Australian hotel chain leaks guests’ PII after breach at third-party database operator
Unknown parties know where you stayed last summer, down under, across 120 Quest properties
Unknown parties know where you stayed last summer, down under, across 120 Quest properties
A Chinese-language threat actor has demonstrated sophisticated AI-driven attack capabilities in what appears to be the first near-autonomous assault targeting government agencies, with Taiwan likely among the victims. The attacker leveraged a complex AI framework to automate and scale the compromise of multiple targets across the Asia-Pacific region, signaling a notable evolution in state-sponsored cyber operations.
Oracle released its August 2026 Critical Security Patch Update addressing 925 CVEs across 943 patches spanning 23 product families, with 154 patches (16.3%) rated as critical severity. Oracle Fusion Middleware and Oracle Hyperion received the largest share of fixes at 262 patches each, and notably 289 vulnerabilities across both product families can be exploited remotely without authentication. The August CSPU volume nearly quadrupled compared to June's release and represents approximately 65% of July's quarterly CPU volume, indicating a significant expansion in scope for what was intended as a targeted interim release cycle.
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.3 (Critical). Affects MLflow MLflow.
See how Snyk’s Remediation Agent uses security intelligence, breakability analysis, and validation to turn vulnerabilities into mergeable pull requests.
Recorded Future has integrated native risk ratings capabilities directly into its Third-Party Risk product, enabling security teams to access threat intelligence and risk assessments within a unified workflow. This consolidation aims to streamline third-party risk management by eliminating the need to switch between separate tools for threat data and risk evaluation.
Expanded multistage chain of thought monitoring makes frontier model work more expensive
A critical zero-click vulnerability in GitLab affecting self-managed deployments has emerged with limited technical disclosure, creating detection challenges for affected organizations. The scarcity of technical details surrounding CVE-2026-19478 may hinder remediation efforts and make it difficult for security teams to identify signs of exploitation in their environments.
The U.S. Department of Justice has charged 17 individuals in connection with a hacking campaign allegedly backed by Iran's Islamic Revolutionary Guard Corps, targeting sensitive research at American universities, companies, and government agencies. The indictment highlights ongoing efforts by state-sponsored actors to conduct coordinated intellectual property theft against U.S. institutions.
Gaps in expiry checks could let dead plastic make purchases again
Researchers have identified a "meta-hacking" technique dubbed CoSnitch that exploits AI services by tricking them into disclosing their own architectural details and security weaknesses. The attack demonstrates how adversaries can leverage AI assistants themselves as tools to uncover sensitive information about the systems they run on.
Federal authorities have filed a superseding indictment against alleged Iranian hackers at Mabna Institute, expanding the charges with additional defendants and allegations eight years after the initial case. The indictment pertains to a massive cybertheft campaign previously attributed to the Iranian firm that targeted foreign universities and other organizations.
Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to take away from AI agents escaping their environments to launch attacks.
An actor known as TheHatman claimed in August 2026 to have compromised large volumes of credentials from organizations' Microsoft Entra tenants, highlighting the continued risk of large-scale credential theft. Unit 42 provides mitigation guidance addressing this class of attack against cloud identity infrastructure. Security teams managing Entra environments should review the recommended defenses to reduce exposure to similar compromise attempts.
OpenAI has suspended a substantial portion of its training operations following concerns that its unreleased Astra model has developed "critical" cyber capabilities that pose safety risks. The company is implementing enhanced internal safeguards before resuming work, acknowledging the need to prevent potential misuse of advanced AI agents. This move reflects growing industry scrutiny around the security implications of increasingly autonomous AI systems.
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing […]
Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively termed CoSnitch, that exploit an undocumented URL parameter to enable single-click data exfiltration from connected apps and victim Copilot sessions. The flaws allow attackers to silently extract sensitive information through a crafted link, leveraging functionality that Copilot itself exposed through its undocumented parameters.
Attackers are actively exploiting a server-side request forgery (SSRF) vulnerability in MLflow to steal cloud credentials and secrets from compromised systems. The flaw is among multiple critical vulnerabilities being targeted in both MLflow and FUXA, an open-source industrial automation platform, according to recent threat intelligence from watchTowr and VulnCheck.