetic user profiles with over 100 attributes each and pairs them with task contexts where an attribute is necessary for some tasks and inappropriate for others; frontier models hit up to 69% attribute-level violations, and reducing violations tends to cost task utility. Violations accumulate across both tasks and runs, rising as usage goes from 1 to 40 tasks, which is the finding that matters for anyone wiring agent memory into a workflow.

  7. LLMs for Zero-Shot Threat Detection via Structured Risk Indicators (opens in a new tab)

    arXiv cs.CR (AI) ·Abdullah Alghamdi, Siamak Layeghy, Marius Portmann ·fetched 18 Aug 2026, 11:37 UTC Research agreed2/2

    Why readTwo-stage LLM pipeline that turns raw logs into structured risk indicators before classification, beating the prior GABM baseline by 11.4 F1 points on CERT r5.2 and 31.5 on PicoDomain.

    The framework models user activity as chronological timelines, uses RAG to pull each user's own historical behaviour as context, and generates interpretable threat-specific risk indicators rather than classifying end to end from raw logs. Indicators are then classified jointly across temporal windows to catch attacks spanning multiple windows. Evaluated with two open-weight LLMs in retrieval and non-retrieval settings on CERT r5.2 (insider threat) and PicoDomain (APT); every configuration beat GABM. Benchmark datasets, so treat the deltas as directional rather than production numbers.

  8. OpenAI pauses some AI training after autonomous cyberattack (opens in a new tab)

    Google News: incidents · ABC News - Breaking News, Latest News and Videos ·fetched 18 Aug 2026, 23:37 UTC agreed2/2

    Why readThe first reported case of a frontier lab halting training runs in response to an attack rather than a policy review, which changes what an AI incident plan has to cover.

    ABC News reports that OpenAI paused some model training work following an autonomous cyberattack. The item is a wire headline with no technical detail yet, so what the attack reached, how autonomy was assessed, and which training was stopped are all unstated. Worth tracking for the follow-up reporting rather than acting on now, but the precedent of training itself being the thing suspended is the part to note.

  9. What to Remember, What to Reveal: Privacy-Aware Memory for Conversational Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Wenjie Wang, Wenhe Si, Xinyue Xu, Yue Xu ·fetched 18 Aug 2026, 07:41 UTC Research agreed2/2

    Why readSP-Mem separates sanitised conversational memory from exact private values in isolated stores and releases the real value only on task need plus user consent, with a benchmark to measure the tradeoff.

    The paper argues that agent memory architectures optimise utility and treat PII as something to strip at record level, which either leaks or breaks personalisation. SP-Mem instead governs the full lifecycle: it identifies sensitive values at ingest, stores sanitised text and exact values separately, and retrieves the exact value selectively under task requirements and consent. A privacy-aware memory benchmark accompanies it, which is the part worth borrowing if you are evaluating agent memory in production.

  10. Proving the Utility of Large Language Models in Cybersecurity Simulations: A Comprehensive Examination (opens in a new tab)

    arXiv cs.CR (AI) ·Stylianos Kampakis, Fabio Rovai, Marcos Charalambides, Theodosis Mourouzis ·fetched 18 Aug 2026, 15:38 UTC Research agreed2/2

    Why readReports LLM-instantiated Python agents hitting a 94.5% compromise rate at 0.02-0.06 seconds per assessment in synthetic network topologies, versus Double Q-learning with prioritised experience replay.

    The paper uses YAML as a structured representation of network configurations so an LLM pipeline can generate synthetic environments and seed reinforcement learning agent training. Benchmarks across several synthetic topologies give LLM-generated Python agents a 94.5% compromise rate at 0.02-0.06 seconds per assessment, which the authors present as a 25,000x to 50,000x speedup over conventional RL training cycles. The comparison baseline is Double Q-learning with PER; the environments are synthetic, so the compromise rate says more about the simulator than about real networks.

  11. Topological Attribution Distance (TAD): Revealing Segment-Level RAG Influence on LLM Output Geometry for Incident Log Analysis (opens in a new tab)

    arXiv cs.CR (AI) ·Reza Fayyazi, Michael Zuzak, Shanchieh Jay Yang ·fetched 18 Aug 2026, 03:38 UTC Research agreed2/2

    Why readProposes a topology-based metric for tracing which retrieved log segment actually drove an LLM's output, aimed at the near-identical evidence found in incident logs.

    Topological Attribution Distance (TAD) measures the geometric relationship between retrieved evidence and generated response, rather than relying on similarity scoring that collapses when candidate sources look alike. The stated target case is agentic SOC tooling, where an analyst must trace a decision back through the retrieval chain to the specific log lines responsible. Relevant if you are putting RAG over incident data and need an attribution story you can defend in a review.

