← Back to Blog
Security News
Security News — 5 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 8 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 5 August 2026 · 17 items.
Government & Critical Vulnerability Advisories
CISA Current Activity05 Aug
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability This type of vulnerabil…
Read at source →
Primary Threat Research & Vendor Intelligence
Microsoft Security Blog05 Aug
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Prot…
Read at source →
Microsoft Security Blog05 Aug
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunitie…
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading05 Aug
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
Read at source →
Dark Reading05 Aug
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.
Read at source →
Dark Reading05 Aug
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.
Read at source →
Dark Reading05 Aug
CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.
Read at source →
The Hacker News05 Aug
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for we…
Read at source →
The Hacker News05 Aug
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that…
Read at source →
The Hacker News05 Aug
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, c…
Read at source →
The Hacker News05 Aug
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importin…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)05 Aug
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident…
Read at source →
SANS Internet Storm Center (Handler Diary)05 Aug
Read at source →
Red Team, Bug Bounty & Exploit Research
PortSwigger Research05 Aug
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
Read at source →
PortSwigger Research05 Aug
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
Read at source →
Security Executive, Architecture & Policy
Schneier on Security05 Aug
This is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any…
Read at source →
Daniel Miessler05 Aug
Dense branching mass compressed through a mechanical iris bottleneck/images/why-arent-things-worse-header.webp/images/why-arent-things-worse-header.webp One of the things I’ve been thinking about for years, but more acutely now because of…
Read at source →