← Back to Blog
Security News
Security News — 4 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 10 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 4 August 2026 · 18 items.
Government & Critical Vulnerability Advisories
CISA Current Activity04 Aug
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authenticatio…
Read at source →
CISA Cybersecurity Advisories04 Aug
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied Bio…
Read at source →
CISA Cybersecurity Advisories04 Aug
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware <July_20_2026…
Read at source →
Primary Threat Research & Vendor Intelligence
Microsoft Security Blog04 Aug
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical gui…
Read at source →
Microsoft Security Blog04 Aug
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first…
Read at source →
Microsoft Security Blog04 Aug
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET…
Read at source →
Palo Alto Unit 4204 Aug
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-D…
Read at source →
Palo Alto Unit 4204 Aug
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42 .
Read at source →
Cisco Talos04 Aug
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI.
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading04 Aug
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
Read at source →
Dark Reading04 Aug
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.
Read at source →
Dark Reading04 Aug
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
Read at source →
Blue Team, Incident Response & Detection Engineering
Elastic Security Labs04 Aug
Public leaderboards can't tell you which LLM to trust in your SOC, so Elastic built an evaluation framework that grades models on the work (tool calls, execution traces, blind judging) across Agent Builder, Attack Discovery, and automatic…
Read at source →
SANS Internet Storm Center (Handler Diary)04 Aug
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven&#;x26;#;39;t noticed before. All of these URLs appear to be associated with diagnostic tools:
Read at source →
TrustedSec Blog04 Aug
<p>Transport Layer Security: the compliance checkbox that's harder to get right than it looks. In this blog, we cover the most common TLS misconfigurations and what organizations need to know to meet the standard.</p>
Read at source →
Elastic Security Labs04 Aug
LLMs made it cheap to flood bug bounty programs with submissions. Here's how Elastic built an AI triage agent that matches human decisions 85% of the time, including the architecture, threat model and calibration against 3,300 real reports
Read at source →
Security Executive, Architecture & Policy
Schneier on Security04 Aug
Attribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnes…
Read at source →
Schneier on Security04 Aug
And it’s personal information (alternate link ): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Expos…
Read at source →