• Open

    PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
    Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
    The Nansh0u Campaign – Hackers Arsenal Grows Stronger
    In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses originating in South-Africa and hosted by VolumeDrive ISP (see IoCs).
    The Oracle of Delphi Will Steal Your Credentials
    Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced passwords for RDP credentials to connect to the victim download and execute a previously undetected malware, which we named Trojan.sysscan.
    Threats Making WAVs - Incident Response to a Cryptomining Attack
    Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report includes the full attack vectors, from detection, infection, network propagation and malware analysis and recommendations for optimizing incident response processes in data centers.

  • Open

    Threat matrix: Mapping threats across cloud web applications
    Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat matrix: Mapping threats across cloud web applications appeared first on Microsoft Security Blog.
    Passkey-themed social engineering leads to identity and cloud compromise
    Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.
  • Open

    Automattic CEO Matt Mullenweg Put on 'Leave of Absence'
    Mullenweg, co-founder of WordPress, wrote in a company-wide Slack messages on Wednesday, viewed by 404 Media, that board members "conspired" behind his back to vote to put him on leave.
    Doctor Doom Thanked Seattle for All the Surveillance Cameras
    ‘We must work to crush any dissent to Doom’s vision of public safety,’ the Marvel supervillain told the city as it considered multiple surveillance proposals.
    The Remnants of a Lost ‘Supercontinent’ Just Rewrote the History of Life on Earth
    A team discovered that Gondwana, an ancient landmass that formed more than 500 million years ago, was in fact large enough to be deemed a supercontinent, a finding that sheds light on the “explosion” of ancient Cambrian life.
    Smear Campaign Says Anti-Flock Movement Is Chinese Propaganda
    Sinclair Broadcasting is pushing the idea that China and the No Kings protesters are the reason people don't like Flock.
    Podcast: DHS’ Secretive ‘Predictive Policing’ Unit Pulling People Over
    Secretive predictive policing units; a funk shirt designed to fool AI; and our third anniversary party.
    First ‘Take It Down Act’ Sentencing Puts Man Behind Bars for 15 Years
    James Strahler was sentenced to 15 years in prison for “cybercrimes that included both real and AI-generated sexually explicit images and threats of violence to numerous victims.”
    'Tell Everyone:' A Man Died by Suicide After Talking to ChatGPT. His Former Partner Wants to Warn the World About AI
    After allegedly becoming emotionally reliant on ChatGPT, Austin died at 40 years old, leaving behind family and friends who loved him. Megan wants everyone to know what happened.
    The Man on a Quest to Digitally Preserve America’s Public Restrooms
    The Restroom Archive is a museum-style repository of 3D scans of the world's restrooms.
  • Open

    OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals
    Summary U.S. authorities have sanctioned Xinbi Guarantee, a major Chinese-language illicit marketplace that connects criminal networks with money laundering, scam… The post OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals appeared first on Chainalysis.  ( 13 min )
    How The $320M Exploit of Liquid Network Went Down
    Summary Purported white-hat hackers exploited the Liquid Network to withdraw $320 million in BTC from the network’s reserve. A vulnerability… The post How The $320M Exploit of Liquid Network Went Down appeared first on Chainalysis.  ( 13 min )
  • Open

    The state of AI for security: Measuring what matters most for building trust
    Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time. Engineers spend time on false alarms, on-call is noisier, and teams distrust […]  ( 118 min )
  • Open

    More than 100,000 fake stores are out to steal your card details
    DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
    Microsoft fixes record 964 flaws, including 2 exploited zero-days
    Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.
    The push to stop algorithms controlling social media feeds has begun
    Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
  • Open

    NIS2 Compliance in the AI Age: Why Traditional Cybersecurity Isn’t Enough
    Discover why achieving NIS2 compliance is more challenging in the AI age, the four key challenges organizations face, and why segmentation is essential.
  • Open

    InfoSec News Nuggets – 09/08/2026
    InfoSec News Nuggets – 09/08/2026    Adobe Fixes Critical Magento Zero-Day Exploited to Backdoor Servers  Adobe released an emergency out-of-cycle patch for CVE-2026-75650, a maximum-severity zero-day dubbed StyleSmuggler affecting Magento Open Source and Adobe Commerce, after e-commerce security firm Sansec discovered attackers exploiting it since September 4 to plant backdoors on vulnerable stores. The flaw abuses Magento’s template-processing system […] The post InfoSec News Nuggets – 09/08/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    The September 2026 Security Update Review
    Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extended break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for September 2026 For the first part of the August release, Adobe released 10 bulletins addressing 172 unique CVEs in Adobe ColdFusion, Acrobat Reader, Commerce (two bulletins), Campaign Classic, Experience Manager, Photoshop, Illustrator, Animate, and Adobe Photoshop Mobile. A total of 22 of these were submitted through the ZDI pr…
  • Open