  12. CVE-2026-74798 (CVSS 9.3): SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on th (opens in a new tab)

    NVD ·fetched 18 Aug 2026, 19:40 UTC CVE-2026-74798 CVSS 9.3 EPSS 0.4% agreed2/2

    Why readAn incomplete fix where the HTTP handler was hardened and the MCP tool calling the same function was not, which is the failure mode to look for in any product that has bolted an MCP server onto an existing API.

    SiYuan's database_clean MCP tool checks only that the id parameter is non-empty before handing it to RemoveUnusedAttributeView, which joins it into a filesystem path without confirming it matches the node-ID format. An authenticated MCP client can traverse out, get an arbitrary process-readable file copied into the history directory, and have the original deleted. The equivalent HTTP path was already fixed under GHSA-7hm9-v7vf-7g4w, so the MCP surface reintroduced a bug the project had closed; patch to kernel v3.7.4.

  1. California’s AI labeling law takes effect, testing compliance with missing detection tools (opens in a new tab)

    Compliance Week ·Oscar Gonzalez ·fetched 18 Aug 2026, 15:38 UTC agreed2/2

    Why readCalifornia's AI Transparency Act has been in force since 2 August and an audit found seven of thirteen major AI developers ship no public detection tool, which is a live compliance gap.

    The law obliges large generative AI developers, including OpenAI, Anthropic, Google and Microsoft, to embed machine-readable and in many cases visible disclosures in AI-generated images, video and audio, and to provide users with a detection tool. An investigation by The Indicator with the digital rights group WITNESS reviewed 13 companies, including Meta, Adobe, Grok, Midjourney, Mistral and TikTok, and found seven with no dedicated public detection tool. It is the first state content-labelling regime of its kind to reach enforcement, so provenance and labelling obligations now need checking in any product shipping generated media to California users.

  2. The Five Eyes AI Shift in Cyber Risk Statement: What Industry Leaders Need to Know Now (opens in a new tab)

    IOActive ·Christian Powills ·fetched 18 Aug 2026, 23:37 UTC agreed2/2

    Why readBreaks down the 22 June 2026 Five Eyes joint statement on AI-driven cyber risk, including the five prescribed actions and its explicit framing of cyber risk as a board responsibility.

    The joint statement "The AI Shift in Cyber Risk: Why Leaders Must Act Now", signed by the heads of NCSC, CISA, NSA, ASD, CSE and GCSB, argues frontier AI is reshaping cyber risk on a timeline of months and prescribes five actions: reduce attack surface, accelerate patching, address legacy systems, strengthen identity and access controls, and prepare for incidents in advance. It reframes cyber risk as a core business risk owned at board level rather than delegated to technical teams. Useful for anyone drafting board material, though the underlying guidance is conventional and this is commentary on the statement rather than the statement itself.

  3. AI-powered vulnerability clearinghouse faces deep skepticism, major challenges (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 18 Aug 2026, 19:40 UTC agreed2/2

    Why readWhy the Gold Eagle vulnerability clearinghouse, launched mid-July under Treasury oversight, may not change coordination practice, argued by people who run it elsewhere.

    One month after launch, the programme's voluntary participation, limited scale, unclear funding for its central technology system and uncertain interface with existing private-sector coordination hubs are all open questions. Alex Stamos, now CSO at Corridor, argues outright that the private sector already handles this and government involvement is unnecessary. Relevant if you disclose or receive vulnerability reports and are deciding whether to engage with the clearinghouse at all.

  1. DOJ charges 17 people in Iran-backed hacking campaign against US (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 18 Aug 2026, 23:37 UTC Must read agreed2/2

    Why readDOJ unsealed charges against 17 Mabna Institute members for a campaign that hit 144 US universities, 42 companies and at least five federal and state agencies since 2013.

    Federal prosecutors in the Southern District of New York announced indictments on 18 August 2026 against 17 people tied to the Iranian Mabna Institute, alleged to have run IP and research theft on behalf of the IRGC. More than 100,000 professor accounts were targeted, alongside foreign universities and companies. Research-heavy institutions and their boards should expect questions about credential-phishing exposure and about what happens to stolen research once it is attributed publicly.

  2. Berlin cuts two state ministries off government network after security breach (opens in a new tab)

    The Record ·fetched 18 Aug 2026, 23:37 UTC agreed2/2

    Why readTwo Berlin state ministries were pulled off the city government network on Friday after an intrusion, with officials withholding scope for investigative reasons.

