← Back to Blog
Security News
Security News — 25 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 6 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 25 August 2026 · 16 items.
Government & Critical Vulnerability Advisories
CISA Current Activity24 Aug
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulner…
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading24 Aug
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
Read at source →
BleepingComputer24 Aug
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the publ…
Read at source →
Dark Reading24 Aug
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
Read at source →
BleepingComputer24 Aug
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Read at source →
BleepingComputer24 Aug
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
Read at source →
The Hacker News24 Aug
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages a…
Read at source →
The Hacker News24 Aug
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts…
Read at source →
BleepingComputer24 Aug
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
Read at source →
Dark Reading24 Aug
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
Read at source →
Dark Reading24 Aug
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
Read at source →
The Hacker News24 Aug
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper…
Read at source →
The Hacker News24 Aug
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLo…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)24 Aug
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#;x26;#;39;t use real steganography:
Read at source →
SANS Internet Storm Center (Handler Diary)24 Aug
Read at source →
Security Executive, Architecture & Policy
Schneier on Security24 Aug
Interesting paper : Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception , employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures a…
Read at source →