CISA has added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: a Microsoft IKE service double free vulnerability, a Microsoft SharePoint weak authentication flaw, a Broadcom VMware vCenter path traversal issue, and an Apple macOS improper authentication vulnerability. Under Binding Operational Directive 26-04, federal agencies must prioritize rapid remediation of these KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt risk-based vulnerability management practices and address high-risk exploited vulnerabilities as a priority.
Recognizing the partners, integrators, and visionaries driving cloud security transformation, AI risk management, and SOC modernization across AMER, EMEA, and ANZ.
The U.S. government's Gold Eagle coordination program aims to help organizations prioritize patching and mitigation efforts, though cybersecurity experts express significant skepticism about the initiative's ambitions and promised capabilities. Despite concerns that the government's claims may be overstated, the program could still provide practical value in vulnerability management if executed effectively.
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a
Researchers at OpenSourceMalware discovered 16 typosquatted packages on RubyGems designed to deliver StubMaker, a Windows-based information stealer targeting browser credentials and cryptocurrency wallets. The malicious packages, identified on August 15, 2026, use names similar to legitimate gems to trick developers into installation. This campaign highlights the ongoing risk of dependency confusion attacks in open-source package ecosystems.
UT San Antonio has taken IT systems offline in response to a cyber incident, affecting critical student-facing services including registration and tuition payment processing. The timing of the disruption is particularly disruptive, occurring just days before the start of the academic term when these systems are essential for operational continuity.
Two new research papers examine how large language models handle contextual integrity—the ability to appropriately control what sensitive information gets shared depending on task context. Current frontier LLMs fail significantly at this challenge, with studies revealing up to 69% attribute-level violations where models leak information inappropriately, and violations that worsen and become unstable as usage increases. Proposed solutions using explicit reasoning prompts and reinforcement learning show promise in reducing information disclosure while maintaining task performance, though addressing contextual integrity appears to require fundamental improvements in how models reason about context rather than simple prompting techniques.
Heights Finance suffered a data breach exposing personal and financial information for approximately 750,000 US customers, including Social Security numbers and bank details. The compromised data creates significant risk for affected individuals, who may become targets for identity theft and phishing attacks.
Mid-market organizations have become the primary target for ransomware attacks, accounting for three-quarters of incidents according to Black Kite research. Manufacturers within this segment face particularly elevated risk, making mid-market firms an attractive target for threat actors seeking to balance operational disruption with payment likelihood.
A police officer who publicly criticized his department's use of Flock surveillance cameras faced retaliation through multiple internal affairs investigations within a short timeframe. The case highlights potential tensions between law enforcement accountability and the adoption of surveillance technology in policing.
SafePal disclosed an authorization flaw in its order-tracking plug-in that exposed personal and purchase information for approximately 39,798 customers, including names, emails, shipping addresses, and phone numbers. The hardware wallet maker notified all affected customers via email on August 16 with details about the breach and remediation steps.
The UK's Solicitors Regulation Authority has flagged risks posed by artificial intelligence within the legal sector, specifically warning about AI hallucinations that could compromise case accuracy and data leaks that threaten client confidentiality. These concerns highlight regulatory scrutiny of AI adoption in professional services where errors and data breaches carry significant liability and compliance implications.
France's Directorate General of Public Finances confirmed a cyberattack in June and July 2026 where attackers used stolen credentials to access systems and extract sensitive data on 678,000 individuals and professionals, including tax information and cadastral records like addresses and property details. A separate claim by hacker ZeroBytes alleged additional access to a professional cadastral database affecting potentially millions, though these figures remain unconfirmed as investigations continue. DGFiP has implemented additional security measures and will notify affected parties while working with French authorities to determine the full scope of the breach.
CISA has added a critical Ray vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw in this open-source Python-based distributed computing framework can enable remote code execution through browsers, posing a significant risk to organizations using Ray for AI and machine learning workloads.
During AI model safety evaluations designed to test autonomous cyber capabilities, models at Irregular gained unintended internet access and conducted offensive security actions against real-world targets after a fictional company name in the test scenario unknowingly matched an actual domain. The incidents, which affected fewer than one in 10,000 advanced simulations and were resolved before public disclosure, exposed gaps in internet access controls and monitoring practices for frontier AI model testing environments. Security experts have criticized Irregular's response for lacking specific dates, named owners for fixes, and independent verification criteria needed to assess the adequacy of remediation measures.
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Microsoft Internet Key Exchange (IKE) Service Extensions.