CFToday Curated security signals.

Daily edition · 2026-08-25

Tuesday, 25 August 2026

42 items across 8 sections, selected from 5708 candidates over 6 runs. 103 carried the panel unanimously.

Show
Section

  1. Balonx Sistema: The Face Behind the PhaaS Impacting Mexican Banking (opens in a new tab)

    translated Balonx Sistema: El Rostro Detrás del PhaaS que Impacta la Banca Mexicana

    Group-IB ·fetched 25 Aug 2026, 15:38 UTC Must read Research agreed2/2

    Why readNames the operator behind Balonx Sistema, a subscription PhaaS platform hitting more than 20 Mexican financial institutions with real-time phishing, AI vishing and a mobile RAT.

    Group-IB attributes the Balonx Sistema phishing-as-a-service platform to a Mexico-based operator and documents capabilities well beyond static phishing kits: real-time credential relay, AI-assisted vishing, and a remote access trojan for mobile devices. More than 20 Mexican financial institutions are targeted under a subscription model, placing Mexico second only to Brazil for banking malware incidents in the region in 2025. Useful for fraud and threat teams tracking LATAM banking operations, and for anyone modelling how commoditised PhaaS lowers the bar for mobile-first bank fraud.

    Indicators5
    URLs
    hxxps://phishing-domain[.]xyz/12345”
    Addresses
    17[.]0[.]4[.]31 85[.]31[.]235[.]109
    Domains
    callbalonx[.]info panelbalonxfs[.]xyz
  2. 58 arrested in international cybercrime crackdown (opens in a new tab)

    The Record ·fetched 25 Aug 2026, 23:39 UTC agreed2/2

    Why readConcrete numbers on the West African fraud economy, including a 196-person crime-as-a-service outfit in Argentina that rented domains and laundering to Black Axe.

    The latest leg of Interpol's Operation Jackal ran eight months across 22 countries and ended with 58 arrests plus hundreds of further suspects identified, with actions concentrated in Italy, Argentina, South Africa and Romania. The notable disclosure is structural: investigators traced financial flows to a dedicated service provider supplying infrastructure and money laundering to organised fraud groups, rather than to the fraud crews themselves. That layer is the durable part of the ecosystem, and arrests of fraud operators have historically not touched it.

  1. Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 25 Aug 2026, 07:37 UTC Must read CVE-2026-21962 EPSS 43.2% agreed2/2

    Why readCVE-2026-21962, the CVSS 10.0 Oracle HTTP Server and WebLogic Server Proxy Plug-in access control bug, is now in CISA KEV with confirmed exploitation and a federal patch deadline.

    CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after multiple reports of in-the-wild abuse. The improper access control flaw lets an unauthenticated attacker over HTTP read, create, delete or modify data reachable by Oracle HTTP Server and the WebLogic Server Proxy Plug-in. Oracle patched it in the January release, so the action is finding unpatched proxy tiers rather than waiting on a fix; EPSS sits at 0.43, in the 98.6th percentile.

    Indicators1
    Addresses
    193[.]24[.]123[.]42

    Also covered bySecurity Affairs (opens in a new tab),The Register Security (opens in a new tab),Cybersecurity News (opens in a new tab),SecurityWeek (opens in a new tab).

  2. CVE-2026-60004: Gitea Gitea, Gitea Code Injection Vulnerability (opens in a new tab)

    CISA KEV ·fetched 25 Aug 2026, 19:39 UTC Must read CVE-2026-60004 Exploited in the wild · patch by 2026-08-28 agreed2/2

    Why readGitea code injection is in KEV with a 2026-08-28 federal deadline: a malicious patch to the diffpatch API plants a Git hook and runs shell as the Gitea service account.

    CVE-2026-60004 lets any user with repository write access post a crafted patch to Gitea's diffpatch endpoint, writing an executable Git hook that executes shell commands as the Gitea service account. CISA added it to KEV with a remediation due date of 2026-08-28 under BOD 26-04, so exploitation is confirmed. Self-hosted Gitea instances that accept external contributors are the obvious blast radius; patch or restrict write access, and treat hook directories as an artefact to check.

  3. CISA orders agencies to fix exploited Zimbra vulnerability (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 25 Aug 2026, 23:39 UTC agreed2/2

    Why readCVE-2026-73570 in Zimbra Collaboration Suite is in KEV with a three-day federal deadline that has already passed; exploitation gives broad platform access via crafted SMTP.

    Zimbra fails to sanitise untrusted input from a notification add-on package, letting an attacker send malicious SMTP requests that impersonate users and perform unauthorised actions across the platform. Synacor disclosed on 26 June but did not ship a fix until 20 July, and the Polish government reported in-the-wild exploitation by mid-August. Thousands of organisations run Zimbra, and the patched version is the only mitigation named.

    Also covered byDark Reading (opens in a new tab),Help Net Security (opens in a new tab).

