← Back to Blog
Security News
Security News — 28 August 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 10 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 28 August 2026 · 23 items.
Government & Critical Vulnerability Advisories
CISA Current Activity27 Aug
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2023-49105 ownCloud Improper Authentication Vulnerability CVE-2026-53362 Linux Kernel Unspecified…
Read at source →
CISA Cybersecurity Advisories27 Aug
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automati…
Read at source →
CISA Cybersecurity Advisories27 Aug
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-7…
Read at source →
CISA Cybersecurity Advisories27 Aug
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi Electri…
Read at source →
CISA Cybersecurity Advisories27 Aug
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product.…
Read at source →
Primary Threat Research & Vendor Intelligence
Cisco Talos27 Aug
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
Read at source →
Microsoft Security Blog27 Aug
This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post What’s…
Read at source →
Cisco Talos27 Aug
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer27 Aug
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]
Read at source →
Dark Reading27 Aug
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Read at source →
The Hacker News27 Aug
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the…
Read at source →
Dark Reading27 Aug
This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.
Read at source →
BleepingComputer27 Aug
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]
Read at source →
BleepingComputer27 Aug
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]
Read at source →
The Hacker News27 Aug
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files…
Read at source →
The Hacker News27 Aug
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in publi…
Read at source →
BleepingComputer27 Aug
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can…
Read at source →
The Hacker News27 Aug
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and…
Read at source →
Dark Reading27 Aug
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.
Read at source →
Krebs on Security27 Aug
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement releas…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)27 Aug
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
Read at source →
SANS Internet Storm Center (Handler Diary)27 Aug
Read at source →
Security Executive, Architecture & Policy
Schneier on Security27 Aug
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators use…
Read at source →