2026-08-19
Review the tracked stories and available summary evidence for the archived period shown.
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- ai security
Researchers say OpenAI revoked their access to limited cyber program
OpenAI revoked access to its Trusted Access for Cyber program for multiple cybersecurity researchers without advance notice. The program provides vetted users with models that have fewer safety restrictions. Researchers reported losing connection to tools they relied on for security work.
Why it matters: Security practitioners using TAC for offensive security research or red teaming have lost tooling and need to understand OpenAI's new access criteria and appeal process.
- cloud saas
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Frost & Sullivan named Microsoft a visionary leader in cloud workload protection platforms for 2026, citing its broad coverage across infrastructure, workloads, identities, and runtime security integrated into a single framework. The analyst report describes a market shift from static scanning and posture management toward unified runtime security that connects code, cloud resources, identities, and detection into one platform. The CWPP market is projected to grow from $6.43 billion in 2025 to $7.95 billion in 2026, with organizations increasingly prioritizing runtime telemetry depth and cloud-native threat detection over vulnerability lists alone.
Why it matters: Security teams evaluating workload protection platforms should assess whether solutions unify posture, runtime, and identity signals in a single system and can block risky workloads before production, rather than relying on post-deployment scanning and fragmented tools.
Grouped: similar headlines and the same names (CLOUD WORKLOAD PROTECTION PLATFORMS, FROST RADAR).
- breaches incidents
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
T-Mobile identified and removed Chinese-backed hackers from its network before a large-scale breach occurred. The carrier took action to expel the threat actors after detecting their presence early in the intrusion.
Why it matters: T-Mobile customers and the telecom industry need to understand that nation-state actors continue targeting major carriers; early detection and rapid response prevented data exfiltration, but enterprises should review their own network segmentation and threat-hunting capabilities.
- vulnerabilitiesCVE-2026-19490
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Citrix released a security advisory on August 19, 2026, for CVE-2026-19490, a critical authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway with a CVSS score of 9.3. The flaw allows remote unauthenticated attackers to exploit these perimeter-deployed products without user interaction or elevated privileges. Fixed versions are available, and organizations should patch affected systems immediately.
Why it matters: Enterprise security teams managing Citrix NetScaler products exposed to the internet face immediate risk of unauthorized access, as these high-value targets typically see rapid exploitation once public details emerge.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-19490).
- government policy
A California county wants to hire Tina Peters to help run its elections
Shasta County, California registrar Clint Curtis plans to hire Tina Peters, a convicted felon and former Colorado election official, as an assistant registrar. Peters served time for stealing voting system software and disabling election office security, then had her sentence commuted earlier this year. The hire has prompted federal lawmakers to request state oversight to prevent Peters' access to election systems and sensitive voter data.
Why it matters: Election officials and state regulators must monitor this appointment closely: Peters has a demonstrated history of breaching election systems and distributing stolen code, and her access to Shasta County's voting infrastructure and voter records poses a direct security and legal risk to over 100,000 registered voters.
- threat intel
US charges Iranian hackers over $3.4 billion intellectual property theft
The US Department of Justice charged 17 Iranian nationals affiliated with Mabna Institute, a hacking-for-hire operation, for conducting multi-year cyber espionage campaigns targeting American organizations. The charges relate to theft of intellectual property valued at approximately $3.4 billion across numerous sectors and industries.
Why it matters: Organizations in all sectors should assume they are or were targets of this prolific theft operation, which was active for years; security teams need to assess exposure, audit for unauthorized access, and monitor for stolen data surfacing on the dark web or in competitor intelligence.
Grouped: similar headlines.
- cloud saas
Wiz Penetration Test Findings is now GA
Wiz announced general availability of its Penetration Test Findings feature, which integrates pen-test results with real-time cloud context on a unified platform. The tool shifts penetration testing from discrete assessments to continuous exposure management.
Why it matters: Security teams using Wiz can now correlate manual pen-test findings with live cloud telemetry to prioritize exposure remediation faster than traditional point-in-time assessments.
