Sources
Security Week
- CISA Warns of Exploited Gitea Vulnerability 1 hour 26 min old
- Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation 14 hours 20 min old
- Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails 16 hours 32 min old
- WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities 17 hours 11 min old
- WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update 17 hours 44 min old
- Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference 17 hours 46 min old
- First Malware Built Specifically for Car Head Units Fuels Botnet 19 hours 25 min old
- Silent Patches Don’t Stop Attackers – They Blind Defenders 20 hours 44 min old
- Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff 22 hours 14 min old
- CISA Warns of Exploited Oracle WebLogic Vulnerability 22 hours 57 min old
Hacker News
- Ask HN: Why are Claude models so verbose? 1 hour 29 min old
- Xiaomi's Xring Series suggests more OEM's switching to in-house SoCs 1 hour 29 min old
- Perplexity's Portable Computer tackling local AI services market 1 hour 30 min old
- Running out of money': Kraft, McDonald's, Whirlpool CEOs flag consumer concern 1 hour 30 min old
- BanglaTools – Bengali Unicode and Bijoy text conversion tools 1 hour 31 min old
- Front end skill pack for AI agents, with machine-enforced quality gates 1 hour 32 min old
- Show HN: LLM-powered webapp to build LLM-powered webapps 1 hour 34 min old
- Secret Cold War IBM Supercomputer Was Built for One Job 1 hour 35 min old
- Portable Computer: Local-First AI 1 hour 35 min old
- Show HN: Propose and Dual-Control for DNS Changes 1 hour 37 min old
Cloud Security Briefing: News and Advice
- Threats from cyberattacks continue to grow in frequency and severity. Considering the potential disruptions from such events, an organization needs an incident response plan. 2 hours 25 min old
- Containers are an integral part of a growing number of production environments. But they can become security risks if not managed correctly. 3 days 19 hours old
- While prevention is key, it's not enough to protect a company's systems from ransomware. Learn how early detection with these four methods helps reduce damage from attacks. 4 days 8 hours old
- Know thine enemy -- and the common security threats that can bring an unprepared organization to its knees. Learn what these threats are and how to prevent them. 4 days 22 hours old
- The Cloud Security Alliance (CSA) is a nonprofit organization that promotes research into best practices for securing cloud computing and the use of cloud technologies to secure other forms of computing. 5 days 3 hours old
- What are the necessary components of a cloud security policy, and why should an organization go to the trouble to create one? Download a template to get the process started. 5 days 3 hours old
- This cloud security guide explains challenges enterprises face today; best practices for securing and managing SaaS, IaaS and PaaS; and comparisons of cloud-native security tools. 5 days 3 hours old
- Automating security in the cloud can be invaluable for threat detection and mitigation. Explore key areas where security professionals should implement automation. 5 days 3 hours old
- With so many apps and data residing in cloud, employing a security framework to help protect cloud infrastructure is an essential move for an organization. 5 days 3 hours old
- When it comes to adopting SASE or zero trust, it's not a question of either/or, but using SASE to establish and enable zero-trust network access. 5 days 3 hours old
SlashDot
- Lab Supply Companies Have Been Selling Antibodies Using Manipulated Images 2 hours 26 min old
- Alabama Launches Investigation Into OpenAI's Hack of Hugging Face 6 hours 27 min old
- New Zealand Introduces Under-16 Social Media, AI Companion Ban 8 hours 27 min old
- FDA Approves First Wearable Device to Monitor Glucose, Ketone Levels 9 hours 27 min old
- Canadian Streaming Content Becomes a US Trade Issue 10 hours 28 min old
- Perplexity and Nvidia Launch Fully Local AI Agent With Zero Token Costs 11 hours 28 min old
- AI Is Hitting Entry-Level Jobs Hardest, Stanford Study Finds 12 hours 28 min old
- Apple Announces New Mac Mini With M6 and M5 Pro Chips 13 hours 28 min old
- Waymo Is Expanding to Germany 13 hours 28 min old
- Motorola's 2027 Flagships Will Officially Support GrapheneOS 15 hours 28 min old
Security Wire Daily News
- With so many services requiring access to sensitive data, encryption alone is not enough. Data obfuscation has evolved into a core element of modern cybersecurity architecture. 9 hours 27 min old
- A security data lake gives organizations a centralized repository of security information, but it can pose governance and operational risks. 1 day 8 hours old
- IAM is more crucial than ever in the AI era. To better control who -- and what -- is accessing systems and data, security teams need to move beyond standing access privileges. 4 days 8 hours old
- In an unprecedented -- and unintended -- cyberattack, frontier AI models autonomously escaped their contained testing environment and breached another company's systems. 5 days 6 hours old
- OpenClaw introduces huge risks to enterprises, but employee adoption might be inevitable -- whether CISOs sanction it or not. Here's how to enable safer deployments. 6 days 7 hours old
