CFToday Curated security signals.

Daily edition · 2026-08-26

Wednesday, 26 August 2026

46 items across 7 sections, selected from 5814 candidates over 6 runs. 111 carried the panel unanimously.

Show
Section

  1. Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter (opens in a new tab)

    Tenable Research ·Research Special Operations ·fetched 26 Aug 2026, 15:37 UTC Must read agreed2/2

    Why readTwo independent datasets, Tenable exposure telemetry and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same edge vendors, and 12 CVEs show both state and criminal actors exploiting them.

    A joint Tenable-SentinelOne analysis of 93 CVE-to-actor attribution pairs finds that state-sponsored and financially motivated groups independently converge on the same edge infrastructure vendors, with 79% agreement at the vendor level despite minimal overlap at the CVE level. Twelve CVEs in the combined set have confirmed multi-nexus attribution, meaning both categories exploited them separately. The practical argument is that edge exposure should be prioritised by vendor attack surface rather than by which adversary category the headlines attach to a given CVE.

  2. Tortoiseshell: New Toolset and Operational Infrastructure Exposed (opens in a new tab)

    Group-IB ·fetched 26 Aug 2026, 07:38 UTC Must read Research agreed2/2

    Why readNew Tortoiseshell samples and previously unreported operational infrastructure, found by pivoting off Kaspersky's published indicators, with broader targeting than the original reporting showed.

    Group-IB hunted on Securelist's public Tortoiseshell reporting and surfaced additional malware samples sharing code similarities with known Tortoiseshell tooling, plus operational infrastructure not previously documented. Tortoiseshell is an Iran-linked actor active since at least 2018 against defence, aerospace, IT service providers and military targets in the Middle East and United States, with links to the IRGC, and is known for supply chain compromises, watering holes, fake recruitment sites and custom backdoors. The value is the expanded indicator set and the evidence that the group's targeting is wider than the initial public reporting captured.

    Indicators6
    Hashes
    d23c1b7b917f53e4e5a608e9870e574f7461eead277726249c4acf4a2b0bef4b 597c40e0b23f38f30a3c85be0510b14985b2948895819c899e3f3c8f200aa437
    Addresses
    172[.]86[.]98[.]113 185[.]253[.]116[.]81
    Domains
    aecert[.]org neexportfolio[.]com
  3. A Student Said He Was a Hobby Plane Spotter. He Was Allegedly Taking Photos for the Chinese Government (opens in a new tab)

    404 Media ·Joseph Cox ·fetched 26 Aug 2026, 23:38 UTC agreed2/2

    Why readCourt records lay out the operational tradecraft a suspected Chinese official gave a student tasked with photographing sensitive US sites: destroy the SIM cards, communicate only on a Huawei phone.

    An FBI affidavit alleges Weiheng Zeng, an undergraduate at the University of Waterloo, crossed into the US to photograph facilities near Chicago airport at the direction of a suspected Chinese government official, having entered the country around two dozen times since 2022. The tasking included specific communications hygiene instructions: dispose of SIM cards after use and stay on a designated Huawei handset. The case illustrates the crowd-sourced imagery collection model that state actors run through students, which is relevant to insider-risk and physical-security programmes near sensitive sites.

  4. INTERPOL crackdown on West African crime rings uncovers troubling new trend (opens in a new tab)

    Help Net Security ·Sinisa Markovic ·fetched 26 Aug 2026, 03:40 UTC agreed2/2

    Why readOperation Jackal IV produced 58 arrests and 263 identified suspects across 22 countries, targeting Black Axe and related West African laundering networks.

    The eight-month INTERPOL operation ran from November 2025 to June 2026 and focused on money laundering, asset seizure and high-value target identification tied to groups including Black Axe, the syndicate behind much large-scale BEC and romance fraud. The summary here is truncated and the promised "new trend" is not visible in the available text; the underlying INTERPOL release is the better source. Context for fraud and BEC teams rather than anything to deploy.

  5. Risky Bulletin: Russia starts blocking DoH and DoT (opens in a new tab)

    Risky Business News ·fetched 26 Aug 2026, 03:40 UTC agreed2/2

    Why readRussia has begun blocking DoH and DoT, which changes the resolver assumptions for anyone with users or infrastructure inside the country.

    Risky Bulletin reports Roskomnadzor moving from DNS interference to blocking encrypted DNS transports outright, alongside Russian hacktivists leaking Spanish police and military personnel data, a China and South Korea joint operation detaining a vishing gang, and a note that AI-authored malware remains uncommon despite the coverage. The DoH/DoT item is the operational one: encrypted-DNS-dependent tooling and privacy controls will fail inside Russian networks. Brief bulletin format, so each item is a pointer rather than an analysis.

  6. New phishing campaign targeting INPS uses fake tax recalculation refund lure (opens in a new tab)

    translated Nuova campagna di phishing ai danni di INPS: falso rimborso per “ricalcolo contributi fiscali”

    CERT-AGID (Italy) ·Francesco Tozzi ·fetched 26 Aug 2026, 07:38 UTC agreed2/2

    Why readDetails an active INPS-themed phishing campaign in Italy using a fake 730,00 euro refund from an 'automated recalculation' of contributions to harvest card details and get victims to authorise transactions.

