supply-chain Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 research reveals a significant shift in supply chain attacks, with attackers now targeting the tools and processes developers use throughout the software development lifecycle (SDLC). The ChainDrop npm worm exemp… Palo Alto Unit 42 · Aug 21, 2026 High CVE-2024-3094supply chainnpmci/cd
other Friday Squid Blogging: Neon Flying Squid This article describes a fascinating natural phenomenon – neon flying squid gliding near a research vessel in the Pacific Ocean. Scientists captured images of these squid using their hyponome to propel themselves above t… Schneier on Security · Aug 21, 2026 Info cephalopodmarine biologyanimal behavior
threat-intel How an Emerging Industrial Protocol Family Could Put OT at Risk A new research report from Nozomi Networks (acquired by Mitsubishi Electric) highlights a significant vulnerability within Time-Sensitive Networking (TSN) protocols, specifically CC-Link IE TSN, a widely deployed industr… Dark Reading · Aug 21, 2026 High tsnindustrial controlcybersecurity
threat-intel Lawmakers call for investigation into impact of CISA staffing cuts Lawmakers are demanding a Government Accountability Office (GAO) investigation into the impact of significant staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA). These cuts, totaling nearly one-… The Record · Aug 21, 2026 High cisacybersecuritycritical infrastructure
threat-intel 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 A new AI-powered Linux backdoor, RedC2 4.0, is being distributed through malicious npm packages, significantly lowering the barrier to entry for attackers. The framework, developed and sold by Red Offsec, offers advanced… The Hacker News · Aug 21, 2026 High npmlinuxbackdoor
threat-intel OWASP Flags Top AI Skill Risks in New Security Blueprint The OWASP has released a new top 10 list focusing on security risks associated with "skills" – essentially, scripts that add functionality to agentic AI platforms. The primary risk is malicious skills, often introduced t… Dark Reading · Aug 21, 2026 High aiskillsagentic ai
threat-intel AI Is Learning to Write Genetic Code Researchers have successfully used AI to design and synthesize entirely new bacteriophages – viruses that target bacteria – demonstrating a significant advancement in synthetic biology and raising concerns about potentia… Schneier on Security · Aug 21, 2026 Medium synthetic biologyaibioweapons
threat-intel Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it US Homeland Security cybersecurity officials are warning users of TrueConf, a video conferencing tool developed in Russia, to urgently patch the software due to a critical vulnerability that could allow attackers to remo… The Register · Aug 21, 2026 Critical CVE-2026-72529CVE-2026-72530RUUSvulnerabilitycybersecurityrussia
threat-intel Former NSA Director Paul Nakasone Launches National Security Advisory Firm Retired NSA Director Paul Nakasone has launched a new national security advisory firm, Nakasone Group, to provide cybersecurity and risk management services to high-profile individuals and organizations. The firm leverag… SecurityWeek · Aug 21, 2026 Medium cybersecuritynational securityrisk management
threat-intel Escape Data ZATAZ 2.0 transforme l’enquête en jeu Escape Data ZATAZ 2.0 is a browser-based escape game designed to simulate and train cybersecurity and OSINT investigation skills. The game encourages players to develop critical observation, logical deduction, and a meth… ZATAZ · Aug 21, 2026 Medium cybersecurityosintinvestigation
threat-intel U.S. Bank says breach claims related to fourth-party incident U.S. Bank is investigating claims of a ransomware attack linked to a third-party contractor, but the bank asserts its own systems and network were not compromised. The incident stems from a LockBit ransomware group leak,… The Record · Aug 21, 2026 Medium ransomwaredata breachthreat intelligence
threat-intel Pokémon Center touché par la cyberattaque d’un prestataire A cyberattack targeting CEVA Logistics, a third-party logistics provider, has exposed customer data of the Pokémon Center in Europe. This follows a similar incident affecting Steam users and The Pokémon Company, with pot… ZATAZ · Aug 21, 2026 High FRsupply-chainphishingdata-breach
threat-intel Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has discovered a method to weaponize Microsoft Defender's own built-in boot-time remediation driver (BTR.sys) to delete security software and manipulate Windows systems. This technique, dubbed ‘BTR R… The Hacker News · Aug 21, 2026 High CVE-2021-24092driverbootremediation
threat-intel Target visé par une nouvelle revendication de fuite A new ransomware group, Xpl0itrs, claims to possess source code stolen from Target, threatening to release it unless the company negotiates. While the claim is unverified and a previous incident in January 2026 involved… ZATAZ · Aug 21, 2026 High USAUransomwaresource codedata breach
threat-intel Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet A new malware family, dubbed JarService, is targeting Android car head units developed by DoFun, leveraging the built-in update mechanism to spread ad fraud and proxy botnet capabilities. The campaign is attributed to th… The Hacker News · Aug 21, 2026 High CNandroidcarmalware
threat-intel Des bases de joueurs européens de casino diffusées sur un forum pirate A hacker is offering for sale databases containing personal information and deposit details of tens of thousands of European casino players. The seller claims to have data from casinos in several European countries, incl… ZATAZ · Aug 21, 2026 High ITDEFRdata breachcasinofraud
threat-intel Checker max cible les portefeuilles Solana en masse Checker Max, a tool for identifying hidden Solana assets, has been advertised on a Russian criminal forum. The tool analyzes up to 1,000 Solana wallet addresses at a time, offering a significant capability for cyber inte… ZATAZ · Aug 21, 2026 Medium RUsolanablockchainthreat intelligence
threat-intel In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug This week’s cybersecurity news highlights a range of active threats and vulnerabilities. A severe code injection flaw in Ray-Project Ray is being actively exploited by a Mirai-based botnet, while T-Mobile took drastic ac… SecurityWeek · Aug 21, 2026 High CVE-2025-62593JACAvulnerabilityddosransomware
data-breach Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen Canada’s Hospital for Sick Children suffered a data breach, exposing the personal information of current and former employees, potentially linked to a third-party software application. This follows a ransomware attack in… The Record · Aug 21, 2026 Medium healthcarecyberattackdata breach
threat-intel Hackers poison popular Rust crates to steal developers' credentials Hackers are exploiting vulnerabilities in popular Rust crates (libraries) to steal developers' credentials. Specifically, flaws in extensions for Joomla websites are being used to gain unauthorized access to developer ac… The Register · Aug 21, 2026 Medium rustjoomlavulnerability