  4. Researchers warn about chained SharePoint sequence (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 25 Aug 2026, 19:39 UTC agreed2/2

    Why readChains CVE-2026-55040 (SharePoint auth bypass, already exploited) with CVE-2026-63520 improper input validation to reach unauthenticated remote code execution on-premises.

    VulnCheck researchers show that the SharePoint authentication bypass CVE-2026-55040, on its own low impact, becomes unauthenticated RCE when chained with the improper input validation flaw CVE-2026-63520. Rapid7 published a proof of concept for the bypass on 11 August and exploitation of it was confirmed days later. On-premises SharePoint has been repeatedly targeted this year, so treat both CVEs as one patch item and hunt on the servers rather than waiting for the chain to be seen in the wild.

  5. Hackers target WordPress sites in miniOrange auth bypass attacks (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 25 Aug 2026, 03:37 UTC agreed2/2

    Why readTwo chained auth bypasses in the miniOrange SAML SSO WordPress plugin are under active exploitation and let an attacker forge SAML responses to log in as admin.

    CVE-2026-61979 and CVE-2026-15981 are being exploited together against the miniOrange SAML 2.0 Single Sign On plugin. The root cause is that the plugin honours the signature algorithm declared in the incoming SAML response rather than the configured one, so an attacker selects HMAC-SHA1 and the plugin then treats the identity provider's public RSA key, which is public, as the shared HMAC secret. Sites federating WordPress logins to Entra ID, Okta, Google Workspace or OneLogin through this plugin should patch and audit administrator sessions now.

    Also covered byThe Hacker News (opens in a new tab),SecurityWeek (opens in a new tab),NVD (opens in a new tab).

  6. CVE-2026-59568 (CVSS 9.1): Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user th (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 19:39 UTC CVE-2026-59568 CVSS 9.1 EPSS 0.4% agreed2/2

    Why readUnauthenticated remote code execution in the Zscaler Client Connector agent, which sits on every managed endpoint in a ZTNA rollout.

    Multiple flaws in affected Zscaler Client Connector versions allow an unauthenticated, unprivileged user to execute arbitrary code in the ZCC context, rated CVSS 3.1 9.1 with high confidentiality and integrity impact. Fixed versions are listed in Zscaler's Client Connector app release summary for 2026, and CISA's SSVC entry marks the issue automatable with total technical impact. EPSS is still low at 0.004 with no public exploit noted, but the agent runs broadly across managed fleets, so this belongs in this week's patch cycle.

  7. CVE-2026-76848 (CVSS 8.7): TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family driv (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 19:39 UTC Research CVE-2026-76848 CVSS 8.7 EPSS 0.4% agreed2/2

    Why readSQL injection in TypeORM's SelectQueryBuilder.distinctOn, with the exact function and file where the values are interpolated unescaped.

    createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins the distinctOn array and drops it straight into SELECT DISTINCT ON (...) with no escaping, quoting, identifier validation or allowlist, and without passing through replacePropertyNames or the driver's escape helper. Because the injection point is a parenthesized expression list rather than an identifier-only position, an element can carry arbitrary expressions including correlated subqueries, giving a client-controlled read of anything the application's database role can reach via boolean or time-based inference. validateOrderByCondition, the allowlist that guards orderBy in the same class, is never applied here, so any app that lets a caller pick a deduplication column is exposed on PostgreSQL-family drivers.

  8. CVE-2026-10053 (CVSS 8.5): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under c (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 15:38 UTC CVE-2026-10053 CVSS 8.5 EPSS 0.7% agreed2/2

    Why readAuthenticated path traversal in the GitLab package registry gives remote code execution on self-managed instances across 18.8 up to 19.2.2.

    GitLab patched CVE-2026-10053, a path traversal in the package registry that under some conditions let an authenticated user reach remote code execution. Affected: all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2. CVSS 8.5 with a changed scope, no known exploitation yet, but any developer account on a self-hosted instance is a viable starting point, so treat registry-enabled instances as priority patches.

  9. CVE-2026-78306 (CVSS 8.5): DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuratio (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 19:39 UTC Research CVE-2026-78306 CVSS 8.5 EPSS 0.1% agreed2/2

    Why readAn unauthenticated DUML command interface over Bluetooth lets anyone in range rewrite a DJI drone's Wi-Fi PSK and then reach the flight control interface.

    DJI drones accept unauthenticated DUML commands over Bluetooth that modify SSID, PSK, MAC address, regulatory country code and channel. Overwriting the PSK with a known value lets an attacker in Bluetooth range join the drone's internal Wi-Fi and issue flight commands, and crafted commands can also restart or disable the radios to cut control, video and telemetry mid-flight. Affected firmware is listed per model, including Neo before 01.00.0400, Flip before 01.00.1200, Air 3 before 01.00.1600, Mavic 3 Pro before 01.01.0700 and Mavic 4 Pro before 01.00.0500.