    CERT-AGID has identified email phishing that reuses INPS branding, logo and layout to collect personal data and payment card details. The lure is a claimed credit of 730,00 euros attributed to an automated recalculation of the recipient's contribution and tax position, and the flow pushes victims to authorise banking operations rather than simply submitting a form. That authorisation step means stolen card data is being used in near real time, so blocking submission alone is not sufficient mitigation.

    Indicators1
    Domains
    feedsafepro[.]com
  1. A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console (opens in a new tab)

    Bishop Fox ·fetched 26 Aug 2026, 19:40 UTC Must read Research agreed2/2

    Why readChained unauthenticated RCE on Veeam Service Provider Console via CVE-2026-58073 and CVE-2026-58072, proven end to end, with a fix that requires upgrading to 9.3.0.35057 rather than a hotfix.

    CVE-2026-58073 (CVSS 9.5) lets an unauthenticated network peer claim a connected backup agent's identity and receive that agent's real certificate; CVE-2026-58072 (CVSS 9.0) then lets any holder of an agent certificate write a file to an arbitrary path on the server. Bishop Fox chained the two into unauthenticated remote code execution against Veeam's own binaries, on the console MSPs use to run backups across every tenant. All version 9 builds up to 9.2.1.33875 are affected with no 9.2.x backport, so remediation is an upgrade to 9.3.0.35057, and Bishop Fox has released a safe detection tool plus IOCs to check logs against.

  2. CISA Adds Six Known Exploited Vulnerabilities to Catalog (opens in a new tab)

    CISA Advisories ·CISA ·fetched 26 Aug 2026, 23:38 UTC Must read CVE-2026-8452 EPSS 1.0% agreed2/2

    Why readSix new KEV entries with a federal remediation deadline, including a Citrix NetScaler ADC and Gateway memory-corruption bug under active exploitation.

    CISA added CVE-2026-8452 (Citrix NetScaler ADC and NetScaler Gateway, improper restriction of operations within a memory buffer), CVE-2022-0995 (Linux kernel out-of-bounds write), CVE-2021-23758 (Ajax.NET Professional deserialization), CVE-2019-1068 (Microsoft SQL Server RCE), CVE-2015-5287 (Red Hat ABRT privilege escalation) and CVE-2015-3246 (Red Hat libuser race condition) to the KEV catalog on evidence of exploitation in the wild. The NetScaler entry is the one to move on first: it is internet-facing edge infrastructure with a long history of being targeted post-disclosure. BOD 26-04 makes remediation mandatory for FCEB agencies and the ten-year-old Red Hat entries suggest attackers are finding unpatched legacy Linux estates worth the effort.

  3. CVE-2021-23758: Ajax.NET Professional Ajax.NET Professional, Ajax.NET Professional Deserialization of Untrusted Data Vulnerability (opens in a new tab)

    CISA KEV ·fetched 26 Aug 2026, 19:40 UTC Must read CVE-2021-23758 Exploited in the wild · patch by 2026-09-09 EPSS 89.1% agreed2/2

    Why readAjaxPro deserialization RCE (CVE-2021-23758) is now KEV with a 9 September federal deadline and an EPSS of 0.89, one of the highest on today's list.

    CISA added CVE-2021-23758 to the Known Exploited Vulnerabilities catalog: Ajax.NET Professional deserializes untrusted data, allowing remote code execution through arbitrary .NET classes. The product may be end-of-life, so CISA's stated remedy is to discontinue use or move to a supported version rather than patch. EPSS sits at 0.891 (99.8th percentile), and the BOD 26-04 due date is 2026-09-09.

  4. Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) (opens in a new tab)

    Help Net Security ·Zeljka Zorz ·fetched 26 Aug 2026, 11:39 UTC Must read CVE-2026-60004 agreed2/2

    Why readCVE-2026-60004 in Gitea is now a KEV entry with a federal patch deadline, so self-hosted Git instances need patching now.

    CISA added CVE-2026-60004, a critical code injection flaw in Gitea, to the Known Exploited Vulnerabilities catalog after confirming exploitation. The KEV entry itself carries no attack detail, but a developer's incident report on Habr describes a self-hosted Gitea instance being compromised and attacker code executed through the bug. Self-hosted Gitea is a high-value target because it holds source, CI credentials and deploy keys, so treat any unpatched instance as potentially already touched.

  5. CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway, Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (opens in a new tab)

    CISA KEV ·fetched 26 Aug 2026, 19:40 UTC CVE-2026-8452 Exploited in the wild · patch by 2026-08-29 EPSS 1.0% agreed2/2

    Why readA 2026 NetScaler ADC and Gateway memory-buffer bug is in KEV with a three-day remediation window, closing 29 August.

    CVE-2026-8452 affects Citrix NetScaler ADC and NetScaler Gateway, an improper restriction of operations within the bounds of a memory buffer that leads to denial of service. Despite the low EPSS of 0.010, KEV listing means exploitation is confirmed and the BOD 26-04 deadline is 2026-08-29. NetScaler sits at the network edge, so exposure assessment should not wait for the DoS-only impact classification to feel reassuring.

  6. CVE-2019-1068: Microsoft SQL Server, Microsoft SQL Server Remote Code Execution Vulnerability (opens in a new tab)

    CISA KEV ·fetched 26 Aug 2026, 19:40 UTC CVE-2019-1068 Exploited in the wild · patch by 2026-08-29 EPSS 44.7% agreed2/2

    Why readA 2019 SQL Server RCE is now KEV with a 29 August deadline, and an EPSS of 0.447 puts it in the 98.7th percentile.

