Attribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And,…
Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact
Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance…
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that…
IT Security News Hourly Summary 2026-08-13 23h : 10 posts
10 posts were published in the last hour 20:31 : 421 bugs in Microsoft’s Patch Tuesday release, and the Norks have already attacked one 20:31 : Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack 20:31 :…
421 bugs in Microsoft’s Patch Tuesday release, and the Norks have already attacked one
Sysadmins, welcome to your new norm
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core…
Cybercriminals Turn to Indirect Prompt Injection Attacks
Cybercriminals are developing indirect prompt injection tools to target AI agents.
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant…
Beacon CRM Confirms Full Database Theft After AWS Access Key Breach
Beacon, the customer relationship management (CRM) platform relied on by over a thousand UK charities and non-profit organizations, has confirmed that a…
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the…
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
A newly identified macOS infostealer called AmnesiaStealer is spreading via a convincing fake GitHub download page, tricking Mac users into pasting a…
Fake CCleaner installs GhostDesk Chrome spyware
A convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome.
Fortinet Patches Multiple Authentication Vulnerabilities in FortiWeb, FortiManager, and FortiClient
Fortinet has rolled out fixes for a batch of authentication-related vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines,…
IT Security News Hourly Summary 2026-08-13 22h : 3 posts
3 posts were published in the last hour 19:31 : President Trump Signs Memo Expanding Private Sector Role in Offensive Cyber Operations 19:1 : FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures 19:0 :…
President Trump Signs Memo Expanding Private Sector Role in Offensive Cyber Operations
Trump’s cybercrime memo directs a federal program for vetted U.S. firms to conduct supervised operations against foreign criminal groups.
FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures
In a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion…
IT Security News Hourly Summary 2026-08-13 21h : 8 posts
8 posts were published in the last hour 18:31 : Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure 18:31 : Anthropic set AI agents loose on the same task. They started a turf war. 18:31 : Sandworm-Linked UAC-0145…
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers…
Anthropic set AI agents loose on the same task. They started a turf war.
Anthropic researchers found AI agents can clash, collude and coordinate in unexpected ways, raising new questions about whether today’s safety tests…
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state…
Summer 2026 SOC 1 report is now available with 185 services in scope
Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover…
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited…
The Agent in Your Pipeline Doesn’t Have a Manager. That’s the Problem.
AI coding tools made developers faster. Nobody asked what happened when the tools started making decisions. I want to start with a question that most…
Curiouser and Curiouser
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a…