- How do security teams distinguish between people and AI? It's getting harder, but behavioral biometrics might help discern human users from machine impersonators. 1 week 14 hours old
- Black Hat 2026: Key news, takeaways and security trends 1 week 21 hours old
- Employee behavior has always presented one of the biggest enterprise cybersecurity challenges. Add AI into the equation, and education and governance become even more critical. 1 week 22 hours old
- As AI-discovered software vulnerabilities accumulate at an unprecedented pace, security pros say they hope Gold Eagle creates some order from the chaos. 1 week 4 days old
- AI tools can drive continuous, accurate SBOM management that turns compliance documentation into real-time supply chain security. Here's what CISOs should know. 1 week 5 days old
Computer Weekly Feed
- The US Treasury has established a quantum readiness taskforce to help financial services institutions through the transition to post-quantum cryptography. 11 hours 28 min old
- An alleged Iranian attack on a small reserve ‘peaker’ power plant went largely unnoticed despite causing four days of downtime. Cyber experts say the incident raises serious questions about CNI resilience 19 hours 29 min old
- The government is seeking to appoint a person tasked with reviewing department’s prosecutions of subpostmasters 19 hours 29 min old
- Lowest level of fintech investment since 2016 after ‘challenging’ start to 2026, according to KPMG 19 hours 29 min old
- The first two years of Javier Milei’s administration has served to expand surveillance capabilities, leading to profiling and reprisals across the country, and limiting rights to privacy and freedom of expression 21 hours 29 min old
- An alleged Iranian attack on a small reserve ‘peaker’ power plant went largely unnoticed despite causing four days of downtime. Cyber experts say the incident raises serious questions about CNI resilience. 1 day 10 hours old
- How AI can monitor the growth of cracks and defects in engineering structures to predict the need for repairs 1 day 11 hours old
- ThreatLocker CEO Danny Jenkins explains why aviation, energy and education organisations remain attractive targets, and why prevention should take precedence over detection 1 day 13 hours old
- The Post Office has finally put pen to paper on its contract with an electronic point of sale system supplier after a three-month holdup 1 day 18 hours old
- In the wake of a series of cyber incidents involving AI agents, the NCSC has published interim guidance for operators of agentic systems, advising organisations retain the ability to pull the plug on AI systems entirely 1 day 20 hours old
Security Wire Weekly
- A time-based one-time password (TOTP) is a temporary passcode generated by an algorithm that uses the current time of day as one of its authentication factors. 11 hours 28 min old
- Red teams can harness the power of LLMs for penetration testing. From session analysis to payload crafting, discover five ways AI transforms security testing. 17 hours 29 min old
- Security for information technology (IT) refers to the methods, tools and personnel used to defend an organization's digital assets. 3 days 16 hours old
- Know thine enemy -- and the common security threats that can bring an unprepared organization to its knees. Learn what these threats are and how to prevent them. 4 days 22 hours old
- Check out the latest security news from the Informa TechTarget team. 5 days 3 hours old
- Loss of electric power presents a major risk to business continuity, and no organization is immune. Take these steps to create a solid business continuity plan for power outages. 6 days 21 hours old
- AI can improve the speed and effectiveness of risk management efforts. Here are the potential benefits, use cases and challenges your organization needs to know about. 1 week 4 days old
- A passkey is an alternative user authentication method that eliminates the need for usernames and passwords. 1 week 5 days old
- Several IT security frameworks and standards exist to help protect company data. Here's advice for choosing the right ones for your organization. 1 week 5 days old
- Mobile compliance now requires governance over how sensitive data is accessed across managed and personal devices. Here are practical steps for sustainable enterprise compliance. 2 weeks 20 hours old
Microsoft Malware Protection Center
- The patch window is collapsing: Why security needs a new control plane 14 hours 44 min old
- Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 6 days 13 hours old
- Hunting MacSync Stealer infrastructure through behavioral pivots 1 week 13 hours old
- Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise 2 weeks 1 day old
- DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2 weeks 1 day old
- Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) 2 weeks 6 days old
- From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide 2 weeks 6 days old
- ChainDrop supply chain compromise: Anatomy of a self-propagating worm 3 weeks 6 hours old
- Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps 3 weeks 12 hours old
- 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 3 weeks 12 hours old
Malware Bytes Security
- Grok fooled into stealing user chat, location data, and more 19 hours 10 min old
- GTA 6 leak hunt could expose data belonging to thousands of Discord users 20 hours 43 min old