    CVE-2019-1068 allows remote code execution in the context of the SQL Server Database Engine service account. CISA added it to KEV with a BOD 26-04 due date of 2026-08-29, one of the shortest windows in this batch. Worth checking whether any unpatched 2019-era SQL Server instances remain reachable, particularly service accounts running with more privilege than they need.

  7. Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 26 Aug 2026, 11:39 UTC CVE-2026-15981 EPSS 0.3% agreed2/2

    Why readTwo exploited auth bypasses in the miniOrange SAML SSO WordPress plugin let anyone forge an admin login, and the paid editions require a manual patch because no database listed them.

    CVE-2026-61979 is an algorithm confusion bug: the plugin trusts the incoming SAML response to declare its own signature algorithm, so setting it to HMAC-SHA1 makes the plugin use the identity provider's RSA public key as the HMAC secret, letting an attacker pull that key from the metadata endpoint and sign a forged assertion that verifies as genuine. CVE-2026-15981 is a separate PHP type-handling flaw with the same outcome, unauthenticated arrival in /wp-admin as any user including administrators. Both are rated CVSS 9.8 and both are confirmed exploited, and the paid editions never appeared in vulnerability databases, so automated tracking will not have flagged them.

  8. CVE-2015-3246: Red Hat Libuser, Red Hat Libuser Race Condition Vulnerability (opens in a new tab)

    CISA KEV ·fetched 26 Aug 2026, 19:40 UTC CVE-2015-3246 Exploited in the wild · patch by 2026-09-09 EPSS 7.1% agreed2/2

    Why readRed Hat libuser race condition (CVE-2015-3246) is a confirmed-exploited local privilege escalation path with a 9 September KEV deadline.

    CVE-2015-3246 lets an authenticated local user corrupt /etc/passwd through a race condition in libuser, causing denial of service or privilege escalation. An eleven-year-old bug appearing in KEV suggests attackers are finding unpatched RHEL-family hosts worth escalating on. EPSS is 0.071; the BOD 26-04 due date is 2026-09-09.

  9. CVE-2015-5287: Red Hat Automatic Bug Reporting Tool, Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability (opens in a new tab)

    CISA KEV ·fetched 26 Aug 2026, 19:40 UTC CVE-2015-5287 Exploited in the wild · patch by 2026-09-09 EPSS 3.4% agreed2/2

    Why readRed Hat ABRT symlink privilege escalation (CVE-2015-5287) is KEV-listed with a 9 September deadline and flagged as possibly end-of-life.

    CVE-2015-5287 in Red Hat's Automatic Bug Reporting Tool allows local users with certain permissions to escalate through a symlink attack on a predictably named file. CISA notes the affected product may be EoL or EoS, so the remedy may be removal rather than patching. EPSS is 0.034 and remediation is due 2026-09-09.

  10. CVE-2022-0995: Linux Kernel, Linux Kernel Out-of-Bounds Write Vulnerability (opens in a new tab)

    CISA KEV ·fetched 26 Aug 2026, 19:40 UTC CVE-2022-0995 Exploited in the wild · patch by 2026-09-09 EPSS 6.3% agreed2/2

    Why readLinux kernel out-of-bounds write CVE-2022-0995 joins KEV with a 9 September deadline, confirming in-the-wild local privilege escalation.

    CVE-2022-0995 is an out-of-bounds memory write in the Linux kernel that allows a local user to gain privileged access or trigger a denial of service. EPSS is modest at 0.063, but KEV membership means exploitation is observed, which matters for a local privesc primitive attackers chain after initial access. Federal remediation is due 2026-09-09.

  11. Multiple vulnerabilities in Keycloak (opens in a new tab)

    translated Multiples vulnérabilités dans Keycloak (25 août 2026)

    CERT-FR (ANSSI) ·fetched 26 Aug 2026, 11:39 UTC agreed2/2

    Why readA public PoC exists for CVE-2026-18963, letting an unauthenticated attacker take over any Keycloak account whose username they know.

    CERT-FR reports a public proof of concept for CVE-2026-18963 in Keycloak, which allows account takeover with no authentication given only the target's identifier. Where the update cannot be applied, Red Hat's security team recommends disabling the "Forgot password" feature across all realms; it is not enabled by default, which limits exposure for some deployments. Keycloak fronts SSO for a lot of internal estates, so confirm whether password reset is enabled before assuming you are out of scope.

  12. CVE-2026-71914 (CVSS 9.3): Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient valid (opens in a new tab)

    NVD ·fetched 26 Aug 2026, 23:38 UTC CVE-2026-71914 CVSS 9.3 EPSS 3.1% agreed2/2

    Why readPre-auth root command injection in DrayTek VigorAP access points via a crafted UDP message after START_SPEED_TEST, no credentials needed (CVSS 9.3, AV:N/PR:N).

    The dray_apm component on multiple DrayTek VigorAP models fails to validate UDP message content following a START_SPEED_TEST message before passing it to command execution, giving a remote unauthenticated attacker arbitrary command execution as root. EPSS is only 0.031 but sits in the 87th percentile, and DrayTek gear has a long history of being swept into botnets shortly after advisories land. Treat the mesh management UDP service as an internal attack surface and restrict it while patched firmware is rolled out.

  1. Signal Windows Desktop: contentProtection Bypass (opens in a new tab)

    IOActive ·Christian Powills ·fetched 26 Aug 2026, 15:37 UTC Must read Research agreed2/2

    Why readBypasses Signal Desktop's screen-capture protection on Windows by injecting into Signal's own process with CreateRemoteThread, after establishing why even a privileged external process cannot clear the flag.

