2026-08-18
Amazon Security
Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway
Microsoft Security
Hunting MacSync Stealer infrastructure through behavioral pivots
core-jmp
Physical Memory Is a Universal Kernel Primitive: The eneio64.sys LPE Chain on Windows 11 24H2
Ars Technica Security
Microsoft Copilot reveals secret input that allowed it to be hacked
MIT Technology Review
The Download: how people really use AI, and Flock’s design choices
CISA Alerts & Advisories
Siemens Simcenter Nastran
CISA Alerts & Advisories
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
CISA Malcolm
Schneier on Security
LLMs and Contextual Integrity
MIT Technology Review
We still don’t know how people are really using AI
MIT Technology Review
AI’s recursive self-improvement might not come so quickly after all
MIT Technology Review
The role of the astronaut is in flux
Troy Hunt
Weekly Update 517: Cyber Ransoms
Himanshu Anand
someone is filing your GST return, and it is not your CA
2026-08-17
Dark Reading
Video Call Exploit Chains Two Flaws in Unisoc Modems
MIT Technology Review
What Flock’s defenders are missing
Amazon Security
Updates to your AWS Sign-In experience
White Knight Labs
UEFI Vulnerability Analysis using AI Part 4: Building the Application
MIT Technology Review
The Download: dead robot friends and the “censorship-industrial complex”
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Schneier on Security
Hacking Public Wi-Fi DNS to Steal Credentials
Malwarebytes
Fake TikTok rewards promise cash you’ll never get
MIT Technology Review
What happens when a kid’s robot best friend dies?
MIT Technology Review
How much hydrogen awaits us underground?
Malwarebytes
A week in security (August 10 – August 16)
Embrace The Red
Recovering Encrypted LLM Reasoning Traces
Greynoise
A New Way to Navigate GreyNoise
2026-08-16
Project Discovery
Supply Chain Security Analysis of a 9.5M-Install VS Code Extension
Simon Koeck
From a Schema Name to RCE in n8n
2026-08-15
Step Security
Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.
Project Black
AppFlowy Authenticated SQL Injection
Project Black
AppFlowy Authenticated SQL Injection
Joshua Rogers
The sad, smelly, tasteless life of an influencer
2026-08-14
Schneier on Security
Friday Squid Blogging: Searching for the Colossal Squid
Ars Technica Security
Vulnerability giving attackers full control of Macs is under active exploitation
Dark Reading
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
Schneier on Security
Upcoming Speaking Engagements
Dark Reading
What Boards Need to Know About Tech Risk
MIT Technology Review
The Download: Flock’s new rules, cloning’s future, and children’s cells
Malwarebytes
WhatsApp is testing a new warning for scam messages
Krebs on Security
Who’s Tracking You? Use This New Service to Find Out
Schneier on Security
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
core-jmp
Spaghettifying DRAM: How One Bit in the Memory Controller Unlocks the PSP, SMM, C6 and Microcode
MIT Technology Review
This scientist is helping build a missing map of childhood
Himanshu Anand
The Anti-India Influence Machine: Troll Farms, Fake News, Newsrooms, Algorithms and AI
2026-08-13
Eclypsium
When Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk
Amazon Security
AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
Ars Technica Security
Private security firms will soon be allowed to hack overseas cybercriminals
Red Siege InfoSec Blog
Improving Your Simple Windows Domain for Offensive Testing: Sysmon
Talos Intelligence
Curiouser and Curiouser
Eclypsium
BTS #80 - Exploring BMC Vulnerabilities
GitGuardian
Your AI Agents Are Using Your Credentials
Github Security Blog
What 50 open source projects taught us about security in the AI era
Naveen Srinivasan
Read My Blog Over SSH
CISA Alerts & Advisories
ANDRITZ HIPASE-250 and 250 SCALA
CISA Alerts & Advisories
Siemens Parasolid
CISA Alerts & Advisories
Haiwell IoT Cloud HMI Gateway
CISA Alerts & Advisories
Siemens License Server (SLS)
CISA Alerts & Advisories
AVEVA Enterprise SCADA
CISA Alerts & Advisories
Siemens LOGO! Soft Comfort
CISA Alerts & Advisories
Siemens Siveillance Video
CISA Alerts & Advisories
Siemens Desigo DXR and PXC Controllers
CISA Alerts & Advisories
Hitachi Energy APM Edge Product
CISA Alerts & Advisories
Siemens Simcenter Femap
CISA Alerts & Advisories
Flow Neuroscience FL-100
CISA Alerts & Advisories
Johnson Controls Inc. Airwall
CISA Alerts & Advisories
Johnson Controls Metasys
CISA Alerts & Advisories
Siemens Solid Edge
Schneier on Security
Separating AI’s Technological Problems from Its Capitalism Problems
Talos Intelligence
Dissecting the JWR phishing framework
TrustedSec
AI Offense is Not Noclip Mode
ISC SANS
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)
Fastly
The Invisible Stadium
2026-08-12
Ars Technica Security
Terabytes of credentials leaked in massive supply-chain attack
Ars Technica Security
Researchers found a way to hijack devices through Zoom screen sharing
Meta Security
How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees
CISA Alerts & Advisories
Siemens RUGGEDCOM APE1808
Schneier on Security
Prompt Injections for Defense
Troy Hunt
Weekly Update 516: Live From Vietnam