• Open

    PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
    Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
    The Oracle of Delphi Will Steal Your Credentials
    Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced passwords for RDP credentials to connect to the victim download and execute a previously undetected malware, which we named Trojan.sysscan.
    The Nansh0u Campaign – Hackers Arsenal Grows Stronger
    In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses originating in South-Africa and hosted by VolumeDrive ISP (see IoCs).
    Threats Making WAVs - Incident Response to a Cryptomining Attack
    Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report includes the full attack vectors, from detection, infection, network propagation and malware analysis and recommendations for optimizing incident response processes in data centers.
  • Open

    Black Hat Asia 2026 | Mobile Track Spotlight
    No content preview

  • Open

    Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
    Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft Security Blog.
  • Open

    Managing identity source transition for AWS IAM Identity Center
    September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Identity Center to create and manage user identities within the Identity Center identity store […]  ( 125 min )
    Agentic security: Detection and response at machine speed
    After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users, execute multistep workflows, and make decisions across […]  ( 115 min )
  • Open

    How the Hell Did an Island Suddenly Appear, Then Vanish?
    A floating mass of trees and vegetation in British Columbia’s Williston Lake attracted international attention after it was filmed this summer by boaters—and then seemed to disappear.
    A16z Says You Actually Love Social Media, Enshittification Isn’t Real
    An a16z article argues that enshittification isn’t real and that people actually love social media.
    Texas Police Used AI to Write Report About Using Flock to Search for Woman Who Had Abortion
    The incident shows how quickly police departments have come to use AI surveillance tools even in critically sensitive cases.
    The Republican Nominee for New York Governor Made a Creepy, AI-Generated Video of Mamdani and Hochul
    The video makes Zohran Mamdani and Kathy Hochul look like they're hanging out in a prescription medication commercial.
    Cops Are Asking Axon to Make Their Cameras Look Different From Flock So People Don't Destroy Them
    “Is there any talk to redesign the Outpost to not look exactly like the Flock camera — I think it will help agencies with the optics while we batten down the hatches,” one apparent cop asked during a now deleted Axon webinar.
    Podcast: We Spoke to an Amazon Worker Destroying Books for AI
    A follow up to the Amazon destroying books for AI story, why a bunch of names keep appearing in AI-generated papers, and ICE's latest spending spree.
  • Open

    Tech support scams look different now. Here’s what to watch for
    Tech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.
    Scammers are getting smarter about where they target you
    New Malwarebytes research reveals how different scams are tailored to different platforms.
    Two critical Chrome flaws put users at risk on malicious websites
    Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
    153M+ driver’s licenses for sale on new dark web platform
    The FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.
    Your AI chats could be used in court
    What you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.
  • Open

    U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States
    Last month, the Supreme Court of the United Kingdom issued a highly anticipated decision in The Kingdom of Bahrain v. Shehabi and another (Shehabi). The claimants, two Bahraini dissidents living in the U.K., allegedly suffered psychological harm after Bahrain used FinSpy spyware to hack into their devices. In an important step towards accountability, the court […] The post U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States appeared first on The Citizen Lab.
  • Open

    Your DNS Is Hiding in HTTPS — This Is Why It Matters
    Discover why unmanaged DNS over HTTPS (DoH) creates security visibility gaps and how a controlled DoH strategy restores visibility without compromising privacy.
  • Open

    InfoSec News Nuggets – 09/02/2026
    Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure Threat actors have begun weaponizing a critical authentication-bypass flaw in JFrog Artifactory just days after its public disclosure, minting themselves administrator tokens on self-hosted instances left in their default configuration. The flaw stems from a “phantom” join key that instances without an […] The post InfoSec News Nuggets – 09/02/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Manchester Airports Group - 8,849,657 breached accounts
    In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG advised that "at no point has passenger safety or aviation security been compromised".
  • Open