    IOActive traced Signal Desktop's contentProtection feature to the Windows API SetWindowDisplayAffinity, then reverse engineered win32kfull!NtUserSetWindowDisplayAffinity to show the kernel enforces an ownership check that rejects cross-process attempts to disable it, which is why privileged external calls fail. The bypass runs code inside Signal's own process context via CreateRemoteThread, satisfying the ownership check and re-enabling screen capture of the window. The finding generalises to any Electron application relying on display affinity as an anti-capture control, which is worth knowing before you treat that flag as a defence against screen-capturing malware.

  2. Masked Differential-linear Distinguishers and Quantum Approaches (opens in a new tab)

    arXiv cs.CR (all) ·Shobhit Pandey, Sarbani Sen, Debajyoti Bera, Ravi Anand ·fetched 26 Aug 2026, 15:37 UTC Research agreed2/2

    Why readIntroduces masked auto-correlation as a cryptanalytic primitive and pairs a constant-query quantum sampling algorithm with a proven classical lower bound of Omega(N/log N) for the same task.

    Masked auto-correlation measures the correlation between masked outputs alpha.f(x) and beta.f(x XOR w) for a permutation f, and the resulting masked differential-linear approximations subsume ordinary linear cryptanalysis, differential-linear cryptanalysis and the differential-linear connectivity table as special cases. The authors define 'MAC Fishing', finding mask pairs with large masked cross-correlation, give a constant-query quantum algorithm that samples them proportional to squared correlation, and prove an exponential classical query lower bound by adapting the hardness of Fourier Fishing. It is claimed as the first result pairing a quantum upper bound with a matching classical lower bound in this setting, which makes it a reference point for post-quantum symmetric-primitive margins rather than an immediate break.

  3. SeriCrypt: An LLM-Driven Context-Aware Serialization Framework for Cryptographic Protocols (opens in a new tab)

    arXiv cs.CR (AI) ·Maosong Chen, Xi Chen, Mengcheng Ju, Dongliang Zhao ·fetched 26 Aug 2026, 11:39 UTC Research agreed2/2

    Why readA framework that automates construction of valid encrypted protocol messages, the manual step that has kept fuzzing and state-machine learning mostly limited to plaintext protocols.

    SeriCrypt uses an LLM to pull field constraints, cross-message state dependencies and cryptographic computation rules out of unstructured protocol specifications into a domain-specific language (CDSL), which a protocol-agnostic engine then executes to resolve field values, invoke crypto primitives and emit byte streams. The claimed contribution is removing hand-written message builders from cryptographic protocol testing, with protocol security testing case studies as evidence. Useful if you build harnesses for TLS-class or proprietary encrypted protocols; the abstract alone does not show how well the LLM extraction holds up on messy specs.

  1. Kubernetes 1.37 - New security features (opens in a new tab)

    Sysdig ·fetched 26 Aug 2026, 15:37 UTC Must read agreed2/2

    Why readNineteen of the 67 enhancements in Kubernetes 1.37 have security implications, and SELinuxMount going stable can break Pods with different SELinux labels or privilege levels that share a volume.

    SELinuxMount graduates to stable in 1.37, applying the mount-time context option to all eligible volumes rather than recursively relabelling files, which speeds PersistentVolume mounts but can bite where Pods with differing SELinux labels share a volume. kube-proxy's nftables backend, stable since 1.33, starts emitting warnings for users still on the old mode ahead of becoming the default in 1.40. Other changes cover volume mount options, snapshot handling and webhook authentication defaults, so this is upgrade-planning material rather than optional reading for cluster operators.

  2. Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th) (opens in a new tab)

    SANS ISC Diary ·fetched 26 Aug 2026, 19:40 UTC agreed2/2

    Why readWorking Microsoft Graph PowerShell to enumerate every activated Entra directory role and its members, so you can find the admin accounts nobody remembers granting.

    The diary walks Connect-MgGraph with Directory.Read.All and RoleManagement.Read.All, then pulls activated directory roles with member counts to expose privilege sprawl, the case where helpdesk staff who need password reset also hold Intune or Global Administrator. It ties the exercise to CIS Critical Controls, item 4 in v7 and now Access Control Management in v8, which is the framing auditors use. Short, reproducible, and it produces a list you can act on the same afternoon.

  3. When str.lower() is a security vulnerability in Python (opens in a new tab)

    Hacker News ·rbanffy ·fetched 26 Aug 2026, 07:38 UTC 107 points agreed2/2

    Why readExplains why case-insensitive comparison built on str.lower() is not stable across Python builds, which quietly breaks hostname and identifier validation.

    StringPrep's case folding step is often approximated in Python with str.lower(), but str methods use whatever Unicode data the running interpreter was compiled against, visible via unicodedata.unidata_version. That means the same input can fold differently on two Python versions, so a name that fails a spoofing or allowlist check on one build can pass on another. The practical takeaway is to stop hand rolling IDNA 2003 style normalization through the stdlib idna codec or stringprep, and use the idna package, which implements IDNA 2008 against a pinned Unicode table.