- ransomwareCVE-2026-12569
The long tail of Clop’s PTC hack is just beginning to emerge
Clop, a prolific data theft extortion group, exploited a critical zero-day vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software products to compromise dozens of organizations across manufacturing, aerospace, and retail sectors. The group deployed custom web shells designed specifically for Windchill that automate credential theft, malware delivery, and data exfiltration while evading detection. PTC patched the vulnerability on June 18, but exploitation occurred in early June, and the full scope of compromise remains unclear as companies continue investigating and Clop sends extortion demands.
Why it matters: Manufacturers, retailers, and enterprises using PTC Windchill or FlexPLM need to verify patching status, hunt for indicators of compromise, and review access logs from June 2026 onward, as this campaign mirrors Clop's pattern of prolonged, widespread exploitation that can take weeks or months to fully discover.
- vulnerabilities
Simple Scans for Cloud Metadata Service
Cloud providers expose a metadata service at 169.254.169.254 that allows virtual machines to retrieve machine-specific data, including IAM credentials and service account tokens. Widespread generic scans are attempting to exploit server-side request forgery (SSRF) vulnerabilities to access this service, following notable breaches like Capital One that leveraged metadata service exploitation. Amazon implemented IMDSv2 to mitigate this attack vector by requiring additional headers beyond simple GET requests.
Why it matters: Practitioners managing cloud infrastructure should verify that IMDSv2 is enforced and that SSRF protections are in place on all endpoints, as attackers are actively scanning for metadata service access across the internet.
- breaches incidents
Prison for data analyst who tried to extort $2.5 million from his employer
A former data analyst at Brightly Software faced prison time after attempting to extort $2.5 million from his employer following non-renewal of his contract. Curry had access to sensitive company data through his role, which he apparently leveraged in the extortion scheme.
Why it matters: Practitioners should ensure robust offboarding procedures, access revocation, and monitoring of departing employees with data access; insider threats from disgruntled staff remain a material risk.
- threat intel
Password spraying attacks surge 155x as hackers exploit MFA gaps
Huntress documented a 155-fold surge in password spraying attacks during the first half of 2026, with one campaign executing over 81 million login attempts in two weeks. The attacks targeted legacy authentication systems and gaps in multifactor authentication (MFA) policies that left certain login flows undefended.
Why it matters: Organizations using legacy authentication or incomplete MFA coverage face immediate exposure to account compromise; practitioners should audit MFA enforcement across all login paths and disable older authentication protocols.
- industry
Intezer adds native response automation without separate SOAR
Intezer announced Workflows, a built-in automation and response tool that lets security teams create custom response actions within the Intezer platform itself. The feature consolidates alert triage, investigation, and automated response in a single system, reducing the need for a separate Security Orchestration, Automation, and Response (SOAR) platform.
Why it matters: Security operations and incident response teams can reduce tooling complexity and speed up post-investigation actions by automating response workflows without deploying additional SOAR infrastructure.
- breaches incidents
Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia's road traffic agency suffered a cyberattack that exposed data on approximately 1.2 million people, representing roughly two-thirds of the country's population. The breach has triggered resignation calls for senior government officials overseeing the agency.
Why it matters: Government IT leaders and policy makers must assess their own exposure reporting and incident response practices, as large-scale government breaches create political and operational pressure to improve security controls and accountability.
- industry
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
CodeSecCon is a virtual event featuring developers and cybersecurity professionals discussing secure application development and maintenance. The event aims to bring together practitioner communities focused on application security.
Why it matters: Development and security teams should attend to learn peer practices on securing code and applications in their operational environment.
- government policy
DOJ secures indictment of 17 Iranians accused of ‘massive’ cyber theft campaign
The Department of Justice unsealed an indictment against 17 Iranian nationals on Tuesday for conducting a cyber theft campaign targeting American and foreign institutions. The defendants, allegedly affiliated with the Mabna Institute, are accused of operating on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) across 14 counts.
Why it matters: Organizations in the US and internationally should assess whether they were targeted or compromised by this Iranian cyber operation and review logs dating back through the campaign's suspected operational period, as attribution and prosecution may reveal previously unknown victim organizations and compromise dates.