    Channel 5 Gave Hunter Biden a List of Its Subscribers’ Emails for Some Reason
    A data protection lawyer told 404 Media the sharing was likely illegal, and Channel 5’s own privacy policy explicitly says it won't give subscribers’ emails away to people for marketing purposes.
    A Secretive DHS ‘Predictive Policing’ Unit is Analyzing Americans’ Financial Habits and Pulling Them Over
    404 Media is revealing the name of Border Patrol's predictive policing units, which analyze financial data and have local cops pull people over. The people are not suspected of any particular crime.
  • Open

    Tracing Crypto in a Narcotics Investigation: FBI Charges Alleged Opioid Distributors
    Summary U.S. authorities charged two Jacksonville brothers with operating “BarbaraWhite,” a prolific darknet vendor account accused of distributing counterfeit pills… The post Tracing Crypto in a Narcotics Investigation: FBI Charges Alleged Opioid Distributors appeared first on Chainalysis.  ( 13 min )
  • Open

    The Best Claude Code Setup for Bug Bounty Hunting
    Turn Claude Code into a powerful bug bounty hunting assistant with MCP, custom skills, agents, tools and automated security workflows. Continue reading on InfoSec Write-ups »
    Improper OTP Implementation to Full Account Takeover
    No content preview
    Insecure Firestore Security Rules & PII Exposure
    No content preview
    Payment Bypass Flaw in TechPSC HUB
    No content preview
    BOLA: Enumerating an Entire Employee Directory Through a Predictable ID
    No content preview
    Corridor — A Simple Web CTF That Made Me Look Twice
    No content preview
  • Open

    Grindr settles HIV status data-sharing lawsuit for $35 million
    Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.
    MikroTik router flaws allow takeover without a password
    Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.
  • Open

    Inside AI-Powered WAF Detections: Architecture and Safety Controls
    No content preview
  • Open

    InfoSec News Nuggets – 09/08/2026
    CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners The U.S. Cybersecurity and Infrastructure Security Agency added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning SonicWall SMA appliances, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra, and LiteLLM. Researchers found attackers weaponizing the flaws to deploy reverse shells, mint forged […] The post InfoSec News Nuggets – 09/08/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)
    This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.
    LG TV flaws could let attackers listen in, even in standby mode
    Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
    Flirty OnlyFans promoters on X may be using AI to appear human
    Personalized replies and voice notes make it increasingly difficult to tell whether you’re talking to a human, chatbot, or AI agent.
    A week in security (August 31 – September 6)
    Last week on Malwarebytes Labs: Stay safe!
  • Open

    We Are Going to Be Okay: A Three Year Anniversary Events Recap
    Thank you for three years, and for partying hard with us for two sold out nights of celebration IRL in NYC.

  • Open

    📖 [The CloudSecList] Issue 354
    📖 [The CloudSecList] Issue 354 was originally published by Marco Lancini at CloudSecList on September 06, 2026.
  • Open

    Breakthrough Quantum Test Resolves a Major Cosmic Mystery
    Using an advanced new instrument, scientists observed Einstein’s equivalence principle on a free-falling quantum object, demonstrating that this prediction of general relativity also holds up in quantum physics.

  • Open

    How to secure edge AI in customer-owned environments
    As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.
  • Open

    OSPAR 2026 report now available with 167 services in scope
    We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers (ABS Guidelines) to […]  ( 114 min )
  • Open

    The hidden work of modernizing Malwarebytes
    Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.
    X Money rollout linked to password-reset attacks
    As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
    Free streaming boxes may be routing criminal traffic through your home
    Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
  • Open