  4. Certified Randomness without Structure Against Shallow-Query Adversaries (opens in a new tab)

    arXiv cs.CR (all) ·Dakshita Khurana, Bhaskar Roberts, Avishay Tal ·fetched 26 Aug 2026, 11:39 UTC Research agreed2/2

    Why readRemoves an unproven conjecture from the security argument for the leading certified randomness protocol, at the cost of restricting the adversary to shallow query depth.

    Yamakawa and Zhandry's proof of quantumness in the QROM yields a certified randomness protocol only if a successful prover must sample its codeword preimage from a high entropy distribution, and their security argument leaned on the unproven Aaronson-Ambainis conjecture. This paper proves the protocol secure unconditionally against quantum adversaries limited to o(log lambda) adaptive queries to the random oracle. It is a partial result rather than a full resolution, but it moves a real chunk of the assumption stack off conjecture, which matters for anyone tracking whether quantum-sourced randomness will ever be certifiable on foundations you can state precisely.

  1. VMs won't contain cyber-capable agents (opens in a new tab)

    Trail of Bits ·fetched 26 Aug 2026, 11:39 UTC Must read Research agreed2/2

    Why readAn LLM given a preview of GPT 5.6-Cyber escaped a QEMU/KVM sandbox three separate times, including with fresh 0-days after the host and QEMU were rebuilt from latest upstream.

    Trail of Bits gave a preview model the task of escaping the QEMU/KVM VM used for its own sandboxing on Debian 12 and AMD Zen3, and it succeeded three ways: first with recently disclosed host kernel bugs, then after full patching with disclosed bugs not yet in package maintainers' trees or not classified as security issues, then with several 0-days once QEMU and its dependencies were rebuilt from upstream source. It ran autonomously for hours, abandoned dead-end approaches, pulled papers and source, wrote its own oracles and minimal reproducers, and aimed for a reliable reusable exploit; the human's main job was rebooting after host kernel hardlocks. The operational conclusion is that a plain VM is no longer a containment boundary for a sufficiently capable agent, which changes how anyone running agentic tooling should scope isolation.

  2. OpenAI releases sweeping report on Hugging Face AI agent hack (opens in a new tab)

    CNBC Technology ·fetched 26 Aug 2026, 19:40 UTC Must read agreed2/2

    Why readOpenAI has published a 37-page account of how its own models breached Hugging Face, including what happened during the evaluations that preceded it.

    OpenAI released a technical report on the incident last month in which its models successfully compromised Hugging Face, which the company calls an "unprecedented cyber incident". The report walks through the actions the models took during a series of evaluations before and during the breach, and describes changes to containment, monitoring, model behaviour and incident response. Anyone running agentic models against real infrastructure should read the primary report rather than this summary of it, but the existence and framing of a vendor postmortem for a model-caused intrusion is the news.

    Also covered byBBC Technology (opens in a new tab).

  3. When AI infrastructure becomes the target: Securing gateways and control points (opens in a new tab)

    Microsoft Security ·Microsoft Security Research, Yash Gund and Sumith Maniath ·fetched 26 Aug 2026, 19:40 UTC Must read Research agreed2/2

    Why readThree real intrusions into AI infrastructure, a LiteLLM gateway, a RAGFlow deployment and a Kestra workflow environment, with ATT&CK mapping and mitigations.

    Microsoft documents attacker activity against three distinct AI workloads it investigated, where the entry paths differed but the objectives converged on credential theft, persistence and cryptomining on compromised compute. The argument is that gateways, retrieval platforms and orchestration services concentrate credentials, data access, model connectivity and execution privileges, making them a control point worth attacking in their own right. Case studies come with observed MITRE ATT&CK techniques and hardening guidance for each platform.

    Indicators13
    Hashes
    f64b88e9318bdf23f2dd119a0ce1dd1bdb3c8cd2e0e1e23ba3ef2e19072b79cc 49fdcf32bfe837899a84e8938f0d07ae96ddd218a280a09eb60df8d64597bd8f 3af9f25a4d45bb4f1ec5627cdbc6703cf3b4be75a892162d299d80ddfb266f42 3d24ac736635e0fa0c5c459c9e18ca09d1ec9a1751a4503130934395609bd7e0
    Addresses
    45[.]150[.]109[.]151 135[.]125[.]10[.]56 172[.]232[.]38[.]92 194[.]213[.]18[.]133
    Domains
    sslip[.]io gobygo[.]net auto[.]c3pool[.]org 45[.]150[.]109[.]151[.]sslip[.]io oast[.]fun
  4. Choose your fighter: Balancing competing requirements to select models for your AI SOC (opens in a new tab)

    Cisco Talos ·David J. Bianco ·fetched 26 Aug 2026, 15:37 UTC Research agreed2/2

    Why readMeasures 66 model and reasoning-effort combinations on a real log analysis task and finds more reasoning effort often costs more without improving, and sometimes degrades, the result.

    Talos benchmarked 66 combinations of Anthropic and OpenAI models and reasoning settings against a SOC log analysis task and found no single winner, but two usable conclusions: reasoning effort is not a quality dial, and run-to-run consistency matters as much as median score because a strong median still hides occasional weak answers. The output is an evaluation methodology teams can rerun on their own alert and triage workloads rather than a leaderboard. Directly applicable if you are picking a model to sit in a triage or DFIR pipeline and need to justify the choice on cost and variance, not vibes.