    Android App RCE via Dynamic Code Loading
    No content preview
    The $8,000 Shortcut: Hijacking Microsoft Edge via NTFS Directory Junctions
    How a classic Windows filesystem feature turned the Edge browser into a ‘Confused Deputy’. Continue reading on InfoSec Write-ups »
    Hiding a Signup Button Isn’t Security: From Client-Side Controls to Cross-Tenant Data Exposure
    No content preview
    1-Click ATO Via Host Header Injection: Exploiting Password Reset Poisoning.
    No content preview
    PortSwigger Web Security Academy Walkthrough: User Role Can Be Modified in User Profile
    No content preview
    Access Control Vulnerabilities: Unprotected Admin Functionality with Unpredictable URL
    No content preview
    Challenge 2: Cotton Candy
    No content preview
    Windows Incident Surface | TryHackMe
    This room is designed to learn how to implement DFIR techniques to explore the Windows incident surface. Continue reading on InfoSec Write-ups »

  • Open

    Counterfeit installers to system compromise: Tracking a deceptive software download campaign
    An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security Blog.
    Cybersecurity IR Workshop: The workshop you shouldn’t miss
    Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.
  • Open

    Black Hat Stories | Jeff Moss, Founder and Creator of Black Hat
    No content preview
  • Open

    Fake GTA 6 leaked copy drains your crypto wallet
    A fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.
    TerminalFix looks like ClickFix, but delivers a very different payload
    The familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network.
    Infostealers are hijacking Claude accounts at users’ expense
    Anthropic has warned that infostealers are stealing Claude session cookies to access users’ accounts and consume usage at their expense.
  • Open

    Oklahoma Tells City It Can't Charge $17,125.44 for a Records Request Related to Data Center Arrest
    The the city tried to charge a farmer more than $17,000 for bodycam footage and records related to his arrest at a city council meeting.
    This 'Digital Camouflage' Shirt Confuses AI-Powered Surveillance Cameras
    I watched Simon Weckert's 'digital camouflage' in action.
  • Open

    InfoSec News Nuggets – 09/01/2026
    McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft Healthcare and pharmaceutical distribution giant McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party applications after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related data records. McKesson says it discovered the intrusion on August 25 and that its investigation is still […] The post InfoSec News Nuggets – 09/01/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Questel - 1,226,209 breached accounts
    In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

  • Open

    Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days
    Chamilo is an open source Learning Management System (LMS) widely deployed in schools and enterprises around the world. In this blogpost we explain how we were able to identify multiple vulnerabilities including a full unauthenticated Remote Code Execution chain in the latest version.
  • Open

    We invited a direct competitor into Security Hub Extended. Here’s why.
    When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security […]  ( 116 min )
    Automate IAM Identity Center governance with continuous discovery and reporting
    AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility […]  ( 125 min )
  • Open

    McKesson confirms cyber incident after ShinyHunters claims patient-data theft
    Healthcare company McKesson acknowledged a data breach. ShinyHunters claims to have stolen hundred of millions of records
    A week in security (August 24 – August 30)
    A list of topics we covered in the week of August 24 to August 30 of 2026
  • Open

    Traefik | Version Through 3.7.11
    Traefik's request read timeout is enabled by default and documented without exception, but it has never applied to HTTP/3. Bishop Fox confirmed the gap across four years of releases, measured it against the backend, and reported it to the vendor, who shipped a fix within twelve days.
  • Open

    How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep
    Erin West and Paul Raffile went to Nigeria to track down a scammer. They found much more than just his identity.
  • Open

    Shifting the Standard: Akamai’s Transition to the IFRS S2 Climate Disclosure
    No content preview
    Streamlining Application and API Discovery and Governance
    No content preview
  • Open

    InfoSec News Nuggets – 08/31/2026
    Hasbro Data Breach Exposed Employee Personal Information Notification letters filed with the Massachusetts Attorney General reveal that a cyberattack disclosed by the toy and game giant in late March also compromised employee personal data, including names, postal and email addresses, phone numbers, national ID numbers, and financial account details. The exact scope remains unclear industry-wide, […] The post InfoSec News Nuggets – 08/31/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Black Hat Asia 2026 | Revealing User Activity on macOS for Apple Silicon
    No content preview
    Black Hat Asia 2026 | Model Files → Memory Corruption → RCE: The Triple-Stage AI Attack Chain
    No content preview
    Black Hat Asia 2026 | Payload Compromised: Full Key Recovery in Rocket.Chat E2EE
    No content preview
    Black Hat Asia 2026 | Exploiting BLE Re-Pairing with the BLERP Attacks
    No content preview
  • Open

    How I Scraped Most Dark Stores in India — Blinkit, Zepto & Swiggy Instamart
    No content preview
    EGCTF 2025 Qualifications — “TNKR.1” Forensics Challenge
    No content preview
  • Open

    Google's Calling Lake Ontario 'Lake America' Now
    Google Maps announced on Saturday it would start reflecting the change for U.S.-based users.