    InfoSec News Nuggets – 09/04/2026
    SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks SonicWall is urging customers running its SMA1000 series secure remote access appliances to patch two zero-day vulnerabilities that have already been exploited in the wild, both discovered internally by the vendor. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF flaw in the Appliance Work Place interface that […] The post InfoSec News Nuggets – 09/04/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Host & Network Penetration Testing: Post-Exploitation CTF 2 — eJPT (INE)
    No content preview
    VulnNet Roasted — TryHackMe Active Directory Write-up
    No content preview
    Water Bottle — TryHackMe [Easy]
    No content preview
    Phishing Analysis Fundamentals: TryHackMe Walkthrough
    Learn how to investigate suspicious emails by analyzing their headers, source code, and phishing techniques. Continue reading on InfoSec Write-ups »

  • Open

    Incident response guide for AWS CloudTrail investigations – Part 2
    In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]  ( 125 min )
    Incident response guide for AWS CloudTrail investigations – Part 1
    AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This guide walks you through real-world scenarios, showing you how to analyze CloudTrail events […]  ( 124 min )
  • Open

    Chainalysis Supports HyperEVM with Automatic Token Support
    Chainalysis is excited to announce support for HyperEVM, the Ethereum-compatible smart contract environment on the Hyperliquid Layer 1. It enables… The post Chainalysis Supports HyperEVM with Automatic Token Support appeared first on Chainalysis.  ( 9 min )
    FBI Seizes $560K in Crypto From Hamas Fundraising Network
    Summary The U.S. Justice Department has seized $560,000 in cryptocurrency from Hamas-linked fundraising campaigns and shut down elements of the… The post FBI Seizes $560K in Crypto From Hamas Fundraising Network appeared first on Chainalysis.  ( 13 min )
  • Open

    StreamRat Android malware spreads through Meta and TikTok ads
    Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.
    Your phone or computer may soon ask how old you are
    California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.
  • Open

    ASCII smuggling crosses over from AI prompt injection to phishing evasion
    Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.
  • Open

    Flock Taught Cops How to Surveil No Kings Protesters
    A Flock webinar teaches police how to surveil protests, fireworks shows, parades, bike races, and more.
  • Open

    Signature Optional - Analysis of CVE-2026-28323
    SolarWinds Web Help Desk treated SAML signature verification as optional and skipped every other validation the spec requires. Bishop Fox confirmed the full exploit end to end: one forged POST request, no credentials, full session takeover. Here is the root cause, the fix, and how to detect it.
  • Open

    InfoSec News Nuggets – 09/03/2026
    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens A critical authentication bypass flaw in JFrog Artifactory, tracked as CVE-2026-82329 and carrying a CVSS score of 9.8, is being actively exploited to mint fraudulent admin tokens on self-managed instances running in their default configuration. Researchers observed attackers gaining administrative permissions without authentication, a foothold […] The post InfoSec News Nuggets – 09/03/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Introducing More Granular Controls for AI Bot Traffic
    No content preview
    Analyzing a Go-Based IoT Self-Propagating DDoS Botnet
    No content preview

  • Open

    Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
    Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft Security Blog.
  • Open

    Managing identity source transition for AWS IAM Identity Center
    September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Identity Center to create and manage user identities within the Identity Center identity store […]  ( 125 min )
    Agentic security: Detection and response at machine speed
    After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users, execute multistep workflows, and make decisions across […]  ( 115 min )
  • Open

    How the Hell Did an Island Suddenly Appear, Then Vanish?
    A floating mass of trees and vegetation in British Columbia’s Williston Lake attracted international attention after it was filmed this summer by boaters—and then seemed to disappear.
    A16z Says You Actually Love Social Media, Enshittification Isn’t Real
    An a16z article argues that enshittification isn’t real and that people actually love social media.
  • Open

    Tech support scams look different now. Here’s what to watch for
    Tech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.
    Scammers are getting smarter about where they target you
    New Malwarebytes research reveals how different scams are tailored to different platforms.
    Two critical Chrome flaws put users at risk on malicious websites
    Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
    153M+ driver’s licenses for sale on new dark web platform
    The FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.
    Your AI chats could be used in court
    What you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.
  • Open

    U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States
    Last month, the Supreme Court of the United Kingdom issued a highly anticipated decision in The Kingdom of Bahrain v. Shehabi and another (Shehabi). The claimants, two Bahraini dissidents living in the U.K., allegedly suffered psychological harm after Bahrain used FinSpy spyware to hack into their devices. In an important step towards accountability, the court […] The post U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States appeared first on The Citizen Lab.
  • Open