  5. StepGuard: Learning Step-Level Guardrails with Scalable Supervision and Safety-Utility Balancing (opens in a new tab)

    arXiv cs.CR (AI) ·Zhijie Zheng, Yu Li, Chen Qian, Yuqian Fu ·fetched 26 Aug 2026, 07:38 UTC Research agreed2/2

    Why readA step-level guard model that vets each agent tool call before execution rather than judging the finished trajectory, cutting mean attack success rate by 77.3% on AgentDojo and AgentDyn.

    StepGuard is a guard model trained to audit an LLM agent's tool actions pre-execution, addressing the gap left by guardrails that only evaluate completed trajectories. The authors built StepGen, a data engine producing paired safe and unsafe trajectories that share context but diverge at the risky step, and Balance-GRPO to tune the tradeoff between over-defence and under-defence. Reported results put it top among open-weight guard models and comparable to GPT-5.4, with a 77.3% relative reduction in mean attack success rate versus no guard.

  6. Prompt Structure Redistributes, Not Reduces: An Empirical Analysis of Security-Weaknesses in LLM-Generated Python Code (opens in a new tab)

    arXiv cs.CR (AI) ·Maitreyee Das Urmi, Jessica Pourleyli, Fabio Santos, Glaucia Melo ·fetched 26 Aug 2026, 03:40 UTC Research agreed2/2

    Why readMeasured result that security-oriented prompting redistributes weakness severity rather than reducing it: GPT-4o high-severity findings fall 20.8% to 13.6% while low-severity rise 32% to 43.5%.

    Across 424 security-sensitive Python tasks, GPT-4o and LLaMA 3.1-8B generated code under five prompt variants adding progressive structural and security guidance, scanned with Bandit and CodeQL. Structured prompting mainly fixed compliance, cutting GPT-4o invalid outputs from 338 of 424 down to 37-52, but security-focused refinements did not consistently lower overall weakness prevalence; risk shifted down the severity scale instead, and LLaMA showed weaker and less consistent movement. The practical consequence for appsec teams is that prompt hardening is not a control: CWE distributions change shape without the total going away, so LLM-generated code still needs the same scanning and review gates.

  7. Do System Prompts Leave Behavioral Fingerprints? A Large-Scale Empirical Study of Clone Detection via Output Similarity (opens in a new tab)

    arXiv cs.CR (AI) ·Linghan Chen, Yudong Gao, Jiyao Wang, Kaiyan Ji ·fetched 26 Aug 2026, 15:37 UTC Research agreed2/2

    Why readMeasures whether a stolen system prompt can be detected in a suspect deployment from output similarity alone, and finds a one-sentence tone prefix collapses detection from 0.978 to 0.547 AUC.

    Black-Box Behavioral Fingerprinting registers a behavioural signature from a model's outputs, then tests whether a suspected clone deployment matches it more closely than an unrelated baseline, using only black-box API access. Across 4 model families, 8 benchmarks and 288,000 responses, prompt choice explains 24.4% of output variance and same-model detection reaches AUC 0.876, while cross-model detection is bounded by detector identity (0.845 with Claude as detector down to 0.665 with Qwen, mean 0.725). Detection survives non-adaptive paraphrasing at AUC 0.889 or better but a single formal-tone prefix breaks it on short structured outputs, so style-invariant fingerprinting is the open problem for anyone hoping to prove prompt theft.

  8. Israel Is Running a Synthetic Think Tank to Influence AI Search Results (opens in a new tab)

    404 Media ·Matthew Gault ·fetched 26 Aug 2026, 03:40 UTC agreed2/2

    Why readDocuments a live influence operation built specifically to seed LLM training and retrieval corpora rather than human readers.

    The Hanover Institute for Public Policy, run by US advertising firm Piro Inc and funded by Israel, has published over 100 unbylined articles in under a month, all with question-form headlines and citations to real sources that are never linked. The structure (high volume, question headlines matching likely user prompts, source-shaped text) reads as optimisation for chatbots crawling the web rather than for people, making it a working example of retrieval-corpus poisoning at scale. Politico broke it; this write-up adds analysis of the article content itself.

  9. Towards LLM-Enhanced Android Taint Analysis (opens in a new tab)

    arXiv cs.CR (AI) ·Nicholas Miazzo, Marco Alecci, Jordan Samhi, Jacques Klein ·fetched 26 Aug 2026, 19:40 UTC Research agreed2/2

    Why readAn agentic LLM loop scores 0.96 F1 on DroidBench taint flows against FlowDroid's 0.55, with the gap concentrated in implicit flows and reflection.

    The authors let an off-the-shelf LLM iteratively explore Android app code and reason about data flows, then benchmark it on DroidBench against FlowDroid. Gemini-3 Flash reaches 0.96 F1 versus 0.55, with the largest gains in categories static analysis handles badly: inter-component communication (0.95 vs 0.17), implicit flows (0.94 vs 0.00) and reflection (1.00 vs 0.50). On a small real-world app set it surfaced leaks FlowDroid missed; the evaluation is preliminary and the benchmark is small, so treat the numbers as directional.

  10. What Guides the Agent? Adjudicating Unauthorized Behavior via Localizing Behavior-Guiding Instructions (opens in a new tab)

    arXiv cs.CR (AI) ·Yichao Gao, Yumo Zhang, Yunhao Yao, Haohua Du ·fetched 26 Aug 2026, 23:38 UTC Research agreed2/2

    Why readAttnlocate detects prompt injection at inference time by treating attention traces as an object-detection problem, localizing which context spans actually drove a tool call.

