← Back to Blog
Security News
Security News — 22 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 7 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 22 August 2026 · 19 items.
Government & Critical Vulnerability Advisories
CISA Current Activity21 Aug
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability This type of vulnerabi…
Read at source →
Primary Threat Research & Vendor Intelligence
Palo Alto Unit 4221 Aug
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development…
Read at source →
Independent Investigative Journalism & Breaking News
The Hacker News21 Aug
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2…
Read at source →
BleepingComputer21 Aug
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
Read at source →
Dark Reading21 Aug
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.
Read at source →
BleepingComputer21 Aug
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Read at source →
The Hacker News21 Aug
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 thr…
Read at source →
The Hacker News21 Aug
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the m…
Read at source →
BleepingComputer21 Aug
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
Read at source →
BleepingComputer21 Aug
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the im…
Read at source →
Dark Reading21 Aug
Government agencies with smaller budgets need support — and here's how you can help.
Read at source →
Dark Reading21 Aug
The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.
Read at source →
The Hacker News21 Aug
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden wit…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)21 Aug
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of a…
Read at source →
SANS Internet Storm Center (Handler Diary)21 Aug
Read at source →
SANS Internet Storm Center (Handler Diary)21 Aug
One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
Read at source →
Security Executive, Architecture & Policy
Schneier on Security21 Aug
The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the firs…
Read at source →
Schneier on Security21 Aug
This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from t…
Read at source →
Schneier on Security21 Aug
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior —while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation w…
Read at source →