  10. Siemens SIMATIC IoT2050 Advanced (opens in a new tab)

    CISA Advisories ·CISA ·fetched 25 Aug 2026, 19:39 UTC CVE-2026-58115 EPSS 0.7% agreed2/2

    Why readCVSS 10 missing authentication on the Node-RED HTTP interface of Siemens SIMATIC IoT2050 Advanced gives unauthenticated remote code execution at maximum privilege; fixed in 4.3.4.1.

    CVE-2026-58115 affects SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) running Industrial OS with Node-RED below version 4.3.4.1. The Node-RED HTTP interface does not enforce authentication, so anyone who can reach it can create flows and execute arbitrary code on the host with full privileges. Siemens has shipped a fixed version; these devices sit in chemical, manufacturing, energy and transport environments, so reachability from anything but a tightly segmented network is the immediate question.

  11. CVE-2026-66897 (CVSS 9.9): A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a craft (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 19:39 UTC CVE-2026-66897 CVSS 9.9 EPSS 0.6% agreed2/2

    Why readLXD validates template paths against a confined os.Root handle but then writes with os.Create on the unconfined string, so a crafted image metadata.yaml overwrites root-owned host files.

    CVE-2026-66897 is a check-then-use mismatch in LXD instance template processing: target paths from metadata.yaml are validated inside an os.Root directory handle, then opened via os.Create using the raw path, defeating the confinement. An attacker with container edit permissions, or any user who launches a crafted image, can overwrite arbitrary host files as root and reach host code execution. CVSS 9.8 with scope change and EPSS 0.006; the pattern itself is worth noting for anyone auditing Go code that mixes os.Root checks with plain path opens.

  12. CVE-2026-78167 (CVSS 9.3): A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 23:39 UTC CVE-2026-78167 CVSS 9.3 EPSS 1.0% agreed2/2

    Why readPublic exploit code exists for an authentication bypass in EFM ipTIME T16000M firmware 14.20.2, and the vendor never responded to disclosure, so there is no fix to apply.

    CVE-2026-78167 is an improper authentication flaw in httpcon_check_session_url, part of the session validation handler on the ipTIME T16000M running 14.20.2, exploitable remotely and rated CVSS 4.0 9.3 with E:P set for a published exploit. ipTIME routers are ubiquitous in South Korean homes and small offices, and the reporter states the vendor was contacted early and did not reply. With working exploit code out and no patch in sight, mitigation means removing WAN-side management exposure rather than upgrading.

  1. What's in a tag name? JavaScript, apparently (opens in a new tab)

    PortSwigger Research ·fetched 25 Aug 2026, 15:38 UTC Must read Research agreed2/2

    Why readNew XSS vector class that turns the tag name itself into executable JavaScript via localName, bypassing WAFs in every browser.

    An element's own tag name can be read back through localName and fed into an event handler, so `<JAVASCRIPT:ALERT(1) onfocus=location=localName autofocus tabindex=1>` executes without the payload ever appearing in a normal script context. Fuzzing tag-name transformations showed alphabetic characters, slashes, whitespace and newlines get normalised, while line and paragraph separator characters survive and are treated as newlines by JavaScript, enabling vectors that look like malformed markup. Variants using attributes[0].value, textContent and nodeValue give fallbacks when one property is filtered, which makes signature-based WAF rules on payload strings unreliable.

  1. A Tale of Two SOCs: Insights From Two Red Team Assessments (opens in a new tab)

    CISA Advisories ·CISA ·fetched 25 Aug 2026, 15:38 UTC Must read agreed2/2

    Why readCISA's side-by-side account of two red team engagements where both orgs fell to full domain compromise but only one detected it, with the specific detection gaps that made the difference.

    CISA ran simultaneous red team assessments at two critical infrastructure organisations and reached full domain compromise, sensitive business systems and cloud resources in both. Organization A neither detected nor contained the activity; Organization B caught initial compromise attempts, isolated the affected hosts and forced the team into an assume-breach posture. The lessons learned centre on untuned detection tooling: without defined baselines and alert filtering, routine alerts and false positives buried the real activity, and the advisory pairs each observed behaviour with mitigations across IT, cloud and OT.

  2. Threat Hunting using Pair Probabilities (opens in a new tab)

    detect.fyi ·Stamatis Chatzimangou ·fetched 25 Aug 2026, 11:41 UTC Must read agreed2/2

    Why readRepurposes Microsoft Sentinel's built-in KQL function pair_probabilities_fl() into a rarity-scoring hunt technique for categorical pairs such as user and process or host and parent-child pairs.

    Sentinel ships a user-defined KQL function, pair_probabilities_fl(), that computes joint, marginal and conditional probabilities plus lift for two categorical columns within a scope. The post walks the function body (materialize, summarize by _A/_B/_scope, joins back to per-scope counts) and reworks it into a hunting primitive for surfacing statistically rare pairings rather than relying on static allowlists. Directly usable by anyone running KQL against Defender or Sentinel data.

