threat-intel Iran-Linked Hackers Shut Down UK Power Plant for Four Days Iranian-linked hackers successfully shut down a British power plant for four days, raising significant concerns about the escalating cyber threat landscape and the vulnerability of UK critical infrastructure. The inciden… SecurityWeek · 6d ago High UKIRUSirancyberattackcritical infrastructure
threat-intel TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy TikTok has agreed to a $400 million settlement with the U.S. Department of Justice to address allegations of violating children's privacy laws and failing to adequately protect user data. This settlement follows a long-s… SecurityWeek · 6d ago Medium USprivacychildrensocial media
threat-intel Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund Anthropic is expanding access to its advanced AI cybersecurity model, Mythos 5, to bolster defenses against cyberattacks. They are doing this through partnerships, a new open-source funding program, and an updated Claude… SecurityWeek · 6d ago Medium USaicybersecurityvulnerability
threat-intel Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Multiple banking trojans – Manic, Grandoreiro, and ToxicPanda 2.0 – are actively targeting users worldwide, with a particular focus on financial institutions in Europe, Latin America, and increasingly, Russia. These troj… SecurityWeek · Aug 22, 2026 High BRUKRUbanking trojanmobile malwaresupply chain
threat-intel Former NSA Director Paul Nakasone Launches National Security Advisory Firm Retired NSA Director Paul Nakasone has launched a new national security advisory firm, Nakasone Group, to provide cybersecurity and risk management services to high-profile individuals and organizations. The firm leverag… SecurityWeek · Aug 21, 2026 Medium cybersecuritynational securityrisk management
threat-intel In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug This week’s cybersecurity news highlights a range of active threats and vulnerabilities. A severe code injection flaw in Ray-Project Ray is being actively exploited by a Mirai-based botnet, while T-Mobile took drastic ac… SecurityWeek · Aug 21, 2026 High CVE-2025-62593JACAvulnerabilityddosransomware
threat-intel Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini Researchers at Adversa AI discovered a new attack technique called ‘Cryptographic Context Injection’ that bypasses AI safety guardrails in xAI’s Grok and Gemini models. They disclosed their findings to xAI in June 2026,… SecurityWeek · Aug 21, 2026 High prompt-injectioncryptographyai-safety
threat-intel New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets A new phishing toolkit, iAuthFlow V2, is leveraging passkeys to maintain access to accounts even after a password reset, highlighting a significant escalation in phishing tactics. The tool, sold for $10,000, utilizes a s… SecurityWeek · Aug 21, 2026 High phishingpasskeysocial engineering
vulnerability Critical Isolated-vm Vulnerability Leads to RCE on Host A critical type confusion vulnerability in the isolated-vm Node.js library is being exploited to achieve remote code execution (RCE) on the host system. The vulnerability stems from a flawed data transfer mechanism withi… SecurityWeek · Aug 21, 2026 Critical rcetype-confusionnode.js
supply-chain Rust Supply Chain Attack Linked to North Korean Hackers North Korean hackers, believed to be the Sapphire Sleet group, orchestrated a sophisticated supply chain attack targeting the Rust ecosystem. The attack leveraged a compromised Rust crate, arrayref, to deliver a maliciou… SecurityWeek · Aug 21, 2026 High KPrustsupply chainnorth korean
threat-intel Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Two recent surveys reveal a significant disconnect between contractors’ confidence in their CMMC compliance and their ability to actually prove it. Despite high levels of self-reported confidence, a substantial portion s… SecurityWeek · Aug 21, 2026 High cmmcdfarscybersecurity
vulnerability Microsoft Rolls Out 22 Fresh Security Patches Microsoft released 22 security patches addressing critical and high-severity vulnerabilities across its Azure, Entra ID, Exchange, Fabric, and Defender products. Several of these flaws, including a zero-day exploit dubbe… SecurityWeek · Aug 21, 2026 Critical CVE-2026-69502CVE-2026-69555CVE-2026-65816vulnerabilitypatchzero-day
vulnerability CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies regarding two critical vulnerabilities in TrueConf, a secure video conferencing platform. Threat actors, spe… SecurityWeek · Aug 21, 2026 High CVE-2026-72529CVE-2026-72530RUBYvulnerabilitypatchtrueconf
vulnerability Hackers Target Zimbra Servers in Active Exploitation Campaign A recently patched Zimbra vulnerability (CVE-2026-73570) is currently being actively exploited by threat actors, primarily linked to Russian and Chinese state-sponsored hackers. Attackers are leveraging this flaw to gain… SecurityWeek · Aug 20, 2026 Critical CVE-2026-73570PLzimbravulnerabilitysnmp
threat-intel Surveillance – Everything You Wanted to Know, But Were Afraid to Ask The article explores the increasingly pervasive use of surveillance technologies by various entities – companies, law enforcement, criminals, and intelligence agencies – and the ethical and legal concerns surrounding thi… SecurityWeek · Aug 20, 2026 High surveillanceprivacydata collection
threat-intel Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia A threat actor, dubbed Operation CameraSwarm, has compromised over 14,000 Dahua IP cameras across Ukraine and Russia through a sophisticated campaign utilizing brute-force attacks and exploiting multiple vulnerabilities… SecurityWeek · Aug 20, 2026 High CVE-2021-33044CVE-2021-33045RUUKip camerasvulnerabilitybackdoor
vulnerability Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Atlassian and Splunk have released patches to address over 250 vulnerabilities across their products, including numerous critical and high-severity flaws in third-party dependencies. These updates aim to mitigate risks s… SecurityWeek · Aug 20, 2026 High vulnerabilitypatchthird-party
vulnerability MLflow Vulnerability Exploited for Cloud Credential Theft A vulnerability in MLflow, a popular AI engineering platform, has been exploited by threat actors to steal cloud credentials and secrets. The flaw, tracked as CVE-2026-64849, allows unauthenticated SSRF attacks, leading… SecurityWeek · Aug 20, 2026 Critical CVE-2026-64849ssrfcloudmlflow
vulnerability Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Cisco has released patches to address 15 critical and high-severity vulnerabilities across its products, including Crosswork and BroadWorks. These flaws could lead to remote code execution, authentication bypasses, and d… SecurityWeek · Aug 20, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358vulnerabilitypatchsecurity
threat-intel AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking Atalanta has developed ‘Argo,’ an AI-assisted tool designed to proactively identify vulnerabilities in software and internet-connected systems, specifically to bolster defenses against ongoing cyber threats from Russia a… SecurityWeek · Aug 20, 2026 High RUIRaivulnerabilitycybersecurity