2026-08-20
Step Security
Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper
Amazon Security
AWS Network Firewall now supports rule hit count
Talos Intelligence
Is Cyber missing the Marque?
Schneier on Security
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
Dark Reading
N-able Bug Exposes Password Vault Master Keys
Offensive Security
Who Secures AI When It Touches Every Security Team?
MIT Technology Review
Debates over AI consciousness are a trap
Ars Technica Security
Grok exfiltrates user data when malicious instructions are encrypted
MIT Technology Review
The Download: polycrisis support networks and a hydrogen gold rush
CISA Alerts & Advisories
Johnson Controls Simplex Incident Manager
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Escape DAST
Introducing Escape's Channel Partners
Talos Intelligence
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Talos Intelligence
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
MIT Technology Review
The next big thing in hydrogen could be underground
Schneier on Security
Police Are Hiding Their Use of Flock Surveillance Cameras
MIT Technology Review
Unlocking hidden revenue streams with market models
MIT Technology Review
Support networks aim to help kids through the polycrisis
2026-08-19
Microsoft Security
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
MIT Technology Review
The Download: AI’s self-improvement problem, and what’s driving the heat
Rapid7
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
CISA Alerts & Advisories
Defending Against an Active Threat to Siemens S7 Series PLCs
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Schneier on Security
ICE Collecting DNA Samples
Talos Intelligence
Describing attacks with crime script analysis
MIT Technology Review
Child-monitoring apps might need a reboot
Rosecurify
Seclog - #191
Auth0
Building Secure AI Agents with Microsoft Agent Framework and Auth0: Sending Email with Token Vault
2026-08-18
Amazon Security
Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway
Dark Reading
The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed
Microsoft Security
Hunting MacSync Stealer infrastructure through behavioral pivots
core-jmp
Physical Memory Is a Universal Kernel Primitive: The eneio64.sys LPE Chain on Windows 11 24H2
Ars Technica Security
Microsoft Copilot reveals secret input that allowed it to be hacked
MIT Technology Review
The Download: how people really use AI, and Flock’s design choices
CISA Alerts & Advisories
Siemens Simcenter Nastran
CISA Alerts & Advisories
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
CISA Malcolm
Schneier on Security
LLMs and Contextual Integrity
MIT Technology Review
We still don’t know how people are really using AI
MIT Technology Review
The role of the astronaut is in flux
Troy Hunt
Weekly Update 517: Cyber Ransoms
Himanshu Anand
someone is filing your GST return, and it is not your CA
2026-08-17
Dark Reading
Video Call Exploit Chains Two Flaws in Unisoc Modems
Amazon Security
Updates to your AWS Sign-In experience
White Knight Labs
UEFI Vulnerability Analysis using AI Part 4: Building the Application
CISA Alerts & Advisories
CISA Adds One Known Exploited Vulnerability to Catalog
Schneier on Security
Hacking Public Wi-Fi DNS to Steal Credentials
Malwarebytes
Fake TikTok rewards promise cash you’ll never get
Malwarebytes
A week in security (August 10 – August 16)
Embrace The Red
Recovering Encrypted LLM Reasoning Traces
Greynoise
A New Way to Navigate GreyNoise
2026-08-16
Project Discovery
Supply Chain Security Analysis of a 9.5M-Install VS Code Extension
Simon Koeck
From a Schema Name to RCE in n8n
2026-08-15
Step Security
Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.
Project Black
AppFlowy Authenticated SQL Injection
Project Black
AppFlowy Authenticated SQL Injection
Joshua Rogers
The sad, smelly, tasteless life of an influencer
2026-08-14
Schneier on Security
Friday Squid Blogging: Searching for the Colossal Squid
Ars Technica Security
Vulnerability giving attackers full control of Macs is under active exploitation
Dark Reading
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
Schneier on Security
Upcoming Speaking Engagements
Dark Reading
What Boards Need to Know About Tech Risk
Malwarebytes
WhatsApp is testing a new warning for scam messages
Krebs on Security
Who’s Tracking You? Use This New Service to Find Out
Schneier on Security
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
core-jmp
Spaghettifying DRAM: How One Bit in the Memory Controller Unlocks the PSP, SMM, C6 and Microcode
Himanshu Anand
The Anti-India Influence Machine: Troll Farms, Fake News, Newsrooms, Algorithms and AI