OtherMicrosoft Security Blog·4 days ago

Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog.

Nation-StateDark Reading·4 days ago

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A China-linked APT group associated with FamousSparrow is conducting spear-phishing campaigns targeting Central Asian organizations to distribute multiple remote access trojans, reflecting broader geopolitical objectives in the region. The SilkParasite campaign demonstrates how Chinese threat actors combine social engineering with RAT deployment to establish persistent access in strategically important territories.

VulnerabilityRapid7 Blog·4 days ago

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-19490 is a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway with a CVSS score of 9.3 that can be exploited remotely by unauthenticated attackers without user interaction. The vulnerability impacts NetScaler ADC and Gateway versions 14.1 prior to 14.1-73.32 and 13.1 prior to 13.1-63.21, along with affected FIPS variants, and organizations should prioritize emergency patching given the high-value nature of these perimeter-deployed systems and their history of rapid exploitation.

Policy & LegalCyberScoop·4 days ago

A California county wants to hire Tina Peters to help run its elections

After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop.

OtherWiz Blog·4 days ago

Wiz Penetration Test Findings is now GA

Wiz has released its Penetration Test Findings capability to general availability, enabling organizations to move beyond traditional one-time pen tests by integrating findings into continuous exposure management workflows. The unified platform merges penetration test results with real-time cloud context to provide ongoing visibility into vulnerabilities and exposures across cloud environments.

VulnerabilityInfosecurity Magazine·4 days ago

Exclusive: Linux Foundation's Akrites to Go Live in September

The Linux Foundation's Akrites initiative is set to launch operationally in September, enabling the submission of AI-generated vulnerability reports for open-source projects. This new system represents an effort to streamline vulnerability disclosure processes for the open-source community through automated analysis capabilities.

MalwareInfosecurity Magazine·4 days ago

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra

eSentire has identified a coordinated malware campaign that leverages ClickFix social engineering lures alongside the ErrTraffic and Cruciferra malware families. The combination of these attack components suggests a sophisticated malware-as-a-service operation designed to increase infection rates and evasion capabilities. This integrated approach demonstrates an evolution in threat delivery tactics where multiple malware families are deployed together to maximize impact.

Data BreachCyberScoop·4 days ago

The long tail of Clop’s PTC hack is just beginning to emerge

Clop data theft extortion group likely exploited a critical vulnerability in PTC's product lifecycle management software in June, with threatening extortion emails following a month later. The full scope of compromised data and affected organizations is still emerging in the aftermath of the incident.

VulnerabilitySANS Internet Storm Center·4 days ago

Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)

Attackers can exploit the cloud metadata service accessible at 169.254.169.254 to retrieve sensitive credentials and IAM role tokens from virtual machines, beyond just benign instance information like region and IP addresses. Cloud providers expose this REST API by design to allow running code access to machine-specific data, but the credential exposure risk makes it an attractive target for adversaries seeking to escalate privileges or move laterally within cloud environments.

MalwareInfosecurity Magazine·4 days ago

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

Grandoreiro malware has resumed operations following its disruption earlier in 2024, demonstrating continued viability despite law enforcement action. The campaign shows a geographic shift with Mexico representing a disproportionate 40% of current detections, suggesting a targeted focus on the region.

VulnerabilityQualys·4 days ago

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle's August 2026 Critical Patch Update addressed 943 security vulnerabilities across multiple product families, with some vulnerabilities affecting more than one product. Oracle Fusion Middleware and Oracle Hyperion received the most patches in this release with 262 each, while the update also included fixes for third-party components integrated into Oracle products.

Nation-StateThe Hacker News·4 days ago

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A previously unreported espionage campaign called SilkParasite has been targeting Central Asian government entities using seven RAT families, five of which are newly discovered: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. First identified in late 2025, the intrusion set represents a significant expansion in the threat landscape for the region, introducing multiple previously undocumented remote access capabilities.

VulnerabilityCISA Advisories·4 days ago

Defending Against an Active Threat to Siemens S7 Series PLCs

Federal agencies including CISA, NSA, and FBI have issued a joint advisory warning of active exploitation of Internet-exposed Siemens S7 Series PLCs across critical infrastructure sectors using AI-generated exploitation scripts that masquerade as legitimate monitoring tools. Threat actors are leveraging internet scanning services to identify vulnerable installations running outdated software and using open-source industrial automation libraries combined with AI assistance to develop custom exploitation tools that can read and write to PLC memory and configuration data via the S7comm protocol. Organizations are urged to immediately inventory their S7 Series PLCs, apply critical security patches, isolate PLCs from Internet access, strengthen access controls, and deploy ICS-aware monitoring to detect unauthorized S7comm activity and anomalous behavior patterns.

VulnerabilityCISA Advisories·4 days ago

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-64849, an MLflow Server-Side Request Forgery vulnerability, to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. Federal agencies are required under Binding Operational Directive 26-04 to prioritize rapid remediation of vulnerabilities listed in the KEV Catalog, particularly those on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices. Organizations aware of other exploited vulnerabilities can submit them for KEV Catalog consideration if they include a CVE ID, exploitation evidence, and mitigation guidance.

OtherRapid7 Blog·4 days ago

Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America

Rapid7 has partnered with Licencias OnLine to expand distribution of its AI-powered cybersecurity operations platform across Latin America, addressing the region's growing security challenges from cloud adoption and digital transformation. The partnership will provide technical training, partner enablement, and go-to-market support to help organizations reduce attack surface blind spots and strengthen their security operations maturity.

Load more