← Back to Blog
Security News
Security News — 21 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 10 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 21 August 2026 · 24 items.
Government & Critical Vulnerability Advisories
CISA Current Activity20 Aug
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability CVE-2026-7253…
Read at source →
CISA Cybersecurity Advisories20 Aug
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized acce…
Read at source →
Primary Threat Research & Vendor Intelligence
Cisco Talos20 Aug
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber o…
Read at source →
Cisco Talos20 Aug
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and…
Read at source →
Cisco Talos20 Aug
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infect…
Read at source →
Palo Alto Unit 4220 Aug
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42 .
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading21 Aug
Government agencies with smaller budgets need support — and here's how you can help.
Read at source →
Dark Reading20 Aug
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.
Read at source →
The Hacker News20 Aug
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a rem…
Read at source →
The Hacker News20 Aug
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe…
Read at source →
Dark Reading20 Aug
In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.
Read at source →
BleepingComputer20 Aug
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]
Read at source →
Dark Reading20 Aug
The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?
Read at source →
The Hacker News20 Aug
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Else…
Read at source →
The Hacker News20 Aug
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgramma…
Read at source →
BleepingComputer20 Aug
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]
Read at source →
BleepingComputer20 Aug
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past…
Read at source →
BleepingComputer20 Aug
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)20 Aug
Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at "Risky" logins.
Read at source →
SANS Internet Storm Center (Handler Diary)20 Aug
Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that new, but it&#;x26;#;39;s new enough that lots of folks (and commercial…
Read at source →
SANS Internet Storm Center (Handler Diary)20 Aug
Read at source →
Security Executive, Architecture & Policy
Daniel Miessler20 Aug
A figure carrying a crate around a deep circular rut worn by dozens of layered footprints, with an angular slot at the rut's edge and one clean line departing from it/images/i-only-do-anything-once.webp/images/i-only-do-anything-once.webp…
Read at source →
Schneier on Security20 Aug
OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.
Read at source →
Schneier on Security20 Aug
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate r…
Read at source →