Updated Hourly

Tech Intelligence

Cybersecurity news, vulnerability advisories, and technology insights — curated from the world's leading security sources.

The Hacker NewsBleepingComputerKrebs on SecuritySANS ISCDark Reading
BCAug 24, 2026

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. […

Read on BleepingComputer
BCAug 24, 2026

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]…

Read on BleepingComputer
BCAug 24, 2026

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]…

Read on BleepingComputer
DRAug 24, 2026

Tricky 'SynkLoader' Multitool May Herald Ransomware

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.…

Read on Dark Reading
DRAug 24, 2026

ToxicPanda Banking Trojan Matures Into Enterprise Threat

The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.…

Read on Dark Reading
THNAug 24, 2026

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes e…

Read on The Hacker News
BCAug 24, 2026

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]…

Read on BleepingComputer
BCAug 24, 2026

South Korean startup platform breach exposes key management failures

A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept s…

Read on BleepingComputer
DRAug 24, 2026

The Vulnerability Gap: Why Discovery Is Outrunning Repair

AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.…

Read on Dark Reading
BCAug 24, 2026

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]…

Read on BleepingComputer
THNAug 24, 2026

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen …

Read on The Hacker News
THNAug 24, 2026

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce ope…

Read on The Hacker News
THNAug 24, 2026

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any use…

Read on The Hacker News
THNAug 24, 2026

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, …

Read on The Hacker News
THNAug 24, 2026

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of…

Read on The Hacker News
BCAug 24, 2026

CISA orders urgent patching of actively exploited Zimbra flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]…

Read on BleepingComputer
BCAug 24, 2026

Microsoft shares temporary fix for Windows 11 gaming issues

Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]…

Read on BleepingComputer
THNAug 24, 2026

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors…

Read on The Hacker News
SANSAug 24, 2026

DOUBLECUP's PNG Payload, (Mon, Aug 24th)

New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;t use real steganography:
…

Read on SANS ISC
SANSAug 24, 2026

ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)

Read on SANS ISC
BCAug 23, 2026

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]…

Read on BleepingComputer
THNAug 22, 2026

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the sett…

Read on The Hacker News
BCAug 22, 2026

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]…

Read on BleepingComputer
BCAug 22, 2026

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict …

Read on BleepingComputer
DRAug 21, 2026

How an Emerging Industrial Protocol Family Could Put OT at Risk

New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes.…

Read on Dark Reading
THNAug 21, 2026

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux i…

Read on The Hacker News
BCAug 21, 2026

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]…

Read on BleepingComputer
DRAug 21, 2026

OWASP Flags Top AI Skill Risks in New Security Blueprint

The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.…

Read on Dark Reading
THNAug 21, 2026

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging…

Read on The Hacker News
THNAug 21, 2026

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said th…

Read on The Hacker News
DRAug 21, 2026

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.…

Read on Dark Reading
DRAug 21, 2026

OpenAI Adds Controls That Should've Been There Already

The new AI security controls follow the Hugging Face incident last month, though experts say many of these additions should have been in place prior to the frontier models escaping.…

Read on Dark Reading
DRAug 21, 2026

Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near

The coming threat of super-powerful computers capable of cracking today's algorithms requires upgrading encryption now. Tech companies have begun building defenses.…

Read on Dark Reading
THNAug 21, 2026

Wazuh and AI For Enhanced SOC Workflows

Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover …

Read on The Hacker News
SANSAug 21, 2026

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s left would be handy. Something quicker than scrolling t…

Read on SANS ISC
SANSAug 21, 2026

ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)

Read on SANS ISC
SANSAug 21, 2026

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
…

Read on SANS ISC
SANSAug 20, 2026

Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)

Building on the last diary on Using MS Graph and Powershell, let&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s look at "Risky" logins.
…

Read on SANS ISC
SANSAug 20, 2026

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

Microsoft Graph is a newer API that is meant to replace several others.&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xc2&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xa0&#x3b; OK, it&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s at version 2.3.9, …

Read on SANS ISC
SANSAug 20, 2026

ISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th)

Read on SANS ISC
KrebsAug 14, 2026

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily pa…

Read on Krebs on Security
KrebsAug 11, 2026

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others tha…

Read on Krebs on Security
KrebsAug 6, 2026

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the…

Read on Krebs on Security
KrebsJul 30, 2026

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connectio…

Read on Krebs on Security
KrebsJul 22, 2026

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after …

Read on Krebs on Security
KrebsJul 14, 2026

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-…

Read on Krebs on Security
KrebsJul 13, 2026

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub …

Read on Krebs on Security
KrebsJul 8, 2026

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures inc…

Read on Krebs on Security
KrebsJul 2, 2026

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli com…

Read on Krebs on Security
KrebsJun 23, 2026

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Great…

Read on Krebs on Security