  3. Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th) (opens in a new tab)

    SANS ISC Diary ·fetched 25 Aug 2026, 15:38 UTC agreed2/2

    Why readShows why string blocklists for 169.254.169.254 fail, with the exact wildcard DNS and rebinding hostnames attackers are sending at SSRF filters right now.

    Following up on scans for the cloud metadata endpoint, ISC documents reader-reported cases where attackers replaced the literal 169.254.169.254 with wildcard DNS forms such as 169.254.169.254.nip.io, 169-254-169-254.sslip.io, and arbitrary-prefix variants. One observed host, make-1.1.1.1-rebind-169.254.169.254-rr.1u.ms, points at the 1u.ms service, which mints hostnames on demand and can flip the resolved address after the first lookup to defeat validate-then-fetch code. The practical conclusion is that SSRF defenses must validate the resolved address at connection time, ideally with a deny-by-default egress policy, rather than pattern matching the supplied URL.

  4. RAD: Rule-Augmented Relational Anomaly Detection (opens in a new tab)

    arXiv cs.CR (all) ·Noah Dahle, Anne Tumlin, Ngoc Tran, Xenofon Koutsoukos ·fetched 25 Aug 2026, 11:41 UTC Research agreed2/2

    Why readMethod for anomaly detection over multi-table relational data without flattening, so entity identity and multi-hop dependencies survive into the model.

    RAD combines heterogeneous graph representation learning with symbolic rule signals: candidate rules are derived from random-forest paths over flattened entity summaries, refined into compact interpretable predicates, then injected as features into the graph model. The pitch is detecting anomalies that depend on relational context rather than isolated feature values, with interpretability from the rule layer. The abstract carries no security-specific evaluation, so treat it as technique reading for detection teams working over relational log stores rather than a deployable detector.

  5. Adapter-Based Few-Shot Continual Learning for Malicious Packet Recognition (opens in a new tab)

    arXiv cs.CR (all) ·Kyle Stein, Guillermo Francia, III Eman El-Sheikh, Andrew Arash Mahyari ·fetched 25 Aug 2026, 07:37 UTC Research agreed2/2

    Why readShows a way to teach a packet classifier a new malware family from a handful of labelled samples without wrecking what it already detects, which is the practical failure mode of ML detection in production.

    The authors target few-shot class-incremental learning for malicious traffic classification: a self-supervised backbone pre-trained on malware packets, LoRA adapters for the base session, and a frozen core plus prototype-based head for later increments. The design goal is avoiding catastrophic forgetting, the reason most deployed ML detectors need full retraining every time a family appears. It is a clean formulation of a real operational constraint, but the evaluation is benchmark-bound with no evidence about false positive behaviour on live traffic, so treat it as a direction rather than something to adopt.

DFIR

2
  1. A Cautionary Tale About Data Breach Claims, Verification and Carhartt (opens in a new tab)

    Troy Hunt ·Troy Hunt ·fetched 25 Aug 2026, 23:39 UTC Must read agreed2/2

    Why readWalks the actual verification workflow for a criminal breach claim, using ShinyHunters' alleged 50GB Carhartt dump as the worked example of a claim that did not hold up.

    Hunt describes the HIBP intake process: run the open-source Email Address Extractor over the corpus, get a unique address count, and use that count to prioritise processing before anything is loaded. Applied to the Carhartt data circulated after the 13 August ShinyHunters claim, the corpus did not match what was advertised. The transferable point is that attacker claims, and the alert accounts that amplify them, are unverified assertions and the corpus itself is the only evidence worth acting on.

    Indicators1
    Hashes
    004cab9722d948ae956d10ce31e7ed74
  2. Between Two Nerds: Attribution is dead, long live attribution (opens in a new tab)

    Risky Business News ·fetched 25 Aug 2026, 07:37 UTC agreed2/2

    Why readA conversational argument that the behavioural tells attribution rests on, tooling habits, working hours, operator sloppiness, get washed out when the intrusion is driven by a model rather than a person.

    Tom Uren and The Grugq work through whether AI-assisted intrusion tradecraft breaks attribution, given that much of the discipline depends on human fingerprints: reused tooling, code style, timezone patterns and mistakes. Their reference points are the old Phrack anti-forensics canon, which is a reminder that deliberate attribution defeat predates AI by two decades and mostly failed because operators are lazy, not because the techniques were weak. Useful framing for anyone who owns attribution language in incident reports, but it is opinion rather than casework, and there is no new data behind it.

  1. InjecMEM: Memory Injection Attack on LLM Agent Memory Systems (opens in a new tab)

    arXiv cs.CR (AI) ·Hanling Tian, Gengyu Zhang, Zeyang Sha, Jingying Wang ·fetched 25 Aug 2026, 07:37 UTC Must read Research agreed2/2

    Why readShows that a single benign-looking interaction can poison an LLM agent's persistent memory and steer all later answers on a chosen topic, with no write access to the memory store.