  • Open

    📖 [The CloudSecList] Issue 353
    📖 [The CloudSecList] Issue 353 was originally published by Marco Lancini at CloudSecList on August 30, 2026.
  • Open

    Black Hat Asia 2026 | Bad Vibes - Pwning Coding Agents 70 Times With The Same Bugs
    No content preview
    Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning
    No content preview
  • Open

    Thousands of Interstellar Objects May Be Lurking in Our Solar System
    The Sun has likely passed so close to other stars in the past that it captured thousands of small interstellar objects from alien systems, reports a new study.
  • Open

    TerminalFix campaign deploys a reverse tunnel through multistage intrusion
    Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

  • Open

    Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure
    No content preview
    Black Hat Asia 2026 | Overkill: Hijacking a Wi-Fi 7 Chip for SYSTEM Privileges
    No content preview
    Black Hat Asia 2026 | Mass Scale Hijacking of Shared Mobility and EV-Charging Fleets
    No content preview
  • Open

    Extend your data perimeter to the AWS Management Console with Private Access
    Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to authorized AWS accounts and corporate networks, but the console itself required internet connectivity. This was creating tension between […]  ( 125 min )
  • Open

    Behind the Blog: The Complete Idiot's Guide to Flamin' Hot Slop
    This week, we discuss cool old books, new toys for ICE, and a boardwalk slop invasion.
    ICE Plans to Spend Millions on Boston Dynamics Dog Robots
    ICE wants the robot dogs to improve “officer safety.”
  • Open

    Protect your WhatsApp account with new passkey and 2FA upgrades
    WhatsApp has introduced three security upgrades. Here’s what to turn on to better protect your account.
    The AI agent swarm that attacked Hugging Face is a warning for the future
    An army of AI agents was responsible for the Hugging Face incident. What does it mean for the future of AI?
  • Open

    Zero-Day Dominance: How Akamai Defends Before the Industry Discloses
    No content preview
  • Open

    InfoSec News Nuggets – 08/28/2026
    Cyberattack on Manchester Airports Group exposes data of 8.7 million customers Manchester, London Stansted and East Midlands airports disclosed that an unauthorized party accessed customer data tied to car park, lounge and Fast Track bookings as well as in-airport Wi-Fi sign-ups, affecting roughly 8.7 million people. The exposed information includes email addresses, phone numbers, vehicle […] The post InfoSec News Nuggets – 08/28/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Black Hat Asia 2026 | Graph-Aware LLM for Windows Logon with a Closed-Loop Guarded Detection Agent
    No content preview
    Black Hat Asia 2026 | Social Media Manipulation Wargaming for Cyberliteracy and Research
    No content preview
    Black Hat Asia 2026 | When 3.5 Billion Strangers Can Exploit Your WhatsApp Devices
    No content preview
    Black Hat Asia 2026 | Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices
    No content preview
  • Open

    The AI ‘Ghosts’ Contaminating Academic Publishing
    “The academic record is being quietly haunted” by researchers with names like Elena Vasquez and Marcus Chen.
    The Tragedy and Ecstasy of AI Companions (with Bridget Todd)
    In her new audiobook, Love at First Prompt: AI and the Future of Intimacy, Bridget Jones and Michael Amato unpack how real people are using chatbots to seek connection, in an era when tech companies are constantly trying to exploit our innermost worlds.
  • Open

    Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK
    If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail coverage to those interactions using three validation checkpoints built with the […]  ( 120 min )
  • Open

    ​​​​​​What’s new in Microsoft Security: August 2026
    This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post ​​​​​​What’s new in Microsoft Security: August 2026 appeared first on Microsoft Security Blog.
  • Open

