← Back to Blog
Security News
Security News — 3 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 8 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 3 August 2026 · 12 items.
Government & Critical Vulnerability Advisories
CISA Current Activity03 Aug
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability Th…
Read at source →
Primary Threat Research & Vendor Intelligence
Cisco Talos03 Aug
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
Read at source →
Palo Alto Unit 4203 Aug
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appe…
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading03 Aug
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.
Read at source →
Dark Reading03 Aug
Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.
Read at source →
Dark Reading03 Aug
Last month's incidents in which the AI model breached real-world systems derived from over-permissioning, especially with Internet access.
Read at source →
Dark Reading03 Aug
Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
Read at source →
Blue Team, Incident Response & Detection Engineering
Elastic Security Labs03 Aug
Elastic Security now tracks every detection rule change with one-click rollback and makes case data queryable out of the box, so SOC teams get audit trails and reporting without configuring anything.
Read at source →
Red Team, Bug Bounty & Exploit Research
ProjectDiscovery Blog03 Aug
What closed and open models actually do when you tell them to hack a website Summary The cybersecurity capability of a model is currently measured by a solve rate, a percentage, and that number tells you almost nothing worth knowing. It do…
Read at source →
Security Executive, Architecture & Policy
Schneier on Security03 Aug
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting sof…
Read at source →
Schneier on Security03 Aug
This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild . OpenAI was running security tests on two of i…
Read at source →
Daniel Miessler03 Aug
Human architects reconstructing a company into a transparent AI-native operating system/images/the-ai-native-company.webp/images/the-ai-native-company.webp Heading into Black Hat / DEF CON this week I think the biggest idea in tech right n…
Read at source →