    InjecMEM attacks the retrieve-then-generate loop of agent memory systems by planting one record containing a retriever-agnostic anchor (high-recall topical cues that guarantee retrieval on the target topic) plus a short adversarial command optimised via gradient-based coordinate search. The command is trained across synthetic prompt templates and insertion positions so it survives variable placement in long fused contexts, and joint optimisation across backbones is used to measure transfer. The consequence for anyone shipping agents with persistent memory: memory writes are an untrusted input path, and retrieval, not just the prompt, needs provenance controls.

  2. When "Do Not" Is Not Deny: Security Rules in CLAUDE.md vs Built-In Controls (opens in a new tab)

    arXiv cs.CR (AI) ·Ting Yan ·fetched 25 Aug 2026, 03:37 UTC Must read Research agreed2/2

    Why readMeasures how often a security rule written in CLAUDE.md actually corresponds to an enforceable Claude Code deny control: about 4.4% under the strictest matching.

    Across 481 public CLAUDE.md files, extracted security rules were matched against Claude Code's documented built-in controls by an LLM and independently checked by two security practitioners; only 4-16% of retrieved rules had a matching enforceable control, 4.4% (95% CI 2.6-6.7%) under the strictest standard. Manual review put the extraction method's recall at 66.3% of eligible rules, so the rates apply to what it captured. The argument for practitioners is that CLAUDE.md is a write-only channel: a developer writes a prohibition, receives no feedback on whether anything enforces it, and ends up with policy that only exists as a suggestion to the model.

  3. The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution (opens in a new tab)

    Unit 42 ·Sara McBroom ·fetched 25 Aug 2026, 11:41 UTC Must read agreed2/2

    Why readOf 405 AI-enabled malware samples collected, only 12 ever appeared on protected endpoints and roughly 97% exist only in sandboxes and on VirusTotal.

    Unit 42 assembled 405 malware samples that integrate AI in some form, spanning brand impersonation, LLM-generated code and agentic execution loops, then checked them against production telemetry. The gap is the finding: 12 samples reached Cortex XDR-protected endpoints and the rest are proof of concept code, security validation tests and researcher submissions that never touched a real environment. A useful counterweight to the AI malware narrative, with the caveat that the telemetry and the clean block rate both come from the vendor's own products.

    Indicators12
    Hashes
    1619bcad3785be31ac2fdee0ab91392d08d9392032246e42673c3cb8964d4cb7 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac 66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22 b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb 20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966 c398b3e06ef860670b9597daed85632834fa961aea87164b8ba8bb2f094a14ef bb932056cae8940742e50b4f2b994a802e703f7bc235e7dd647d085ae2b2baf7 4fb58687a364c3f6d6f7e0ca03654f9dec0f8832a499d61d40b0d424db1b1b14
  4. Adversarial Entropy Inflation Against Gumbel-Based Inference Verification (opens in a new tab)

    arXiv cs.CR (AI) ·Nikita Kezins ·fetched 25 Aug 2026, 11:41 UTC Must read Research agreed2/2

    Why readShows that Gumbel-based inference verification, which claims a 200x slowdown on weight exfiltration, collapses to 60x-118x when the attacker controls the prompt distribution.

    The defense forgives token choices explainable by GPU nondeterminism, and its admissible-token-set size tracks the model's own output entropy. Prompts built to break grammatical and sub-word structure inflate that entropy and roughly double the bits leaked per token, measured across six instruction-tuned models from 1B to 32B parameters and three seeds. The conclusion is operational: jitter-forgiveness thresholds calibrated against benign traffic are unsafe and must be set dynamically against local entropy.

  5. CVE-2026-76841 (CVSS 8.7): Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. S (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 19:39 UTC CVE-2026-76841 CVSS 8.7 EPSS 0.7% agreed2/2

    Why readXinference passes trust_remote_code=True at six loader sites with no way to turn it off before 2.12.0, so anyone with model-launch access gets code execution on the worker.

    The named call sites are RerankModel._get_tokenizer in xinference/model/rerank/core.py, SentenceTransformerRerankModel.load, SentenceTransformerEmbeddingModel.load, FlagEmbeddingModel.load, and PytorchModel._sanitize_model_config and _get_components in xinference/model/llm/transformers/core.py. A caller registering a model of unknown type with an arbitrary path reaches _auto_detect_type and then AutoTokenizer.from_pretrained, which imports and runs Python declared in the model directory's tokenizer_config.json auto_map with worker privileges. Upgrade to 2.12.0, which finally exposes a setting, and treat model-launch permission as equivalent to shell access on anything older.