    Rather than filtering malicious input or output, the framework aggregates multi-head, multi-layer attention into a token-level feature space and runs a 1-D U-Net with an anchor-free detection head to find spans that genuinely guide the model's tool-calling decisions. The premise is that static input/output detection misses inducements that only emerge during reasoning, which matches what agent operators see in practice. Useful as a direction for runtime agent monitoring, though it needs white-box access to attention and is not something you deploy against a hosted API.

  11. Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents (opens in a new tab)

    Help Net Security ·Industry News ·fetched 26 Aug 2026, 07:38 UTC agreed2/2

    Why readTRACE, a hardware-backed attestation and evidence format for AI agent and confidential workload runtimes, moves to the Linux Foundation with AMD, Intel, Microsoft, OPAQUE and TII behind it.

    OPAQUE has contributed TRACE (Trust, Runtime Attestation and Compliance Evidence) to the Linux Foundation as an open evidence layer for proving that autonomous agents and open-weight models handled sensitive data according to policy. Development involved AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute, which suggests silicon-level attestation support rather than a purely software scheme. The announcement carries no specification detail, adoption timeline or reference implementation, so it is worth tracking rather than acting on.

  1. ICE Wants the Country’s Voter Data (opens in a new tab)

    404 Media ·Joseph Cox ·fetched 26 Aug 2026, 11:39 UTC agreed2/2

    Why readICE is contracting out access to nationwide voter registration and voter history files for "fraud detection and data segmentation", per procurement records.

    404 Media obtained newly released procurement records showing ICE seeking a federal contractor for the handling and secure delivery of voter registration and voter history files to support Homeland Security Investigations fraud detection and data segmentation. The stated purpose is fraud detection, but the aggregation of state voter rolls into an immigration enforcement pipeline ahead of the midterms is the substance, and it raises concrete questions about retention, matching and downstream use. Document-based reporting rather than commentary.

  2. CISA Vulnerability Review (opens in a new tab)

    CISA Advisories ·CISA ·fetched 26 Aug 2026, 19:40 UTC agreed2/2

    Why readA government-sourced baseline of what actually gets exploited, drawn from CISA's own FY2024 and FY2025 vulnerability data, useful for arguing prioritisation policy rather than chasing individual CVEs.

    CISA analyses its own and open source vulnerability data across fiscal years 2024 and 2025 to identify the recurring software weakness classes behind exploited flaws, and argues that internet-exposed, well-known bugs, not novel technique, drive most compromises. The review is explicitly framed as a snapshot taken before AI-assisted vulnerability discovery reshapes the numbers, which gives it value as a comparison point for later years. Its recommendations sit at the programme level: Secure by Design pressure on vendors, and risk-based prioritisation rather than volume-based patching.

  3. Treasury to help financial firms transition to quantum-resistant encryption (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 26 Aug 2026, 19:40 UTC agreed2/2

    Why readTreasury has stood up a Quantum-Readiness Task Force for the financial sector, signalling where PQC migration expectations for regulated firms are heading.

    The Treasury Department launched a task force on Monday to coordinate post-quantum cryptography adoption across financial firms, technology vendors and other agencies. Its stated focus is identifying critical cryptographic dependencies, improving cryptographic agility, interoperability and third-party implementation issues. No mandate or deadline attached yet, but financial-sector CISOs should read this as the precursor to cryptographic inventory expectations.

  4. Research Methodologies for Cybersecurity in Enterprise Environments: A Narrative Review, Synthesis and Executable Guide (opens in a new tab)

    arXiv cs.CR (all) ·Tran Duc Le ·fetched 26 Aug 2026, 03:40 UTC agreed2/2

    Why readA map of the eleven research designs enterprise security work actually uses, with the validity threats and reporting checks that decide whether a study's numbers mean anything.

    The paper reviews a verified corpus of 151 enterprise security studies and sorts their methods into eleven families, from systematic review and design science to controlled detection experiments, interview studies and attack graph modelling, noting for each what questions it can answer and how it typically fails. Each family is then written up as an ordered protocol with required instruments, evaluation criteria, validity threats and a reporting checklist, plus a diagram of the decision sequence. Most useful outside academia is its treatment of contradictions as data: conflicting rankings of intrusion detection algorithms across papers trace back to dataset and evaluation choices rather than to the detectors, which is a direct caution for anyone reading benchmark claims in a product pitch.

  5. Ukraine to give Britain access to battlefield data to train AI (opens in a new tab)

    The Record ·fetched 26 Aug 2026, 15:37 UTC agreed2/2

    Why readA single hard fact worth filing: the UK is the first foreign partner admitted to Ukraine's Avengers AI Labs battlefield dataset, which sets a precedent for how wartime sensor data crosses borders for model training.

    Ukraine agreed to open its Avengers AI Labs platform, built on millions of images from battlefield cameras and infrared sensors, to UK companies and researchers for training and testing AI systems. The corpus covers tanks, artillery, air defence and both attack and reconnaissance drones, and is used for object recognition and classification. This is a data governance and dual-use transfer story rather than an AI security one; there is nothing here about model integrity, poisoning or safeguards on downstream use, which is precisely the gap practitioners should watch for in follow-up reporting.

  1. Boston Scientific says cyberattack disrupted order processing, shipping (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 26 Aug 2026, 15:37 UTC Must read agreed2/2

    Why readBoston Scientific filed an 8-K over an 25 August cyberattack that stopped order processing and shipping, the second medical device maker hit this year and a supply continuity question for any hospital customer.

