threat-intel Smashing Security podcast #481: Never say this to a robot dog This podcast episode centers around a social engineering attempt targeting the new Prime Minister of the UK, Andy Burnham, with a fabricated call from the Trump administration. The discussion then shifts to Black Hat 202… Graham Cluley · Aug 19, 2026 High social engineeringrobot dogai hacking
threat-intel 'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers Federal agencies are warning that attackers are now leveraging AI-generated code to target critical infrastructure controllers, presenting a significant and rapidly evolving threat. This isn't a theoretical risk; it's a… The Register · Aug 19, 2026 High IRaicyberattackcritical infrastructure
threat-intel ICE boss to agents: Leave the Meta spy glasses at home Several security-related stories are emerging, including a warning about Meta’s spy glasses being used for phishing, a vulnerability exploited in Joomla extensions, and ongoing efforts to combat Iranian propaganda and ra… The Register · Aug 19, 2026 Medium IRcybersecuritythreat intelligencephishing
threat-intel Flock surveillance backlash mounts as fiendish Halloween plans circulate Several security-related stories are circulating, including a backlash against surveillance technology from Flock, a method for social engineering AI reasoning engines, a zero-day attack targeting vulnerable SharePoint s… The Register · Aug 19, 2026 Medium CHIRsurveillancephishingvulnerability
threat-intel Virtual Event Today: CodeSecCon – Secure Your Code and Applications CodeSecCon, a virtual event focused on software security, is taking place today. The event aims to help developers and cybersecurity professionals improve application security practices and address challenges in DevSecOp… SecurityWeek · Aug 19, 2026 Info devsecopssecure codingai security
threat-intel Comcast gives its Wi-Fi motion detector a security makeover This article highlights a variety of cybersecurity and technology news stories, including a security update for Comcast's Wi-Fi motion detector, a method for social engineering AI reasoning engines, and ongoing efforts t… The Register · Aug 19, 2026 Medium IRsecurityphishingransomware
threat-intel Phishing 3.0: The Fight Moves to Agent Versus Agent Phishing has evolved beyond simple email attacks into a sophisticated, AI-powered threat landscape – Phishing 3.0. Attackers are now utilizing AI agents to research targets, craft personalized lures, and execute multi-ch… The Hacker News · Aug 19, 2026 High HOphishingaideepfake
threat-intel Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation Four critical vulnerabilities – affecting macOS, SharePoint, vCenter, and IKE – are currently being actively exploited in the wild. These flaws have led to widespread attacks, including the deployment of ransomware and b… The Hacker News · Aug 19, 2026 Critical CVE-2026-65400CVE-2026-55040CVE-2026-59310DEUSTRvulnerabilitycyberattackransomware
threat-intel CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities The CISA has issued an urgent warning about four actively exploited vulnerabilities affecting Microsoft, VMware, and Apple products. These flaws, including a double-free in Windows IKE and a weak authentication bypass in… SecurityWeek · Aug 19, 2026 Critical CVE-2026-33824CVE-2026-55040CVE-2026-59310CHvulnerabilitypatchingremote code execution
threat-intel Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure Microsoft has linked over 30 web domains to MacSync Stealer, a macOS information stealer, after observing recurring network behaviors and endpoint activity. The malware uses various techniques, including AppleScript, to… The Hacker News · Aug 19, 2026 High macmacosstealer
threat-intel 'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture Researchers discovered a novel 'meta-hacking' technique that tricked Microsoft Copilot Personal into revealing its own security vulnerabilities, allowing attackers to map out its architecture and subsequently steal enter… Dark Reading · Aug 18, 2026 High CVE-2026-24301prompt-injectionmeta-hackingdata-exfiltration
threat-intel The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed Rich Mogull, a senior analyst at the Cloud Security Alliance, highlights a growing trend of "industrial accidents" – rogue AI agent attacks – stemming from a lack of robust safety protocols and sandboxing around increasi… Dark Reading · Aug 18, 2026 High CHUNaiartificial intelligencecybersecurity
vulnerability Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps Varonis Threat Labs discovered three vulnerabilities, collectively named ‘CoSnitch,’ in Microsoft Copilot Personal that could allow a single click on a crafted link to silently exfiltrate data from connected apps. The fl… The Hacker News · Aug 18, 2026 High CVE-2026-24301CVE-2026-24299prompt injectiondata exfiltrationmemory poisoning
threat-intel Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 A threat actor calling itself Ransom Busters is offering to delete stolen ransomware data from servers in exchange for a payment, ranging from $20,000 to $60,000. GuidePoint Research and Intelligence Team (GRIT) has iden… The Hacker News · Aug 18, 2026 High USransomwaredata exfiltrationcredential theft
threat-intel CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Nico Waisman’s cybersecurity journey is a remarkable and almost accidental one, beginning with a childhood fascination with hacking in Argentina and culminating in his current role as CISO at XBOW, a company specializing… SecurityWeek · Aug 18, 2026 High ARcybersecurityoffensive-securityai
threat-intel AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Rapid7’s analysis reveals a significant shift in the cybersecurity landscape driven by AI, leading to a dramatic increase in disclosed and exploited vulnerabilities. The traditional patching model is becoming obsolete du… SecurityWeek · Aug 18, 2026 High CHRUIRaivulnerabilitiespatching
threat-intel Copilot tricked into telling reseachers how to hack itself Researchers successfully tricked Microsoft's Copilot AI assistant into revealing instructions on how to exploit vulnerabilities within itself, highlighting a significant weakness in AI reasoning and a potential avenue fo… The Register · Aug 18, 2026 High aivulnerabilityprompt-injection
threat-intel Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud TwinLoot, a sophisticated Python-based malware framework, operates entirely from within Microsoft's Azure and 365 cloud services, using various Microsoft services – SharePoint Online, Microsoft Graph API, and Teams TURN… Dark Reading · Aug 18, 2026 High living-off-the-landcloud-basedpersistence
threat-intel TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across netw… The Hacker News · Aug 18, 2026 High c2microsoftlateral movement
threat-intel 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets A new typosquatting campaign targeting RubyGems users has been identified, leveraging a Rust-based stealer to steal browser credentials, cryptocurrency wallets, and Telegram data. The campaign utilizes a 'StubMaker' tool… The Hacker News · Aug 18, 2026 High typosquattingrubymalware