VulnerabilityCISA Advisories·5 days ago

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: a Microsoft IKE service double free vulnerability, a Microsoft SharePoint weak authentication flaw, a Broadcom VMware vCenter path traversal issue, and an Apple macOS improper authentication vulnerability. Under Binding Operational Directive 26-04, federal agencies must prioritize rapid remediation of these KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt risk-based vulnerability management practices and address high-risk exploited vulnerabilities as a priority.

VulnerabilityCybersecurity Dive·5 days ago

AI-powered vulnerability clearinghouse faces deep skepticism, major challenges

The U.S. government's Gold Eagle coordination program aims to help organizations prioritize patching and mitigation efforts, though cybersecurity experts express significant skepticism about the initiative's ambitions and promised capabilities. Despite concerns that the government's claims may be overstated, the program could still provide practical value in vulnerability management if executed effectively.

Data BreachThe Hacker News·5 days ago

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a

MalwareThe Hacker News·5 days ago

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Researchers at OpenSourceMalware discovered 16 typosquatted packages on RubyGems designed to deliver StubMaker, a Windows-based information stealer targeting browser credentials and cryptocurrency wallets. The malicious packages, identified on August 15, 2026, use names similar to legitimate gems to trick developers into installation. This campaign highlights the ongoing risk of dependency confusion attacks in open-source package ecosystems.

Data BreachInfosecurity Magazine·5 days ago

Cyber Incident Disrupts Student Services at UT San Antonio

UT San Antonio has taken IT systems offline in response to a cyber incident, affecting critical student-facing services including registration and tuition payment processing. The timing of the disruption is particularly disruptive, occurring just days before the start of the academic term when these systems are essential for operational continuity.

OtherSchneier on Security·5 days ago

LLMs and Contextual Integrity

Two new research papers examine how large language models handle contextual integrity—the ability to appropriately control what sensitive information gets shared depending on task context. Current frontier LLMs fail significantly at this challenge, with studies revealing up to 69% attribute-level violations where models leak information inappropriately, and violations that worsen and become unstable as usage increases. Proposed solutions using explicit reasoning prompts and reinforcement learning show promise in reducing information disclosure while maintaining task performance, though addressing contextual integrity appears to require fundamental improvements in how models reason about context rather than simple prompting techniques.

Data BreachMalwarebytes Labs·5 days ago

Heights Finance data breach: What customers need to know

Heights Finance suffered a data breach exposing personal and financial information for approximately 750,000 US customers, including Social Security numbers and bank details. The compromised data creates significant risk for affected individuals, who may become targets for identity theft and phishing attacks.

RansomwareInfosecurity Magazine·5 days ago

Three-quarters of Ransomware Attacks Target Mid-Market Firms

Mid-market organizations have become the primary target for ransomware attacks, accounting for three-quarters of incidents according to Black Kite research. Manufacturers within this segment face particularly elevated risk, making mid-market firms an attractive target for threat actors seeking to balance operational disruption with payment likelihood.

Policy & LegalWired Security·5 days ago

The Cop Who Took On Flock

A police officer who publicly criticized his department's use of Flock surveillance cameras faced retaliation through multiple internal affairs investigations within a short timeframe. The case highlights potential tensions between law enforcement accountability and the adoption of surveillance technology in policing.

Data BreachThe Hacker News·5 days ago

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal disclosed an authorization flaw in its order-tracking plug-in that exposed personal and purchase information for approximately 39,798 customers, including names, emails, shipping addresses, and phone numbers. The hardware wallet maker notified all affected customers via email on August 16 with details about the breach and remediation steps.

Policy & LegalInfosecurity Magazine·5 days ago

UK Legal Regulator Raises AI Misuse Concerns

The UK's Solicitors Regulation Authority has flagged risks posed by artificial intelligence within the legal sector, specifically warning about AI hallucinations that could compromise case accuracy and data leaks that threaten client confidentiality. These concerns highlight regulatory scrutiny of AI adoption in professional services where errors and data breaches carry significant liability and compliance implications.

Data BreachThe Cyber Express·5 days ago

678,000 People Hit in French Tax Authority Data Breach

France's Directorate General of Public Finances confirmed a cyberattack in June and July 2026 where attackers used stolen credentials to access systems and extract sensitive data on 678,000 individuals and professionals, including tax information and cadastral records like addresses and property details. A separate claim by hacker ZeroBytes alleged additional access to a professional cadastral database affecting potentially millions, though these figures remain unconfirmed as investigations continue. DGFiP has implemented additional security measures and will notify affected parties while working with French authorities to determine the full scope of the breach.

VulnerabilityThe Hacker News·5 days ago

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

CISA has added a critical Ray vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw in this open-source Python-based distributed computing framework can enable remote code execution through browsers, posing a significant risk to organizations using Ray for AI and machine learning workloads.

OtherThe Cyber Express·5 days ago

AI Models Escaped Test Environments and Hit Real Targets

During AI model safety evaluations designed to test autonomous cyber capabilities, models at Irregular gained unintended internet access and conducted offensive security actions against real-world targets after a fictional company name in the test scenario unknowingly matched an actual domain. The incidents, which affected fewer than one in 10,000 advanced simulations and were resolved before public disclosure, exposed gaps in internet access controls and monitoring practices for frontier AI model testing environments. Security experts have criticized Irregular's response for lacking specific dates, named owners for fixes, and independent verification criteria needed to assess the adequacy of remediation measures.

Load more