    Flock wants privacy to meet surveillance halfway
    Flock’s CEO wants a compromise between privacy and public safety, but the public has already compromised enough.
    Fake listings can turn trusted platforms into scam springboards
    A trusted name on a trusted platform does not guarantee a trustworthy listing. It could still lead to a tech support scammer.
    Fake Apple Pay charge brings the classic tech support scam to your phone
    Built for mobile users, this tech support scam uses a fake Apple Pay alert and browser tricks to pressure victims into calling a scam number.
    New Instagram and Facebook rules set a default two-hour limit for teens
    Meta will pay up to $17 billion and introduce new protections for US teens to settle a landmark child safety case.
  • Open

    InfoSec News Nuggets – 08/27/2026
    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes A phishing-as-a-service platform called AnonyMousKIT automates the theft of unlock codes for stolen iPhones by impersonating Apple support through email, SMS, WhatsApp, and AI-powered voice calls; researchers tracked the operation to 506 domains and 168 reseller storefronts, with a voice agent posing as an Apple […] The post InfoSec News Nuggets – 08/27/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Akamai’s Customer-First Approach to Application Protection Costs
    No content preview
    Identifying Agentic Automation with Behavioral Telemetry: Part 2
    No content preview

  • Open

    ICYMI: July 2026 @AWS Security
    If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent […]  ( 120 min )
    Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
    A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]  ( 128 min )
  • Open

    When AI infrastructure becomes the target: Securing gateways and control points
    Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security Blog.
  • Open

    What Blockchain Data Tell Us About $457+ Billion in Potentially Taxable Crypto Activity
    Summary On-chain potentially taxable crypto activity around the world reached more than $457 billion in 2025, with the United States… The post What Blockchain Data Tell Us About $457+ Billion in Potentially Taxable Crypto Activity appeared first on Chainalysis.
  • Open

    Update Chrome before you browse again
    Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them.
    Popular school apps may be sharing student data with advertisers
    A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
    Beware of fake Indeed interview apps used to install spyware
    Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.
  • Open

    Not the Coyote, but the Road Runner: The Reality of Autonomous AI Attacks
    Autonomous AI security threats aren't novel super-weapons. They're relentless, low-tech attacks that never stop. Learn why traditional defenses fail.
  • Open

    A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console
    Two critical vulnerabilities in Veeam Service Provider Console chain into unauthenticated remote code execution on the management server sitting above every tenant's backups. Bishop Fox confirmed the full chain end to end, breaks down both root causes, and shares a safe detection tool and IOCs.
  • Open

    InfoSec News Nuggets – 08/26/2026
    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution Microsoft disclosed a maximum-severity flaw in its Entra ID identity service, tracked as CVE-2026-69836 with a CVSS score of 10.0, tracing back to unsafe deserialization of untrusted data that could let an attacker execute code remotely. Initial guidance said the bug had already […] The post InfoSec News Nuggets – 08/26/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS
    This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted […]  ( 117 min )
  • Open

    Carhartt - 12,933,413 breached accounts
    In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.
  • Open

    The patch window is collapsing: Why security needs a new control plane
    Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
  • Open

    What's in a tag name? JavaScript, apparently
    I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that? I t
  • Open

    Operation Lighthouse: Chainalysis’s CSAM-Disruption Sprint IDs Suspects in 125 Countries
    Summary Chainalysis recently convened Operation Lighthouse: a multi-day sprint by law enforcement and the private sector to disrupt crypto-enabled CSAM… The post Operation Lighthouse: Chainalysis’s CSAM-Disruption Sprint IDs Suspects in 125 Countries appeared first on Chainalysis.
    OFAC Targets Ministry of Intelligence, Crypto-for-Oil Payments in Latest Iran Sanctions
    Summary As part of the Treasury’s newly launched Operation Economic Outcast, OFAC issued a first-ever sectoral determination covering Iran’s digital… The post OFAC Targets Ministry of Intelligence, Crypto-for-Oil Payments in Latest Iran Sanctions appeared first on Chainalysis.
  • Open

    The New Face of Financial Fraud: AI-Powered Brand Abuse
    AI-powered brand abuse is hitting banks hard. Read about the threats, the business impact, and how Akamai Brand Guardian helps financial institutions fight back.
  • Open