- threat intel
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A cyber espionage campaign called SilkParasite has targeted Central Asian government entities using seven remote access tool (RAT) families, five of which are newly documented. The operation, discovered in late 2025, deploys DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT alongside two previously known RATs.
Why it matters: Central Asian government practitioners should assess exposure to these RATs and coordinate with threat intelligence teams to identify any intrusions; the five new malware families lack public detection signatures and require urgent analysis for defensive coverage.
Grouped: similar headlines.
- threat intel
US charges Iranians for sprawling hacking campaign on government agencies, universities
The U.S. Justice Department charged 17 individuals linked to Iran with hacking email accounts at federal agencies. The alleged campaign also involved theft of intellectual property from numerous universities. The indictment highlights ongoing state-sponsored cyber threats targeting government and academic networks.
Why it matters: U.S. federal agencies and university networks face compromised email and IP loss; practitioners should validate email defenses and monitor for data exfiltration.
- industry
Prevalent AI Raises $22 Million to Expand Data Fabric Platform
Prevalent artificial intelligence (AI), a bootstrapped company, secured $22 million in funding to expand its data fabric platform for secure and reliable operation of artificial intelligence (AI) agents at scale. The funding round marks a milestone for the vendor's growth beyond its initial bootstrap phase.
Why it matters: Security teams evaluating AI agent infrastructure should monitor Prevalent AI's expanded platform capabilities as part of their evaluation of data fabric solutions for managing AI workloads securely.
- ot ics
Defending Against an Active Threat to Siemens S7 Series PLCs
Federal agencies (NSA, CISA, FBI, DOE, EPA) are warning of an active cyber threat targeting Internet-exposed Siemens S7 Series programmable logic controllers (PLCs) using artificial intelligence (AI)-generated exploitation scripts. Threat actors leverage Internet scanning services to identify poorly protected PLCs and use AI-assisted tools that mimic legitimate monitoring software to gain read/write access via the S7comm protocol. The advisory urges owners and operators of critical manufacturing, energy, water, chemical, food, and commercial facilities to immediately inventory systems, apply security patches, isolate PLCs from the Internet, strengthen access controls, and deploy intrusion detection to monitor for anomalous activity.
Why it matters: PLC operators and critical infrastructure owners in manufacturing, energy, water, chemical, and food sectors must act immediately to audit and secure Siemens S7 systems, as threat actors are actively conducting reconnaissance and testing exploitation capabilities that could disrupt industrial processes, cause safety incidents, damage equipment, or compromise operational data.
Grouped: the same names (ENVIRONMENTAL PROTECTION AGENCY, INFRASTRUCTURE SECURITY AGENCY, INTERNET-EXPOSED PLCS).
- vulnerabilities
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Rapid7 and Licencias OnLine announced a strategic distribution partnership to expand cybersecurity offerings across Latin America. The collaboration will provide technical training, joint marketing, and go to market programs to help partners grow managed security services and improve customer resilience.
Why it matters: Security practitioners in Latin America gain localized enablement and integrated tools to reduce blind spots and improve cyber resilience.
- threat intel
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Researchers at Hunt.io documented a campaign called Operation CameraSwarm that compromised over 14,530 Dahua devices between June 17 and July 22, 2026. The attackers exploited credential attacks, two authentication-bypass vulnerabilities, and a peer-to-peer relay method, with evidence reconstructed from an exposed 407 MB working directory containing 2,616 files.
Why it matters: Organizations using Dahua devices must investigate for compromise indicators within the attack window and patch authentication-bypass flaws immediately; credential attacks suggest weak or reused passwords require review and rotation.
Grouped: similar headlines.
- threat intel
Phishing 3.0: The Fight Moves to Agent Versus Agent
Email defenses that once scanned for malicious payloads are losing effectiveness as attackers shift to intent‑based phishing. The article describes how phishing has evolved from bad content to bad intent and now involves artificial intelligence (AI) on both attacker and defender sides. It notes that traditional filters struggle to detect these newer tactics.
Why it matters: Security teams depending on legacy email gateways must evaluate artificial intelligence (AI)-driven detection tools to counter intent‑based phishing targeting employees.
