← Back to Blog

Security News — 18 August 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 7 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 18 August 2026 · 21 items.

Government & Critical Vulnerability Advisories

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

SANS Internet Storm Center (Handler Diary)17 Aug

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerab…

Read at source →
SANS Internet Storm Center (Handler Diary)17 Aug

Apple Screen Sharing Security, (Mon, Aug 17th)

About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP p…

Read at source →

Security Executive, Architecture & Policy

Daniel Miessler17 Aug

How to Get Started in Cybersecurity 2026

A person vaulting on a machine lever toward a glowing keyhole/images/how-to-get-started-in-cybersecurity-2026.webp/images/how-to-get-started-in-cybersecurity-2026.webp I've been writing versions of this guide since 2008. The most recent bi…

Read at source →
Daniel Miessler17 Aug

How AI Builders Will Get Hacked

How AI Builders Will Get Hacked/images/how-ai-builders-get-hacked.webp/images/how-ai-builders-get-hacked.webp If you are building stuff with AI I have a critical security recommendation for you. Create a continuously-running security testi…

Read at source →
Schneier on Security17 Aug

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

Read at source →
Daniel Miessler17 Aug

Fix Execution, Not the SOP

A flood of documents pours into a funnel that drips onto a tiny model a man is polishing, while real unbuilt work waits through an open door/images/fix-execution-not-the-sop.webp/images/fix-execution-not-the-sop.webp AI is multiplying the…

Read at source →
Daniel Miessler17 Aug

Stolen Authority

Stolen Authority/images/stolen-authority.webp/images/stolen-authority.webp We need to label this parasitic marketing technique with an adequately strong term. Stolen Authority. From stolen Valorhttps://en.wikipedia.org/wiki/Stolen_valor It…

Read at source →
← All blog posts