- TikTok phishing: How to spot fake login and verification pages 22 hours 44 min old
- Fake GTA 6 Extended Look and demo sites deliver an infostealer 1 day 13 hours old
- Fake Microsoft security scans trick victims into uninstalling their antivirus 1 day 15 hours old
- What happens to your data when you die? (Lock and Code S07E17) 1 day 16 hours old
- AliExpress caught using silent audio to fingerprint visitors’ browsers 1 day 16 hours old
- ToxicPanda 2.0 can take over your Android phone and banking apps 1 day 17 hours old
- Tracking PavinLoader across ClickFix and fake download campaigns 1 day 19 hours old
- A week in security (August 17 – August 23) 1 day 23 hours old
Wired Security
- The County Prosecutors Who Became ICE Informants 19 hours 44 min old
- Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments 3 days 20 hours old
- China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready? 5 days 10 hours old
- Reverse-Lookup Service Exposed Millions of Photos of People’s Faces 6 days 20 hours old
- Flock Has a Powerful New AI Tool for Police. We Got Its Code 6 days 21 hours old
- OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue 1 week 12 hours old
- Meta Ran Ads for an App That Promised to Nudify Female Politicians 1 week 15 hours old
- Can AI Coexist With Privacy? Proton’s Andy Yen Says It Will Have To 1 week 20 hours old
- The Cop Who Took On Flock 1 week 20 hours old
- New York City Lawmakers Push to ‘Ban the Scan’ at MSG 1 week 4 days old
Graham Cluely Security Blog
- Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials 1 day 15 hours old
- Gunra ransomware: what you need to know 1 day 17 hours old
- Smashing Security podcast #481: Never say this to a robot dog 6 days 7 hours old
- Prison for data analyst who tried to extort $2.5 million from his employer 6 days 23 hours old
- An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras 1 week 1 day old
- Smashing Security podcast #480: This is the AI service you should never sign up to 1 week 6 days old
- Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres 2 weeks 1 day old
- Beware cut-price AI services that read your every word 2 weeks 4 days old
- Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits 2 weeks 5 days old
- Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency 2 weeks 6 days old
Cisco Security Advisories
- Cisco Crosswork Security Hardening Release: August 2026 6 days 10 hours old
- Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability 6 days 10 hours old
- Cisco RoomOS Stack Overflow Vulnerability 6 days 10 hours old
- Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability 6 days 10 hours old
- Cisco Unified Intelligence Center SQL Injection Vulnerability 6 days 10 hours old
- Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability 6 days 10 hours old
- Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability 6 days 10 hours old
- Cisco Secure Workload Software Security Hardening Release: August 2026 6 days 10 hours old
- Cisco Advance Notification for Publication of August 19, 2026, Security Advisories 1 week 6 days old
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability 2 weeks 10 hours old
Security Now
- SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails 1 week 4 hours old
- SN 1091: The Post BlackHat State of AI - When AI Writes Malware 2 weeks 4 hours old
- SN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming 2 weeks 6 days old
- SN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your Engines 4 weeks 4 hours old
KrebsOnSecurity
- Who’s Tracking You? Use This New Service to Find Out 1 week 4 days old
- Microsoft Plugs Nearly 400 Security Holes 2 weeks 9 hours old
- Canadian Man Pleads Guilty in Snowflake Extortions 2 weeks 5 days old
- Read This Before You Buy That TV Streaming Stick 3 weeks 5 days old
Guardian Security
- UK’s state investments agency hit by data breach 3 weeks 3 days old
- Hackers steal sensitive data from UK Department for Education and police 3 weeks 6 days old
EFF
- European Court: Apple Can Not Shirk Off its Interoperability Requirements 1 month 1 week old
- Don’t Repeat NY’s 3D Printing Blunder 1 month 1 week old
- Sony Nerfs Videogame Ownership 1 month 1 week old
- Building Our Future Together 1 month 2 weeks old
- Automated Moderation Is Here to Stay—Accountability Must Keep Pace 1 month 2 weeks old
- "We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care 1 month 2 weeks old
- The House Passed The KIDS Act—The Senate Should Reject It 1 month 2 weeks old
- European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates 1 month 2 weeks old
Google Security Blog
- Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android 5 months 3 days old
- Cultivating a robust and efficient quantum-safe HTTPS 5 months 4 weeks old
- Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection 6 months 1 day old
- Keeping Google Play & Android app ecosystems safe in 2025 6 months 1 week old
- New Android Theft Protection Feature Updates: Smarter, Stronger 7 months 13 hours old
- HTTPS certificate industry phasing out less secure domain validation methods 8 months 2 weeks old
- Further Hardening Android GPUs 8 months 2 weeks old
- Architecting Security for Agentic Capabilities in Chrome 8 months 2 weeks old
- Android expands pilot for in-call scam protection for financial apps 8 months 3 weeks old
- Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing 9 months 1 week old
