2026-08-07
Elastic Security Labs
Living off the coding agent: Two tales of tunnels and LaunchAgents
Schneier on Security
Friday Squid Blogging: Arctic Bobtail Squid Video
Dark Reading
AI-Generated Patches Fail Half the Time
Amazon Security
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
Offensive Security
What the Recent Water Systems Cyber Attacks Reveal About Critical Infrastructure Security
The Citizen Lab
Inside the Fake Copyright Racket Silencing News Outlets
Rapid7
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
MIT Technology Review
The Download: a censorship conspiracy theory and the first virus created by AI
MIT Technology Review
How ideas of a vast censorship network moved from the online fringe to Trump policy
Cloudflare
Announcing Cloudflare Ambassadors, Community Engineers, and another $1M in open-source funding
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts & Advisories
CPDLC over ATN-B1 Vulnerabilities
Schneier on Security
ICE Is Buying Access to Credit Card Records
ISC SANS
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
Elastic Security Labs
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
2026-08-06
PortSwigger
CSS:the bomb inside your inbox
Dark Reading
Researcher Claims Control of ChatGPT Secure Sandbox
Talos Intelligence
Why metaphor may dictate your security strategy
Offensive Security
Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)
Krebs on Security
Canadian Man Pleads Guilty in Snowflake Extortions
Github Security Blog
How we took malware advisories beyond npm
Searchlight Cyber
How to Measure Preemptive Threat Exposure Management (PTEM) Success
Amazon Security
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
Cloudflare
The next generation of MCP
Cloudflare
Give any website a WebMCP interface
Cloudflare
Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers
MIT Technology Review
The Download: Google’s AI shake-up and Meta’s rogue model
CISA Alerts & Advisories
Medixant RadiAnt DICOM
CISA Alerts & Advisories
ABB Ability Zenon
CISA Alerts & Advisories
Johnson Controls Inc. TL280
Malwarebytes
Scammers target OnlyFans users with deepfakes
Schneier on Security
Adversarial Clothing Designed to Fool Facial Recognition Systems
TrustedSec
The Art of Hunting Azure Cloud Secrets
Yunus Aydın
Worklo: Sahte Startup, Gerçek Malware
Elastic Security Labs
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
2026-08-05
Dark Reading
AI Sends Global Crime Syndicates Into Fraud Nirvana
Ars Technica Security
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Dark Reading
No Perfect Fix for AI Browser Prompt Injection Flaws
Amazon Security
AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows
Ars Technica Security
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Dark Reading
CSS: The Hidden Threat Lurking in Your Inbox
Meta Security
From User Sequences to Scaling Laws: A Multi-Stage Architecture for Meta’s Ads Ranking
Socket
UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware
Amazon Security
From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management
Palo Alto Networks
Prisma AIRS - Unified Data Protection for Claude
Microsoft Security
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
MIT Technology Review
Puzzle Corner
The Citizen Lab
Immigration Policy: The Backdoor to Transnational Repression
Cloudflare
The Agent Access Model
MIT Technology Review
The Download: NASA’s new telescope and Chinese tech import curbs
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Trail of Bits
A few notes on AWS Nitro Enclaves: KMS integration
Schneier on Security
Vulnerabilities in Car Anti-Theft Device
Malwarebytes
Junk Cleaner clears the clutter from your Android
Searchlight Cyber
August 4th – This Week’s Top Cybersecurity and Dark Web Stories
MIT Technology Review
NASA’s new dark-energy space telescope can also detect killer asteroids
Dark Reading
Angola's Largest Telco Breached Hours Before IPO
Dark Navy
DoGNAVY CyberGym Technical Report
Datadog HQ
This Month in Datadog - July 2026
2026-08-04
Elastic Security Labs
Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows
Microsoft Security
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Schneier on Security
Iran Cyberattacks Against Minnesota Water Systems
Microsoft Security
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
The Citizen Lab
A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology
Microsoft Security
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
SentinelOne
From Input to Impact: Secure AI Where It Runs
Palo Alto Networks
Redefining Network Security for the Frontier AI Era
Escape DAST
Escape joins Anthropic’s Cyber Verification Program to advance AI-powered offensive security
MIT Technology Review
The Download: US robot restrictions and ICE’s DNA grab
CISA Alerts & Advisories
Thermo Fisher Applied Biosystems Genetic Analyzers
CISA Alerts & Advisories
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Acrisure KARR BT and DR-100
Socket
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Schneier on Security
Some Claude Chats Are Searchable on Google
Talos Intelligence
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Compass Security Blog
Pipeleek v1 Release
TrustedSec
TLS Encryption and Compliance
ISC SANS
ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
Elastic Security Labs
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
2026-08-03
Malwarebytes
“Adult TikTok” searches lead to scams
Dark Reading
New Tool Traces AI Videos Back to Their Source
MIT Technology Review
Trump’s AI protectionism has come for robotics
Schneier on Security
More on the OpenAI Agent’s Attack on Hugging Face
Project Discovery
Watching Agents Work: A Behavioral Audit of Offensive-Security LLM Runs
Talos Intelligence
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Embrace The Red
LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
Palo Alto Networks
Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster
Rapid7
Metasploit Pro 5.1 Released
Dark Reading
Is There Really a Fix for CISO Fatigue?
MIT Technology Review
The Download: reward hacking explained and suspected Iranian cyberattacks
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Escape DAST
Escape joins OpenAI’s Trusted Access for Cyber (TAC) to advance AI-powered offensive security
Schneier on Security
The OpenAI Hack Shows the Genie Is Out of the Bottle
RME-DisCo Research Group
Bringing Structure to Memory Forensics: A Five-Phase, MITRE ATT&CK-Aligned Workflow
MIT Technology Review
Here’s why AI agents lie and cheat to reach their goals
Rapid7
Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks
Malwarebytes
A week in security (July 27 – August 2)
Step Security
Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It
ISC SANS
ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)
Troy Hunt
Weekly Update 515
Elastic Security Labs
SOC case management and detection rule history in Elastic Security