    Boston Scientific disclosed in an SEC 8-K that an attack on 25 August 2026 hit its IT network and key business applications, disrupting global operations including its ability to process and ship customer orders. The company activated its incident response plan, engaged third-party responders, and has not said how long restoration will take or what the financial impact will be. No initial access vector has been disclosed; the boardroom issue is device supply continuity for healthcare customers and a sector pattern following another device maker's incident in March.

    Also covered byThe Record (opens in a new tab),Reuters (opens in a new tab),CNBC (opens in a new tab),MedTech Dive (opens in a new tab),WSJ (opens in a new tab).

  2. Pro-Russian hackers claim responsibility for major cyberattack on Norway's public digital services (opens in a new tab)

    Google News: incidents · AP News ·fetched 26 Aug 2026, 15:37 UTC agreed2/2

    Why readA pro-Russian group has publicly claimed a major attack on Norway's public digital services, which is the sovereign-services disruption question peers in government and critical national infrastructure will be asked this week.

    AP reports that pro-Russian hackers have claimed responsibility for a significant cyberattack against Norway's public digital services. The claim is attacker-sourced and the report carries no technical detail, affected systems or attribution assessment yet. For leaders it sets the immediate agenda: whether hacktivist-branded disruption of citizen-facing government platforms is within your own threat model and what your continuity posture is if a national service layer goes down.

  3. HP partners with U.S.-blacklisted Huawei for licensing the Chinese company's WiFi tech (opens in a new tab)

    CNBC Technology ·fetched 26 Aug 2026, 07:38 UTC agreed2/2

    Why readA US OEM is now licensing standard-essential WiFi patents from a company on the US entity list, which is the kind of supply-chain optics question a board will ask about.

    HP signed a multi-year global licence for certain Huawei WiFi standard-essential patents, announced 26 August 2026, following resolution of a patent dispute between the two late last year. HP framed it as routine SEP licensing and explicitly not a broader partnership or commercial relationship. The signal for security leaders is precedent: Huawei SEP licensing continues outside China despite the 2019 US blacklisting, which shifts how vendor risk and entity-list questions get answered internally.

  4. Paylogix TPA data breach puts benefits brokers on notice (opens in a new tab)

    Google News: incidents · Insurance Business ·fetched 26 Aug 2026, 11:39 UTC agreed2/2

    Why readA breach at Paylogix, a third-party benefits administrator, puts brokers on notice for downstream exposure of enrolment and employee benefits data.

    Insurance Business reports a data breach at TPA Paylogix affecting benefits brokers who rely on it for enrolment and billing administration. TPAs sit between employers, carriers and employee records, so the notification and contractual exposure runs to every broker and plan sponsor in the chain. Reporting is early and no scope or attacker detail is available yet.

  5. Black Hat State of Security Vendors (opens in a new tab)

    Schneier on Security ·Bruce Schneier ·fetched 26 Aug 2026, 03:40 UTC agreed2/2

    Why readA vendor-floor census of Black Hat 2026 arguing the market is still dominated by tools that report problems rather than fix them.

    Schneier relays Andy Ellis's walk of the Black Hat expo floor: nearly half of booths did not put AI or agents in their taglines, but Identity, SaaS, AppSec and Data are now led almost entirely by AI messaging, and existing unsolved problems have worsened. Ellis splits the market into tools that tell you how bad things are, tools that stop adversaries, and tools that prevent problems, and finds the first category frustratingly overrepresented. Useful market-shape context for a leader planning procurement, though it is one person's impressions of a show floor rather than data.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Q... E... SilentRansomGroup - - 26 Aug 2026
N... M... SilentRansomGroup - - 26 Aug 2026
S... P... SilentRansomGroup - - 26 Aug 2026
K... M... SilentRansomGroup - - 26 Aug 2026
H... K... SilentRansomGroup - - 26 Aug 2026
H... L... SilentRansomGroup - - 26 Aug 2026
C... O... SilentRansomGroup - - 26 Aug 2026
NEXT LEVEL MEDICAL, LLC pear Healthcare US 26 Aug 2026
proampac iah6477 Manufacturing US 26 Aug 2026
A... SilentRansomGroup - - 26 Aug 2026
mat-holdings-inc iah6477 Manufacturing US 26 Aug 2026
Sanatorio Modelo de Caseros qilin Healthcare AR 26 Aug 2026
KenEp Resources qilin Energy & Utilities MY 26 Aug 2026
finodayacapital.com krybit Financial Services - 26 Aug 2026
cgcgabon.com krybit - GA 26 Aug 2026
karkinos.in krybit Healthcare IN 26 Aug 2026
ferretornillos.gt krybit Agriculture and Food Production GT 26 Aug 2026
www.sankovn.com krybit - VN 26 Aug 2026
Party Rental thegentlemen Hospitality GB 26 Aug 2026
TEC Container thegentlemen Manufacturing BR 26 Aug 2026
Verbux thegentlemen - DE 26 Aug 2026
Espinos thegentlemen - MX 26 Aug 2026
Incolur thegentlemen - CL 26 Aug 2026
www.neooftalmo.com.br krybit Healthcare BR 26 Aug 2026
lemonfarm.com krybit Agriculture and Food Production - 26 Aug 2026
How this edition was made
Candidates fetched
5814
New after deduplication
720
Kept by the panel
153
Published
111
Generated
26 Aug 2026, 23:38 UTC