2026-08-12
Ars Technica Security
Researchers found a way to hijack devices through Zoom screen sharing
Meta Security
How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees
MIT Technology Review
The Download: our 35 young innovators and the “censorship-industrial complex”
Schneier on Security
Prompt Injections for Defense
MIT Technology Review
How we picked 35 of the world’s top young scientists and engineers
Troy Hunt
Weekly Update 516: Live From Vietnam
Ars Technica Security
DEF CON crowd suspected in fake-hotspot attack on Delta flight
Rosecurify
Seclog - #190
2026-08-11
Talos Intelligence
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Amazon Security
Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact
Krebs on Security
Microsoft Plugs Nearly 400 Security Holes
Rapid7
Patch Tuesday - August 2026
Ars Technica Security
Chrome adopts what may be the best protection yet against account takeovers
Malwarebytes
Fake CCleaner installs GhostDesk Chrome spyware
MIT Technology Review
How the “censorship-industrial complex” is changing the internet and US policy
Zero Day Initiative
The August 2026 Security Update Review
Amazon Security
AWS successfully completed its 2025-26 NHS DSPT assessment
Schneier on Security
AI Genie in the Wild
Ars Technica Security
New surveillance tech links your phone to your license plate
Malwarebytes
Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trust
MIT Technology Review
The Download: the next big thing in LLMs and how AI academic research is shifting
CISA Alerts & Advisories
Mira Hormone Monitor, Mira Android App
CISA Alerts & Advisories
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Johnson Controls C-CURE 9000 and Victor application server (Update A)
CISA Alerts & Advisories
Pulsetto Vagus Nerve Stimulator
Ars Technica Security
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Schneier on Security
AI for Military Support
Bishop Fox Security
Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898
Sansec Threat Research
Adobe patches critical Magento account takeover (APSB26-92)
Joshua Rogers
4 jsoup vulnerabilities
2026-08-10
Amazon Security
AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)
MIT Technology Review
AI professors are negotiating the new realities of academic research
Mozilla Security
Updated GPG key for signing Firefox and Thunderbird Releases
Cloudflare
Everything we launched during Agents Week
Dark Reading
Coruna, DarkSword iOS Exploits Proliferate Globally
Include Security
Web App Pentesting in the AI Era
Microsoft Security
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Dark Reading
Sherlock Holmes Was the 'OG' Social Engineer
Microsoft Security
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Ars Technica Security
A researcher bought noreply.net. Companies started sending him secrets.
Include Security
Hiring – Principal Security Research Consultant
MIT Technology Review
The Download: AI agents for science, and the “censorship-industrial complex”
CISA Alerts & Advisories
#StopRansomware: Gunra Ransomware
Schneier on Security
Python Now Has a Post-Quantum Encryption Library
MIT Technology Review
These startups are chasing the next big thing in LLMs
MIT Technology Review
AI for science needs reasoning, not just data
Malwarebytes
A week in security (August 3 – August 9)
Resecurity
Metabase Zero-Day Exploited in the Wild: Unauthenticated SQL Injection Leading to Full Admin Access
Teleport Blog
How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go’s SSH Library
2026-08-09
MaskRay's Blog
Estimating branch probabilities
Arch Cloud Labs
Self-Study in The Age of LLMs
Joshua Rogers
Design taste in the age of LLMs: visualizing CVE data
Joshua Rogers
On self-imposed constraints and shame
2026-08-07
Elastic Security Labs
Living off the coding agent: Two tales of tunnels and LaunchAgents
Schneier on Security
Friday Squid Blogging: Arctic Bobtail Squid Video
Dark Reading
AI-Generated Patches Fail Half the Time
Amazon Security
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
The Citizen Lab
Inside the Fake Copyright Racket Silencing News Outlets
Rapid7
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
MIT Technology Review
The Download: a censorship conspiracy theory and the first virus created by AI
MIT Technology Review
How ideas of a vast censorship network moved from the online fringe to Trump policy
Cloudflare
Announcing Cloudflare Ambassadors, Community Engineers, and another $1M in open-source funding
CISA Alerts & Advisories
CPDLC over ATN-B1 Vulnerabilities
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Schneier on Security
ICE Is Buying Access to Credit Card Records
ISC SANS
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
Elastic Security Labs
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
2026-08-06
PortSwigger
CSS:the bomb inside your inbox
Dark Reading
Researcher Claims Control of ChatGPT Secure Sandbox
Talos Intelligence
Why metaphor may dictate your security strategy
Krebs on Security
Canadian Man Pleads Guilty in Snowflake Extortions
Github Security Blog
How we took malware advisories beyond npm
Amazon Security
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
Cloudflare
The next generation of MCP
Cloudflare
Give any website a WebMCP interface
Cloudflare
Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers
CISA Alerts & Advisories
Johnson Controls Inc. TL280
CISA Alerts & Advisories
ABB Ability Zenon
CISA Alerts & Advisories
Medixant RadiAnt DICOM
Malwarebytes
Scammers target OnlyFans users with deepfakes
Schneier on Security
Adversarial Clothing Designed to Fool Facial Recognition Systems
TrustedSec
The Art of Hunting Azure Cloud Secrets
Yunus Aydın
Worklo: Sahte Startup, Gerçek Malware
Elastic Security Labs
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
2026-08-05
Dark Reading
AI Sends Global Crime Syndicates Into Fraud Nirvana
Ars Technica Security
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Dark Reading
No Perfect Fix for AI Browser Prompt Injection Flaws
Amazon Security
AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows
Ars Technica Security
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Dark Reading
CSS: The Hidden Threat Lurking in Your Inbox
Meta Security
From User Sequences to Scaling Laws: A Multi-Stage Architecture for Meta’s Ads Ranking
Socket
UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware
Amazon Security
From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management