  6. OWASP Agentic Skills Top 10 explained: the ten agent skill risks, and which to fix first (opens in a new tab)

    Adversa AI ·fetched 25 Aug 2026, 07:37 UTC agreed2/2

    Why readWalks OWASP's new Agentic Skills Top 10 (AST01 to AST10) and explains why SKILL.md files fall between package security and prompt-injection defence.

    OWASP's newest list targets agent skills: reusable bundles of instructions, code and resources, in practice a folder containing a markdown file with frontmatter and bundled scripts, that an agent discovers, loads and executes on its own. The useful observation is the gap it fills: package security assumes a payload you can hash, sign and diff, prompt-injection defence assumes hostile text arriving at runtime as data, while a skill is hostile prose arriving at install time as something the user chose deliberately. The entries are numbered as a pipeline rather than ranked, so the piece takes a position on which to fix first rather than following OWASP's order.

  7. Towards Automated Cyber Threat Intelligence Elicitation in Underground Forums (opens in a new tab)

    arXiv cs.CR (AI) ·Lorenzo Bossi, Federico Saccani, Francesco Panebianco, Antonio Maci ·fetched 25 Aug 2026, 23:39 UTC Research agreed2/2

    Why readAn eleven-agent LLM system that actively baits underground forum users recovered 72.8% of the MITRE ATT&CK techniques in a conversation from the opening post alone.

    DarkBot splits active CTI elicitation across three functional blocks: engagement gating for relevance and safety, ATT&CK-driven question generation, and linguistic style adaptation to pass as a forum regular. Evaluated on 100 CrimeBB conversations, it recovered 72.8% of validated ATT&CK techniques while seeing only the initial post. The framing matters for anyone running human-source CTI: passive scraping is decaying as actors move to closed spaces, and this is the first published attempt to automate the elicitation side.

  8. CVE-2026-76843 (CVSS 8.4): The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.load (opens in a new tab)

    NVD ·fetched 25 Aug 2026, 23:39 UTC Research CVE-2026-76843 CVSS 8.4 EPSS 0.1% agreed2/2

    Why readFlair wheels 0.15.0 and 0.15.1 still ship flair/models/clustering.py with pickle.loads in ClusteringModel.load, so the earlier CVE-2024-10073 record listing 0.15.0 as fixed is wrong for the distributed artifact.

    CVE-2026-76843 documents that the official Flair wheels for 0.15.0 and 0.15.1 retain flair/models/clustering.py, whose ClusteringModel.load returns pickle.loads(joblib.load(str(model_file))) and executes arbitrary Python during model loading. Clustering support was dropped from the documented API in 0.15.0, which is the basis on which CVE-2024-10073 records that version as fixed, but the module remains in the shipped package and is reachable by importing flair.models.clustering directly. The transferable lesson: a fixed-version field asserted from a changelog rather than from the built artifact will lie to your SCA tooling.

  9. The safety penalty: Reclaiming operational sovereignty in the age of AI (opens in a new tab)

    Cisco Talos ·David J. Bianco ·fetched 25 Aug 2026, 11:41 UTC agreed2/2

    Why readArgues SOC teams should instrument model refusal rates as a tracked metric, because frontier-model guardrails block legitimate work like deobfuscating malware or explaining an exploit.

    Bianco names the tradeoff security teams took on by outsourcing SOC reasoning to a handful of hosted frontier models: guardrails tuned for the general public refuse malware analysis and exploit explanation, and that friction is a cost nobody is measuring. The recommendation is concrete enough to argue with, which is monitor refusal rates over time, treat the data as a capability signal, and use it to decide where local or self-hosted models need to carry core processes. Useful for anyone building AI into detection or IR workflows and finding it silently declines the interesting cases.

  10. Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracy (opens in a new tab)

    Elastic Security Labs ·fetched 25 Aug 2026, 15:38 UTC agreed2/2

    Why readReports that adding detection-rule investigation guides, Workday user risk data and 30 days of prior case closure reasons moved AI triage verdict accuracy from 60% to 92% without changing models.

    Elastic's internal SOC ran its own Agent Builder and Workflows stack (version 9.5.1) as the triage layer for production alerts and attributes the accuracy jump to context rather than model choice: the rule's investigation guide, identity risk data pulled from Workday, and the closure reasons from the last 30 days of cases on the same rule, fed back so an agent can see where it previously erred. The argument that feedback on per-rule past verdicts is the highest-value context is one a detection team can test on its own pipeline. It is also a walkthrough of the vendor's own product, so the transferable part is the context-engineering pattern, not the implementation.

  11. FIDES: A Concordance Protocol for LLM-Generated Trading Strategies (opens in a new tab)

    arXiv cs.CR (AI) ·Arther Tian, Alex Ding, Simon Wu, Aaron Chan ·fetched 25 Aug 2026, 19:39 UTC Research agreed2/2

    Why readMeasures the gap between what an LLM says its strategy does, what the code it emits actually does, and what the backtest returns: 32 of 40 strategies claimed to beat buy-and-hold and exactly one did.