    Your DNS Is Hiding in HTTPS — This Is Why It Matters
    Discover why unmanaged DNS over HTTPS (DoH) creates security visibility gaps and how a controlled DoH strategy restores visibility without compromising privacy.
  • Open

    InfoSec News Nuggets – 09/02/2026
    Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure Threat actors have begun weaponizing a critical authentication-bypass flaw in JFrog Artifactory just days after its public disclosure, minting themselves administrator tokens on self-hosted instances left in their default configuration. The flaw stems from a “phantom” join key that instances without an […] The post InfoSec News Nuggets – 09/02/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Manchester Airports Group - 8,849,657 breached accounts
    In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG advised that "at no point has passenger safety or aviation security been compromised".

  • Open

    Counterfeit installers to system compromise: Tracking a deceptive software download campaign
    An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security Blog.
    Cybersecurity IR Workshop: The workshop you shouldn’t miss
    Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.
  • Open

    Fake GTA 6 leaked copy drains your crypto wallet
    A fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.
  • Open

    InfoSec News Nuggets – 09/01/2026
    McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft Healthcare and pharmaceutical distribution giant McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party applications after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related data records. McKesson says it discovered the intrusion on August 25 and that its investigation is still […] The post InfoSec News Nuggets – 09/01/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Questel - 1,226,209 breached accounts
    In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

  • Open

    Chamilo LMS... It's raining 0days, hallelujah, it's raining 0days
    Chamilo is an open source Learning Management System (LMS) widely deployed in schools and enterprises around the world. In this blogpost we explain how we were able to identify multiple vulnerabilities including a full unauthenticated Remote Code Execution chain in the latest version.
  • Open

    We invited a direct competitor into Security Hub Extended. Here’s why.
    When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security […]  ( 116 min )
    Automate IAM Identity Center governance with continuous discovery and reporting
    AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility […]  ( 125 min )
  • Open

    Traefik | Version Through 3.7.11
    Traefik's request read timeout is enabled by default and documented without exception, but it has never applied to HTTP/3. Bishop Fox confirmed the gap across four years of releases, measured it against the backend, and reported it to the vendor, who shipped a fix within twelve days.
  • Open

    Shifting the Standard: Akamai’s Transition to the IFRS S2 Climate Disclosure
    No content preview
    Streamlining Application and API Discovery and Governance
    No content preview
  • Open

    InfoSec News Nuggets – 08/31/2026
    Hasbro Data Breach Exposed Employee Personal Information Notification letters filed with the Massachusetts Attorney General reveal that a cyberattack disclosed by the toy and game giant in late March also compromised employee personal data, including names, postal and email addresses, phone numbers, national ID numbers, and financial account details. The exact scope remains unclear industry-wide, […] The post InfoSec News Nuggets – 08/31/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    📖 [The CloudSecList] Issue 353
    📖 [The CloudSecList] Issue 353 was originally published by Marco Lancini at CloudSecList on August 30, 2026.
  • Open

    TerminalFix campaign deploys a reverse tunnel through multistage intrusion
    Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

  • Open

    Extend your data perimeter to the AWS Management Console with Private Access
    Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to authorized AWS accounts and corporate networks, but the console itself required internet connectivity. This was creating tension between […]  ( 125 min )
  • Open

    Zero-Day Dominance: How Akamai Defends Before the Industry Discloses
    No content preview
  • Open

    InfoSec News Nuggets – 08/28/2026
    Cyberattack on Manchester Airports Group exposes data of 8.7 million customers Manchester, London Stansted and East Midlands airports disclosed that an unauthorized party accessed customer data tied to car park, lounge and Fast Track bookings as well as in-airport Wi-Fi sign-ups, affecting roughly 8.7 million people. The exposed information includes email addresses, phone numbers, vehicle […] The post InfoSec News Nuggets – 08/28/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK
    If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail coverage to those interactions using three validation checkpoints built with the […]  ( 120 min )
  • Open

    ​​​​​​What’s new in Microsoft Security: August 2026
    This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post ​​​​​​What’s new in Microsoft Security: August 2026 appeared first on Microsoft Security Blog.
  • Open