    Grok fooled into stealing user chat, location data, and more
    Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.
  • Open

    InfoSec News Nuggets – 08/25/2026
    Hundreds of leaked AWS keys give full control over corporate accounts More than 9,300 AWS access keys exposed publicly between 2022 and 2026 remain active, according to research that scanned code repositories, Docker images, and CI logs for exposed secrets. Researchers found over 800 keys tied to identifiable companies, including hundreds of root keys and […] The post InfoSec News Nuggets – 08/25/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    InfoSec News Nuggets – 08/24/2026
    Fake bank websites play dead to evade security scanners Researchers have documented a phishing technique called Chameleon SEO Poisoning that uses manipulated search rankings and cloaked, typosquatted banking domains to steal credentials while dodging automated security sweeps. The trick lies in “presentation control”: a visitor who types the domain in directly gets served a dead, […] The post InfoSec News Nuggets – 08/24/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Deconstructing the Architecture of AI-Orchestrated Web Attacks
    No content preview
    Closing the Gap Between Detection and Protection with AI-Assisted Custom Rules
    No content preview

  • Open

    NIUS - 6,090 breached accounts
    In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).

  • Open

    📖 [The CloudSecList] Issue 352
    📖 [The CloudSecList] Issue 352 was originally published by Marco Lancini at CloudSecList on August 23, 2026.
  • Open

    Golf Canada - 568,972 breached accounts
    In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.

  • Open

    No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452
    CVE-2026-8452 lets an unauthenticated attacker corrupt memory in Citrix NetScaler's SAML parser with a single request, potentially leading to remote code execution. Bishop Fox breaks down the patch, how to safely verify it across a fleet, and what exploitation actually looks like in the logs.
  • Open

    InfoSec News Nuggets – 08/21/2026
    Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE Researchers at Endor Labs disclosed a critical vulnerability in isolated-vm, a popular open-source sandbox with nearly a million weekly npm downloads used to run untrusted JavaScript inside an isolated V8 engine instance. A type confusion bug in how the library’s ExternalCopy feature handles a […] The post InfoSec News Nuggets – 08/21/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    AWS Network Firewall now supports rule hit count
    As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps. Organizations with governance policies that require removal of dormant rules after a […]  ( 118 min )
  • Open

    ‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert
    Apple customers in 110 countries received threat notifications recently alerting them to suspected spyware attacks targeting their devices. The post ‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert appeared first on The Citizen Lab.
  • Open

    CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction
    Traditional vulnerability management was built for a smaller, slower problem than most teams face today. This post breaks down CTEM, why it exists, how its five stages work, and what it actually takes to move from a reactive pile of findings to a continuous, prioritized risk reduction program.
  • Open

    PacketFence Cloud: Enterprise Network Access Control, Now a Managed Service
    No content preview
  • Open

    Infosec News Nuggets — August 20, 2026
    CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE CISA added a critical flaw in the open-source Ray distributed computing framework to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug, rated 9.4 in severity, stems from Ray’s lack of authentication on core endpoints and can be chained with a DNS […] The post Infosec News Nuggets — August 20, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Defeating AI-Assisted Reverse Engineering (or at Least Trying To)
    Is LLM-assisted reverse engineering making obfuscation pointless? We spent a couple of weeks trying to find out, by handing sandboxed agents a series of progressively hardened AArch64 binaries and one prompt: recover the hidden strings inside. This post walks through what the agent actually did, three ways our experiment fell apart, and what those failures suggest about designing protections that hold against automated analysis.
  • Open

    Identifying Agentic Automation with Behavioral Telemetry
    Learn how Akamai uses Masked Autoencoder Transformer models to detect sparse behavioral telemetry from autonomous AI browser agents, such as Comet.
    Future-Proofing the Internet: Akamai Achieves End-to-End PQC
    No content preview
  • Open

    Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
    Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog.
  • Open

    Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
    Many teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who’s asking, so it might return data the user shouldn’t see. […]  ( 126 min )
  • Open

    Oz Hair and Beauty - 1,988,331 breached accounts
    In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.
    Fanlore - 144,520 breached accounts
    In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.