- threat intel
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Researchers identified a cybercrime operation called StopAndProtect that exploits approximately 2,000 compromised WordPress websites to distribute malware and exfiltrate data. The operation uses infected hosts to store stolen documents, screenshots, and logs while deploying a toolkit of multiple malware variants rather than relying on a single tool.
Why it matters: WordPress site owners and administrators need to audit their installations for compromise, as thousands of legitimate websites are being weaponized as malware distribution and data theft infrastructure that directly impacts their users and reputation.
Grouped: similar headlines.
- vulnerabilities
Microsoft fixes known issue causing Windows Defender crashes
Microsoft patched a bug in Windows Defender that triggered access violation errors and system crashes following a recent security update. The fix resolves the 0xc0000005 error affecting some users after the problematic security update was deployed.
Why it matters: Windows administrators and Defender users need to apply the fix to prevent crashes and restore endpoint protection on affected systems.
- ransomware
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware group has publicly named over 40 victims from a campaign exploiting PTC Windchill vulnerabilities, including major corporations in energy, healthcare, manufacturing, and financial services sectors. The victims disclosed include Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision, among others. This represents a significant escalation in the group's extortion campaign tied to the PTC Windchill exploitation activity.
Why it matters: Organizations running PTC Windchill should immediately assess their exposure and patching status, as the named victims confirm Cl0p is actively leveraging these vulnerabilities for extortion; this affects manufacturing, healthcare, energy, and financial services companies that depend on Windchill for product development and supply chain management.
- vulnerabilitiesCVE-2026-65400
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on August 19, 2026, including CVE-2026-65400, an improper authentication flaw in Apple macOS with a CVSS score of 7.1. All four vulnerabilities are confirmed to be exploited in the wild.
Why it matters: Organizations running macOS, SharePoint, vCenter, and systems using Microsoft IKE must prioritize patching these vulnerabilities immediately, as exploitation is already active.
- government policy
ICE Collecting DNA Samples
U.S. Immigration and Customs Enforcement (ICE) collected approximately one million DNA samples during the previous year. The scale of collection reflects the agency's expanded use of genetic data in immigration enforcement processes.
Why it matters: Practitioners managing identity systems, biometric databases, and privacy controls should monitor government expansion of DNA collection and retention policies, as these practices may influence organizational data handling requirements and compliance obligations.
- vulnerabilities
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
CISA has issued an urgent advisory for immediate patching of actively exploited vulnerabilities affecting Microsoft, VMware, and Apple products. These flaws enable remote code execution, authentication bypass, and device takeover across multiple platforms.
Why it matters: Organizations running Microsoft, VMware, or Apple systems face active exploitation of these vulnerabilities; patching should be prioritized immediately to prevent compromise.
- vulnerabilities
Critical RCE flaw in Windows IKE Extension now actively exploited
The Cybersecurity and Infrastructure Security Agency (CISA) noted that threat actors are actively exploiting a critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component. The agency urged administrators to apply the latest security updates and review IKE configurations to mitigate the risk.
Why it matters: Windows administrators responsible for systems with the IKE Service Extensions should prioritize patching and reviewing configurations to avoid potential remote compromise.
- threat intel
Describing attacks with crime script analysis
Crime script analysis is a narrative-driven methodology that describes cyberattacks in accessible language for non-technical audiences, complementing technical frameworks like MITRE ATT&CK and Attack Flow diagrams. Applied to business email compromise (BEC), the approach decomposes attacks into discrete steps, revealing how artificial intelligence can automate reconnaissance and social engineering to scale attacks against previously unprofitable targets. Defenders can identify critical intervention points where defenses can disrupt the attack flow, from honeypot decoys and email provider blocks to victim awareness and payment verification processes.
Why it matters: Security leaders and defenders responsible for BEC prevention need this model to communicate threats to executives and non-technical stakeholders, and to recognize how AI-driven attackers are expanding targeting from high-value firms to commodity targets like small organizations.
- breaches incidents
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
ClarityCheck, a people-search tool, failed to secure a database containing over 9 million image files associated with its reverse image search service. The exposure contradicts the company's claims about the privacy and security of the service.
