Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
One ad blocker is giving up the fight against Facebook ads. The consequences could go beyond annoying advertising.
A list of topics we covered in the week of August 10 to August 16 of 2026
<p>423 CVEs, no Edge patches, and a small shift in CWE findings</p>Categories: Threat ResearchTags: Patch Tuesday, MICROSOFT PATCH TUESDAY
Apple explains how Threat Notifications help protect iPhone users targeted by mercenary spyware.
An optional new feature uses on-device AI to flag messages that look like scams.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
Social engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It's no joke. Together, they can empty your bank account.
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
It's the biggest legal challenge yet to addictive social media design and its impact on children.
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the data against VirusTotal and CyberGordon. 
Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis.
Update Zoom now to protect against critical vulnerabilities that could allow an attacker in the same meeting to run malicious code on your device.
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#x5f;history"&#xc2;&#xa0;and collecting meaningful additional data. Our reader David commented that this can also be done quite well with Linux&#39;s kernel process accounting feature, and I think he is very right. I really like Linux process accounting for a number of reasons, so here is a quick introduction.
Microsoft's August Patch Tuesday fixes 421 vulnerabilities, including three zero-days, 62 critical flaws, and dozens of Office remote code execution bugs.
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
透明性は私たちの企業運営の根幹をなすものです。最近発生したサードパーティベンダーによるセキュリティインシデントに関する声明をご覧ください。調査結果および、お客様の情報を保護するために講じた対策について記載しております。
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
A convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome.
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs. 
The warning affects recent buyers of Steam hardware, including the hugely popular Steam Deck.
Researchers found that games and major US social media platforms were used to lure young people into jobs in Russia's drone industry.
The FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.
The same technology making our lives easier is also making it harder. How are young people navigating this new world?
TikTok Shop is huge, so it's no wonder that impersonation shops have popped up. Here's how to stay safe.
Fake branded download pages are tricking Windows users into installing legitimate remote-access software that's being abused by attackers.