← Back to Blog
Security News
Security News — 19 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 19 August 2026 · 21 items.
Government & Critical Vulnerability Advisories
CISA Current Activity18 Aug
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-…
Read at source →
CISA Cybersecurity Advisories18 Aug
View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application bin…
Read at source →
CISA Cybersecurity Advisories18 Aug
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm <26.06.1 (CVE-2026-55…
Read at source →
Primary Threat Research & Vendor Intelligence
Palo Alto Unit 4218 Aug
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-S…
Read at source →
Microsoft Security Blog18 Aug
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavi…
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading18 Aug
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
Read at source →
Dark Reading18 Aug
Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.
Read at source →
BleepingComputer18 Aug
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
Read at source →
Dark Reading18 Aug
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community.
Read at source →
The Hacker News18 Aug
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copil…
Read at source →
The Hacker News18 Aug
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing m…
Read at source →
BleepingComputer18 Aug
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
Read at source →
The Hacker News18 Aug
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000…
Read at source →
BleepingComputer18 Aug
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is ne…
Read at source →
Dark Reading18 Aug
A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.
Read at source →
The Hacker News18 Aug
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent har…
Read at source →
BleepingComputer18 Aug
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
Read at source →
Blue Team, Incident Response & Detection Engineering
TrustedSec Blog18 Aug
<p>Manufacturing knows what happens when IT and OT divide; AI governance is an unexpected chance to do it differently. In this blog, we walk through a unified governance model that bridges both before bad habits set in.</p>
Read at source →
SANS Internet Storm Center (Handler Diary)18 Aug
Read at source →
Security Executive, Architecture & Policy
Daniel Miessler18 Aug
A rigid purple lattice of identical cells cracking and warping into warm organic curves around a single figure whose chest emits an irregular waveform/images/unconventional-thought-differentiator.webp/images/unconventional-thought-differen…
Read at source →
Schneier on Security18 Aug
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “ CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs “: Abstract: L…
Read at source →