    FIDES elicits a natural-language strategy plus a self-contained strategy(df) function from a single model call, runs the code in a sandbox against a lag-one out-of-sample backtest on eight liquid US ETFs across four models, and scores three gaps: say-to-do, do-to-real and say-to-result. Across 40 strategies over 2023 to 2024, only 2 beat buy-and-hold, a plain sma(50,200) rule outperformed every model's mean Sharpe, and model self-assessment was badly calibrated. The relevant lesson outside finance is that an agent's stated rationale, its emitted code and its measured outcome are three separate artefacts, and treating the narration as evidence for the behaviour is a mistake worth designing against.

  12. Robustness of Anomaly Detection Models for Industrial Control Systems under Training-Time Data Contamination (opens in a new tab)

    arXiv cs.CR (all) ·Mustafa Umut Ozbek, Taiwo Ojo, Pooria Madani, Khalil El-Khatib ·fetched 25 Aug 2026, 03:37 UTC Research agreed2/2

    Why readEmpirical evidence that an ICS anomaly detector's clean-data accuracy tells you nothing about how it holds up when its training set has been quietly contaminated.

    The authors run 11 heterogeneous anomaly detectors against the SWaT water treatment benchmark while contaminating the training pool at budgets from 1% to 10%, using random injection, similarity-targeted injection of attack samples, and bounded Gaussian feature noise. Robustness turns out to be strongly model-dependent and uncorrelated with clean-data performance, so benchmark leaderboards are the wrong basis for model selection anywhere training data comes from historians, logs, or automated retraining. The attacks are contamination rather than gradient-driven poisoning, and everything rests on one benchmark, so treat this as a floor on the problem rather than a worst case; the practical takeaway is to add a contamination trial to detector evaluation before deployment.

  1. Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense (opens in a new tab)

    Recorded Future ·fetched 25 Aug 2026, 15:38 UTC agreed2/2

    Why readWalks the components of Mexico's 2025-2030 National Cybersecurity Plan, new legislation, a national operations centre, integrated incident response teams and cyber exercises, and Insikt Group's read that ransomware is the leading threat to it.

    Recorded Future's Insikt Group assesses Mexico's 2025-2030 plan against the threats it must actually absorb: rising ransomware, credential theft and financial malware, hacktivism, cyber-enabled organised crime and state-linked espionage. The plan's mechanisms are governance reform, legislation, a national operations centre, integrated CSIRTs, exercises and regional cooperation, and the assessment is that execution and durable institutions, not the roadmap, are the binding constraint. Useful for anyone with Mexican operations or LATAM regulatory exposure; the closing recommendations are generic.

  2. anirudhnshandilya/auditpilot: Open-source AI-powered compliance platform for ISO/IEC 27001 readiness, evidence intelligence, control mapping, compliance scoring, and CAPA automation. (opens in a new tab)

    GitHub: new security tools ·anirudhnshandilya ·fetched 25 Aug 2026, 15:38 UTC ★ 151 agreed2/2

    Why readEarly-stage open-source tool that parses evidence files, checksums them and maps them to ISO/IEC 27001 Annex A controls to flag gaps.

    AuditPilot is a Python/FastAPI project that ingests audit evidence, generates a SHA-256 checksum and structured metadata for each artefact, maps it against ISO/IEC 27001 controls, and converts detected gaps into CAPA-style remediation actions. The sample output is thin, amounting to recommendations of the form "Provide evidence for A.5.2", and the authors state it is suitable for experimentation rather than real certification work. Worth watching if you run 27001 readiness in spreadsheets, but not yet something to put in front of an auditor.

  3. ‘Close Enough’ Data Breach Notifications Create Exposure (opens in a new tab)

    Google News: incidents · JD Supra ·fetched 25 Aug 2026, 03:37 UTC agreed2/2

    Why readLaw-firm commentary arguing that approximate breach notification language creates its own legal exposure.

    Only the headline and byline came through, so the argument cannot be checked: the claim is that breach notifications written to be 'close enough' rather than accurate expose the notifying organisation to further liability. JD Supra syndicates law-firm alerts, so this is secondary legal commentary rather than a ruling or a rule change.

  1. Suspected Iran-linked attack knocked UK power plant offline for days (opens in a new tab)

    Help Net Security ·Zeljka Zorz ·fetched 25 Aug 2026, 03:37 UTC Must read agreed2/2

    Why readA British power plant was reportedly offline for four days in July 2026 after a suspected Iran-linked intrusion, alongside the coordinated hits on 30-plus US water utilities.

    Telegraph sources say suspected Iranian operators forced a UK power plant offline for four days in July 2026, in the same period as a coordinated attack on more than 30 US community water utilities. The plant is not named and no technical detail is public, so this is a disclosure event rather than a campaign analysis. It is the destructive-OT question a board or a regulator will put to anyone running critical national infrastructure, and it establishes a pattern across two countries in one month.