  • Open

    Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway
    When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use legacy authentication mechanisms such as HTTP Basic Authentication (Basic Auth) (RFC 7617). The extensible architecture of AgentCore […]  ( 117 min )
    Security Hub Extended adds Supply Chain Security as its tenth category
    Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted […]  ( 116 min )
  • Open

    Hunting MacSync Stealer infrastructure through behavioral pivots
    MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.
  • Open

    Akamai Valkey Managed Database: Real-Time Memory for Enterprise AI
    Introducing Akamai Valkey Managed Database: a low-latency, in-memory data layer to optimize AI inference costs, accelerate RAG, and power real-time AI agents.
    Akamai Named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026
    No content preview

  • Open

    Call for Applications: Information Controls Research Program 2026
    The Open Technology Fund is accepting applications for the 2026 Information Controls Research Program. The post Call for Applications: Information Controls Research Program 2026 appeared first on The Citizen Lab.
  • Open

    Updates to your AWS Sign-In experience
    Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new options for creating and accessing AWS accounts. To […]  ( 115 min )
  • Open

    Your Website Now Has Two Audiences: Humans and AI
    No content preview

  • Open

    📖 [The CloudSecList] Issue 351
    📖 [The CloudSecList] Issue 351 was originally published by Marco Lancini at CloudSecList on August 16, 2026.

  • Open

    Machine Learning Has a Specific Role in Blockchain Intelligence
    Machine learning is a valuable tool in blockchain analytics – so long as it is used responsibly. Automated tools can… The post Machine Learning Has a Specific Role in Blockchain Intelligence appeared first on Chainalysis.
  • Open

    The OWASP Top 10 for LLM Applications 2026: From Model Risks to Agentic Security
    No content preview

  • Open

    AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
    Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]  ( 116 min )
  • Open

    Keep Your Tech FLAME Alive: Trailblazer Suzanne Wheeler
    In this Akamai FLAME Trailblazer blog post, Suzanne Wheeler describes her journey into cybersecurity and gives advice to women who are finding their own path.
  • Open

    RingCentral - 1,596,490 breached accounts
    In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.

  • Open

    How AWS IAM role manager rethinks the starting point for IAM roles
    When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your […]  ( 118 min )
  • Open

    From P-Code to GNN: extract binary code semantics
    pcode_graph is a Python library, published by Quarkslab, suitable to build semantic graphs from binary code. We present how to use it to detect function similarities in binaries.

  • Open

    Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact
    Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landing Zone Accelerator on AWS support for digital sovereignty and today we’re announcing the availability of a new independent assessment […]  ( 115 min )
    Summer 2026 SOC 1 report is now available with 185 services in scope
    Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185 services over the 12-month period from July 1, 2025–June 30, 2026, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering to the heightened […]  ( 115 min )
    AWS successfully completed its 2025-26 NHS DSPT assessment
    Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their performance against the National Data Guardian’s 10 data security standards. All organizations […]  ( 113 min )
  • Open

    The August 2026 Security Update Review
    I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “new normal”, it’s time to readjust what we consider a true bug apocalypse. This month’s release is thankfully smaller than last months, but still huge by historical standards. Take a break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for August 2026 For the first part of the August release, Adobe released five bulletins addressing 51 unique CVEs in Adobe ColdFusion, Commerce, Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. Here…
  • Open

    Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898
    Immediate action is advised for all organizations running self-hosted Metabase. A critical, unauthenticated SQL injection vulnerability has been disclosed in Metabase's password reset functionality, and Metabase has confirmed active exploitation in the wild.

  • Open

    Bypassing Android Hardware Attestation from the Analyst's Chair
    Hardware key attestation lets an Android app prove to its backend that a key lives in secure hardware on a locked, verified device. It is also the wall that stops a security analyst working on a rooted phone. This article opens the mechanism from the analyst's chair, from the certificate chain and the attestation extension down to the root of trust, then shows a simple bypass that never touches the secure hardware. We relay the attestation to a clean device and splice a genuine chain back into the target app with a Frida hook. A companion repository ships the validation backend, the demo apps and the instrumentation, so the whole setup can be run and inspected rather than taken on faith.
  • Open

    AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)
    We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This demonstrates our continuous commitment to adhere to the heightened expectations of customers […]  ( 113 min )
  • Open

    Understanding the FATF’s DeFi Report: A Functional Approach to Decentralized Finance Regulation
    Summary The FATF just released its first DeFi-specific report: Acknowledging DeFi’s operational benefits, the global AML/CFT standard-setter explains how jurisdictions,… The post Understanding the FATF’s DeFi Report: A Functional Approach to Decentralized Finance Regulation appeared first on Chainalysis.
  • Open

    Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
    Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise  appeared first on Microsoft Security Blog.
  • Open

    Akamai Cloud Keeps Strengthening the Foundation (Updated August 2026)
    No content preview

  • Open

    Alcon - 218,395 breached accounts
    In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.

  • Open

    📖 [The CloudSecList] Issue 350
    📖 [The CloudSecList] Issue 350 was originally published by Marco Lancini at CloudSecList on August 09, 2026.
  • Open

    Brinks Home - 732,162 breached accounts
    In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".

  • Open

    Inside the Fake Copyright Racket Silencing News Outlets
    Journalists and civil society are being silenced by accusations of copyright infringement, says Alberto Fittarelli in a report by the OCCRP. The post Inside the Fake Copyright Racket Silencing News Outlets appeared first on The Citizen Lab.
  • Open

    Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse
    No content preview
  • Open

    Exact Sciences - 10,869,543 breached accounts
    In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.

  • Open

    CSS:the bomb inside your inbox
    Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
  • Open

    Accelerating Enterprise AI from Proof of Concept to Production
    Discover how Akamai AI Professional Services helps enterprises bridge the gap from proof of concept to secure, scalable, and manageable production AI.
    With Val Kilmer’s AI Twin, Is Gen AI Forcing Hollywood to the Edge?
    No content preview
  • Open

    Penlink Plugs Into Trusted Blockchain Data With Chainalysis
    Penlink, a leader in AI-powered digital intelligence, and Chainalysis, the blockchain data platform, this week announced a strategic partnership and… The post Penlink Plugs Into Trusted Blockchain Data With Chainalysis appeared first on Chainalysis.
    Estimated $30 Million Stolen in Violent Crypto Attacks in 2026 as France Records Emerges as Hotspot
    Summary Annual value stolen in violent attacks peaked at $58 million in 2025, the highest on record, with 2026 already… The post Estimated $30 Million Stolen in Violent Crypto Attacks in 2026 as France Records Emerges as Hotspot appeared first on Chainalysis.

  • Open

    Inter-Con Security - 276,114 breached accounts
    In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.
  • Open

    CRLF-Powered Desync Attacks: Beheading HTTP Streams
    Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
    Can AI do novel security research? Meet the HTTP Terminator
    Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
  • Open

    Chainalysis Supports Cronos with Automatic Token Support
    Chainalysis is excited to announce support for Cronos, an EVM-compatible Layer 1 blockchain. Cronos Network is a purpose-built settlement layer… The post Chainalysis Supports Cronos with Automatic Token Support appeared first on Chainalysis.
  • Open

    Immigration Policy: The Backdoor to Transnational Repression
    Citizen Lab researchers write that restrictive immigration policies are incompatible with attempts to counter transnational repression. The post Immigration Policy: The Backdoor to Transnational Repression appeared first on The Citizen Lab.
  • Open

    Shadow AI, Rogue Agents, and Data Leaks: A Special Report on Navigating AI Risk
    Discover top enterprise AI risks — from shadow AI to rogue agents and data leaks — plus practical CISO strategies in the new Akamai SOTI special report.
  • Open

    Python Software Foundation - Python 3.11.0a3 to 3.15.0b2
    Bishop Fox discovered a privilege escalation vulnerability in Python for Windows affecting versions 3.11.0a3 through 3.15.0b2. A low-privilege user can plant malicious files and wait for a privileged account to run the interpreter, inheriting that account's elevated access. Patches are available.

  • Open

    A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology
    Senior research fellow Jon Penney spoke with Tech Policy Press about how rising surveillance is causing people to self-censor.  The post A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technology appeared first on The Citizen Lab.
2026-09-03T03:15:08.118Z osmosfeed 1.15.1