Why it matters: Organizations and individuals using ClarityCheck's reverse image search face privacy risks from exposed facial photos; practitioners should assess whether their organization uses this tool and review data handling practices.
- industry
Brinqa acquires PlexTrac to bring validated remediation to exposure management
Brinqa has acquired PlexTrac to add remediation validation capabilities to its exposure management platform. The combined offering aims to help security teams identify, prioritize, and remediate exposures while verifying that fixes remain effective.
Why it matters: Security leaders managing exposure and vulnerability programs should evaluate whether integrated validation and remediation tracking improves their ability to close gaps and sustain remediation over time.
- regulatory
Windows 11 24H2 Home and Pro reach end of support in 2 months
Microsoft announced that Windows 11 24H2 Home and Pro editions will reach end of support in approximately two months, after which systems will no longer receive updates. Organizations and users running these editions need to plan upgrades or migrations before the deadline to avoid running unsupported operating systems.
Why it matters: IT teams and Windows users on Home and Pro editions must upgrade within two months or face exposure to unpatched vulnerabilities and loss of security support.
- ai security
Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google's Mandiant disclosed an internal tool called the Agentic Vulnerability Discovery Harness (AVDH) that uses chains of artificial intelligence (AI) agents to identify vulnerabilities in source code. During a two-day investigation into stolen corporate repositories, the tool discovered over 100 verified high-severity flaws. AVDH has operated within Mandiant for ten months and scanned tens of millions of lines of code.
Why it matters: Security teams and code repository owners should understand that AI-powered vulnerability scanning can rapidly surface critical flaws at scale, informing decisions about code review processes and threat hunting prioritization.
- government policy
Flock Has a Powerful New AI Tool for Police. We Got Its Code
Flock's law enforcement surveillance system incorporates advanced artificial intelligence capabilities that extend significantly beyond license plate recognition. WIRED obtained and analyzed the underlying code to demonstrate the scope of the AI tool's capabilities currently deployed with police agencies.
Why it matters: Law enforcement practitioners and civil liberties stakeholders should understand the full scope of surveillance technologies in use; security and policy teams need clarity on data handling, retention, and algorithmic bias in these systems.
- ai security
OpenAI puts major frontier AI training run on hold over cyber risks
OpenAI paused a major reinforcement learning (RL) training run for two weeks to strengthen its research environment security, conduct red-team testing, and expand monitoring. The company is performing smaller-scale training and evaluations to validate safeguards and assess model behavior before resuming the larger frontier artificial intelligence (AI) training deployment.
Why it matters: Security teams managing AI systems should track OpenAI's operational security practices, as the pause signals heightened concern about training infrastructure vulnerabilities that could affect production AI deployments and inform defense strategies.
Grouped: similar headlines.
- vulnerabilities
Chrome, Firefox Updates Patch Dozens of Vulnerabilities
Chrome and Firefox have released updates addressing dozens of vulnerabilities, including flaws that could enable code execution, privilege escalation, sandbox escape, and information disclosure. The vendors have patched the issues to mitigate the associated risks.
Why it matters: All Chrome and Firefox users face potential code execution and sandbox bypass risks; practitioners should prioritize testing and deployment of these updates in their environments.
- ai security
F5 enhances AI Gateway to control AI costs, access, and security
F5 announced enhancements to its artificial intelligence (AI) Gateway and integration into the F5 AI Security Platform. The updated solution provides a unified control plane for enterprises to enforce policies on AI requests, manage access to AI models and agents, and optimize AI spending at scale.
Why it matters: Enterprise security teams responsible for governing AI tool usage and costs need visibility and control over how AI models are accessed and used across their organization.
- breaches incidents
CareCloud Data Breach Impact Grows to 3.7 Million Individuals
CareCloud, a healthcare IT provider, experienced a data breach initially estimated to affect 350,000 people, but the U.S. Department of Health and Human Services (HHS) breach tracker now reflects a substantially larger impact of 3.7 million individuals. The scope of the incident has grown significantly as more affected records were identified during investigation and notification processes.