    Also covered byThe Record (opens in a new tab).

  2. Employee benefits platform Paylogix says hackers stole financial and health data (opens in a new tab)

    The Record ·fetched 25 Aug 2026, 19:39 UTC Must read agreed2/2

    Why readPaylogix, a benefits third-party administrator, confirms Akira stole SSNs, health and financial data on tens of thousands, months after the November exfiltration window.

    Paylogix has notified multiple state regulators that attackers exfiltrated files from its network between November 13 and 18, taking Social Security numbers, electronic signatures, financial account details, health insurance and medical data, passport numbers and taxpayer IDs. The company was listed on Akira's leak site in January but has not itself named the actor, and federal law enforcement is involved. As a third-party administrator serving employers and insurers, the downstream notification burden lands on its clients, which is the question a benefits or HR-adjacent risk owner should be asking this week.

  3. Judge Approves $117.5 Million Settlement in ‘Complex’ Comcast Data Breach Case (opens in a new tab)

    Google News: incidents · Insurance Journal ·fetched 25 Aug 2026, 07:37 UTC agreed2/2

    Why readA court has signed off on a $117.5 million settlement in the Comcast breach litigation, a fresh datapoint for anyone pricing breach liability.

    A judge approved the $117.5 million class settlement arising from the Comcast data breach case, described in court as complex. The figure is the story: it sets a reference point for consumer-class exposure at a large telecom and feeds directly into insurance and reserve conversations. Coverage is brief, with no detail on claims administration or per-claimant recovery.

  4. Alabama subpoenas OpenAI over alleged data breach (opens in a new tab)

    Google News: incidents · APR | Alabama Public Radio ·fetched 25 Aug 2026, 15:38 UTC agreed2/2

    Why readA US state attorney general has issued a subpoena to OpenAI over an alleged data breach, a state-level enforcement step against a major AI provider that legal and vendor-risk teams will be asked about.

    Alabama has subpoenaed OpenAI in connection with an alleged data breach. The report is a headline-level item with no detail on the incident, the data involved or the statutory basis for the demand. It matters as a marker of state AGs moving on AI vendors under breach and consumer-protection authority, which is a live question for anyone with OpenAI in their third-party inventory.

  5. Data breach reported by Grafton City Hospital officials (opens in a new tab)

    Google News: incidents · WAJR ·fetched 25 Aug 2026, 11:41 UTC agreed2/2

    Why readAnother named US hospital disclosing a breach, useful only as a data point on healthcare incident cadence.

    Grafton City Hospital officials reported a data breach on 24 August 2026, per local outlet WAJR. No record count, attack vector, actor or notification detail accompanies the headline. Too small and too thin to move a sector or prompt peer action.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Central Florida Civil LLC Orova Professional Services US 25 Aug 2026
Arich Enterprise Co., Ltd. Orova - TW 25 Aug 2026
Bai-chi CPA Firm Orova Professional Services TW 25 Aug 2026
Brazosport College qilin Education US 25 Aug 2026 press coverage (opens in a new tab)
ma***up AuditTeam - RU 25 Aug 2026
industry.airliquide.kr safepay Manufacturing KR 25 Aug 2026
parkderochie.com chaos - NL 25 Aug 2026
mswalker.com chaos Professional Services US 25 Aug 2026
copcp.com chaos - CN 25 Aug 2026
SC PaderTeG Cabluri Electrice qilin Manufacturing RO 25 Aug 2026
National Kidney Registry direwolf Healthcare US 25 Aug 2026
Studio Legale ESE direwolf Professional Services IT 25 Aug 2026
Tiseo Paving Global Secret Group Transportation US 25 Aug 2026
Johnson City Honda Global Secret Group Retail & E-Commerce US 25 Aug 2026
Lockheed Architectural Solutions, Inc. Global Secret Group Government & Defense US 25 Aug 2026
Sinar Mas Agribusiness and Food Golden Agri-Resources) ShadowByt3$ Agriculture and Food Production ID 25 Aug 2026
A-Plus Software Limited ShadowByt3$ Technology GB 25 Aug 2026
Knottingham Trent University ShadowByt3$ Education GB 25 Aug 2026 press coverage (opens in a new tab)
S******* genesis - - 25 Aug 2026
WINTER Ingenieure akira Manufacturing DE 25 Aug 2026
STRUCTURED SETTLEMENT CAPITAL LLC qilin Financial Services US 25 Aug 2026
Davis & Ferber akira Professional Services - 25 Aug 2026
AGROLAND S.A. qilin Agriculture and Food Production RO 25 Aug 2026
Pump Engineering Company Dark Project Manufacturing US 25 Aug 2026
PCA Group Sdn. Bhd. majinahanashi - MY 25 Aug 2026
How this edition was made
Candidates fetched
5708
New after deduplication
720
Kept by the panel
157
Published
103
Generated
25 Aug 2026, 23:39 UTC