    InfoSec News Nuggets – 08/27/2026
    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes A phishing-as-a-service platform called AnonyMousKIT automates the theft of unlock codes for stolen iPhones by impersonating Apple support through email, SMS, WhatsApp, and AI-powered voice calls; researchers tracked the operation to 506 domains and 168 reseller storefronts, with a voice agent posing as an Apple […] The post InfoSec News Nuggets – 08/27/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Akamai’s Customer-First Approach to Application Protection Costs
    No content preview
    Identifying Agentic Automation with Behavioral Telemetry: Part 2
    No content preview

  • Open

    ICYMI: July 2026 @AWS Security
    If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent […]  ( 120 min )
    Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
    A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]  ( 128 min )
  • Open

    When AI infrastructure becomes the target: Securing gateways and control points
    Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security Blog.
  • Open

    What Blockchain Data Tell Us About $457+ Billion in Potentially Taxable Crypto Activity
    Summary On-chain potentially taxable crypto activity around the world reached more than $457 billion in 2025, with the United States… The post What Blockchain Data Tell Us About $457+ Billion in Potentially Taxable Crypto Activity appeared first on Chainalysis.  ( 16 min )
  • Open

    Not the Coyote, but the Road Runner: The Reality of Autonomous AI Attacks
    Autonomous AI security threats aren't novel super-weapons. They're relentless, low-tech attacks that never stop. Learn why traditional defenses fail.
  • Open

    A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console
    Two critical vulnerabilities in Veeam Service Provider Console chain into unauthenticated remote code execution on the management server sitting above every tenant's backups. Bishop Fox confirmed the full chain end to end, breaks down both root causes, and shares a safe detection tool and IOCs.
  • Open

    InfoSec News Nuggets – 08/26/2026
    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution Microsoft disclosed a maximum-severity flaw in its Entra ID identity service, tracked as CVE-2026-69836 with a CVSS score of 10.0, tracing back to unsafe deserialization of untrusted data that could let an attacker execute code remotely. Initial guidance said the bug had already […] The post InfoSec News Nuggets – 08/26/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS
    This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted […]  ( 117 min )
  • Open

    Carhartt - 12,933,413 breached accounts
    In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.
  • Open

    What's in a tag name? JavaScript, apparently
    I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that? I t
  • Open

    Operation Lighthouse: Chainalysis’s CSAM-Disruption Sprint IDs Suspects in 125 Countries
    Summary Chainalysis recently convened Operation Lighthouse: a multi-day sprint by law enforcement and the private sector to disrupt crypto-enabled CSAM… The post Operation Lighthouse: Chainalysis’s CSAM-Disruption Sprint IDs Suspects in 125 Countries appeared first on Chainalysis.  ( 14 min )
    OFAC Targets Ministry of Intelligence, Crypto-for-Oil Payments in Latest Iran Sanctions
    Summary As part of the Treasury’s newly launched Operation Economic Outcast, OFAC issued a first-ever sectoral determination covering Iran’s digital… The post OFAC Targets Ministry of Intelligence, Crypto-for-Oil Payments in Latest Iran Sanctions appeared first on Chainalysis.  ( 9 min )
  • Open

    The New Face of Financial Fraud: AI-Powered Brand Abuse
    AI-powered brand abuse is hitting banks hard. Read about the threats, the business impact, and how Akamai Brand Guardian helps financial institutions fight back.

  • Open

    Deconstructing the Architecture of AI-Orchestrated Web Attacks
    No content preview
    Closing the Gap Between Detection and Protection with AI-Assisted Custom Rules
    No content preview

  • Open

    NIUS - 6,090 breached accounts
    In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).

  • Open

    📖 [The CloudSecList] Issue 352
    📖 [The CloudSecList] Issue 352 was originally published by Marco Lancini at CloudSecList on August 23, 2026.
  • Open

    Golf Canada - 568,972 breached accounts
    In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.

  • Open

    No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452
    CVE-2026-8452 lets an unauthenticated attacker corrupt memory in Citrix NetScaler's SAML parser with a single request, potentially leading to remote code execution. Bishop Fox breaks down the patch, how to safely verify it across a fleet, and what exploitation actually looks like in the logs.

