← Back to Blog
Security News
Security News — 20 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 10 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 20 August 2026 · 18 items.
Government & Critical Vulnerability Advisories
CISA Current Activity19 Aug
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent…
Read at source →
CISA Cybersecurity Advisories19 Aug
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply r…
Read at source →
Primary Threat Research & Vendor Intelligence
Microsoft Security Blog19 Aug
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud…
Read at source →
Cisco Talos19 Aug
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer20 Aug
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]
Read at source →
BleepingComputer19 Aug
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fe…
Read at source →
BleepingComputer19 Aug
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]
Read at source →
Dark Reading19 Aug
The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.
Read at source →
BleepingComputer19 Aug
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
Read at source →
The Hacker News19 Aug
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rat…
Read at source →
The Hacker News19 Aug
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert anoth…
Read at source →
Dark Reading19 Aug
A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.
Read at source →
The Hacker News19 Aug
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been prev…
Read at source →
The Hacker News19 Aug
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)19 Aug
Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its M…
Read at source →
SANS Internet Storm Center (Handler Diary)19 Aug
Read at source →
Security Executive, Architecture & Policy
Schneier on Security19 Aug
ICE collected nearly a million DNA samples last year.
Read at source →
Daniel Miessler19 Aug
A honeycomb of small cells, one person at a screen in each, a purple filament threading cell to cell and turning each one cold while bundles are drawn out the bottom/images/prompt-injection-worm.webp/images/prompt-injection-worm.webp I thi…
Read at source →