Why it matters: Healthcare organizations and their patients should assess whether their records were included in this breach and ensure breach notification procedures are followed, while healthcare IT buyers should evaluate CareCloud's security posture and incident response capabilities.
Grouped: similar headlines.
- threat intel
Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
Slovakia's national security service (NBU) identified a backdoor in NERO R-ONE traffic speed cameras that executes malicious code triggered by SMS messages from hardcoded Russian phone numbers. The agency launched an investigation after reports revealed the devices were procured through a no-bid contract from a Cyprus shell company using fraudulent certifications.
Why it matters: Government agencies and municipalities operating these cameras face potential compromise of critical infrastructure and surveillance systems; practitioners should audit deployed NERO R-ONE units and evaluate procurement controls for similar supply chain vulnerabilities.
- threat intel
Banks look for fraud signals in customer behavior
Banks face rising fraud in which criminals use social engineering to manipulate customers into authorizing payments. A ThreatMark survey found that 55 percent of institutions report social engineering in most of their fraud cases, with criminals impersonating bank employees or other trusted contacts. Detection strategies now focus on customer behavior signals as the fraud risk shifts to the customer interaction layer.
Why it matters: Bank fraud teams and risk officers need to invest in behavioral analytics and customer education to detect manipulation tactics before authorized transfers complete, as social engineering is now the primary attack vector for account takeover and financial loss.
- ai security
ChatGPT’s new feature could give infostealers a map of your Mac activity
OpenAI released a Computer History feature that logs recent Mac activity for use by ChatGPT and Codex. The feature aggregates actions into summaries and records which applications and websites contributed to each entry. Security researchers warn that the stored timeline could be harvested by infostealers to reconstruct user behavior.
Why it matters: Mac users who have enabled ChatGPT’s Computer History feature are exposed to infostealers that could extract the activity timeline to map behavior, so practitioners should review the feature’s settings and monitor for unauthorized access.
- threat intel
China-Linked Hacker Shows AI Capabilities in APAC Attack
A Chinese-language operator employed an artificial intelligence (AI) framework to conduct what researchers describe as a near-autonomous attack targeting government agencies, with the operations likely directed at Taiwan. The incident represents an escalation in the sophistication of nation-state-linked cyber operations by integrating autonomous decision-making capabilities.
Why it matters: Government and defense organizations in Asia-Pacific face exposure to AI-augmented targeting and compromise techniques; security teams should review detection and response protocols for adversary-controlled autonomous systems.
- vulnerabilities
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle released its August 2026 Critical Security Patch Update on August 18, addressing 925 CVEs across 943 patches in 23 product families, with 154 patches rated critical severity. This represents a significant increase from the June 2026 CSPU and comprises approximately 65 percent of the quarterly July CPU volume, blurring the distinction between monthly targeted and quarterly comprehensive releases. Oracle Fusion Middleware and Hyperion accounted for over half of all patches, with 182 and 107 issues respectively exploitable remotely without authentication.
Why it matters: Organizations running Oracle Fusion Middleware, Hyperion, E-Business Suite, or other affected products must prioritize patching 154 critical vulnerabilities, particularly the 289 remote network exploits without authentication in Middleware and Hyperion, to prevent immediate compromise.
Grouped: similar headlines.
- threat intel
Fake AI, real malware: Attackers impersonating AI brands
Sophos X-Ops research tracking managed detection and response (MDR) cases over the past year found attackers impersonating popular artificial intelligence (AI) brands to distribute malware and infostealers. Threat actors capitalize on rising demand for AI tools by using malvertising and fake applications to compromise users. The campaign demonstrates a sustained effort to abuse consumer interest in AI technologies for initial access and credential theft.
Why it matters: Security teams and employees need to verify AI tool sources and watch for impersonation campaigns, as users seeking legitimate AI applications remain vulnerable to fake downloads that deliver malware and steal credentials.
- industry
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future added native risk ratings capabilities to its Third-Party Risk product, integrating threat intelligence and risk assessment into a unified workflow.
Why it matters: Organizations managing vendor and supplier security exposure can now assess third-party risk more efficiently within a single platform rather than using separate tools.