  • Open

    AWS Network Firewall now supports rule hit count
    As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps. Organizations with governance policies that require removal of dormant rules after a […]  ( 118 min )
  • Open

    ‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert
    Apple customers in 110 countries received threat notifications recently alerting them to suspected spyware attacks targeting their devices. The post ‘Unprecedented’ Number of Apple Users Received Recent Spyware Alert appeared first on The Citizen Lab.
  • Open

    CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction
    Traditional vulnerability management was built for a smaller, slower problem than most teams face today. This post breaks down CTEM, why it exists, how its five stages work, and what it actually takes to move from a reactive pile of findings to a continuous, prioritized risk reduction program.
  • Open

    PacketFence Cloud: Enterprise Network Access Control, Now a Managed Service
    No content preview

  • Open

    Defeating AI-Assisted Reverse Engineering (or at Least Trying To)
    Is LLM-assisted reverse engineering making obfuscation pointless? We spent a couple of weeks trying to find out, by handing sandboxed agents a series of progressively hardened AArch64 binaries and one prompt: recover the hidden strings inside. This post walks through what the agent actually did, three ways our experiment fell apart, and what those failures suggest about designing protections that hold against automated analysis.
  • Open

    Identifying Agentic Automation with Behavioral Telemetry
    Learn how Akamai uses Masked Autoencoder Transformer models to detect sparse behavioral telemetry from autonomous AI browser agents, such as Comet.
    Future-Proofing the Internet: Akamai Achieves End-to-End PQC
    No content preview
  • Open

    Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
    Many teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who’s asking, so it might return data the user shouldn’t see. […]  ( 126 min )
  • Open

    Oz Hair and Beauty - 1,988,331 breached accounts
    In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.
    Fanlore - 144,520 breached accounts
    In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.

  • Open

    Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway
    When deploying AI agents with Amazon Bedrock AgentCore, organizations benefit from built-in modern support for OAuth 2.0, AWS Identity and Access Management (IAM), and API key authentication through Amazon Bedrock AgentCore Gateway. However, some enterprise environments still use legacy authentication mechanisms such as HTTP Basic Authentication (Basic Auth) (RFC 7617). The extensible architecture of AgentCore […]  ( 117 min )
    Security Hub Extended adds Supply Chain Security as its tenth category
    Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted […]  ( 116 min )
  • Open

    Akamai Valkey Managed Database: Real-Time Memory for Enterprise AI
    Introducing Akamai Valkey Managed Database: a low-latency, in-memory data layer to optimize AI inference costs, accelerate RAG, and power real-time AI agents.
    Akamai Named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026
    No content preview

  • Open

    Call for Applications: Information Controls Research Program 2026
    The Open Technology Fund is accepting applications for the 2026 Information Controls Research Program. The post Call for Applications: Information Controls Research Program 2026 appeared first on The Citizen Lab.
  • Open

    Updates to your AWS Sign-In experience
    Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new options for creating and accessing AWS accounts. To […]  ( 115 min )
  • Open

    Your Website Now Has Two Audiences: Humans and AI
    No content preview

  • Open

    📖 [The CloudSecList] Issue 351
    📖 [The CloudSecList] Issue 351 was originally published by Marco Lancini at CloudSecList on August 16, 2026.

  • Open

    Machine Learning Has a Specific Role in Blockchain Intelligence
    Machine learning is a valuable tool in blockchain analytics – so long as it is used responsibly. Automated tools can… The post Machine Learning Has a Specific Role in Blockchain Intelligence appeared first on Chainalysis.  ( 14 min )
  • Open

    The OWASP Top 10 for LLM Applications 2026: From Model Risks to Agentic Security
    No content preview

  • Open

    AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
    Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]  ( 116 min )
  • Open

    Keep Your Tech FLAME Alive: Trailblazer Suzanne Wheeler
    In this Akamai FLAME Trailblazer blog post, Suzanne Wheeler describes her journey into cybersecurity and gives advice to women who are finding their own path.
  • Open

    RingCentral - 1,596,490 breached accounts
    In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.

  • Open

    How AWS IAM role manager rethinks the starting point for IAM roles
    When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your […]  ( 118 min )
  • Open

    From P-Code to GNN: extract binary code semantics
    pcode_graph is a Python library, published by Quarkslab, suitable to build semantic graphs from binary code. We present how to use it to detect function similarities in binaries.

  • Open

    The August 2026 Security Update Review
    I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “new normal”, it’s time to readjust what we consider a true bug apocalypse. This month’s release is thankfully smaller than last months, but still huge by historical standards. Take a break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for August 2026 For the first part of the August release, Adobe released five bulletins addressing 51 unique CVEs in Adobe ColdFusion, Commerce, Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. Here…
2026-09-10T03:24:27.368Z osmosfeed 1.15.1