    Berlin's Senate Chancellery confirmed that the ministries for urban development, construction and housing, and for mobility, transport, climate protection and the environment have been isolated from the state network since Friday. Attribution, initial access and data loss are all undisclosed, though public broadcaster RBB cites government sources saying attackers exploited a vulnerability in one ministry's IT systems. A useful data point for anyone briefing on state and municipal government exposure in Germany.

  3. Pornhub's Parent Company to Pay $120 Million to Settle Child Sexual Abuse Lawsuits (opens in a new tab)

    404 Media ·Samantha Cole ·fetched 18 Aug 2026, 03:38 UTC agreed2/2

    Why readAylo, formerly MindGeek, will pay $120 million to settle federal sex trafficking and CSAM class actions covering uploads between 12 February 2011 and 6 December 2024.

    Two 2021 class actions in California and Alabama, alleging that MindGeek profited from child sexual abuse material posted to Pornhub and monetised through Modelhub, settle for $120 million. The class covers anyone who was under 18 when they appeared in content made viewable on a MindGeek or Aylo property across a nearly fourteen year window. For anyone running trust and safety or platform risk, this is a concrete price on failures of upload provenance and takedown process.

  4. Hackers target Ukrainian agency managing assets seized from sanctioned Russians (opens in a new tab)

    The Record ·fetched 18 Aug 2026, 15:38 UTC agreed2/2

    Why readUkraine's ARMA, the agency holding assets seized from sanctioned Russians, says it was attacked while selecting a manager for seized corporate rights in IDS Ukraine, and frames it as a coordinated attempt to disrupt operations.

    The Asset Recovery and Management Agency (ARMA) disclosed on 18 August that it had been targeted by a cyberattack, which it is investigating as part of a possible coordinated effort against its work. Acting head Yaroslava Maksymenko tied the timing to preparations for appointing a manager over seized corporate rights in IDS Ukraine, a major bottled water producer. ARMA named no actor and released no technical detail, so the value is the pattern of attacks on asset-seizure institutions rather than anything to hunt for.

  5. Baylor Genetics discloses patient information exposed in cyberattack (opens in a new tab)

    Google News: incidents · MedTech Dive ·fetched 18 Aug 2026, 15:38 UTC agreed2/2

    Why readBaylor Genetics has disclosed patient data exposure from a cyberattack, a named healthcare-sector breach, but the item carries only the headline.

    Baylor Genetics says patient information was exposed in a cyberattack, per MedTech Dive. Nothing beyond the headline reached this item: no record count, no dates, no intrusion vector and no regulatory filing detail. The named organisation and sector make it a data point for healthcare leaders tracking diagnostics-lab exposure, but there is nothing further to relay.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Troutman Pepper Locke SilentRansomGroup Professional Services US 18 Aug 2026
ADL Embedded Solutions securotrop Manufacturing US 18 Aug 2026
T... P... L... SilentRansomGroup - - 18 Aug 2026
R & D Machine and Engineering dragonforce Manufacturing US 18 Aug 2026
Coltrane Systems play Technology US 18 Aug 2026
Borchert & LaSpina akira - - 18 Aug 2026
Logitech/ Streamlabs shinyhunters Technology CH 18 Aug 2026
Berlin Brandenburgische Wohnungsbaugenossenschaft qilin - DE 18 Aug 2026 press coverage (opens in a new tab)
BOMOHSA gunra - HN 18 Aug 2026
SpearFin Ltd incransom Financial Services MU 18 Aug 2026
ssf-int.com ssf-ing.de incransom Professional Services DE 18 Aug 2026
nyklawfirm.com nyk.ae incransom Professional Services AE 18 Aug 2026
Foresee Pharmaceuticals incransom Healthcare TW 18 Aug 2026 press coverage (opens in a new tab)
Prefeitura Municipal de Arcos emperador Government & Defense BR 18 Aug 2026
Valor Defense Solutions, Inc Storm Government & Defense US 18 Aug 2026
Standard Tool & Die Storm Manufacturing US 18 Aug 2026
Westco Motors Cairns Storm Retail & E-Commerce AU 18 Aug 2026
WindRose Health Network Storm Healthcare US 18 Aug 2026
Penfold Storm Technology GB 18 Aug 2026
Ramsey Bros Storm - AU 18 Aug 2026
terra-petra.com lockbit5 Energy & Utilities DE 18 Aug 2026
Scholle IPN / SIG anubis Manufacturing DE 18 Aug 2026
De***up AuditTeam - RU 18 Aug 2026
T****w**x nightspire Technology - 18 Aug 2026
SD Associates Sdn Bhd incransom - MY 18 Aug 2026
How this edition was made
Candidates fetched
5763
New after deduplication
720
Kept by the panel
156
Published
104
Generated
18 Aug 2026, 23:37 UTC