Tag: cybersecurity
-
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of First…
-
Exploited RCE Flaws and Infrastructure Attacks Define this Cybersecurity Week in August 2026
Weekly summary of Cybersecurity Insider newsletters for August 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/exploited-rce-flaws-and-infrastructure-attacks-define-this-cybersecurity-week-in-august-2026/
-
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active…
-
Cato-CrowdStrike Partnership Is ‘Massive’ Win For Reducing Security Complexity, Improving Efficacy: Solution Provider CTO
Cato Networks’ recently expanded partnership with CrowdStrike brings together two of the industry’s most highly effective cybersecurity platforms with huge promise for reducing complexity for customers, a top partner of the two vendors tells CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/cato-crowdstrike-partnership-is-massive-win-for-reducing-security-complexity-improving-efficacy-solution-provider-cto
-
Identity-Based Attacks Drive 85% of Education Ransomware, Sophos Finds
Identity-based cyberattacks accounted for 85% of ransomware attacks experienced by education organizations over the past year, according to a new Sophos survey. The findings show ransomware attackers turning more often to identity abuse for initial access. The State of Ransomware in Education 2026 report draws on responses from 226 IT and cybersecurity leaders at lower..…
-
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: CVE-2023-49105 (CVSS score of 9.8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality. An unauthenticated attacker who…
-
Palo Alto Networks Researchers Say First Wave of AI-Enabled Attacks Has Begun
Cybersecurity researchers from Palo Alto Networks this week reported that it became apparent that the latest generation of AI models would be able to discover thousands of vulnerabilities in applications. A wave of attacks that are leveraging AI to exploit those vulnerabilities is now underway. Sam Rubin, senior vice president of the Unit 42 cybersecurity..…
-
AI Governance Has a Control Problem, Not a Policy Problem
Tags: access, ai, business, control, credentials, cybersecurity, data, finance, governance, identity, least-privilege, risk, technology, toolWe’re getting good at writing policies about how AI should be used. Responsible AI principles. Acceptable-use policies. AI risk frameworks. Approval processes. Governance committees. All of these have a place. But there is a harder question that I think organisations need to start asking: What evidence proves those controls actually work? Because AI is changing…
-
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
-
700 AI Agents Linked to Hugging Face Security Breach
Around 700 AI agents created by OpenAI participated in the breach of Hugging Face during a cybersecurity evaluation, according to an independent investigation that has revealed the scale of the incident. METR and Redwood Research published the findings after being brought in to independently investigate the July incident and examine the agents’ behaviour, reasoning, and…
-
The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown
Tags: ai, cloud, cyber, cybercrime, cybersecurity, exploit, flaw, identity, infrastructure, international, law, risk, technologyThis weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-microsoft-entra-id-ai-risks/
-
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, microsoft, sql, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let…
-
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that’s distributed via First seen…
-
Cyber Talk -12 Lacework: When the Right Market Isn’t Enough
In cybersecurity, choosing the right market matters enormously, but Lacework is a reminder that even a company that identifies the right market, builds meaningful technology, assembles a strong team, and raises enormous amounts of capital may still fail to become the company that ultimately defines the category. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cyber-talk-12-lacework-when-the-right-market-isnt-enough/
-
How Security Buyers Actually Buy: The Committee, The Triggers, and The Quiet Veto
Most cybersecurity vendors sell to the CISO and lose the deal to a security engineer they never spoke to. Security purchases are committee decisions with an asymmetric structure: many people can kill a deal, few can approve one. Here is how it actually works. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-security-buyers-actually-buy-the-committee-the-triggers-and-the-quiet-veto/
-
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May.The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
This installment of the Reporters’ Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI’s effects on vulnerability reporting and security research. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/agentic-ai-risks-cve-program-concerns-black-hat-usa-2026
-
Cisco Report Shows How AI Agents Are Changing Cybersecurity Jobs
Cisco research shows how AI agents are reshaping cybersecurity roles and skills. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/cisco-report-shows-how-ai-agents-are-changing-cybersecurity-jobs/
-
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of First…
-
AI Agents Used by 68% of Top-Performing Cybersecurity Teams
AI agents are already finding their way into the working methods of some of the highest-performing cybersecurity teams, according to new three-year benchmark data from Hack The Box (HTB). The 2026 Global Cyber Skills Benchmark found that 68% of the top 25 teams included an AI agent, despite AI agents accounting for just 2.7% of…
-
What the Data Says About AI in Security Operations in 2026
AI is officially mainstream in security operations. According to Prophet Security’s State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it.For the teams already using…
-
CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability
Tags: cisa, citrix, cve, cyber, cybersecurity, exploit, infrastructure, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. This vulnerability was added on August 26, 2026, and federal civilian agencies are required to apply vendor-recommended mitigations by August 29, 2026. Citrix…
-
CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability
Tags: cisa, cve, cyber, cybersecurity, exploit, infrastructure, kev, microsoft, rce, remote-code-execution, service, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution vulnerability affecting Microsoft SQL Server, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability allows an attacker to execute code in the security context of the SQL Server Database Engine service account. Microsoft SQL Server…
-
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, remote-code-execution, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.The vulnerabilities are listed below – CVE-2019-1068 – A remote code execution vulnerability in First seen on thehackernews.com Jump…
-
CrowdStrike Is ‘Cybersecurity’s Infrastructure Layer’ For AI Era: CEO George Kurtz
CrowdStrike has all the right elements to position its comprehensive Falcon platform as the go-to way to secure the usage of AI and agentic tools going forward, CrowdStrike CEO George Kurtz said Wednesday. First seen on crn.com Jump to article: www.crn.com/news/security/2026/crowdstrike-is-cybersecurity-s-infrastructure-layer-for-ai-era-ceo-george-kurtz
-
WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks
WordPress sites depend heavily on plugins to add functionality such as contact forms, file uploads, payment features, and integrations. But when a plugin mishandles uploaded files, a seemingly ordinary website feature can become a direct path to server compromise. According to Cybersecurity News, a critical vulnerability in the Everest Forms WordPress plugin has exposed more…
-
Medical device firm Boston Scientific says cyberattack has disrupted shipment processes
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday. First seen on therecord.media Jump to article: therecord.media/boston-scientific-cyberattack-disrupts-shipment-processes
-
Attackers Targeted Over 100 US Water Systems in July Hacks
CISA Guidance Reveals First Federal Count of July Water Sector Targeting. The U.S. Cybersecurity and Infrastructure Security Agency said it observed more than 100 internet-exposed water systems targeted in cyberattacks in July, most reached through programmable logic controllers wired directly to cellular modems, according to recent internet exposure reduction guidance. First seen on govinfosecurity.com Jump…

