π UK Legal Regulator Raises AI Misuse Concerns π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π’ Hacker claims to have stolen millions of Azure customer records from McDonaldβs, Vodafone, Kyndryl, and others β here's what we know so far π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
TheHatman claims the data has been stolen from the victims' Azure and Entra tenants using compromised credentials.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Hacker claims to have stolen millions of Azure customer records from McDonaldβs, Vodafone, Kyndryl, and others β here's what weβ¦
TheHatman claims the data has been stolen from the victims' Azure and Entra tenants using compromised credentials
ποΈ 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windowsbased information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below ubnuler ubnlder ri18nr reaker rakier orakw joxn.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server 158.220.87.79, hosted on a.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
SafePal has disclosed that an authorization flaw in an ordertracking plugin exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from securitysafepal.com, with the subject line "Important Your SafePal Order.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities KEV catalog, citing evidence of active exploitation. Ray is an opensource, Pythonnative distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Cyber Incident Disrupts Student Services at UT San Antonio π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π Three-quarters of Ransomware Attacks Target Mid-Market Firms π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Black Kite finds midmarket is the sweet spot for ransomware as manufacturers are most likely to be hit.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Three-quarters of Ransomware Attacks Target Mid-Market Firms
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
π AI SOC vs. SOAR: What the Architectural Difference Means for a Team Evaluating Both π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
AI SOC vs SOAR vs MDR explained by practitioners see how architecture decides breach outcomes. Discover which layer your team should run today. The post AI SOC vs. SOAR What the Architectural Difference Means for a Team Evaluating Both appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
AI SOC vs SOAR: What Every Security Team Must Know
AI SOC vs SOAR explained by practitioners: see how architecture decides breach outcomes. Discover which layer your team should run today.
π¦Ώ FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Federal court records show how far the FBIs Pegasus review progressed and why new US spyware reporting will still leave major gaps in government hacking transparency. The post FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight - TechRepublic
FBI Pegasus records reveal gaps in new US spyware oversight, showing what future court wiretap statistics may still fail to capture.
π΅οΈββοΈ 'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
'Ransom Busters': Ransomware Actor Poses as Recovery Service
A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.
ποΈ AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that selfpropagating payloads can spread from one artificial intelligence AI agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated sixagent coding.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmorhardened Python implant designed to operate its entire commandandcontrol infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π NASA Ground Control Software Flaw Enables Unauthenticated Commands π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Critical AITGUI flaws expose spacecraft commands and scripts to unauthenticated attackers.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
NASA Ground Control Software Flaw Enables Unauthenticated Commands
Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers
π₯1
π Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Enterprise Applications Carry 4.31x More Critical and High Vulnerabili
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds
π¦Ώ Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help. The post Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss - TechRepublic
Apple warns targeted users in 110 countries of mercenary spyware attacks as new iPhone alerts surface on the Lock Screen and in Settings.
π Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The security flaw in Snowflakes GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw
The security flaw in Snowflakeβs GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
π’ Why software supply chain security is the next accountability challenge for channel partners π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Partners need to be able to confidently answer key client questions relating to supply chain security going forward...π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
ChannelPro
Why software supply chain security is the next accountability challenge for channel partners
Partners need to be able to confidently answer key client questions relating to supply chain security going forward...
π΅οΈββοΈ China-Linked Hacker Shows AI Capabilities in APAC Attack π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
In the first purported "nearautonomous" attack on a nationstate, a Chineselanguage operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
π΅οΈββοΈ Critical GitLab Zero-Click Flaw Poses Mitigation Challenges π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
A lack of technical details could make it hard for organizations running selfmanaged GitLab versions to detect potential exploitation of CVE202619478.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
π΅οΈββοΈ 'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Researchers discovered a "metahacking" technique that can manipulate the AI service into revealing its own security weaknesses.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
'CoSnitch' Attack Tricked Copilot Into Revealing Own Architecture
Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.