← Back to Blog
Security News
Security News — 7 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 9 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 7 August 2026 · 18 items.
Government & Critical Vulnerability Advisories
CISA Current Activity07 Aug
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability This type of vulnerability is a frequen…
Read at source →
CISA Cybersecurity Advisories07 Aug
View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session reset…
Read at source →
Primary Threat Research & Vendor Intelligence
Palo Alto Unit 4207 Aug
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42 .
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer07 Aug
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]
Read at source →
BleepingComputer07 Aug
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
Read at source →
The Hacker News07 Aug
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatte…
Read at source →
The Hacker News07 Aug
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is de…
Read at source →
The Hacker News07 Aug
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterpr…
Read at source →
Dark Reading07 Aug
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
Read at source →
BleepingComputer07 Aug
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]
Read at source →
BleepingComputer07 Aug
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [.…
Read at source →
The Hacker News07 Aug
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on…
Read at source →
Blue Team, Incident Response & Detection Engineering
Elastic Security Labs07 Aug
Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.
Read at source →
SANS Internet Storm Center (Handler Diary)07 Aug
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed comm…
Read at source →
SANS Internet Storm Center (Handler Diary)07 Aug
Read at source →
Elastic Security Labs07 Aug
A 40-line CEL integration snapshots .npmrc files every 6 hours to catch cooldown removals. This post walks through the three ways we broke filestream before landing on snapshot semantics.
Read at source →
Security Executive, Architecture & Policy
Schneier on Security07 Aug
Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Read at source →
Schneier on Security07 Aug
Through data brokers, ICE is buying the information you provided to open a credit card.
Read at source →